################################################################ # abuse.ch SSLBL Snort / Suricata Botnet C2 IP Ruleset # # Aggressive # # Last updated: 2024-09-06 14:47:02 UTC # # # # Terms Of Use: https://sslbl.abuse.ch/blacklist/ # # For questions please contact sslbl [at] abuse.ch # ################################################################ # alert tcp $HOME_NET any -> [104.21.57.118] 443 (msg:"SSLBL: Traffic to malicious host (likely Latrodectus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200000; rev:1;) alert tcp $HOME_NET any -> [104.21.59.197] 443 (msg:"SSLBL: Traffic to malicious host (likely Latrodectus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200001; rev:1;) alert tcp $HOME_NET any -> [95.179.246.167] 1024 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200002; rev:1;) alert tcp $HOME_NET any -> [164.92.232.138] 9928 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200003; rev:1;) alert tcp $HOME_NET any -> [193.233.74.21] 7777 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200004; rev:1;) alert tcp $HOME_NET any -> [195.85.250.221] 4827 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200005; rev:1;) alert tcp $HOME_NET any -> [217.197.107.154] 443 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200006; rev:1;) alert tcp $HOME_NET any -> [101.34.82.220] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200007; rev:1;) alert tcp $HOME_NET any -> [217.197.107.204] 443 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200008; rev:1;) alert tcp $HOME_NET any -> [51.75.171.9] 5151 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200009; rev:1;) alert tcp $HOME_NET any -> [216.74.123.97] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200010; rev:1;) alert tcp $HOME_NET any -> [12.202.180.114] 8797 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200011; rev:1;) alert tcp $HOME_NET any -> [12.187.175.72] 6757 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200012; rev:1;) alert tcp $HOME_NET any -> [95.217.44.124] 7584 (msg:"SSLBL: Traffic to malicious host (likely DarkGate C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200013; rev:1;) alert tcp $HOME_NET any -> [94.130.188.148] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200014; rev:1;) alert tcp $HOME_NET any -> [154.216.19.149] 2047 (msg:"SSLBL: Traffic to malicious host (likely XWorm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200015; rev:1;) alert tcp $HOME_NET any -> [148.113.165.11] 3090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200016; rev:1;) alert tcp $HOME_NET any -> [213.159.74.80] 9792 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200017; rev:1;) alert tcp $HOME_NET any -> [5.42.99.131] 443 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200018; rev:1;) alert tcp $HOME_NET any -> [45.138.16.215] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200019; rev:1;) alert tcp $HOME_NET any -> [91.92.240.138] 1337 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200020; rev:1;) alert tcp $HOME_NET any -> [178.211.130.175] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200021; rev:1;) alert tcp $HOME_NET any -> [154.216.18.122] 2013 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200022; rev:1;) alert tcp $HOME_NET any -> [80.209.243.182] 8094 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200023; rev:1;) alert tcp $HOME_NET any -> [89.197.154.116] 7810 (msg:"SSLBL: Traffic to malicious host (likely Metasploit C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200024; rev:1;) alert tcp $HOME_NET any -> [116.203.10.69] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200025; rev:1;) alert tcp $HOME_NET any -> [176.111.174.140] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200026; rev:1;) alert tcp $HOME_NET any -> [110.42.66.74] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200027; rev:1;) alert tcp $HOME_NET any -> [80.240.28.67] 3827 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200028; rev:1;) alert tcp $HOME_NET any -> [83.168.110.21] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200029; rev:1;) alert tcp $HOME_NET any -> [213.159.74.80] 14143 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200030; rev:1;) alert tcp $HOME_NET any -> [209.126.4.168] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200031; rev:1;) alert tcp $HOME_NET any -> [195.201.118.191] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200032; rev:1;) alert tcp $HOME_NET any -> [91.110.119.191] 1500 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200033; rev:1;) alert tcp $HOME_NET any -> [45.83.140.79] 15153 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200034; rev:1;) alert tcp $HOME_NET any -> [120.79.211.9] 8919 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200035; rev:1;) alert tcp $HOME_NET any -> [91.92.249.33] 10443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200036; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 34180 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200037; rev:1;) alert tcp $HOME_NET any -> [89.110.82.139] 56001 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200038; rev:1;) alert tcp $HOME_NET any -> [194.26.192.177] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200039; rev:1;) alert tcp $HOME_NET any -> [43.154.203.129] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200040; rev:1;) alert tcp $HOME_NET any -> [154.216.20.190] 56001 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200041; rev:1;) alert tcp $HOME_NET any -> [78.46.239.218] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200042; rev:1;) alert tcp $HOME_NET any -> [147.45.44.138] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200043; rev:1;) alert tcp $HOME_NET any -> [116.203.5.69] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200044; rev:1;) alert tcp $HOME_NET any -> [103.174.191.71] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200045; rev:1;) alert tcp $HOME_NET any -> [103.174.191.71] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200046; rev:1;) alert tcp $HOME_NET any -> [91.92.243.78] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureCrypter C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200047; rev:1;) alert tcp $HOME_NET any -> [45.66.231.202] 7777 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200048; rev:1;) alert tcp $HOME_NET any -> [154.216.20.242] 5000 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200049; rev:1;) alert tcp $HOME_NET any -> [103.252.123.135] 2424 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200050; rev:1;) alert tcp $HOME_NET any -> [87.89.82.13] 1337 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200051; rev:1;) alert tcp $HOME_NET any -> [188.245.87.202] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200052; rev:1;) alert tcp $HOME_NET any -> [1.12.181.191] 5487 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200053; rev:1;) alert tcp $HOME_NET any -> [20.199.84.103] 1024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200054; rev:1;) alert tcp $HOME_NET any -> [176.111.174.140] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200055; rev:1;) alert tcp $HOME_NET any -> [91.217.76.162] 56004 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200056; rev:1;) alert tcp $HOME_NET any -> [176.124.198.186] 443 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200057; rev:1;) alert tcp $HOME_NET any -> [147.185.221.19] 59786 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200058; rev:1;) alert tcp $HOME_NET any -> [45.90.13.137] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200059; rev:1;) alert tcp $HOME_NET any -> [5.252.74.251] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200060; rev:1;) alert tcp $HOME_NET any -> [194.26.192.202] 1010 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200061; rev:1;) alert tcp $HOME_NET any -> [8.218.154.78] 8443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200062; rev:1;) alert tcp $HOME_NET any -> [45.89.247.46] 3030 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200063; rev:1;) alert tcp $HOME_NET any -> [182.188.47.2] 7776 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200064; rev:1;) alert tcp $HOME_NET any -> [20.82.141.111] 6576 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200065; rev:1;) alert tcp $HOME_NET any -> [110.42.66.74] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200066; rev:1;) alert tcp $HOME_NET any -> [193.23.160.13] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200067; rev:1;) alert tcp $HOME_NET any -> [168.119.176.241] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200068; rev:1;) alert tcp $HOME_NET any -> [176.111.174.140] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200069; rev:1;) alert tcp $HOME_NET any -> [193.42.11.9] 4329 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200070; rev:1;) alert tcp $HOME_NET any -> [156.255.2.100] 18896 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200071; rev:1;) alert tcp $HOME_NET any -> [193.29.13.46] 5850 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200072; rev:1;) alert tcp $HOME_NET any -> [5.75.212.60] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200073; rev:1;) alert tcp $HOME_NET any -> [4.233.220.67] 6670 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200074; rev:1;) alert tcp $HOME_NET any -> [109.120.176.41] 4394 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200075; rev:1;) alert tcp $HOME_NET any -> [91.92.247.147] 8080 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200076; rev:1;) alert tcp $HOME_NET any -> [45.148.244.13] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200077; rev:1;) alert tcp $HOME_NET any -> [45.83.246.140] 3232 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200078; rev:1;) alert tcp $HOME_NET any -> [82.65.19.134] 4443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200079; rev:1;) alert tcp $HOME_NET any -> [144.126.149.221] 9999 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200080; rev:1;) alert tcp $HOME_NET any -> [27.124.45.70] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200081; rev:1;) alert tcp $HOME_NET any -> [45.77.45.120] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200082; rev:1;) alert tcp $HOME_NET any -> [185.165.171.49] 443 (msg:"SSLBL: Traffic to malicious host (likely Havoc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200083; rev:1;) alert tcp $HOME_NET any -> [45.139.198.242] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200084; rev:1;) alert tcp $HOME_NET any -> [65.109.241.221] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200085; rev:1;) alert tcp $HOME_NET any -> [15.235.151.228] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200086; rev:1;) alert tcp $HOME_NET any -> [158.247.208.174] 443 (msg:"SSLBL: Traffic to malicious host (likely Sliver C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200087; rev:1;) alert tcp $HOME_NET any -> [95.217.27.167] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200088; rev:1;) alert tcp $HOME_NET any -> [93.115.10.211] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200089; rev:1;) alert tcp $HOME_NET any -> [163.5.64.209] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200090; rev:1;) alert tcp $HOME_NET any -> [188.114.96.3] 443 (msg:"SSLBL: Traffic to malicious host (likely Latrodectus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200091; rev:1;) alert tcp $HOME_NET any -> [195.201.89.97] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200092; rev:1;) alert tcp $HOME_NET any -> [171.50.172.165] 6996 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200093; rev:1;) alert tcp $HOME_NET any -> [94.232.249.204] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200094; rev:1;) alert tcp $HOME_NET any -> [81.19.137.226] 2024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200095; rev:1;) alert tcp $HOME_NET any -> [104.234.195.153] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200096; rev:1;) alert tcp $HOME_NET any -> [37.27.31.150] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200097; rev:1;) alert tcp $HOME_NET any -> [5.75.221.27] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200098; rev:1;) alert tcp $HOME_NET any -> [116.202.180.70] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200099; rev:1;) alert tcp $HOME_NET any -> [195.10.205.82] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200100; rev:1;) alert tcp $HOME_NET any -> [49.13.159.121] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200101; rev:1;) alert tcp $HOME_NET any -> [94.156.79.137] 5650 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200102; rev:1;) alert tcp $HOME_NET any -> [157.20.182.5] 741 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200103; rev:1;) alert tcp $HOME_NET any -> [147.185.221.18] 63974 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200104; rev:1;) alert tcp $HOME_NET any -> [114.116.244.244] 4495 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200105; rev:1;) alert tcp $HOME_NET any -> [45.40.96.164] 3232 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200106; rev:1;) alert tcp $HOME_NET any -> [94.232.249.111] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200107; rev:1;) alert tcp $HOME_NET any -> [195.201.251.214] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200108; rev:1;) alert tcp $HOME_NET any -> [194.55.186.155] 2424 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200109; rev:1;) alert tcp $HOME_NET any -> [117.18.7.76] 3782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200110; rev:1;) alert tcp $HOME_NET any -> [91.92.242.80] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200111; rev:1;) alert tcp $HOME_NET any -> [49.13.33.235] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200112; rev:1;) alert tcp $HOME_NET any -> [103.35.191.31] 7444 (msg:"SSLBL: Traffic to malicious host (likely BruteRatel C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200113; rev:1;) alert tcp $HOME_NET any -> [109.176.30.246] 56002 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200114; rev:1;) alert tcp $HOME_NET any -> [47.242.70.176] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200115; rev:1;) alert tcp $HOME_NET any -> [94.232.249.87] 7444 (msg:"SSLBL: Traffic to malicious host (likely BruteRatel C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200116; rev:1;) alert tcp $HOME_NET any -> [94.232.249.86] 7444 (msg:"SSLBL: Traffic to malicious host (likely BruteRatel C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200117; rev:1;) alert tcp $HOME_NET any -> [147.185.221.19] 25944 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200118; rev:1;) alert tcp $HOME_NET any -> [45.92.1.7] 7000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200119; rev:1;) alert tcp $HOME_NET any -> [194.55.186.121] 1313 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200120; rev:1;) alert tcp $HOME_NET any -> [94.228.166.40] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200121; rev:1;) alert tcp $HOME_NET any -> [162.55.53.18] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200122; rev:1;) alert tcp $HOME_NET any -> [192.227.228.34] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200123; rev:1;) alert tcp $HOME_NET any -> [192.227.228.34] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200124; rev:1;) alert tcp $HOME_NET any -> [61.14.233.130] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200125; rev:1;) alert tcp $HOME_NET any -> [157.20.182.102] 4449 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200126; rev:1;) alert tcp $HOME_NET any -> [109.248.151.34] 4445 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200127; rev:1;) alert tcp $HOME_NET any -> [103.244.226.189] 7415 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200128; rev:1;) alert tcp $HOME_NET any -> [195.201.251.58] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200129; rev:1;) alert tcp $HOME_NET any -> [45.8.146.124] 2005 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200130; rev:1;) alert tcp $HOME_NET any -> [162.252.172.67] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200131; rev:1;) alert tcp $HOME_NET any -> [5.180.155.40] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200132; rev:1;) alert tcp $HOME_NET any -> [38.180.9.93] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200133; rev:1;) alert tcp $HOME_NET any -> [20.199.91.184] 1024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200134; rev:1;) alert tcp $HOME_NET any -> [5.75.212.114] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200135; rev:1;) alert tcp $HOME_NET any -> [222.253.182.185] 9090 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200136; rev:1;) alert tcp $HOME_NET any -> [49.13.235.244] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200137; rev:1;) alert tcp $HOME_NET any -> [147.124.221.241] 1149 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200138; rev:1;) alert tcp $HOME_NET any -> [116.203.2.129] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200139; rev:1;) alert tcp $HOME_NET any -> [94.156.69.160] 2020 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200140; rev:1;) alert tcp $HOME_NET any -> [49.13.158.245] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200141; rev:1;) alert tcp $HOME_NET any -> [88.99.127.107] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200142; rev:1;) alert tcp $HOME_NET any -> [45.90.123.184] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200143; rev:1;) alert tcp $HOME_NET any -> [91.92.243.101] 1081 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200144; rev:1;) alert tcp $HOME_NET any -> [159.69.102.132] 5432 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200145; rev:1;) alert tcp $HOME_NET any -> [95.217.241.137] 443 (msg:"SSLBL: Traffic to malicious host (likely Steal C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200146; rev:1;) alert tcp $HOME_NET any -> [116.202.190.18] 443 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200147; rev:1;) alert tcp $HOME_NET any -> [49.13.227.86] 5432 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200148; rev:1;) alert tcp $HOME_NET any -> [37.27.34.12] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200149; rev:1;) alert tcp $HOME_NET any -> [194.59.31.74] 5552 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200150; rev:1;) alert tcp $HOME_NET any -> [141.98.7.186] 65525 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200151; rev:1;) alert tcp $HOME_NET any -> [65.109.242.59] 443 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200152; rev:1;) alert tcp $HOME_NET any -> [78.46.237.77] 443 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200153; rev:1;) alert tcp $HOME_NET any -> [88.198.124.82] 443 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200154; rev:1;) alert tcp $HOME_NET any -> [66.235.168.242] 3232 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200155; rev:1;) alert tcp $HOME_NET any -> [185.169.54.165] 7331 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200156; rev:1;) alert tcp $HOME_NET any -> [78.47.123.174] 443 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200157; rev:1;) alert tcp $HOME_NET any -> [80.76.49.22] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200158; rev:1;) alert tcp $HOME_NET any -> [65.108.55.55] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200159; rev:1;) alert tcp $HOME_NET any -> [45.95.203.63] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200160; rev:1;) alert tcp $HOME_NET any -> [101.43.96.90] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200161; rev:1;) alert tcp $HOME_NET any -> [18.192.31.165] 15221 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200162; rev:1;) alert tcp $HOME_NET any -> [154.212.149.59] 446 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200163; rev:1;) alert tcp $HOME_NET any -> [51.158.20.251] 56002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200164; rev:1;) alert tcp $HOME_NET any -> [95.217.28.63] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200165; rev:1;) alert tcp $HOME_NET any -> [94.228.162.82] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200166; rev:1;) alert tcp $HOME_NET any -> [91.92.248.187] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200167; rev:1;) alert tcp $HOME_NET any -> [92.44.20.216] 9733 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200168; rev:1;) alert tcp $HOME_NET any -> [65.21.183.11] 443 (msg:"SSLBL: Traffic to malicious host (likely Stealc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200169; rev:1;) alert tcp $HOME_NET any -> [77.91.68.75] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200170; rev:1;) alert tcp $HOME_NET any -> [159.100.13.218] 8889 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200171; rev:1;) alert tcp $HOME_NET any -> [142.202.48.115] 4449 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200172; rev:1;) alert tcp $HOME_NET any -> [50.63.7.226] 443 (msg:"SSLBL: Traffic to malicious host (likely ConnectWise C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200173; rev:1;) alert tcp $HOME_NET any -> [87.121.105.252] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200174; rev:1;) alert tcp $HOME_NET any -> [65.109.242.112] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200175; rev:1;) alert tcp $HOME_NET any -> [3.127.59.75] 15176 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200176; rev:1;) alert tcp $HOME_NET any -> [12.202.180.134] 8797 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200177; rev:1;) alert tcp $HOME_NET any -> [107.148.46.18] 22 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200178; rev:1;) alert tcp $HOME_NET any -> [114.132.87.123] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200179; rev:1;) alert tcp $HOME_NET any -> [103.165.81.103] 1145 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200180; rev:1;) alert tcp $HOME_NET any -> [20.117.109.69] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200181; rev:1;) alert tcp $HOME_NET any -> [207.148.109.8] 443 (msg:"SSLBL: Traffic to malicious host (likely Metasploit C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200182; rev:1;) alert tcp $HOME_NET any -> [41.216.183.41] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200183; rev:1;) alert tcp $HOME_NET any -> [163.5.210.97] 3307 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200184; rev:1;) alert tcp $HOME_NET any -> [93.123.85.108] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200185; rev:1;) alert tcp $HOME_NET any -> [95.217.245.42] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200186; rev:1;) alert tcp $HOME_NET any -> [154.19.164.108] 446 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200187; rev:1;) alert tcp $HOME_NET any -> [95.217.242.142] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200188; rev:1;) alert tcp $HOME_NET any -> [45.146.255.167] 8500 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200189; rev:1;) alert tcp $HOME_NET any -> [37.27.87.155] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200190; rev:1;) alert tcp $HOME_NET any -> [45.133.174.75] 8795 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200191; rev:1;) alert tcp $HOME_NET any -> [95.211.208.153] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200192; rev:1;) alert tcp $HOME_NET any -> [95.217.245.42] 443 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200193; rev:1;) alert tcp $HOME_NET any -> [98.66.160.134] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200194; rev:1;) alert tcp $HOME_NET any -> [77.221.151.42] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200195; rev:1;) alert tcp $HOME_NET any -> [95.217.244.99] 443 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200196; rev:1;) alert tcp $HOME_NET any -> [103.249.112.118] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200197; rev:1;) alert tcp $HOME_NET any -> [194.26.192.196] 1610 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200198; rev:1;) alert tcp $HOME_NET any -> [121.43.48.30] 8448 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200199; rev:1;) alert tcp $HOME_NET any -> [65.109.242.73] 443 (msg:"SSLBL: Traffic to malicious host (likely zgRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200200; rev:1;) alert tcp $HOME_NET any -> [45.32.168.59] 4040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200201; rev:1;) alert tcp $HOME_NET any -> [173.211.46.114] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200202; rev:1;) alert tcp $HOME_NET any -> [157.90.25.39] 5432 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200203; rev:1;) alert tcp $HOME_NET any -> [49.13.149.204] 9000 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200204; rev:1;) alert tcp $HOME_NET any -> [65.109.242.131] 443 (msg:"SSLBL: Traffic to malicious host (likely MarsStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200205; rev:1;) alert tcp $HOME_NET any -> [195.201.47.150] 5432 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200206; rev:1;) alert tcp $HOME_NET any -> [45.11.229.96] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200207; rev:1;) alert tcp $HOME_NET any -> [91.207.102.163] 9899 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200208; rev:1;) alert tcp $HOME_NET any -> [51.79.171.174] 1337 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200209; rev:1;) alert tcp $HOME_NET any -> [185.125.50.121] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200210; rev:1;) alert tcp $HOME_NET any -> [91.92.241.169] 3434 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200211; rev:1;) alert tcp $HOME_NET any -> [45.88.186.209] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200212; rev:1;) alert tcp $HOME_NET any -> [16.171.25.219] 8099 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200213; rev:1;) alert tcp $HOME_NET any -> [162.230.48.189] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200214; rev:1;) alert tcp $HOME_NET any -> [162.230.48.189] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200215; rev:1;) alert tcp $HOME_NET any -> [95.217.42.84] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200216; rev:1;) alert tcp $HOME_NET any -> [144.217.189.92] 3000 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200217; rev:1;) alert tcp $HOME_NET any -> [94.156.10.119] 443 (msg:"SSLBL: Traffic to malicious host (likely AgentTesla C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200218; rev:1;) alert tcp $HOME_NET any -> [94.156.8.44] 4787 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200219; rev:1;) alert tcp $HOME_NET any -> [217.63.234.90] 1313 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200220; rev:1;) alert tcp $HOME_NET any -> [91.92.243.85] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200221; rev:1;) alert tcp $HOME_NET any -> [194.62.248.64] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200222; rev:1;) alert tcp $HOME_NET any -> [45.157.69.156] 443 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200223; rev:1;) alert tcp $HOME_NET any -> [172.94.105.163] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200224; rev:1;) alert tcp $HOME_NET any -> [51.142.10.24] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200225; rev:1;) alert tcp $HOME_NET any -> [45.91.226.131] 1145 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200226; rev:1;) alert tcp $HOME_NET any -> [46.246.84.18] 1128 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200227; rev:1;) alert tcp $HOME_NET any -> [103.211.56.154] 14782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200228; rev:1;) alert tcp $HOME_NET any -> [154.30.255.175] 8887 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200229; rev:1;) alert tcp $HOME_NET any -> [185.196.10.24] 8808 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200230; rev:1;) alert tcp $HOME_NET any -> [154.27.70.229] 56002 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200231; rev:1;) alert tcp $HOME_NET any -> [175.42.18.7] 4784 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200232; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 41985 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200233; rev:1;) alert tcp $HOME_NET any -> [103.155.214.203] 443 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200234; rev:1;) alert tcp $HOME_NET any -> [91.92.252.228] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200235; rev:1;) alert tcp $HOME_NET any -> [94.156.8.83] 4785 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200236; rev:1;) alert tcp $HOME_NET any -> [109.61.95.120] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200237; rev:1;) alert tcp $HOME_NET any -> [93.123.39.28] 8075 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200238; rev:1;) alert tcp $HOME_NET any -> [192.151.244.144] 14782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200239; rev:1;) alert tcp $HOME_NET any -> [168.75.105.185] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200240; rev:1;) alert tcp $HOME_NET any -> [49.13.200.170] 7878 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200241; rev:1;) alert tcp $HOME_NET any -> [118.195.235.103] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200242; rev:1;) alert tcp $HOME_NET any -> [147.185.221.18] 56901 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200243; rev:1;) alert tcp $HOME_NET any -> [45.134.83.165] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200244; rev:1;) alert tcp $HOME_NET any -> [20.117.169.244] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200245; rev:1;) alert tcp $HOME_NET any -> [193.26.115.138] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200246; rev:1;) alert tcp $HOME_NET any -> [172.174.236.21] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200247; rev:1;) alert tcp $HOME_NET any -> [154.27.70.229] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200248; rev:1;) alert tcp $HOME_NET any -> [20.26.126.28] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200249; rev:1;) alert tcp $HOME_NET any -> [196.112.147.229] 5566 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200250; rev:1;) alert tcp $HOME_NET any -> [18.134.234.207] 3306 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200251; rev:1;) alert tcp $HOME_NET any -> [104.243.46.129] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200252; rev:1;) alert tcp $HOME_NET any -> [104.21.44.122] 443 (msg:"SSLBL: Traffic to malicious host (likely Latrodectus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200253; rev:1;) alert tcp $HOME_NET any -> [172.67.221.168] 443 (msg:"SSLBL: Traffic to malicious host (likely Latrodectus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200254; rev:1;) alert tcp $HOME_NET any -> [186.169.36.241] 7082 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200255; rev:1;) alert tcp $HOME_NET any -> [45.88.186.16] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200256; rev:1;) alert tcp $HOME_NET any -> [1.14.206.144] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200257; rev:1;) alert tcp $HOME_NET any -> [185.16.39.253] 8888 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200258; rev:1;) alert tcp $HOME_NET any -> [91.92.242.133] 2025 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200259; rev:1;) alert tcp $HOME_NET any -> [20.117.106.245] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200260; rev:1;) alert tcp $HOME_NET any -> [212.193.11.40] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200261; rev:1;) alert tcp $HOME_NET any -> [88.80.145.97] 56001 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200262; rev:1;) alert tcp $HOME_NET any -> [91.92.251.202] 2024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200263; rev:1;) alert tcp $HOME_NET any -> [94.156.68.217] 3162 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200264; rev:1;) alert tcp $HOME_NET any -> [91.134.150.145] 56001 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200265; rev:1;) alert tcp $HOME_NET any -> [110.139.46.105] 36969 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200266; rev:1;) alert tcp $HOME_NET any -> [90.15.154.112] 4789 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200267; rev:1;) alert tcp $HOME_NET any -> [193.233.132.186] 6606 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200268; rev:1;) alert tcp $HOME_NET any -> [45.145.55.81] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200269; rev:1;) alert tcp $HOME_NET any -> [103.13.210.210] 8080 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200270; rev:1;) alert tcp $HOME_NET any -> [109.61.95.120] 56002 (msg:"SSLBL: Traffic to malicious host (likely PureLogStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200271; rev:1;) alert tcp $HOME_NET any -> [194.147.140.138] 3320 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200272; rev:1;) alert tcp $HOME_NET any -> [80.79.7.197] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200273; rev:1;) alert tcp $HOME_NET any -> [172.94.32.33] 8881 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200274; rev:1;) alert tcp $HOME_NET any -> [139.84.229.159] 1980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200275; rev:1;) alert tcp $HOME_NET any -> [94.102.155.46] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200276; rev:1;) alert tcp $HOME_NET any -> [172.203.173.71] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200277; rev:1;) alert tcp $HOME_NET any -> [91.92.254.14] 4412 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200278; rev:1;) alert tcp $HOME_NET any -> [80.85.142.30] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200279; rev:1;) alert tcp $HOME_NET any -> [146.70.161.85] 4217 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200280; rev:1;) alert tcp $HOME_NET any -> [103.67.162.240] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200281; rev:1;) alert tcp $HOME_NET any -> [203.20.113.158] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200282; rev:1;) alert tcp $HOME_NET any -> [72.11.158.94] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200283; rev:1;) alert tcp $HOME_NET any -> [64.52.171.220] 56003 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200284; rev:1;) alert tcp $HOME_NET any -> [64.52.171.220] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200285; rev:1;) alert tcp $HOME_NET any -> [85.217.170.160] 3232 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200286; rev:1;) alert tcp $HOME_NET any -> [209.145.59.89] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200287; rev:1;) alert tcp $HOME_NET any -> [91.92.241.54] 4782 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200288; rev:1;) alert tcp $HOME_NET any -> [91.92.248.67] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200289; rev:1;) alert tcp $HOME_NET any -> [45.144.153.54] 9495 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200290; rev:1;) alert tcp $HOME_NET any -> [147.124.212.75] 2010 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200291; rev:1;) alert tcp $HOME_NET any -> [45.15.156.13] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200292; rev:1;) alert tcp $HOME_NET any -> [98.26.85.5] 6969 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200293; rev:1;) alert tcp $HOME_NET any -> [91.92.254.40] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200294; rev:1;) alert tcp $HOME_NET any -> [43.248.140.95] 3261 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200295; rev:1;) alert tcp $HOME_NET any -> [91.92.240.231] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200296; rev:1;) alert tcp $HOME_NET any -> [94.249.3.0] 6565 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200297; rev:1;) alert tcp $HOME_NET any -> [77.105.132.124] 2525 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200298; rev:1;) alert tcp $HOME_NET any -> [116.202.0.196] 10220 (msg:"SSLBL: Traffic to malicious host (likely njrat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200299; rev:1;) alert tcp $HOME_NET any -> [87.251.66.248] 443 (msg:"SSLBL: Traffic to malicious host (likely T34loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200300; rev:1;) alert tcp $HOME_NET any -> [49.12.114.15] 10220 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200301; rev:1;) alert tcp $HOME_NET any -> [65.20.67.1] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200302; rev:1;) alert tcp $HOME_NET any -> [46.246.6.15] 1234 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200303; rev:1;) alert tcp $HOME_NET any -> [45.145.229.151] 19505 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200304; rev:1;) alert tcp $HOME_NET any -> [193.56.253.102] 25565 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200305; rev:1;) alert tcp $HOME_NET any -> [162.14.105.120] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200306; rev:1;) alert tcp $HOME_NET any -> [91.92.250.243] 4887 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200307; rev:1;) alert tcp $HOME_NET any -> [105.157.214.201] 8844 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200308; rev:1;) alert tcp $HOME_NET any -> [3.121.139.82] 10680 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200309; rev:1;) alert tcp $HOME_NET any -> [3.127.253.86] 10680 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200310; rev:1;) alert tcp $HOME_NET any -> [52.28.112.211] 10680 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200311; rev:1;) alert tcp $HOME_NET any -> [81.70.183.244] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200312; rev:1;) alert tcp $HOME_NET any -> [27.147.169.101] 3333 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200313; rev:1;) alert tcp $HOME_NET any -> [91.198.66.47] 1881 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200314; rev:1;) alert tcp $HOME_NET any -> [5.75.220.180] 2024 (msg:"SSLBL: Traffic to malicious host (likely Vidar C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200315; rev:1;) alert tcp $HOME_NET any -> [103.13.209.45] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200316; rev:1;) alert tcp $HOME_NET any -> [45.88.186.145] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200317; rev:1;) alert tcp $HOME_NET any -> [27.102.134.120] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200318; rev:1;) alert tcp $HOME_NET any -> [101.43.228.101] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200319; rev:1;) alert tcp $HOME_NET any -> [147.189.169.67] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200320; rev:1;) alert tcp $HOME_NET any -> [15.235.3.1] 2000 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200321; rev:1;) alert tcp $HOME_NET any -> [15.235.3.1] 2001 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200322; rev:1;) alert tcp $HOME_NET any -> [87.121.87.36] 1335 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200323; rev:1;) alert tcp $HOME_NET any -> [206.123.135.125] 2008 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200324; rev:1;) alert tcp $HOME_NET any -> [27.124.3.19] 6606 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200325; rev:1;) alert tcp $HOME_NET any -> [91.92.247.130] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200326; rev:1;) alert tcp $HOME_NET any -> [91.92.246.124] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200327; rev:1;) alert tcp $HOME_NET any -> [139.155.155.148] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200328; rev:1;) alert tcp $HOME_NET any -> [42.192.132.36] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200329; rev:1;) alert tcp $HOME_NET any -> [222.211.73.134] 5666 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200330; rev:1;) alert tcp $HOME_NET any -> [5.75.147.113] 3000 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200331; rev:1;) alert tcp $HOME_NET any -> [5.75.147.113] 3000 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200332; rev:1;) alert tcp $HOME_NET any -> [20.199.26.211] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200333; rev:1;) alert tcp $HOME_NET any -> [8.212.49.198] 9827 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200334; rev:1;) alert tcp $HOME_NET any -> [207.246.82.230] 5290 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200335; rev:1;) alert tcp $HOME_NET any -> [139.84.229.159] 1988 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200336; rev:1;) alert tcp $HOME_NET any -> [77.232.132.25] 4999 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200337; rev:1;) alert tcp $HOME_NET any -> [181.41.200.232] 4000 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200338; rev:1;) alert tcp $HOME_NET any -> [141.255.159.0] 80 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200339; rev:1;) alert tcp $HOME_NET any -> [198.13.49.217] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200340; rev:1;) alert tcp $HOME_NET any -> [43.248.185.248] 53779 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200341; rev:1;) alert tcp $HOME_NET any -> [113.207.105.241] 17803 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200342; rev:1;) alert tcp $HOME_NET any -> [91.92.248.48] 5552 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200343; rev:1;) alert tcp $HOME_NET any -> [149.13.5.179] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200344; rev:1;) alert tcp $HOME_NET any -> [38.181.25.204] 5858 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200345; rev:1;) alert tcp $HOME_NET any -> [91.92.247.96] 5531 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200346; rev:1;) alert tcp $HOME_NET any -> [91.92.247.123] 5531 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200347; rev:1;) alert tcp $HOME_NET any -> [41.216.183.22] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200348; rev:1;) alert tcp $HOME_NET any -> [80.253.246.12] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200349; rev:1;) alert tcp $HOME_NET any -> [172.208.93.32] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200350; rev:1;) alert tcp $HOME_NET any -> [106.160.59.123] 5468 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200351; rev:1;) alert tcp $HOME_NET any -> [88.99.214.187] 3232 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200352; rev:1;) alert tcp $HOME_NET any -> [139.59.72.48] 9443 (msg:"SSLBL: Traffic to malicious host (likely PoshC2 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200353; rev:1;) alert tcp $HOME_NET any -> [193.222.96.19] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200354; rev:1;) alert tcp $HOME_NET any -> [113.207.105.200] 3201 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200355; rev:1;) alert tcp $HOME_NET any -> [142.202.188.201] 9901 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200356; rev:1;) alert tcp $HOME_NET any -> [41.216.183.84] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200357; rev:1;) alert tcp $HOME_NET any -> [62.210.207.211] 443 (msg:"SSLBL: Traffic to malicious host (likely Havoc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200358; rev:1;) alert tcp $HOME_NET any -> [113.207.105.195] 15806 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200359; rev:1;) alert tcp $HOME_NET any -> [91.92.252.74] 56002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200360; rev:1;) alert tcp $HOME_NET any -> [122.144.6.226] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200361; rev:1;) alert tcp $HOME_NET any -> [31.214.240.57] 3232 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200362; rev:1;) alert tcp $HOME_NET any -> [95.214.25.72] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200363; rev:1;) alert tcp $HOME_NET any -> [202.146.218.35] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200364; rev:1;) alert tcp $HOME_NET any -> [91.92.248.239] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200365; rev:1;) alert tcp $HOME_NET any -> [113.207.105.229] 8302 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200366; rev:1;) alert tcp $HOME_NET any -> [103.168.19.82] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200367; rev:1;) alert tcp $HOME_NET any -> [118.89.85.106] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200368; rev:1;) alert tcp $HOME_NET any -> [113.207.105.224] 16804 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200369; rev:1;) alert tcp $HOME_NET any -> [146.196.80.168] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200370; rev:1;) alert tcp $HOME_NET any -> [45.145.229.147] 9606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200371; rev:1;) alert tcp $HOME_NET any -> [94.242.53.198] 443 (msg:"SSLBL: Traffic to malicious host (likely Havoc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200372; rev:1;) alert tcp $HOME_NET any -> [202.63.172.63] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200373; rev:1;) alert tcp $HOME_NET any -> [45.145.229.151] 9603 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200374; rev:1;) alert tcp $HOME_NET any -> [116.103.214.233] 1704 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200375; rev:1;) alert tcp $HOME_NET any -> [3.68.56.232] 10644 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200376; rev:1;) alert tcp $HOME_NET any -> [3.141.177.1] 11465 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200377; rev:1;) alert tcp $HOME_NET any -> [213.65.233.25] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200378; rev:1;) alert tcp $HOME_NET any -> [172.171.254.153] 4748 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200379; rev:1;) alert tcp $HOME_NET any -> [181.90.42.189] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200380; rev:1;) alert tcp $HOME_NET any -> [87.248.157.179] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200381; rev:1;) alert tcp $HOME_NET any -> [45.145.225.162] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200382; rev:1;) alert tcp $HOME_NET any -> [95.214.27.253] 1357 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200383; rev:1;) alert tcp $HOME_NET any -> [91.207.57.115] 45529 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200384; rev:1;) alert tcp $HOME_NET any -> [52.186.179.225] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200385; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 59460 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200386; rev:1;) alert tcp $HOME_NET any -> [179.13.0.48] 4422 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200387; rev:1;) alert tcp $HOME_NET any -> [213.139.207.234] 56001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200388; rev:1;) alert tcp $HOME_NET any -> [20.199.45.15] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200389; rev:1;) alert tcp $HOME_NET any -> [37.1.222.7] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200390; rev:1;) alert tcp $HOME_NET any -> [40.67.150.126] 2000 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200391; rev:1;) alert tcp $HOME_NET any -> [185.221.67.19] 17722 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200392; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 63447 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200393; rev:1;) alert tcp $HOME_NET any -> [95.214.27.6] 4545 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200394; rev:1;) alert tcp $HOME_NET any -> [20.211.121.138] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200395; rev:1;) alert tcp $HOME_NET any -> [2.58.56.68] 4334 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200396; rev:1;) alert tcp $HOME_NET any -> [134.255.254.225] 5058 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200397; rev:1;) alert tcp $HOME_NET any -> [94.156.253.168] 1990 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200398; rev:1;) alert tcp $HOME_NET any -> [147.189.169.231] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200399; rev:1;) alert tcp $HOME_NET any -> [95.214.25.90] 32400 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200400; rev:1;) alert tcp $HOME_NET any -> [77.97.164.31] 6969 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200401; rev:1;) alert tcp $HOME_NET any -> [163.5.215.216] 4788 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200402; rev:1;) alert tcp $HOME_NET any -> [178.250.189.225] 9901 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200403; rev:1;) alert tcp $HOME_NET any -> [138.201.18.225] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200404; rev:1;) alert tcp $HOME_NET any -> [103.82.38.49] 4449 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200405; rev:1;) alert tcp $HOME_NET any -> [185.17.0.246] 1419 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200406; rev:1;) alert tcp $HOME_NET any -> [27.124.4.200] 6606 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200407; rev:1;) alert tcp $HOME_NET any -> [185.81.157.218] 9090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200408; rev:1;) alert tcp $HOME_NET any -> [18.118.199.163] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200409; rev:1;) alert tcp $HOME_NET any -> [154.221.25.208] 8849 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200410; rev:1;) alert tcp $HOME_NET any -> [45.66.230.22] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200411; rev:1;) alert tcp $HOME_NET any -> [79.134.225.113] 9346 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200412; rev:1;) alert tcp $HOME_NET any -> [5.249.163.45] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200413; rev:1;) alert tcp $HOME_NET any -> [209.25.142.181] 30254 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200414; rev:1;) alert tcp $HOME_NET any -> [14.225.254.32] 9090 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200415; rev:1;) alert tcp $HOME_NET any -> [51.103.217.70] 8585 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200416; rev:1;) alert tcp $HOME_NET any -> [37.221.92.28] 8488 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200417; rev:1;) alert tcp $HOME_NET any -> [90.62.249.133] 2585 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200418; rev:1;) alert tcp $HOME_NET any -> [77.91.97.56] 4543 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200419; rev:1;) alert tcp $HOME_NET any -> [185.17.0.246] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200420; rev:1;) alert tcp $HOME_NET any -> [46.35.26.183] 24670 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200421; rev:1;) alert tcp $HOME_NET any -> [42.51.40.184] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200422; rev:1;) alert tcp $HOME_NET any -> [137.220.48.214] 24535 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200423; rev:1;) alert tcp $HOME_NET any -> [80.76.51.237] 2023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200424; rev:1;) alert tcp $HOME_NET any -> [3.121.139.82] 19801 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200425; rev:1;) alert tcp $HOME_NET any -> [95.214.27.6] 2442 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200426; rev:1;) alert tcp $HOME_NET any -> [4.151.131.10] 1011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200427; rev:1;) alert tcp $HOME_NET any -> [72.18.130.237] 7321 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200428; rev:1;) alert tcp $HOME_NET any -> [194.180.48.53] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200429; rev:1;) alert tcp $HOME_NET any -> [179.13.2.154] 7000 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200430; rev:1;) alert tcp $HOME_NET any -> [95.214.25.236] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200431; rev:1;) alert tcp $HOME_NET any -> [193.203.238.54] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200432; rev:1;) alert tcp $HOME_NET any -> [179.43.154.184] 11371 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200433; rev:1;) alert tcp $HOME_NET any -> [185.183.33.129] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200434; rev:1;) alert tcp $HOME_NET any -> [172.94.40.145] 8004 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200435; rev:1;) alert tcp $HOME_NET any -> [89.23.101.212] 3232 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200436; rev:1;) alert tcp $HOME_NET any -> [167.86.88.89] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200437; rev:1;) alert tcp $HOME_NET any -> [199.127.60.151] 8889 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200438; rev:1;) alert tcp $HOME_NET any -> [103.149.201.212] 8910 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200439; rev:1;) alert tcp $HOME_NET any -> [65.108.24.87] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200440; rev:1;) alert tcp $HOME_NET any -> [163.5.215.237] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200441; rev:1;) alert tcp $HOME_NET any -> [185.212.47.90] 8843 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200442; rev:1;) alert tcp $HOME_NET any -> [38.6.189.150] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200443; rev:1;) alert tcp $HOME_NET any -> [80.66.79.27] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200444; rev:1;) alert tcp $HOME_NET any -> [4.212.242.253] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200445; rev:1;) alert tcp $HOME_NET any -> [193.43.104.22] 3232 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200446; rev:1;) alert tcp $HOME_NET any -> [8.210.13.235] 17099 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200447; rev:1;) alert tcp $HOME_NET any -> [58.87.71.58] 14199 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200448; rev:1;) alert tcp $HOME_NET any -> [139.180.143.50] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200449; rev:1;) alert tcp $HOME_NET any -> [95.173.247.110] 8810 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200450; rev:1;) alert tcp $HOME_NET any -> [213.3.43.23] 58640 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200451; rev:1;) alert tcp $HOME_NET any -> [156.236.72.121] 443 (msg:"SSLBL: Traffic to malicious host (likely Fabookie C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200452; rev:1;) alert tcp $HOME_NET any -> [45.141.215.12] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200453; rev:1;) alert tcp $HOME_NET any -> [193.142.146.212] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200454; rev:1;) alert tcp $HOME_NET any -> [83.143.112.45] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200455; rev:1;) alert tcp $HOME_NET any -> [154.12.90.31] 2023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200456; rev:1;) alert tcp $HOME_NET any -> [154.91.227.35] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200457; rev:1;) alert tcp $HOME_NET any -> [51.210.170.204] 5138 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200458; rev:1;) alert tcp $HOME_NET any -> [107.182.228.197] 2124 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200459; rev:1;) alert tcp $HOME_NET any -> [141.95.11.145] 81 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200460; rev:1;) alert tcp $HOME_NET any -> [154.12.90.49] 2023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200461; rev:1;) alert tcp $HOME_NET any -> [164.155.255.168] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200462; rev:1;) alert tcp $HOME_NET any -> [18.197.239.5] 18516 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200463; rev:1;) alert tcp $HOME_NET any -> [103.144.247.227] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200464; rev:1;) alert tcp $HOME_NET any -> [198.44.168.227] 2023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200465; rev:1;) alert tcp $HOME_NET any -> [185.106.94.122] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200466; rev:1;) alert tcp $HOME_NET any -> [194.67.206.185] 666 (msg:"SSLBL: Traffic to malicious host (likely EmpireRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200467; rev:1;) alert tcp $HOME_NET any -> [45.141.215.252] 53631 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200468; rev:1;) alert tcp $HOME_NET any -> [37.139.129.231] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200469; rev:1;) alert tcp $HOME_NET any -> [77.232.132.25] 5001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200470; rev:1;) alert tcp $HOME_NET any -> [86.252.133.190] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200471; rev:1;) alert tcp $HOME_NET any -> [37.139.129.145] 5512 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200472; rev:1;) alert tcp $HOME_NET any -> [31.210.55.202] 81 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200473; rev:1;) alert tcp $HOME_NET any -> [91.103.252.25] 4681 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200474; rev:1;) alert tcp $HOME_NET any -> [185.225.73.49] 4851 (msg:"SSLBL: Traffic to malicious host (likely Rhadamanthys C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200475; rev:1;) alert tcp $HOME_NET any -> [193.163.88.106] 38440 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200476; rev:1;) alert tcp $HOME_NET any -> [185.180.230.132] 1488 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200477; rev:1;) alert tcp $HOME_NET any -> [20.187.118.150] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200478; rev:1;) alert tcp $HOME_NET any -> [147.185.221.16] 10735 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200479; rev:1;) alert tcp $HOME_NET any -> [61.136.166.128] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200480; rev:1;) alert tcp $HOME_NET any -> [213.238.177.40] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200481; rev:1;) alert tcp $HOME_NET any -> [176.111.174.101] 443 (msg:"SSLBL: Traffic to malicious host (likely NetSupport C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200482; rev:1;) alert tcp $HOME_NET any -> [161.35.128.227] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200483; rev:1;) alert tcp $HOME_NET any -> [165.227.8.65] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200484; rev:1;) alert tcp $HOME_NET any -> [167.94.81.75] 54321 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200485; rev:1;) alert tcp $HOME_NET any -> [92.178.8.159] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200486; rev:1;) alert tcp $HOME_NET any -> [171.22.30.13] 1276 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200487; rev:1;) alert tcp $HOME_NET any -> [209.25.141.181] 56493 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200488; rev:1;) alert tcp $HOME_NET any -> [152.89.247.113] 2 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200489; rev:1;) alert tcp $HOME_NET any -> [3.125.223.134] 15861 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200490; rev:1;) alert tcp $HOME_NET any -> [20.199.73.159] 1024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200491; rev:1;) alert tcp $HOME_NET any -> [147.50.253.108] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200492; rev:1;) alert tcp $HOME_NET any -> [95.169.196.222] 1609 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200493; rev:1;) alert tcp $HOME_NET any -> [52.28.112.211] 19945 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200494; rev:1;) alert tcp $HOME_NET any -> [185.17.3.72] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200495; rev:1;) alert tcp $HOME_NET any -> [24.199.83.51] 443 (msg:"SSLBL: Traffic to malicious host (likely Meterpreter C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200496; rev:1;) alert tcp $HOME_NET any -> [103.170.118.35] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200497; rev:1;) alert tcp $HOME_NET any -> [172.245.23.178] 7777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200498; rev:1;) alert tcp $HOME_NET any -> [158.247.227.231] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200499; rev:1;) alert tcp $HOME_NET any -> [193.233.133.58] 5631 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200500; rev:1;) alert tcp $HOME_NET any -> [193.109.85.128] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200501; rev:1;) alert tcp $HOME_NET any -> [209.25.140.181] 45937 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200502; rev:1;) alert tcp $HOME_NET any -> [172.245.23.178] 4775 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200503; rev:1;) alert tcp $HOME_NET any -> [209.141.35.5] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200504; rev:1;) alert tcp $HOME_NET any -> [111.90.150.186] 8977 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200505; rev:1;) alert tcp $HOME_NET any -> [193.149.185.150] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200506; rev:1;) alert tcp $HOME_NET any -> [104.243.47.45] 5230 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200507; rev:1;) alert tcp $HOME_NET any -> [20.216.165.135] 1024 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200508; rev:1;) alert tcp $HOME_NET any -> [193.42.40.39] 65503 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200509; rev:1;) alert tcp $HOME_NET any -> [173.44.50.86] 7788 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200510; rev:1;) alert tcp $HOME_NET any -> [3.88.20.74] 1111 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200511; rev:1;) alert tcp $HOME_NET any -> [84.54.50.31] 8877 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200512; rev:1;) alert tcp $HOME_NET any -> [185.246.220.65] 888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200513; rev:1;) alert tcp $HOME_NET any -> [34.92.66.146] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200514; rev:1;) alert tcp $HOME_NET any -> [216.172.99.151] 8080 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200515; rev:1;) alert tcp $HOME_NET any -> [91.134.150.158] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200516; rev:1;) alert tcp $HOME_NET any -> [124.248.66.67] 22391 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200517; rev:1;) alert tcp $HOME_NET any -> [179.13.3.110] 7575 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200518; rev:1;) alert tcp $HOME_NET any -> [5.230.54.132] 4449 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200519; rev:1;) alert tcp $HOME_NET any -> [194.9.6.69] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200520; rev:1;) alert tcp $HOME_NET any -> [212.193.30.230] 56609 (msg:"SSLBL: Traffic to malicious host (likely zgRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200521; rev:1;) alert tcp $HOME_NET any -> [47.87.136.103] 400 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200522; rev:1;) alert tcp $HOME_NET any -> [65.2.185.165] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200523; rev:1;) alert tcp $HOME_NET any -> [198.12.123.17] 5004 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200524; rev:1;) alert tcp $HOME_NET any -> [185.252.179.71] 8075 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200525; rev:1;) alert tcp $HOME_NET any -> [20.150.193.28] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200526; rev:1;) alert tcp $HOME_NET any -> [109.195.94.247] 8096 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200527; rev:1;) alert tcp $HOME_NET any -> [18.136.148.247] 13000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200528; rev:1;) alert tcp $HOME_NET any -> [5.161.192.28] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200529; rev:1;) alert tcp $HOME_NET any -> [103.169.34.151] 2245 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200530; rev:1;) alert tcp $HOME_NET any -> [74.119.194.154] 2060 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200531; rev:1;) alert tcp $HOME_NET any -> [194.59.31.39] 2025 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200532; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 30878 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200533; rev:1;) alert tcp $HOME_NET any -> [45.81.39.62] 7011 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200534; rev:1;) alert tcp $HOME_NET any -> [91.213.50.52] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200535; rev:1;) alert tcp $HOME_NET any -> [95.214.27.44] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200536; rev:1;) alert tcp $HOME_NET any -> [79.110.49.40] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200537; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 47169 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200538; rev:1;) alert tcp $HOME_NET any -> [147.135.165.27] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200539; rev:1;) alert tcp $HOME_NET any -> [74.234.104.236] 3131 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200540; rev:1;) alert tcp $HOME_NET any -> [45.80.29.139] 1337 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200541; rev:1;) alert tcp $HOME_NET any -> [43.138.166.76] 6593 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200542; rev:1;) alert tcp $HOME_NET any -> [144.202.52.245] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200543; rev:1;) alert tcp $HOME_NET any -> [195.178.120.6] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200544; rev:1;) alert tcp $HOME_NET any -> [43.226.49.147] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200545; rev:1;) alert tcp $HOME_NET any -> [185.204.1.182] 54823 (msg:"SSLBL: Traffic to malicious host (likely VenomRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200546; rev:1;) alert tcp $HOME_NET any -> [154.29.75.191] 2027 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200547; rev:1;) alert tcp $HOME_NET any -> [64.235.61.43] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200548; rev:1;) alert tcp $HOME_NET any -> [146.56.36.222] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200549; rev:1;) alert tcp $HOME_NET any -> [185.161.248.49] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200550; rev:1;) alert tcp $HOME_NET any -> [80.66.79.137] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200551; rev:1;) alert tcp $HOME_NET any -> [91.215.85.153] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200552; rev:1;) alert tcp $HOME_NET any -> [45.125.67.100] 443 (msg:"SSLBL: Traffic to malicious host (likely Havoc C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200553; rev:1;) alert tcp $HOME_NET any -> [128.59.46.185] 50272 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200554; rev:1;) alert tcp $HOME_NET any -> [208.67.107.168] 9055 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200555; rev:1;) alert tcp $HOME_NET any -> [139.99.114.150] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200556; rev:1;) alert tcp $HOME_NET any -> [124.248.66.67] 23524 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200557; rev:1;) alert tcp $HOME_NET any -> [193.32.127.144] 57147 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200558; rev:1;) alert tcp $HOME_NET any -> [95.214.27.146] 47600 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200559; rev:1;) alert tcp $HOME_NET any -> [61.83.40.108] 3072 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200560; rev:1;) alert tcp $HOME_NET any -> [172.81.184.73] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200561; rev:1;) alert tcp $HOME_NET any -> [80.66.79.104] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200562; rev:1;) alert tcp $HOME_NET any -> [194.165.16.94] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200563; rev:1;) alert tcp $HOME_NET any -> [141.98.6.3] 4973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200564; rev:1;) alert tcp $HOME_NET any -> [23.94.36.185] 56609 (msg:"SSLBL: Traffic to malicious host (likely zgRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200565; rev:1;) alert tcp $HOME_NET any -> [87.121.221.16] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200566; rev:1;) alert tcp $HOME_NET any -> [38.242.128.85] 5559 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200567; rev:1;) alert tcp $HOME_NET any -> [217.195.197.82] 81 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200568; rev:1;) alert tcp $HOME_NET any -> [45.204.126.250] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200569; rev:1;) alert tcp $HOME_NET any -> [45.77.34.211] 9999 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200570; rev:1;) alert tcp $HOME_NET any -> [45.66.230.222] 6547 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200571; rev:1;) alert tcp $HOME_NET any -> [141.98.102.235] 16296 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200572; rev:1;) alert tcp $HOME_NET any -> [84.54.50.51] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200573; rev:1;) alert tcp $HOME_NET any -> [35.157.111.131] 15748 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200574; rev:1;) alert tcp $HOME_NET any -> [209.90.234.22] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200575; rev:1;) alert tcp $HOME_NET any -> [194.87.151.125] 7399 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200576; rev:1;) alert tcp $HOME_NET any -> [193.169.255.152] 6969 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200577; rev:1;) alert tcp $HOME_NET any -> [45.137.22.182] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200578; rev:1;) alert tcp $HOME_NET any -> [15.165.236.45] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200579; rev:1;) alert tcp $HOME_NET any -> [45.80.158.114] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200580; rev:1;) alert tcp $HOME_NET any -> [194.87.151.134] 7878 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200581; rev:1;) alert tcp $HOME_NET any -> [31.41.244.251] 7570 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200582; rev:1;) alert tcp $HOME_NET any -> [95.214.27.226] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200583; rev:1;) alert tcp $HOME_NET any -> [45.141.27.208] 4780 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200584; rev:1;) alert tcp $HOME_NET any -> [87.121.221.179] 4920 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200585; rev:1;) alert tcp $HOME_NET any -> [37.120.210.219] 48408 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200586; rev:1;) alert tcp $HOME_NET any -> [75.127.254.214] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200587; rev:1;) alert tcp $HOME_NET any -> [120.78.151.171] 55233 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200588; rev:1;) alert tcp $HOME_NET any -> [15.228.89.234] 7000 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200589; rev:1;) alert tcp $HOME_NET any -> [125.177.149.143] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200590; rev:1;) alert tcp $HOME_NET any -> [104.243.37.167] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200591; rev:1;) alert tcp $HOME_NET any -> [194.55.224.44] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200592; rev:1;) alert tcp $HOME_NET any -> [51.161.107.21] 666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200593; rev:1;) alert tcp $HOME_NET any -> [45.81.243.217] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200594; rev:1;) alert tcp $HOME_NET any -> [147.185.221.181] 2044 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200595; rev:1;) alert tcp $HOME_NET any -> [61.136.162.141] 8899 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200596; rev:1;) alert tcp $HOME_NET any -> [64.188.16.136] 39583 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200597; rev:1;) alert tcp $HOME_NET any -> [104.219.237.59] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200598; rev:1;) alert tcp $HOME_NET any -> [193.200.134.9] 9969 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200599; rev:1;) alert tcp $HOME_NET any -> [147.189.170.192] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200600; rev:1;) alert tcp $HOME_NET any -> [162.211.180.79] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200601; rev:1;) alert tcp $HOME_NET any -> [94.198.40.27] 5030 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200602; rev:1;) alert tcp $HOME_NET any -> [85.31.45.38] 8808 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200603; rev:1;) alert tcp $HOME_NET any -> [8.217.67.228] 80 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200604; rev:1;) alert tcp $HOME_NET any -> [114.132.232.148] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200605; rev:1;) alert tcp $HOME_NET any -> [212.252.198.21] 1337 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200606; rev:1;) alert tcp $HOME_NET any -> [45.136.4.101] 888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200607; rev:1;) alert tcp $HOME_NET any -> [58.221.72.142] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200608; rev:1;) alert tcp $HOME_NET any -> [193.42.32.159] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200609; rev:1;) alert tcp $HOME_NET any -> [75.136.204.139] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200610; rev:1;) alert tcp $HOME_NET any -> [93.177.135.66] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200611; rev:1;) alert tcp $HOME_NET any -> [124.120.53.223] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200612; rev:1;) alert tcp $HOME_NET any -> [43.137.15.104] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200613; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 28132 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200614; rev:1;) alert tcp $HOME_NET any -> [185.246.220.251] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200615; rev:1;) alert tcp $HOME_NET any -> [65.0.50.125] 22247 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200616; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 48452 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200617; rev:1;) alert tcp $HOME_NET any -> [209.25.141.211] 33901 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200618; rev:1;) alert tcp $HOME_NET any -> [209.25.141.211] 33901 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200619; rev:1;) alert tcp $HOME_NET any -> [91.213.50.8] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200620; rev:1;) alert tcp $HOME_NET any -> [45.12.253.77] 8889 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200621; rev:1;) alert tcp $HOME_NET any -> [3.69.115.178] 15409 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200622; rev:1;) alert tcp $HOME_NET any -> [31.42.188.159] 4000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200623; rev:1;) alert tcp $HOME_NET any -> [181.141.1.67] 4243 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200624; rev:1;) alert tcp $HOME_NET any -> [144.126.133.48] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200625; rev:1;) alert tcp $HOME_NET any -> [62.210.11.126] 9024 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200626; rev:1;) alert tcp $HOME_NET any -> [43.139.124.22] 6666 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200627; rev:1;) alert tcp $HOME_NET any -> [5.188.86.237] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200628; rev:1;) alert tcp $HOME_NET any -> [139.180.143.50] 11334 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200629; rev:1;) alert tcp $HOME_NET any -> [146.70.128.174] 55178 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200630; rev:1;) alert tcp $HOME_NET any -> [160.178.206.45] 65 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200631; rev:1;) alert tcp $HOME_NET any -> [154.53.51.201] 9901 (msg:"SSLBL: Traffic to malicious host (likely zgRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200632; rev:1;) alert tcp $HOME_NET any -> [45.155.158.187] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200633; rev:1;) alert tcp $HOME_NET any -> [8.130.34.250] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200634; rev:1;) alert tcp $HOME_NET any -> [23.227.193.141] 443 (msg:"SSLBL: Traffic to malicious host (likely Nemesis C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200635; rev:1;) alert tcp $HOME_NET any -> [149.202.88.107] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200636; rev:1;) alert tcp $HOME_NET any -> [216.250.106.236] 8881 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200637; rev:1;) alert tcp $HOME_NET any -> [40.113.131.31] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200638; rev:1;) alert tcp $HOME_NET any -> [154.39.252.24] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200639; rev:1;) alert tcp $HOME_NET any -> [141.95.84.40] 4040 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200640; rev:1;) alert tcp $HOME_NET any -> [38.47.205.151] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200641; rev:1;) alert tcp $HOME_NET any -> [157.90.51.195] 6980 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200642; rev:1;) alert tcp $HOME_NET any -> [103.117.72.103] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200643; rev:1;) alert tcp $HOME_NET any -> [147.185.221.180] 64654 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200644; rev:1;) alert tcp $HOME_NET any -> [104.238.147.18] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200645; rev:1;) alert tcp $HOME_NET any -> [172.104.148.228] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200646; rev:1;) alert tcp $HOME_NET any -> [154.23.133.89] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200647; rev:1;) alert tcp $HOME_NET any -> [45.9.16.242] 5200 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200648; rev:1;) alert tcp $HOME_NET any -> [47.87.239.56] 312 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200649; rev:1;) alert tcp $HOME_NET any -> [185.246.220.122] 1488 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200650; rev:1;) alert tcp $HOME_NET any -> [209.25.142.180] 10569 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200651; rev:1;) alert tcp $HOME_NET any -> [172.94.111.4] 2008 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200652; rev:1;) alert tcp $HOME_NET any -> [206.123.132.68] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200653; rev:1;) alert tcp $HOME_NET any -> [45.81.39.83] 3456 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200654; rev:1;) alert tcp $HOME_NET any -> [194.59.218.147] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200655; rev:1;) alert tcp $HOME_NET any -> [103.213.111.207] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200656; rev:1;) alert tcp $HOME_NET any -> [171.247.70.48] 88 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200657; rev:1;) alert tcp $HOME_NET any -> [185.81.157.28] 2030 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200658; rev:1;) alert tcp $HOME_NET any -> [95.168.191.181] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200659; rev:1;) alert tcp $HOME_NET any -> [154.91.228.23] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200660; rev:1;) alert tcp $HOME_NET any -> [84.21.172.55] 1339 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200661; rev:1;) alert tcp $HOME_NET any -> [194.5.98.6] 20 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200662; rev:1;) alert tcp $HOME_NET any -> [89.38.131.104] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200663; rev:1;) alert tcp $HOME_NET any -> [91.134.187.20] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200664; rev:1;) alert tcp $HOME_NET any -> [20.77.74.136] 1337 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200665; rev:1;) alert tcp $HOME_NET any -> [209.25.141.180] 10569 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200666; rev:1;) alert tcp $HOME_NET any -> [209.25.141.180] 10569 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200667; rev:1;) alert tcp $HOME_NET any -> [209.25.140.180] 10569 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200668; rev:1;) alert tcp $HOME_NET any -> [108.143.240.80] 313 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200669; rev:1;) alert tcp $HOME_NET any -> [109.206.240.5] 5992 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200670; rev:1;) alert tcp $HOME_NET any -> [43.154.97.109] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200671; rev:1;) alert tcp $HOME_NET any -> [23.224.131.154] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200672; rev:1;) alert tcp $HOME_NET any -> [23.254.253.134] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200673; rev:1;) alert tcp $HOME_NET any -> [80.66.88.145] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200674; rev:1;) alert tcp $HOME_NET any -> [89.23.107.39] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200675; rev:1;) alert tcp $HOME_NET any -> [85.239.52.234] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200676; rev:1;) alert tcp $HOME_NET any -> [79.110.62.147] 2025 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200677; rev:1;) alert tcp $HOME_NET any -> [193.200.134.9] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200678; rev:1;) alert tcp $HOME_NET any -> [68.235.43.14] 58811 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200679; rev:1;) alert tcp $HOME_NET any -> [3.86.249.47] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200680; rev:1;) alert tcp $HOME_NET any -> [62.150.88.68] 9514 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200681; rev:1;) alert tcp $HOME_NET any -> [179.43.142.197] 5789 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200682; rev:1;) alert tcp $HOME_NET any -> [185.246.221.7] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200683; rev:1;) alert tcp $HOME_NET any -> [37.120.210.219] 9771 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200684; rev:1;) alert tcp $HOME_NET any -> [193.138.195.211] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200685; rev:1;) alert tcp $HOME_NET any -> [209.127.19.155] 5200 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200686; rev:1;) alert tcp $HOME_NET any -> [43.249.30.55] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200687; rev:1;) alert tcp $HOME_NET any -> [185.33.234.172] 3131 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200688; rev:1;) alert tcp $HOME_NET any -> [121.62.17.105] 8848 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200689; rev:1;) alert tcp $HOME_NET any -> [206.238.115.140] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200690; rev:1;) alert tcp $HOME_NET any -> [104.194.10.209] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200691; rev:1;) alert tcp $HOME_NET any -> [135.181.204.51] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200692; rev:1;) alert tcp $HOME_NET any -> [66.63.167.121] 57913 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200693; rev:1;) alert tcp $HOME_NET any -> [20.226.0.95] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200694; rev:1;) alert tcp $HOME_NET any -> [91.209.226.129] 4477 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200695; rev:1;) alert tcp $HOME_NET any -> [46.196.26.192] 4784 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200696; rev:1;) alert tcp $HOME_NET any -> [167.71.56.116] 22993 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200697; rev:1;) alert tcp $HOME_NET any -> [20.203.175.5] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200698; rev:1;) alert tcp $HOME_NET any -> [139.155.57.162] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200699; rev:1;) alert tcp $HOME_NET any -> [23.251.17.65] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200700; rev:1;) alert tcp $HOME_NET any -> [185.250.241.219] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200701; rev:1;) alert tcp $HOME_NET any -> [20.223.155.39] 8808 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200702; rev:1;) alert tcp $HOME_NET any -> [20.197.196.201] 7749 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200703; rev:1;) alert tcp $HOME_NET any -> [147.185.221.212] 15420 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200704; rev:1;) alert tcp $HOME_NET any -> [135.148.113.4] 6789 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200705; rev:1;) alert tcp $HOME_NET any -> [192.188.88.248] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200706; rev:1;) alert tcp $HOME_NET any -> [157.254.194.6] 600 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200707; rev:1;) alert tcp $HOME_NET any -> [89.190.226.232] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200708; rev:1;) alert tcp $HOME_NET any -> [185.255.95.191] 99 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200709; rev:1;) alert tcp $HOME_NET any -> [38.45.124.106] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200710; rev:1;) alert tcp $HOME_NET any -> [23.94.159.165] 17251 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200711; rev:1;) alert tcp $HOME_NET any -> [45.12.253.31] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200712; rev:1;) alert tcp $HOME_NET any -> [185.213.155.163] 57808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200713; rev:1;) alert tcp $HOME_NET any -> [109.107.174.128] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200714; rev:1;) alert tcp $HOME_NET any -> [192.3.193.136] 2023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200715; rev:1;) alert tcp $HOME_NET any -> [194.26.192.221] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200716; rev:1;) alert tcp $HOME_NET any -> [179.14.168.33] 3003 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200717; rev:1;) alert tcp $HOME_NET any -> [103.146.23.112] 1571 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200718; rev:1;) alert tcp $HOME_NET any -> [94.130.170.166] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200719; rev:1;) alert tcp $HOME_NET any -> [38.242.228.203] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200720; rev:1;) alert tcp $HOME_NET any -> [185.243.181.86] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200721; rev:1;) alert tcp $HOME_NET any -> [185.246.220.63] 3395 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200722; rev:1;) alert tcp $HOME_NET any -> [159.65.235.56] 6666 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200723; rev:1;) alert tcp $HOME_NET any -> [95.216.102.32] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200724; rev:1;) alert tcp $HOME_NET any -> [20.4.6.16] 43521 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200725; rev:1;) alert tcp $HOME_NET any -> [77.83.242.206] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200726; rev:1;) alert tcp $HOME_NET any -> [154.12.234.207] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200727; rev:1;) alert tcp $HOME_NET any -> [3.22.53.161] 15845 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200728; rev:1;) alert tcp $HOME_NET any -> [179.43.187.19] 2326 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200729; rev:1;) alert tcp $HOME_NET any -> [116.205.161.193] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200730; rev:1;) alert tcp $HOME_NET any -> [124.221.236.175] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200731; rev:1;) alert tcp $HOME_NET any -> [80.240.18.7] 3131 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200732; rev:1;) alert tcp $HOME_NET any -> [209.126.2.34] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200733; rev:1;) alert tcp $HOME_NET any -> [209.126.2.34] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200734; rev:1;) alert tcp $HOME_NET any -> [43.138.160.55] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200735; rev:1;) alert tcp $HOME_NET any -> [45.133.174.122] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200736; rev:1;) alert tcp $HOME_NET any -> [45.133.174.122] 7707 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200737; rev:1;) alert tcp $HOME_NET any -> [45.143.8.181] 13389 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200738; rev:1;) alert tcp $HOME_NET any -> [185.176.220.29] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200739; rev:1;) alert tcp $HOME_NET any -> [95.216.102.32] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200740; rev:1;) alert tcp $HOME_NET any -> [103.173.226.172] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200741; rev:1;) alert tcp $HOME_NET any -> [185.176.220.145] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200742; rev:1;) alert tcp $HOME_NET any -> [190.2.147.39] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200743; rev:1;) alert tcp $HOME_NET any -> [193.111.248.239] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200744; rev:1;) alert tcp $HOME_NET any -> [5.161.56.132] 2347 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200745; rev:1;) alert tcp $HOME_NET any -> [45.138.16.40] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200746; rev:1;) alert tcp $HOME_NET any -> [45.138.16.148] 5050 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200747; rev:1;) alert tcp $HOME_NET any -> [20.25.94.83] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200748; rev:1;) alert tcp $HOME_NET any -> [20.125.118.35] 2244 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200749; rev:1;) alert tcp $HOME_NET any -> [45.139.105.207] 4782 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200750; rev:1;) alert tcp $HOME_NET any -> [154.12.250.38] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200751; rev:1;) alert tcp $HOME_NET any -> [85.105.88.221] 2531 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200752; rev:1;) alert tcp $HOME_NET any -> [185.241.208.233] 5430 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200753; rev:1;) alert tcp $HOME_NET any -> [23.254.224.102] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200754; rev:1;) alert tcp $HOME_NET any -> [51.222.98.70] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200755; rev:1;) alert tcp $HOME_NET any -> [51.222.98.70] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200756; rev:1;) alert tcp $HOME_NET any -> [185.241.208.134] 7331 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200757; rev:1;) alert tcp $HOME_NET any -> [147.189.168.100] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200758; rev:1;) alert tcp $HOME_NET any -> [104.168.149.16] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200759; rev:1;) alert tcp $HOME_NET any -> [67.191.63.138] 4781 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200760; rev:1;) alert tcp $HOME_NET any -> [107.213.220.165] 53 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200761; rev:1;) alert tcp $HOME_NET any -> [154.12.250.38] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200762; rev:1;) alert tcp $HOME_NET any -> [193.149.176.156] 8080 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200763; rev:1;) alert tcp $HOME_NET any -> [142.44.252.26] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200764; rev:1;) alert tcp $HOME_NET any -> [20.100.196.69] 9281 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200765; rev:1;) alert tcp $HOME_NET any -> [23.94.236.147] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200766; rev:1;) alert tcp $HOME_NET any -> [23.254.225.181] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200767; rev:1;) alert tcp $HOME_NET any -> [157.245.44.217] 8448 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200768; rev:1;) alert tcp $HOME_NET any -> [23.226.77.22] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200769; rev:1;) alert tcp $HOME_NET any -> [195.206.235.234] 1907 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200770; rev:1;) alert tcp $HOME_NET any -> [66.85.173.3] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200771; rev:1;) alert tcp $HOME_NET any -> [4.201.51.87] 5786 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200772; rev:1;) alert tcp $HOME_NET any -> [156.96.156.177] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200773; rev:1;) alert tcp $HOME_NET any -> [185.225.70.150] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200774; rev:1;) alert tcp $HOME_NET any -> [123.253.35.251] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200775; rev:1;) alert tcp $HOME_NET any -> [23.236.181.126] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200776; rev:1;) alert tcp $HOME_NET any -> [185.246.220.208] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200777; rev:1;) alert tcp $HOME_NET any -> [165.227.31.192] 22781 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200778; rev:1;) alert tcp $HOME_NET any -> [152.89.247.44] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200779; rev:1;) alert tcp $HOME_NET any -> [103.144.139.170] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200780; rev:1;) alert tcp $HOME_NET any -> [185.173.34.241] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200781; rev:1;) alert tcp $HOME_NET any -> [4.231.233.180] 25310 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200782; rev:1;) alert tcp $HOME_NET any -> [103.144.139.157] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200783; rev:1;) alert tcp $HOME_NET any -> [84.38.133.197] 1337 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200784; rev:1;) alert tcp $HOME_NET any -> [160.20.145.136] 3392 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200785; rev:1;) alert tcp $HOME_NET any -> [194.5.98.198] 4545 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200786; rev:1;) alert tcp $HOME_NET any -> [18.158.249.75] 18867 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200787; rev:1;) alert tcp $HOME_NET any -> [45.137.22.111] 8787 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200788; rev:1;) alert tcp $HOME_NET any -> [91.192.100.36] 8084 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200789; rev:1;) alert tcp $HOME_NET any -> [101.43.238.170] 60001 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200790; rev:1;) alert tcp $HOME_NET any -> [91.178.236.90] 8808 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200791; rev:1;) alert tcp $HOME_NET any -> [81.68.193.9] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200792; rev:1;) alert tcp $HOME_NET any -> [193.233.48.17] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200793; rev:1;) alert tcp $HOME_NET any -> [138.99.211.39] 2119 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200794; rev:1;) alert tcp $HOME_NET any -> [147.185.221.212] 34218 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200795; rev:1;) alert tcp $HOME_NET any -> [147.189.172.218] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200796; rev:1;) alert tcp $HOME_NET any -> [2.58.56.22] 5211 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200797; rev:1;) alert tcp $HOME_NET any -> [78.166.31.7] 4444 (msg:"SSLBL: Traffic to malicious host (likely Meterpreter C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200798; rev:1;) alert tcp $HOME_NET any -> [150.253.77.7] 6520 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200799; rev:1;) alert tcp $HOME_NET any -> [185.81.157.202] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200800; rev:1;) alert tcp $HOME_NET any -> [95.211.140.160] 777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200801; rev:1;) alert tcp $HOME_NET any -> [198.20.177.229] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200802; rev:1;) alert tcp $HOME_NET any -> [207.180.221.51] 6922 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200803; rev:1;) alert tcp $HOME_NET any -> [103.136.199.131] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200804; rev:1;) alert tcp $HOME_NET any -> [52.28.247.255] 13890 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200805; rev:1;) alert tcp $HOME_NET any -> [103.239.247.113] 33279 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200806; rev:1;) alert tcp $HOME_NET any -> [20.111.63.231] 7072 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200807; rev:1;) alert tcp $HOME_NET any -> [91.109.178.8] 4777 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200808; rev:1;) alert tcp $HOME_NET any -> [172.86.120.88] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200809; rev:1;) alert tcp $HOME_NET any -> [192.236.163.13] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200810; rev:1;) alert tcp $HOME_NET any -> [8.210.121.56] 10165 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200811; rev:1;) alert tcp $HOME_NET any -> [193.164.17.129] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200812; rev:1;) alert tcp $HOME_NET any -> [194.110.112.45] 54956 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200813; rev:1;) alert tcp $HOME_NET any -> [185.62.56.163] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200814; rev:1;) alert tcp $HOME_NET any -> [4.227.187.147] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200815; rev:1;) alert tcp $HOME_NET any -> [152.89.247.216] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200816; rev:1;) alert tcp $HOME_NET any -> [212.193.30.230] 7011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200817; rev:1;) alert tcp $HOME_NET any -> [146.190.69.247] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200818; rev:1;) alert tcp $HOME_NET any -> [159.89.35.152] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200819; rev:1;) alert tcp $HOME_NET any -> [159.89.35.152] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200820; rev:1;) alert tcp $HOME_NET any -> [159.89.35.152] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200821; rev:1;) alert tcp $HOME_NET any -> [172.93.193.231] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200822; rev:1;) alert tcp $HOME_NET any -> [154.204.180.237] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200823; rev:1;) alert tcp $HOME_NET any -> [37.49.230.198] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200824; rev:1;) alert tcp $HOME_NET any -> [193.47.61.249] 1024 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200825; rev:1;) alert tcp $HOME_NET any -> [91.109.188.2] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200826; rev:1;) alert tcp $HOME_NET any -> [212.83.173.68] 2576 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200827; rev:1;) alert tcp $HOME_NET any -> [20.166.62.124] 49264 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200828; rev:1;) alert tcp $HOME_NET any -> [20.166.62.124] 49264 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200829; rev:1;) alert tcp $HOME_NET any -> [172.86.120.138] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200830; rev:1;) alert tcp $HOME_NET any -> [114.116.34.118] 7777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200831; rev:1;) alert tcp $HOME_NET any -> [91.227.113.154] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200832; rev:1;) alert tcp $HOME_NET any -> [91.109.178.9] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200833; rev:1;) alert tcp $HOME_NET any -> [190.2.147.39] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200834; rev:1;) alert tcp $HOME_NET any -> [107.182.129.146] 4343 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200835; rev:1;) alert tcp $HOME_NET any -> [107.182.129.146] 6000 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200836; rev:1;) alert tcp $HOME_NET any -> [92.99.178.55] 1444 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200837; rev:1;) alert tcp $HOME_NET any -> [20.8.122.174] 31682 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200838; rev:1;) alert tcp $HOME_NET any -> [149.102.129.194] 22 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200839; rev:1;) alert tcp $HOME_NET any -> [209.25.141.180] 52932 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200840; rev:1;) alert tcp $HOME_NET any -> [20.238.78.172] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200841; rev:1;) alert tcp $HOME_NET any -> [101.99.94.203] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200842; rev:1;) alert tcp $HOME_NET any -> [51.83.137.127] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200843; rev:1;) alert tcp $HOME_NET any -> [173.234.105.145] 5201 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200844; rev:1;) alert tcp $HOME_NET any -> [179.43.187.19] 4523 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200845; rev:1;) alert tcp $HOME_NET any -> [45.142.213.194] 44352 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200846; rev:1;) alert tcp $HOME_NET any -> [20.169.8.10] 5877 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200847; rev:1;) alert tcp $HOME_NET any -> [1.15.67.80] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200848; rev:1;) alert tcp $HOME_NET any -> [171.22.30.33] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200849; rev:1;) alert tcp $HOME_NET any -> [109.206.241.84] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200850; rev:1;) alert tcp $HOME_NET any -> [188.114.96.0] 2053 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200851; rev:1;) alert tcp $HOME_NET any -> [103.149.201.214] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200852; rev:1;) alert tcp $HOME_NET any -> [194.61.119.50] 8884 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200853; rev:1;) alert tcp $HOME_NET any -> [15.204.13.245] 5000 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200854; rev:1;) alert tcp $HOME_NET any -> [192.3.76.153] 5200 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200855; rev:1;) alert tcp $HOME_NET any -> [20.127.173.166] 8973 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200856; rev:1;) alert tcp $HOME_NET any -> [20.127.173.166] 8973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200857; rev:1;) alert tcp $HOME_NET any -> [41.216.183.61] 8973 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200858; rev:1;) alert tcp $HOME_NET any -> [20.240.61.211] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200859; rev:1;) alert tcp $HOME_NET any -> [20.212.19.59] 51585 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200860; rev:1;) alert tcp $HOME_NET any -> [162.19.131.197] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200861; rev:1;) alert tcp $HOME_NET any -> [103.125.190.185] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200862; rev:1;) alert tcp $HOME_NET any -> [92.222.212.65] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200863; rev:1;) alert tcp $HOME_NET any -> [147.50.253.97] 8454 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200864; rev:1;) alert tcp $HOME_NET any -> [18.189.106.45] 13405 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200865; rev:1;) alert tcp $HOME_NET any -> [154.16.67.29] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200866; rev:1;) alert tcp $HOME_NET any -> [175.10.103.11] 8443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200867; rev:1;) alert tcp $HOME_NET any -> [107.174.212.121] 5005 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200868; rev:1;) alert tcp $HOME_NET any -> [82.65.64.66] 1234 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200869; rev:1;) alert tcp $HOME_NET any -> [3.69.115.178] 12104 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200870; rev:1;) alert tcp $HOME_NET any -> [192.3.101.108] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200871; rev:1;) alert tcp $HOME_NET any -> [20.16.8.148] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200872; rev:1;) alert tcp $HOME_NET any -> [20.107.115.162] 50239 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200873; rev:1;) alert tcp $HOME_NET any -> [77.34.128.25] 8080 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200874; rev:1;) alert tcp $HOME_NET any -> [171.235.66.23] 233 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200875; rev:1;) alert tcp $HOME_NET any -> [45.76.184.89] 90 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200876; rev:1;) alert tcp $HOME_NET any -> [13.59.15.185] 19091 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200877; rev:1;) alert tcp $HOME_NET any -> [181.141.1.86] 1994 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200878; rev:1;) alert tcp $HOME_NET any -> [80.66.88.146] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200879; rev:1;) alert tcp $HOME_NET any -> [45.76.184.89] 92 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200880; rev:1;) alert tcp $HOME_NET any -> [20.205.136.175] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200881; rev:1;) alert tcp $HOME_NET any -> [64.44.167.136] 46452 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200882; rev:1;) alert tcp $HOME_NET any -> [20.98.138.214] 2288 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200883; rev:1;) alert tcp $HOME_NET any -> [103.74.101.124] 2245 (msg:"SSLBL: Traffic to malicious host (likely Vjw0rm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200884; rev:1;) alert tcp $HOME_NET any -> [173.225.115.99] 7702 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200885; rev:1;) alert tcp $HOME_NET any -> [185.248.140.146] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200886; rev:1;) alert tcp $HOME_NET any -> [45.82.179.76] 4499 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200887; rev:1;) alert tcp $HOME_NET any -> [45.14.13.20] 4499 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200888; rev:1;) alert tcp $HOME_NET any -> [45.61.136.197] 443 (msg:"SSLBL: Traffic to malicious host (likely DoNot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200889; rev:1;) alert tcp $HOME_NET any -> [44.192.67.149] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200890; rev:1;) alert tcp $HOME_NET any -> [37.0.14.203] 1905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200891; rev:1;) alert tcp $HOME_NET any -> [179.13.3.107] 4203 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200892; rev:1;) alert tcp $HOME_NET any -> [80.76.51.137] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200893; rev:1;) alert tcp $HOME_NET any -> [95.107.48.217] 6666 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200894; rev:1;) alert tcp $HOME_NET any -> [45.154.98.214] 6606 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200895; rev:1;) alert tcp $HOME_NET any -> [20.111.19.215] 3152 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200896; rev:1;) alert tcp $HOME_NET any -> [2.59.119.84] 7943 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200897; rev:1;) alert tcp $HOME_NET any -> [86.63.204.69] 5000 (msg:"SSLBL: Traffic to malicious host (likely AveMariaRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200898; rev:1;) alert tcp $HOME_NET any -> [20.171.107.243] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200899; rev:1;) alert tcp $HOME_NET any -> [190.123.44.184] 8201 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200900; rev:1;) alert tcp $HOME_NET any -> [64.44.135.174] 105 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200901; rev:1;) alert tcp $HOME_NET any -> [39.107.242.96] 47820 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200902; rev:1;) alert tcp $HOME_NET any -> [102.159.236.65] 90 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200903; rev:1;) alert tcp $HOME_NET any -> [3.72.110.63] 9087 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200904; rev:1;) alert tcp $HOME_NET any -> [159.223.57.212] 8471 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200905; rev:1;) alert tcp $HOME_NET any -> [85.31.46.207] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200906; rev:1;) alert tcp $HOME_NET any -> [66.94.108.214] 6655 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200907; rev:1;) alert tcp $HOME_NET any -> [18.192.31.165] 10108 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200908; rev:1;) alert tcp $HOME_NET any -> [54.84.208.91] 58466 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200909; rev:1;) alert tcp $HOME_NET any -> [209.25.141.180] 56956 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200910; rev:1;) alert tcp $HOME_NET any -> [209.127.186.218] 6305 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200911; rev:1;) alert tcp $HOME_NET any -> [151.80.238.28] 6606 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200912; rev:1;) alert tcp $HOME_NET any -> [146.70.101.97] 8080 (msg:"SSLBL: Traffic to malicious host (likely Meterpreter C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200913; rev:1;) alert tcp $HOME_NET any -> [188.227.57.46] 22 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200914; rev:1;) alert tcp $HOME_NET any -> [40.90.168.244] 9909 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200915; rev:1;) alert tcp $HOME_NET any -> [20.42.114.46] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200916; rev:1;) alert tcp $HOME_NET any -> [207.32.218.123] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200917; rev:1;) alert tcp $HOME_NET any -> [79.134.225.22] 7936 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200918; rev:1;) alert tcp $HOME_NET any -> [91.109.178.7] 7505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200919; rev:1;) alert tcp $HOME_NET any -> [172.94.11.178] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200920; rev:1;) alert tcp $HOME_NET any -> [91.151.88.159] 3131 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200921; rev:1;) alert tcp $HOME_NET any -> [45.154.98.87] 8453 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200922; rev:1;) alert tcp $HOME_NET any -> [93.177.103.26] 1992 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200923; rev:1;) alert tcp $HOME_NET any -> [43.142.80.49] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200924; rev:1;) alert tcp $HOME_NET any -> [3.69.115.178] 10448 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200925; rev:1;) alert tcp $HOME_NET any -> [51.38.112.16] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200926; rev:1;) alert tcp $HOME_NET any -> [149.248.52.31] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200927; rev:1;) alert tcp $HOME_NET any -> [115.75.66.68] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200928; rev:1;) alert tcp $HOME_NET any -> [85.217.145.55] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200929; rev:1;) alert tcp $HOME_NET any -> [64.44.98.23] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200930; rev:1;) alert tcp $HOME_NET any -> [43.129.88.120] 60002 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200931; rev:1;) alert tcp $HOME_NET any -> [213.152.162.181] 50548 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200932; rev:1;) alert tcp $HOME_NET any -> [194.9.172.60] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200933; rev:1;) alert tcp $HOME_NET any -> [119.23.227.43] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200934; rev:1;) alert tcp $HOME_NET any -> [192.158.232.67] 1431 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200935; rev:1;) alert tcp $HOME_NET any -> [185.225.73.150] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200936; rev:1;) alert tcp $HOME_NET any -> [35.193.72.139] 6877 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200937; rev:1;) alert tcp $HOME_NET any -> [195.178.120.187] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200938; rev:1;) alert tcp $HOME_NET any -> [50.54.215.55] 4444 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200939; rev:1;) alert tcp $HOME_NET any -> [89.23.97.5] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200940; rev:1;) alert tcp $HOME_NET any -> [123.160.10.39] 60756 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200941; rev:1;) alert tcp $HOME_NET any -> [161.97.106.212] 6655 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200942; rev:1;) alert tcp $HOME_NET any -> [213.152.161.5] 6397 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200943; rev:1;) alert tcp $HOME_NET any -> [79.134.225.115] 6061 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200944; rev:1;) alert tcp $HOME_NET any -> [164.92.113.92] 9007 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200945; rev:1;) alert tcp $HOME_NET any -> [37.0.14.196] 2050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200946; rev:1;) alert tcp $HOME_NET any -> [107.182.129.16] 8010 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200947; rev:1;) alert tcp $HOME_NET any -> [52.220.121.212] 15817 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200948; rev:1;) alert tcp $HOME_NET any -> [59.22.167.217] 13345 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200949; rev:1;) alert tcp $HOME_NET any -> [176.232.184.98] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200950; rev:1;) alert tcp $HOME_NET any -> [45.140.146.241] 443 (msg:"SSLBL: Traffic to malicious host (likely RM3 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200951; rev:1;) alert tcp $HOME_NET any -> [5.182.37.136] 443 (msg:"SSLBL: Traffic to malicious host (likely RM3 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200952; rev:1;) alert tcp $HOME_NET any -> [31.214.245.229] 3399 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200953; rev:1;) alert tcp $HOME_NET any -> [34.125.93.181] 8080 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200954; rev:1;) alert tcp $HOME_NET any -> [3.125.115.192] 18 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200955; rev:1;) alert tcp $HOME_NET any -> [212.114.52.212] 1893 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200956; rev:1;) alert tcp $HOME_NET any -> [76.8.53.133] 62520 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200957; rev:1;) alert tcp $HOME_NET any -> [91.109.188.12] 7505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200958; rev:1;) alert tcp $HOME_NET any -> [176.124.213.115] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200959; rev:1;) alert tcp $HOME_NET any -> [194.26.192.190] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200960; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 52307 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200961; rev:1;) alert tcp $HOME_NET any -> [38.17.51.104] 1989 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200962; rev:1;) alert tcp $HOME_NET any -> [185.105.237.113] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200963; rev:1;) alert tcp $HOME_NET any -> [20.199.43.130] 3421 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200964; rev:1;) alert tcp $HOME_NET any -> [45.95.11.50] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200965; rev:1;) alert tcp $HOME_NET any -> [124.223.14.242] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200966; rev:1;) alert tcp $HOME_NET any -> [194.5.97.232] 3738 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200967; rev:1;) alert tcp $HOME_NET any -> [52.88.36.247] 50679 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200968; rev:1;) alert tcp $HOME_NET any -> [124.221.219.55] 4433 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200969; rev:1;) alert tcp $HOME_NET any -> [190.123.45.9] 443 (msg:"SSLBL: Traffic to malicious host (likely IceXLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200970; rev:1;) alert tcp $HOME_NET any -> [87.251.79.117] 10101 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200971; rev:1;) alert tcp $HOME_NET any -> [147.185.221.180] 25384 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200972; rev:1;) alert tcp $HOME_NET any -> [23.101.213.237] 4546 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200973; rev:1;) alert tcp $HOME_NET any -> [191.101.30.16] 2323 (msg:"SSLBL: Traffic to malicious host (likely Vjw0rm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200974; rev:1;) alert tcp $HOME_NET any -> [3.219.26.62] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200975; rev:1;) alert tcp $HOME_NET any -> [18.207.218.15] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200976; rev:1;) alert tcp $HOME_NET any -> [95.13.149.131] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200977; rev:1;) alert tcp $HOME_NET any -> [185.236.78.58] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200978; rev:1;) alert tcp $HOME_NET any -> [124.222.98.55] 3000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200979; rev:1;) alert tcp $HOME_NET any -> [18.169.191.45] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200980; rev:1;) alert tcp $HOME_NET any -> [185.225.73.183] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200981; rev:1;) alert tcp $HOME_NET any -> [191.101.130.243] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200982; rev:1;) alert tcp $HOME_NET any -> [61.14.233.88] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200983; rev:1;) alert tcp $HOME_NET any -> [185.173.34.75] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200984; rev:1;) alert tcp $HOME_NET any -> [182.186.88.126] 6907 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200985; rev:1;) alert tcp $HOME_NET any -> [77.91.72.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200986; rev:1;) alert tcp $HOME_NET any -> [103.207.36.123] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200987; rev:1;) alert tcp $HOME_NET any -> [20.12.204.46] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200988; rev:1;) alert tcp $HOME_NET any -> [213.152.162.149] 46525 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200989; rev:1;) alert tcp $HOME_NET any -> [109.206.241.81] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200990; rev:1;) alert tcp $HOME_NET any -> [185.112.83.206] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200991; rev:1;) alert tcp $HOME_NET any -> [185.236.78.58] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200992; rev:1;) alert tcp $HOME_NET any -> [179.43.187.131] 6000 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200993; rev:1;) alert tcp $HOME_NET any -> [173.234.155.109] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200994; rev:1;) alert tcp $HOME_NET any -> [20.127.4.172] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200995; rev:1;) alert tcp $HOME_NET any -> [38.105.209.167] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200996; rev:1;) alert tcp $HOME_NET any -> [77.192.68.90] 1900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200997; rev:1;) alert tcp $HOME_NET any -> [185.141.63.211] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200998; rev:1;) alert tcp $HOME_NET any -> [186.169.80.56] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905200999; rev:1;) alert tcp $HOME_NET any -> [86.106.74.55] 54966 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201000; rev:1;) alert tcp $HOME_NET any -> [62.210.57.2] 1284 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201001; rev:1;) alert tcp $HOME_NET any -> [165.22.226.149] 8008 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201002; rev:1;) alert tcp $HOME_NET any -> [108.62.118.133] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201003; rev:1;) alert tcp $HOME_NET any -> [51.12.89.205] 8361 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201004; rev:1;) alert tcp $HOME_NET any -> [172.93.193.21] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201005; rev:1;) alert tcp $HOME_NET any -> [62.108.37.84] 8881 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201006; rev:1;) alert tcp $HOME_NET any -> [185.140.53.159] 7659 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201007; rev:1;) alert tcp $HOME_NET any -> [70.36.108.28] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201008; rev:1;) alert tcp $HOME_NET any -> [23.94.82.24] 10240 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201009; rev:1;) alert tcp $HOME_NET any -> [5.181.166.139] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201010; rev:1;) alert tcp $HOME_NET any -> [186.152.129.124] 2113 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201011; rev:1;) alert tcp $HOME_NET any -> [184.75.221.59] 56390 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201012; rev:1;) alert tcp $HOME_NET any -> [184.75.221.59] 3195 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201013; rev:1;) alert tcp $HOME_NET any -> [185.112.83.106] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201014; rev:1;) alert tcp $HOME_NET any -> [45.136.4.99] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201015; rev:1;) alert tcp $HOME_NET any -> [198.23.191.98] 6075 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201016; rev:1;) alert tcp $HOME_NET any -> [23.105.131.196] 9128 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201017; rev:1;) alert tcp $HOME_NET any -> [194.5.97.228] 5069 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201018; rev:1;) alert tcp $HOME_NET any -> [207.32.218.12] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201019; rev:1;) alert tcp $HOME_NET any -> [20.206.75.106] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201020; rev:1;) alert tcp $HOME_NET any -> [160.20.147.52] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201021; rev:1;) alert tcp $HOME_NET any -> [103.133.105.50] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201022; rev:1;) alert tcp $HOME_NET any -> [3.64.4.198] 13315 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201023; rev:1;) alert tcp $HOME_NET any -> [185.156.172.149] 2271 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201024; rev:1;) alert tcp $HOME_NET any -> [203.78.128.202] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201025; rev:1;) alert tcp $HOME_NET any -> [80.253.246.144] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201026; rev:1;) alert tcp $HOME_NET any -> [68.196.160.138] 55552 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201027; rev:1;) alert tcp $HOME_NET any -> [103.142.218.119] 99 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201028; rev:1;) alert tcp $HOME_NET any -> [149.28.31.166] 443 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201029; rev:1;) alert tcp $HOME_NET any -> [62.210.55.136] 3566 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201030; rev:1;) alert tcp $HOME_NET any -> [37.1.222.208] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201031; rev:1;) alert tcp $HOME_NET any -> [185.200.116.219] 9016 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201032; rev:1;) alert tcp $HOME_NET any -> [212.193.30.96] 5022 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201033; rev:1;) alert tcp $HOME_NET any -> [212.114.52.113] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201034; rev:1;) alert tcp $HOME_NET any -> [194.5.98.251] 4598 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201035; rev:1;) alert tcp $HOME_NET any -> [185.222.57.72] 8780 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201036; rev:1;) alert tcp $HOME_NET any -> [185.222.57.72] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201037; rev:1;) alert tcp $HOME_NET any -> [185.222.57.72] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201038; rev:1;) alert tcp $HOME_NET any -> [18.196.41.122] 9087 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201039; rev:1;) alert tcp $HOME_NET any -> [78.173.187.50] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201040; rev:1;) alert tcp $HOME_NET any -> [188.132.156.147] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201041; rev:1;) alert tcp $HOME_NET any -> [2.56.59.146] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201042; rev:1;) alert tcp $HOME_NET any -> [213.248.179.19] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201043; rev:1;) alert tcp $HOME_NET any -> [213.152.162.79] 25256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201044; rev:1;) alert tcp $HOME_NET any -> [3.68.56.232] 12728 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201045; rev:1;) alert tcp $HOME_NET any -> [3.67.15.169] 12728 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201046; rev:1;) alert tcp $HOME_NET any -> [45.134.140.152] 60060 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201047; rev:1;) alert tcp $HOME_NET any -> [3.125.188.168] 12728 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201048; rev:1;) alert tcp $HOME_NET any -> [51.116.125.149] 3537 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201049; rev:1;) alert tcp $HOME_NET any -> [20.54.113.5] 3131 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201050; rev:1;) alert tcp $HOME_NET any -> [192.99.131.239] 25565 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201051; rev:1;) alert tcp $HOME_NET any -> [196.77.237.119] 55555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201052; rev:1;) alert tcp $HOME_NET any -> [62.197.136.167] 1111 (msg:"SSLBL: Traffic to malicious host (likely AgentTesla C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201053; rev:1;) alert tcp $HOME_NET any -> [62.197.136.195] 3333 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201054; rev:1;) alert tcp $HOME_NET any -> [91.192.100.8] 8153 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201055; rev:1;) alert tcp $HOME_NET any -> [185.237.96.105] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201056; rev:1;) alert tcp $HOME_NET any -> [104.168.33.53] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201057; rev:1;) alert tcp $HOME_NET any -> [23.105.131.209] 1137 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201058; rev:1;) alert tcp $HOME_NET any -> [89.246.100.9] 8700 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201059; rev:1;) alert tcp $HOME_NET any -> [104.168.33.53] 8808 (msg:"SSLBL: Traffic to malicious host (likely Vjw0rm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201060; rev:1;) alert tcp $HOME_NET any -> [63.141.237.188] 9954 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201061; rev:1;) alert tcp $HOME_NET any -> [147.135.106.246] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201062; rev:1;) alert tcp $HOME_NET any -> [20.114.139.208] 4498 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201063; rev:1;) alert tcp $HOME_NET any -> [185.140.53.15] 3023 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201064; rev:1;) alert tcp $HOME_NET any -> [74.201.28.166] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201065; rev:1;) alert tcp $HOME_NET any -> [141.255.147.50] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201066; rev:1;) alert tcp $HOME_NET any -> [79.134.225.9] 2349 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201067; rev:1;) alert tcp $HOME_NET any -> [85.239.33.172] 443 (msg:"SSLBL: Traffic to malicious host (likely BumbleBee C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201068; rev:1;) alert tcp $HOME_NET any -> [213.142.151.33] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201069; rev:1;) alert tcp $HOME_NET any -> [203.78.129.202] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201070; rev:1;) alert tcp $HOME_NET any -> [212.192.241.130] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201071; rev:1;) alert tcp $HOME_NET any -> [51.81.105.238] 1981 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201072; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 31639 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201073; rev:1;) alert tcp $HOME_NET any -> [193.233.203.224] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201074; rev:1;) alert tcp $HOME_NET any -> [87.249.134.18] 59004 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201075; rev:1;) alert tcp $HOME_NET any -> [68.235.43.172] 59004 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201076; rev:1;) alert tcp $HOME_NET any -> [67.241.61.219] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201077; rev:1;) alert tcp $HOME_NET any -> [193.233.191.150] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201078; rev:1;) alert tcp $HOME_NET any -> [185.225.28.148] 57652 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201079; rev:1;) alert tcp $HOME_NET any -> [142.126.195.122] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201080; rev:1;) alert tcp $HOME_NET any -> [45.158.77.78] 10135 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201081; rev:1;) alert tcp $HOME_NET any -> [5.39.15.167] 88 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201082; rev:1;) alert tcp $HOME_NET any -> [193.23.160.250] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201083; rev:1;) alert tcp $HOME_NET any -> [212.220.202.104] 1604 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201084; rev:1;) alert tcp $HOME_NET any -> [107.182.128.18] 3030 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201085; rev:1;) alert tcp $HOME_NET any -> [62.204.41.213] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201086; rev:1;) alert tcp $HOME_NET any -> [62.204.41.134] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201087; rev:1;) alert tcp $HOME_NET any -> [62.204.41.212] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201088; rev:1;) alert tcp $HOME_NET any -> [213.226.114.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201089; rev:1;) alert tcp $HOME_NET any -> [106.55.17.200] 62002 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201090; rev:1;) alert tcp $HOME_NET any -> [45.137.22.152] 8472 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201091; rev:1;) alert tcp $HOME_NET any -> [103.147.185.182] 1170 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201092; rev:1;) alert tcp $HOME_NET any -> [119.91.100.114] 7890 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201093; rev:1;) alert tcp $HOME_NET any -> [198.23.200.102] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201094; rev:1;) alert tcp $HOME_NET any -> [193.233.185.161] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201095; rev:1;) alert tcp $HOME_NET any -> [77.247.127.10] 9898 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201096; rev:1;) alert tcp $HOME_NET any -> [96.8.112.20] 3355 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201097; rev:1;) alert tcp $HOME_NET any -> [185.29.8.22] 4444 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201098; rev:1;) alert tcp $HOME_NET any -> [185.66.91.81] 6121 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201099; rev:1;) alert tcp $HOME_NET any -> [45.133.1.152] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201100; rev:1;) alert tcp $HOME_NET any -> [208.109.33.30] 7777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201101; rev:1;) alert tcp $HOME_NET any -> [45.133.1.152] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201102; rev:1;) alert tcp $HOME_NET any -> [104.250.169.66] 1994 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201103; rev:1;) alert tcp $HOME_NET any -> [213.152.187.205] 51833 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201104; rev:1;) alert tcp $HOME_NET any -> [107.175.3.110] 6900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201105; rev:1;) alert tcp $HOME_NET any -> [91.203.192.213] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201106; rev:1;) alert tcp $HOME_NET any -> [193.37.213.16] 443 (msg:"SSLBL: Traffic to malicious host (likely DarkWatchman C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201107; rev:1;) alert tcp $HOME_NET any -> [198.23.145.147] 1137 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201108; rev:1;) alert tcp $HOME_NET any -> [194.147.140.17] 9300 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201109; rev:1;) alert tcp $HOME_NET any -> [208.109.33.30] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201110; rev:1;) alert tcp $HOME_NET any -> [2.56.56.88] 2406 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201111; rev:1;) alert tcp $HOME_NET any -> [80.66.64.42] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201112; rev:1;) alert tcp $HOME_NET any -> [195.2.81.11] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201113; rev:1;) alert tcp $HOME_NET any -> [5.188.90.197] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201114; rev:1;) alert tcp $HOME_NET any -> [85.202.169.140] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201115; rev:1;) alert tcp $HOME_NET any -> [85.202.169.140] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201116; rev:1;) alert tcp $HOME_NET any -> [92.255.111.11] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201117; rev:1;) alert tcp $HOME_NET any -> [62.197.136.69] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201118; rev:1;) alert tcp $HOME_NET any -> [182.186.84.121] 6904 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201119; rev:1;) alert tcp $HOME_NET any -> [5.188.89.1] 443 (msg:"SSLBL: Traffic to malicious host (likely Smoke Loader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201120; rev:1;) alert tcp $HOME_NET any -> [217.195.197.70] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201121; rev:1;) alert tcp $HOME_NET any -> [45.131.109.121] 8080 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201122; rev:1;) alert tcp $HOME_NET any -> [157.90.206.56] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201123; rev:1;) alert tcp $HOME_NET any -> [20.77.254.176] 2200 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201124; rev:1;) alert tcp $HOME_NET any -> [91.109.188.10] 7782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201125; rev:1;) alert tcp $HOME_NET any -> [62.197.136.165] 8080 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201126; rev:1;) alert tcp $HOME_NET any -> [172.93.179.212] 443 (msg:"SSLBL: Traffic to malicious host (likely Neurevt C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201127; rev:1;) alert tcp $HOME_NET any -> [147.189.174.182] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201128; rev:1;) alert tcp $HOME_NET any -> [92.42.46.216] 1996 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201129; rev:1;) alert tcp $HOME_NET any -> [194.31.98.80] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201130; rev:1;) alert tcp $HOME_NET any -> [5.230.68.234] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201131; rev:1;) alert tcp $HOME_NET any -> [51.195.196.86] 8868 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201132; rev:1;) alert tcp $HOME_NET any -> [20.224.162.224] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201133; rev:1;) alert tcp $HOME_NET any -> [2.224.144.191] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201134; rev:1;) alert tcp $HOME_NET any -> [207.32.218.11] 1996 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201135; rev:1;) alert tcp $HOME_NET any -> [37.0.11.155] 4670 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201136; rev:1;) alert tcp $HOME_NET any -> [147.189.168.74] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201137; rev:1;) alert tcp $HOME_NET any -> [194.156.91.122] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201138; rev:1;) alert tcp $HOME_NET any -> [84.54.13.44] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201139; rev:1;) alert tcp $HOME_NET any -> [46.183.220.21] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201140; rev:1;) alert tcp $HOME_NET any -> [85.239.53.9] 443 (msg:"SSLBL: Traffic to malicious host (likely BlackGuard C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201141; rev:1;) alert tcp $HOME_NET any -> [191.101.130.32] 1121 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201142; rev:1;) alert tcp $HOME_NET any -> [20.89.177.186] 21245 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201143; rev:1;) alert tcp $HOME_NET any -> [185.94.29.170] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201144; rev:1;) alert tcp $HOME_NET any -> [37.48.117.136] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201145; rev:1;) alert tcp $HOME_NET any -> [212.174.54.164] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201146; rev:1;) alert tcp $HOME_NET any -> [136.144.41.223] 8394 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201147; rev:1;) alert tcp $HOME_NET any -> [178.255.148.221] 1974 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201148; rev:1;) alert tcp $HOME_NET any -> [23.106.215.217] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201149; rev:1;) alert tcp $HOME_NET any -> [78.142.29.103] 7332 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201150; rev:1;) alert tcp $HOME_NET any -> [3.144.124.4] 7771 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201151; rev:1;) alert tcp $HOME_NET any -> [182.190.87.87] 1555 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201152; rev:1;) alert tcp $HOME_NET any -> [78.186.210.130] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201153; rev:1;) alert tcp $HOME_NET any -> [45.176.91.143] 9001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201154; rev:1;) alert tcp $HOME_NET any -> [156.249.29.8] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201155; rev:1;) alert tcp $HOME_NET any -> [45.242.220.23] 50 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201156; rev:1;) alert tcp $HOME_NET any -> [213.226.114.92] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201157; rev:1;) alert tcp $HOME_NET any -> [205.185.121.4] 8790 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201158; rev:1;) alert tcp $HOME_NET any -> [2.56.56.180] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201159; rev:1;) alert tcp $HOME_NET any -> [185.38.84.34] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201160; rev:1;) alert tcp $HOME_NET any -> [185.199.226.19] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201161; rev:1;) alert tcp $HOME_NET any -> [3.83.129.253] 4747 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201162; rev:1;) alert tcp $HOME_NET any -> [217.64.31.3] 8437 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201163; rev:1;) alert tcp $HOME_NET any -> [45.10.40.116] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201164; rev:1;) alert tcp $HOME_NET any -> [192.236.147.212] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201165; rev:1;) alert tcp $HOME_NET any -> [217.195.197.85] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201166; rev:1;) alert tcp $HOME_NET any -> [84.54.13.124] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201167; rev:1;) alert tcp $HOME_NET any -> [192.236.160.249] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201168; rev:1;) alert tcp $HOME_NET any -> [192.236.176.108] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201169; rev:1;) alert tcp $HOME_NET any -> [212.193.30.144] 7331 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201170; rev:1;) alert tcp $HOME_NET any -> [93.177.75.30] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201171; rev:1;) alert tcp $HOME_NET any -> [185.81.157.169] 2022 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201172; rev:1;) alert tcp $HOME_NET any -> [201.219.204.73] 1882 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201173; rev:1;) alert tcp $HOME_NET any -> [185.171.91.4] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201174; rev:1;) alert tcp $HOME_NET any -> [92.118.36.201] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201175; rev:1;) alert tcp $HOME_NET any -> [51.83.134.252] 17650 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201176; rev:1;) alert tcp $HOME_NET any -> [185.222.57.203] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201177; rev:1;) alert tcp $HOME_NET any -> [107.182.237.14] 58453 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201178; rev:1;) alert tcp $HOME_NET any -> [89.134.228.127] 45000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201179; rev:1;) alert tcp $HOME_NET any -> [3.141.210.37] 12300 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201180; rev:1;) alert tcp $HOME_NET any -> [119.91.99.194] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201181; rev:1;) alert tcp $HOME_NET any -> [3.141.142.211] 10164 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201182; rev:1;) alert tcp $HOME_NET any -> [176.9.31.109] 3674 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201183; rev:1;) alert tcp $HOME_NET any -> [27.50.175.215] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201184; rev:1;) alert tcp $HOME_NET any -> [104.37.172.204] 56777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201185; rev:1;) alert tcp $HOME_NET any -> [8.218.16.104] 65500 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201186; rev:1;) alert tcp $HOME_NET any -> [45.32.26.164] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201187; rev:1;) alert tcp $HOME_NET any -> [192.30.89.51] 29843 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201188; rev:1;) alert tcp $HOME_NET any -> [185.81.157.202] 2535 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201189; rev:1;) alert tcp $HOME_NET any -> [92.118.36.201] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201190; rev:1;) alert tcp $HOME_NET any -> [49.12.0.239] 3760 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201191; rev:1;) alert tcp $HOME_NET any -> [193.29.104.92] 3579 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201192; rev:1;) alert tcp $HOME_NET any -> [5.249.161.198] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201193; rev:1;) alert tcp $HOME_NET any -> [181.130.9.145] 6525 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201194; rev:1;) alert tcp $HOME_NET any -> [2.58.56.184] 1337 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201195; rev:1;) alert tcp $HOME_NET any -> [161.97.148.204] 1604 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201196; rev:1;) alert tcp $HOME_NET any -> [66.135.4.203] 2022 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201197; rev:1;) alert tcp $HOME_NET any -> [2.56.59.189] 8898 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201198; rev:1;) alert tcp $HOME_NET any -> [194.33.45.175] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201199; rev:1;) alert tcp $HOME_NET any -> [141.255.156.118] 2000 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201200; rev:1;) alert tcp $HOME_NET any -> [142.202.240.88] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201201; rev:1;) alert tcp $HOME_NET any -> [185.140.53.63] 8721 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201202; rev:1;) alert tcp $HOME_NET any -> [178.208.94.214] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201203; rev:1;) alert tcp $HOME_NET any -> [103.89.88.236] 1998 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201204; rev:1;) alert tcp $HOME_NET any -> [149.56.43.121] 4199 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201205; rev:1;) alert tcp $HOME_NET any -> [194.104.136.213] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201206; rev:1;) alert tcp $HOME_NET any -> [182.191.220.118] 1555 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201207; rev:1;) alert tcp $HOME_NET any -> [163.123.142.251] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201208; rev:1;) alert tcp $HOME_NET any -> [194.31.98.58] 2405 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201209; rev:1;) alert tcp $HOME_NET any -> [3.132.159.158] 15838 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201210; rev:1;) alert tcp $HOME_NET any -> [185.62.58.85] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201211; rev:1;) alert tcp $HOME_NET any -> [139.60.161.165] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201212; rev:1;) alert tcp $HOME_NET any -> [154.212.139.228] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201213; rev:1;) alert tcp $HOME_NET any -> [95.217.146.171] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201214; rev:1;) alert tcp $HOME_NET any -> [91.240.118.99] 2780 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201215; rev:1;) alert tcp $HOME_NET any -> [91.193.75.135] 47582 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201216; rev:1;) alert tcp $HOME_NET any -> [159.69.234.4] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201217; rev:1;) alert tcp $HOME_NET any -> [89.223.71.59] 5856 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201218; rev:1;) alert tcp $HOME_NET any -> [208.51.61.44] 128 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201219; rev:1;) alert tcp $HOME_NET any -> [212.68.34.230] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201220; rev:1;) alert tcp $HOME_NET any -> [207.32.217.246] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201221; rev:1;) alert tcp $HOME_NET any -> [172.247.14.52] 12530 (msg:"SSLBL: Traffic to malicious host (likely PhoenixRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201222; rev:1;) alert tcp $HOME_NET any -> [144.126.209.63] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201223; rev:1;) alert tcp $HOME_NET any -> [159.69.234.3] 4041 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201224; rev:1;) alert tcp $HOME_NET any -> [159.69.234.3] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201225; rev:1;) alert tcp $HOME_NET any -> [52.15.81.204] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201226; rev:1;) alert tcp $HOME_NET any -> [129.151.83.165] 7177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201227; rev:1;) alert tcp $HOME_NET any -> [41.225.46.176] 1234 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201228; rev:1;) alert tcp $HOME_NET any -> [141.255.144.117] 2000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201229; rev:1;) alert tcp $HOME_NET any -> [85.202.169.69] 4573 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201230; rev:1;) alert tcp $HOME_NET any -> [3.141.177.1] 19070 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201231; rev:1;) alert tcp $HOME_NET any -> [35.170.192.250] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201232; rev:1;) alert tcp $HOME_NET any -> [104.128.189.120] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201233; rev:1;) alert tcp $HOME_NET any -> [45.242.93.241] 5 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201234; rev:1;) alert tcp $HOME_NET any -> [103.153.73.37] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201235; rev:1;) alert tcp $HOME_NET any -> [3.128.107.74] 10328 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201236; rev:1;) alert tcp $HOME_NET any -> [122.186.23.243] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201237; rev:1;) alert tcp $HOME_NET any -> [51.81.142.111] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201238; rev:1;) alert tcp $HOME_NET any -> [193.176.87.152] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201239; rev:1;) alert tcp $HOME_NET any -> [23.146.242.85] 1111 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201240; rev:1;) alert tcp $HOME_NET any -> [62.197.136.175] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201241; rev:1;) alert tcp $HOME_NET any -> [158.69.144.161] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201242; rev:1;) alert tcp $HOME_NET any -> [20.113.159.145] 3162 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201243; rev:1;) alert tcp $HOME_NET any -> [159.65.243.143] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201244; rev:1;) alert tcp $HOME_NET any -> [159.203.126.35] 22339 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201245; rev:1;) alert tcp $HOME_NET any -> [51.222.69.215] 8320 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201246; rev:1;) alert tcp $HOME_NET any -> [2.56.57.55] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201247; rev:1;) alert tcp $HOME_NET any -> [20.111.34.199] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201248; rev:1;) alert tcp $HOME_NET any -> [185.140.53.165] 55441 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201249; rev:1;) alert tcp $HOME_NET any -> [147.50.253.67] 3926 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201250; rev:1;) alert tcp $HOME_NET any -> [193.124.57.113] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201251; rev:1;) alert tcp $HOME_NET any -> [185.140.53.60] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201252; rev:1;) alert tcp $HOME_NET any -> [5.230.70.13] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201253; rev:1;) alert tcp $HOME_NET any -> [212.192.246.87] 5803 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201254; rev:1;) alert tcp $HOME_NET any -> [23.100.22.106] 5877 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201255; rev:1;) alert tcp $HOME_NET any -> [62.197.136.175] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201256; rev:1;) alert tcp $HOME_NET any -> [158.69.152.26] 54329 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201257; rev:1;) alert tcp $HOME_NET any -> [20.69.124.187] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201258; rev:1;) alert tcp $HOME_NET any -> [146.70.51.37] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201259; rev:1;) alert tcp $HOME_NET any -> [94.103.87.238] 10135 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201260; rev:1;) alert tcp $HOME_NET any -> [101.99.94.33] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201261; rev:1;) alert tcp $HOME_NET any -> [194.127.179.167] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201262; rev:1;) alert tcp $HOME_NET any -> [194.5.98.120] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201263; rev:1;) alert tcp $HOME_NET any -> [91.245.255.120] 4040 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201264; rev:1;) alert tcp $HOME_NET any -> [185.61.151.24] 1177 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201265; rev:1;) alert tcp $HOME_NET any -> [185.140.53.198] 62748 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201266; rev:1;) alert tcp $HOME_NET any -> [41.234.46.29] 1338 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201267; rev:1;) alert tcp $HOME_NET any -> [45.61.184.36] 5050 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201268; rev:1;) alert tcp $HOME_NET any -> [104.215.84.159] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201269; rev:1;) alert tcp $HOME_NET any -> [15.235.10.108] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201270; rev:1;) alert tcp $HOME_NET any -> [5.95.206.230] 1609 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201271; rev:1;) alert tcp $HOME_NET any -> [51.178.13.102] 8324 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201272; rev:1;) alert tcp $HOME_NET any -> [15.235.13.122] 3000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201273; rev:1;) alert tcp $HOME_NET any -> [185.162.74.65] 4044 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201274; rev:1;) alert tcp $HOME_NET any -> [15.235.10.108] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201275; rev:1;) alert tcp $HOME_NET any -> [185.162.74.65] 5455 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201276; rev:1;) alert tcp $HOME_NET any -> [91.193.75.176] 7469 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201277; rev:1;) alert tcp $HOME_NET any -> [103.153.157.33] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201278; rev:1;) alert tcp $HOME_NET any -> [139.162.103.105] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201279; rev:1;) alert tcp $HOME_NET any -> [5.34.178.178] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201280; rev:1;) alert tcp $HOME_NET any -> [212.192.246.239] 1001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201281; rev:1;) alert tcp $HOME_NET any -> [185.14.31.158] 443 (msg:"SSLBL: Traffic to malicious host (likely Matanbuchus C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201282; rev:1;) alert tcp $HOME_NET any -> [212.192.246.239] 8000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201283; rev:1;) alert tcp $HOME_NET any -> [66.29.141.227] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201284; rev:1;) alert tcp $HOME_NET any -> [18.189.106.45] 12394 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201285; rev:1;) alert tcp $HOME_NET any -> [5.161.76.198] 2003 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201286; rev:1;) alert tcp $HOME_NET any -> [20.83.245.27] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201287; rev:1;) alert tcp $HOME_NET any -> [212.192.246.239] 228 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201288; rev:1;) alert tcp $HOME_NET any -> [37.0.10.214] 6171 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201289; rev:1;) alert tcp $HOME_NET any -> [172.245.94.220] 10090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201290; rev:1;) alert tcp $HOME_NET any -> [2.56.59.53] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201291; rev:1;) alert tcp $HOME_NET any -> [3.128.107.74] 16030 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201292; rev:1;) alert tcp $HOME_NET any -> [195.133.18.32] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201293; rev:1;) alert tcp $HOME_NET any -> [89.238.150.43] 57095 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201294; rev:1;) alert tcp $HOME_NET any -> [3.134.125.175] 17709 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201295; rev:1;) alert tcp $HOME_NET any -> [141.95.89.79] 2005 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201296; rev:1;) alert tcp $HOME_NET any -> [2.56.59.167] 420 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201297; rev:1;) alert tcp $HOME_NET any -> [41.102.117.114] 500 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201298; rev:1;) alert tcp $HOME_NET any -> [5.230.72.132] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201299; rev:1;) alert tcp $HOME_NET any -> [185.29.8.124] 54882 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201300; rev:1;) alert tcp $HOME_NET any -> [137.117.100.173] 443 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201301; rev:1;) alert tcp $HOME_NET any -> [194.5.98.120] 8647 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201302; rev:1;) alert tcp $HOME_NET any -> [78.191.189.97] 81 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201303; rev:1;) alert tcp $HOME_NET any -> [78.171.150.184] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201304; rev:1;) alert tcp $HOME_NET any -> [135.148.74.241] 8080 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201305; rev:1;) alert tcp $HOME_NET any -> [52.188.19.78] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201306; rev:1;) alert tcp $HOME_NET any -> [167.71.7.168] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201307; rev:1;) alert tcp $HOME_NET any -> [185.222.57.80] 6275 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201308; rev:1;) alert tcp $HOME_NET any -> [162.33.177.154] 706 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201309; rev:1;) alert tcp $HOME_NET any -> [3.142.81.166] 18921 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201310; rev:1;) alert tcp $HOME_NET any -> [45.138.99.3] 3796 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201311; rev:1;) alert tcp $HOME_NET any -> [138.201.2.2] 2022 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201312; rev:1;) alert tcp $HOME_NET any -> [104.243.37.4] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201313; rev:1;) alert tcp $HOME_NET any -> [23.94.159.212] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201314; rev:1;) alert tcp $HOME_NET any -> [191.101.130.4] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201315; rev:1;) alert tcp $HOME_NET any -> [217.64.149.171] 9009 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201316; rev:1;) alert tcp $HOME_NET any -> [195.242.111.73] 8848 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201317; rev:1;) alert tcp $HOME_NET any -> [14.32.99.105] 808 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201318; rev:1;) alert tcp $HOME_NET any -> [212.192.241.87] 3678 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201319; rev:1;) alert tcp $HOME_NET any -> [212.192.241.194] 7271 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201320; rev:1;) alert tcp $HOME_NET any -> [212.192.241.51] 9173 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201321; rev:1;) alert tcp $HOME_NET any -> [193.142.146.212] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201322; rev:1;) alert tcp $HOME_NET any -> [88.248.18.120] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201323; rev:1;) alert tcp $HOME_NET any -> [2.56.57.210] 7787 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201324; rev:1;) alert tcp $HOME_NET any -> [79.18.45.237] 1900 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201325; rev:1;) alert tcp $HOME_NET any -> [3.91.91.127] 3071 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201326; rev:1;) alert tcp $HOME_NET any -> [2.58.149.136] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201327; rev:1;) alert tcp $HOME_NET any -> [45.32.92.219] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201328; rev:1;) alert tcp $HOME_NET any -> [144.126.129.113] 54809 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201329; rev:1;) alert tcp $HOME_NET any -> [136.144.41.207] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201330; rev:1;) alert tcp $HOME_NET any -> [172.94.118.99] 1117 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201331; rev:1;) alert tcp $HOME_NET any -> [20.108.44.45] 3152 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201332; rev:1;) alert tcp $HOME_NET any -> [193.164.7.108] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201333; rev:1;) alert tcp $HOME_NET any -> [146.19.57.77] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201334; rev:1;) alert tcp $HOME_NET any -> [3.22.30.40] 16416 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201335; rev:1;) alert tcp $HOME_NET any -> [181.141.3.105] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201336; rev:1;) alert tcp $HOME_NET any -> [94.130.208.107] 2021 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201337; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 27383 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201338; rev:1;) alert tcp $HOME_NET any -> [89.238.150.43] 5512 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201339; rev:1;) alert tcp $HOME_NET any -> [14.32.99.105] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201340; rev:1;) alert tcp $HOME_NET any -> [20.124.111.166] 2223 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201341; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 23636 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201342; rev:1;) alert tcp $HOME_NET any -> [154.16.248.173] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201343; rev:1;) alert tcp $HOME_NET any -> [185.20.187.18] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201344; rev:1;) alert tcp $HOME_NET any -> [193.149.3.239] 1938 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201345; rev:1;) alert tcp $HOME_NET any -> [107.172.44.141] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201346; rev:1;) alert tcp $HOME_NET any -> [35.195.10.252] 443 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201347; rev:1;) alert tcp $HOME_NET any -> [185.7.214.8] 4449 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201348; rev:1;) alert tcp $HOME_NET any -> [23.19.58.166] 21501 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201349; rev:1;) alert tcp $HOME_NET any -> [179.13.1.253] 8055 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201350; rev:1;) alert tcp $HOME_NET any -> [103.151.239.166] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201351; rev:1;) alert tcp $HOME_NET any -> [135.125.27.236] 22 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201352; rev:1;) alert tcp $HOME_NET any -> [177.153.55.100] 443 (msg:"SSLBL: Traffic to malicious host (likely Ousaban C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201353; rev:1;) alert tcp $HOME_NET any -> [194.180.174.113] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201354; rev:1;) alert tcp $HOME_NET any -> [185.140.53.161] 6600 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201355; rev:1;) alert tcp $HOME_NET any -> [84.140.101.75] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201356; rev:1;) alert tcp $HOME_NET any -> [107.182.128.19] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201357; rev:1;) alert tcp $HOME_NET any -> [103.89.89.172] 5200 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201358; rev:1;) alert tcp $HOME_NET any -> [107.182.128.19] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201359; rev:1;) alert tcp $HOME_NET any -> [34.140.211.85] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201360; rev:1;) alert tcp $HOME_NET any -> [185.140.53.242] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201361; rev:1;) alert tcp $HOME_NET any -> [185.140.53.137] 2331 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201362; rev:1;) alert tcp $HOME_NET any -> [5.68.138.73] 3939 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201363; rev:1;) alert tcp $HOME_NET any -> [103.133.111.110] 5200 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201364; rev:1;) alert tcp $HOME_NET any -> [103.133.111.110] 5200 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201365; rev:1;) alert tcp $HOME_NET any -> [104.41.145.218] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201366; rev:1;) alert tcp $HOME_NET any -> [79.110.52.215] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201367; rev:1;) alert tcp $HOME_NET any -> [79.110.52.217] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201368; rev:1;) alert tcp $HOME_NET any -> [216.126.224.171] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201369; rev:1;) alert tcp $HOME_NET any -> [2.59.119.56] 3131 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201370; rev:1;) alert tcp $HOME_NET any -> [23.106.122.216] 8808 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201371; rev:1;) alert tcp $HOME_NET any -> [38.130.221.190] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201372; rev:1;) alert tcp $HOME_NET any -> [191.101.130.175] 7663 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201373; rev:1;) alert tcp $HOME_NET any -> [185.163.45.124] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201374; rev:1;) alert tcp $HOME_NET any -> [194.5.98.25] 3389 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201375; rev:1;) alert tcp $HOME_NET any -> [193.56.146.74] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201376; rev:1;) alert tcp $HOME_NET any -> [193.56.146.73] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201377; rev:1;) alert tcp $HOME_NET any -> [193.56.146.72] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201378; rev:1;) alert tcp $HOME_NET any -> [129.151.91.127] 7177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201379; rev:1;) alert tcp $HOME_NET any -> [194.124.76.239] 50354 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201380; rev:1;) alert tcp $HOME_NET any -> [185.140.53.50] 3472 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201381; rev:1;) alert tcp $HOME_NET any -> [2.56.56.122] 2022 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201382; rev:1;) alert tcp $HOME_NET any -> [185.81.157.254] 1010 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201383; rev:1;) alert tcp $HOME_NET any -> [3.138.180.119] 18729 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201384; rev:1;) alert tcp $HOME_NET any -> [194.85.248.211] 1337 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201385; rev:1;) alert tcp $HOME_NET any -> [84.38.130.171] 9216 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201386; rev:1;) alert tcp $HOME_NET any -> [13.66.153.98] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201387; rev:1;) alert tcp $HOME_NET any -> [3.94.85.211] 1177 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201388; rev:1;) alert tcp $HOME_NET any -> [185.244.30.237] 1195 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201389; rev:1;) alert tcp $HOME_NET any -> [194.104.136.42] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201390; rev:1;) alert tcp $HOME_NET any -> [91.151.94.59] 1212 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201391; rev:1;) alert tcp $HOME_NET any -> [20.151.221.59] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201392; rev:1;) alert tcp $HOME_NET any -> [74.119.195.9] 4821 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201393; rev:1;) alert tcp $HOME_NET any -> [194.85.248.114] 3462 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201394; rev:1;) alert tcp $HOME_NET any -> [136.144.41.186] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201395; rev:1;) alert tcp $HOME_NET any -> [129.151.93.162] 7177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201396; rev:1;) alert tcp $HOME_NET any -> [168.119.140.238] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201397; rev:1;) alert tcp $HOME_NET any -> [91.192.10.70] 63803 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201398; rev:1;) alert tcp $HOME_NET any -> [185.19.85.149] 4898 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201399; rev:1;) alert tcp $HOME_NET any -> [5.181.156.19] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201400; rev:1;) alert tcp $HOME_NET any -> [93.190.8.71] 3131 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201401; rev:1;) alert tcp $HOME_NET any -> [45.72.78.38] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201402; rev:1;) alert tcp $HOME_NET any -> [94.26.90.47] 2030 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201403; rev:1;) alert tcp $HOME_NET any -> [185.92.74.18] 3391 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201404; rev:1;) alert tcp $HOME_NET any -> [89.44.9.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201405; rev:1;) alert tcp $HOME_NET any -> [54.233.90.128] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201406; rev:1;) alert tcp $HOME_NET any -> [98.238.116.145] 30815 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201407; rev:1;) alert tcp $HOME_NET any -> [116.202.14.219] 443 (msg:"SSLBL: Traffic to malicious host (likely ArkeiStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201408; rev:1;) alert tcp $HOME_NET any -> [152.89.162.59] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201409; rev:1;) alert tcp $HOME_NET any -> [20.113.26.85] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201410; rev:1;) alert tcp $HOME_NET any -> [20.199.120.149] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201411; rev:1;) alert tcp $HOME_NET any -> [37.0.11.190] 7358 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201412; rev:1;) alert tcp $HOME_NET any -> [88.235.10.23] 9812 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201413; rev:1;) alert tcp $HOME_NET any -> [31.220.44.253] 28754 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201414; rev:1;) alert tcp $HOME_NET any -> [192.3.121.153] 7917 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201415; rev:1;) alert tcp $HOME_NET any -> [91.208.206.44] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201416; rev:1;) alert tcp $HOME_NET any -> [84.201.188.187] 666 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201417; rev:1;) alert tcp $HOME_NET any -> [45.144.225.178] 1616 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201418; rev:1;) alert tcp $HOME_NET any -> [74.201.73.122] 10600 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201419; rev:1;) alert tcp $HOME_NET any -> [194.5.97.149] 2050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201420; rev:1;) alert tcp $HOME_NET any -> [37.0.11.53] 7719 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201421; rev:1;) alert tcp $HOME_NET any -> [194.5.97.54] 4449 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201422; rev:1;) alert tcp $HOME_NET any -> [95.217.25.51] 443 (msg:"SSLBL: Traffic to malicious host (likely ArkeiStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201423; rev:1;) alert tcp $HOME_NET any -> [31.210.20.192] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201424; rev:1;) alert tcp $HOME_NET any -> [197.26.105.145] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201425; rev:1;) alert tcp $HOME_NET any -> [45.144.225.192] 1008 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201426; rev:1;) alert tcp $HOME_NET any -> [79.134.225.29] 2331 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201427; rev:1;) alert tcp $HOME_NET any -> [5.181.80.10] 443 (msg:"SSLBL: Traffic to malicious host (likely VoidLogger traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201428; rev:1;) alert tcp $HOME_NET any -> [88.214.56.192] 2021 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201429; rev:1;) alert tcp $HOME_NET any -> [41.79.11.214] 61032 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201430; rev:1;) alert tcp $HOME_NET any -> [107.175.178.6] 7277 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201431; rev:1;) alert tcp $HOME_NET any -> [136.144.41.24] 3091 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201432; rev:1;) alert tcp $HOME_NET any -> [173.225.115.240] 3333 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201433; rev:1;) alert tcp $HOME_NET any -> [5.230.70.106] 1560 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201434; rev:1;) alert tcp $HOME_NET any -> [136.144.41.203] 1008 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201435; rev:1;) alert tcp $HOME_NET any -> [34.68.50.44] 8888 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201436; rev:1;) alert tcp $HOME_NET any -> [191.91.177.6] 7784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201437; rev:1;) alert tcp $HOME_NET any -> [41.36.83.211] 1440 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201438; rev:1;) alert tcp $HOME_NET any -> [89.248.173.187] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201439; rev:1;) alert tcp $HOME_NET any -> [212.192.246.217] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201440; rev:1;) alert tcp $HOME_NET any -> [212.192.241.135] 4449 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201441; rev:1;) alert tcp $HOME_NET any -> [185.19.85.155] 1609 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201442; rev:1;) alert tcp $HOME_NET any -> [91.193.75.132] 5529 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201443; rev:1;) alert tcp $HOME_NET any -> [40.88.44.226] 2223 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201444; rev:1;) alert tcp $HOME_NET any -> [213.227.155.219] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201445; rev:1;) alert tcp $HOME_NET any -> [96.9.210.115] 4449 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201446; rev:1;) alert tcp $HOME_NET any -> [207.32.218.40] 5505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201447; rev:1;) alert tcp $HOME_NET any -> [185.163.45.157] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201448; rev:1;) alert tcp $HOME_NET any -> [185.170.144.51] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201449; rev:1;) alert tcp $HOME_NET any -> [74.81.52.179] 2610 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201450; rev:1;) alert tcp $HOME_NET any -> [34.121.150.14] 4542 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201451; rev:1;) alert tcp $HOME_NET any -> [185.127.19.10] 80 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201452; rev:1;) alert tcp $HOME_NET any -> [185.140.53.129] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201453; rev:1;) alert tcp $HOME_NET any -> [136.144.41.115] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201454; rev:1;) alert tcp $HOME_NET any -> [136.144.41.115] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201455; rev:1;) alert tcp $HOME_NET any -> [23.105.171.80] 33957 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201456; rev:1;) alert tcp $HOME_NET any -> [136.144.41.115] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201457; rev:1;) alert tcp $HOME_NET any -> [136.144.41.42] 6703 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201458; rev:1;) alert tcp $HOME_NET any -> [91.193.75.132] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201459; rev:1;) alert tcp $HOME_NET any -> [202.55.133.118] 5200 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201460; rev:1;) alert tcp $HOME_NET any -> [178.20.226.121] 404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201461; rev:1;) alert tcp $HOME_NET any -> [91.92.109.70] 5353 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201462; rev:1;) alert tcp $HOME_NET any -> [185.29.11.28] 43147 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201463; rev:1;) alert tcp $HOME_NET any -> [212.192.246.236] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201464; rev:1;) alert tcp $HOME_NET any -> [3.121.139.82] 19858 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201465; rev:1;) alert tcp $HOME_NET any -> [185.222.57.71] 783 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201466; rev:1;) alert tcp $HOME_NET any -> [103.167.90.172] 6275 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201467; rev:1;) alert tcp $HOME_NET any -> [110.40.185.35] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201468; rev:1;) alert tcp $HOME_NET any -> [45.130.41.15] 443 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201469; rev:1;) alert tcp $HOME_NET any -> [91.151.88.146] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201470; rev:1;) alert tcp $HOME_NET any -> [52.183.37.26] 1452 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201471; rev:1;) alert tcp $HOME_NET any -> [178.20.40.235] 7777 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201472; rev:1;) alert tcp $HOME_NET any -> [85.209.87.175] 8668 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201473; rev:1;) alert tcp $HOME_NET any -> [194.5.97.212] 1199 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201474; rev:1;) alert tcp $HOME_NET any -> [185.250.148.54] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201475; rev:1;) alert tcp $HOME_NET any -> [40.90.210.21] 3054 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201476; rev:1;) alert tcp $HOME_NET any -> [45.137.22.70] 36374 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201477; rev:1;) alert tcp $HOME_NET any -> [185.222.58.154] 6275 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201478; rev:1;) alert tcp $HOME_NET any -> [194.127.178.3] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201479; rev:1;) alert tcp $HOME_NET any -> [194.127.178.3] 3578 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201480; rev:1;) alert tcp $HOME_NET any -> [178.238.8.157] 9091 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201481; rev:1;) alert tcp $HOME_NET any -> [195.133.40.157] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201482; rev:1;) alert tcp $HOME_NET any -> [78.135.85.3] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201483; rev:1;) alert tcp $HOME_NET any -> [185.222.58.151] 59790 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201484; rev:1;) alert tcp $HOME_NET any -> [185.222.58.154] 45216 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201485; rev:1;) alert tcp $HOME_NET any -> [104.37.175.107] 2003 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201486; rev:1;) alert tcp $HOME_NET any -> [37.120.222.175] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201487; rev:1;) alert tcp $HOME_NET any -> [79.134.225.36] 4044 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201488; rev:1;) alert tcp $HOME_NET any -> [185.222.58.151] 59668 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201489; rev:1;) alert tcp $HOME_NET any -> [185.222.58.154] 51390 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201490; rev:1;) alert tcp $HOME_NET any -> [193.29.104.96] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201491; rev:1;) alert tcp $HOME_NET any -> [185.157.160.136] 1973 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201492; rev:1;) alert tcp $HOME_NET any -> [193.29.104.92] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201493; rev:1;) alert tcp $HOME_NET any -> [185.19.85.171] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201494; rev:1;) alert tcp $HOME_NET any -> [45.137.22.70] 24626 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201495; rev:1;) alert tcp $HOME_NET any -> [91.151.94.60] 1212 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201496; rev:1;) alert tcp $HOME_NET any -> [20.36.20.111] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201497; rev:1;) alert tcp $HOME_NET any -> [52.144.47.89] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201498; rev:1;) alert tcp $HOME_NET any -> [193.187.91.102] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201499; rev:1;) alert tcp $HOME_NET any -> [45.133.1.54] 43417 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201500; rev:1;) alert tcp $HOME_NET any -> [207.32.217.158] 2021 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201501; rev:1;) alert tcp $HOME_NET any -> [45.137.22.115] 14496 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201502; rev:1;) alert tcp $HOME_NET any -> [47.96.125.245] 45002 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201503; rev:1;) alert tcp $HOME_NET any -> [37.120.222.178] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201504; rev:1;) alert tcp $HOME_NET any -> [46.183.221.26] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201505; rev:1;) alert tcp $HOME_NET any -> [180.214.239.36] 6090 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201506; rev:1;) alert tcp $HOME_NET any -> [185.163.45.248] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201507; rev:1;) alert tcp $HOME_NET any -> [65.108.23.97] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201508; rev:1;) alert tcp $HOME_NET any -> [181.141.1.250] 2424 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201509; rev:1;) alert tcp $HOME_NET any -> [45.95.169.112] 7760 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201510; rev:1;) alert tcp $HOME_NET any -> [185.19.85.133] 5529 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201511; rev:1;) alert tcp $HOME_NET any -> [185.157.160.136] 1975 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201512; rev:1;) alert tcp $HOME_NET any -> [213.152.186.24] 16941 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201513; rev:1;) alert tcp $HOME_NET any -> [64.56.68.30] 5885 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201514; rev:1;) alert tcp $HOME_NET any -> [2.133.130.23] 443 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201515; rev:1;) alert tcp $HOME_NET any -> [94.158.245.140] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201516; rev:1;) alert tcp $HOME_NET any -> [20.203.173.201] 58110 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201517; rev:1;) alert tcp $HOME_NET any -> [45.133.1.179] 442 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201518; rev:1;) alert tcp $HOME_NET any -> [212.192.246.4] 5523 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201519; rev:1;) alert tcp $HOME_NET any -> [45.133.1.47] 3264 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201520; rev:1;) alert tcp $HOME_NET any -> [45.95.168.110] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201521; rev:1;) alert tcp $HOME_NET any -> [142.202.240.117] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201522; rev:1;) alert tcp $HOME_NET any -> [139.99.244.21] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201523; rev:1;) alert tcp $HOME_NET any -> [23.105.131.212] 4409 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201524; rev:1;) alert tcp $HOME_NET any -> [194.5.98.135] 5900 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201525; rev:1;) alert tcp $HOME_NET any -> [168.90.65.230] 5552 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201526; rev:1;) alert tcp $HOME_NET any -> [31.210.20.187] 43417 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201527; rev:1;) alert tcp $HOME_NET any -> [14.17.115.109] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201528; rev:1;) alert tcp $HOME_NET any -> [45.144.225.194] 2424 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201529; rev:1;) alert tcp $HOME_NET any -> [185.195.79.212] 5656 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201530; rev:1;) alert tcp $HOME_NET any -> [193.187.91.115] 1234 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201531; rev:1;) alert tcp $HOME_NET any -> [185.215.113.62] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201532; rev:1;) alert tcp $HOME_NET any -> [2.56.59.227] 8081 (msg:"SSLBL: Traffic to malicious host (likely hVNC C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201533; rev:1;) alert tcp $HOME_NET any -> [2.56.59.227] 8082 (msg:"SSLBL: Traffic to malicious host (likely hVNC C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201534; rev:1;) alert tcp $HOME_NET any -> [2.56.59.227] 8083 (msg:"SSLBL: Traffic to malicious host (likely hVNC C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201535; rev:1;) alert tcp $HOME_NET any -> [23.227.202.152] 446 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201536; rev:1;) alert tcp $HOME_NET any -> [23.82.19.235] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201537; rev:1;) alert tcp $HOME_NET any -> [185.195.25.72] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201538; rev:1;) alert tcp $HOME_NET any -> [136.144.41.171] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201539; rev:1;) alert tcp $HOME_NET any -> [2.59.119.75] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201540; rev:1;) alert tcp $HOME_NET any -> [141.95.6.169] 9404 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201541; rev:1;) alert tcp $HOME_NET any -> [156.146.50.177] 25727 (msg:"SSLBL: Traffic to malicious host (likely DcRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201542; rev:1;) alert tcp $HOME_NET any -> [178.200.180.146] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201543; rev:1;) alert tcp $HOME_NET any -> [154.48.237.186] 8808 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201544; rev:1;) alert tcp $HOME_NET any -> [89.40.13.195] 4908 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201545; rev:1;) alert tcp $HOME_NET any -> [172.94.16.182] 6060 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201546; rev:1;) alert tcp $HOME_NET any -> [194.5.98.33] 55441 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201547; rev:1;) alert tcp $HOME_NET any -> [45.142.215.144] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201548; rev:1;) alert tcp $HOME_NET any -> [103.96.131.29] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201549; rev:1;) alert tcp $HOME_NET any -> [185.222.57.204] 8787 (msg:"SSLBL: Traffic to malicious host (likely Vjw0rm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201550; rev:1;) alert tcp $HOME_NET any -> [3.138.228.94] 24138 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201551; rev:1;) alert tcp $HOME_NET any -> [107.173.219.111] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201552; rev:1;) alert tcp $HOME_NET any -> [81.31.197.143] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201553; rev:1;) alert tcp $HOME_NET any -> [87.90.86.173] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201554; rev:1;) alert tcp $HOME_NET any -> [176.159.113.196] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201555; rev:1;) alert tcp $HOME_NET any -> [199.195.253.181] 50721 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201556; rev:1;) alert tcp $HOME_NET any -> [216.108.228.52] 1100 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201557; rev:1;) alert tcp $HOME_NET any -> [185.205.210.40] 1337 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201558; rev:1;) alert tcp $HOME_NET any -> [195.133.95.3] 2874 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201559; rev:1;) alert tcp $HOME_NET any -> [84.252.95.55] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201560; rev:1;) alert tcp $HOME_NET any -> [79.69.56.209] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201561; rev:1;) alert tcp $HOME_NET any -> [84.38.129.115] 43147 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201562; rev:1;) alert tcp $HOME_NET any -> [185.53.46.9] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201563; rev:1;) alert tcp $HOME_NET any -> [45.142.212.34] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201564; rev:1;) alert tcp $HOME_NET any -> [194.127.179.131] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201565; rev:1;) alert tcp $HOME_NET any -> [35.177.17.33] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201566; rev:1;) alert tcp $HOME_NET any -> [194.163.152.240] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201567; rev:1;) alert tcp $HOME_NET any -> [51.89.194.152] 7777 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201568; rev:1;) alert tcp $HOME_NET any -> [20.98.113.24] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201569; rev:1;) alert tcp $HOME_NET any -> [178.62.232.196] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201570; rev:1;) alert tcp $HOME_NET any -> [45.76.189.89] 5555 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201571; rev:1;) alert tcp $HOME_NET any -> [136.144.41.83] 4102 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201572; rev:1;) alert tcp $HOME_NET any -> [37.0.11.177] 4444 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201573; rev:1;) alert tcp $HOME_NET any -> [195.85.201.65] 6106 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201574; rev:1;) alert tcp $HOME_NET any -> [212.129.30.248] 6000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201575; rev:1;) alert tcp $HOME_NET any -> [23.106.223.154] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201576; rev:1;) alert tcp $HOME_NET any -> [45.77.214.96] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201577; rev:1;) alert tcp $HOME_NET any -> [3.138.45.170] 12214 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201578; rev:1;) alert tcp $HOME_NET any -> [5.196.174.49] 433 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201579; rev:1;) alert tcp $HOME_NET any -> [172.67.156.42] 443 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201580; rev:1;) alert tcp $HOME_NET any -> [2.56.59.239] 7355 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201581; rev:1;) alert tcp $HOME_NET any -> [104.21.64.226] 443 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201582; rev:1;) alert tcp $HOME_NET any -> [203.159.80.52] 5800 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201583; rev:1;) alert tcp $HOME_NET any -> [103.72.4.163] 27011 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201584; rev:1;) alert tcp $HOME_NET any -> [188.215.229.22] 8900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201585; rev:1;) alert tcp $HOME_NET any -> [179.43.140.136] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201586; rev:1;) alert tcp $HOME_NET any -> [91.151.88.245] 2070 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201587; rev:1;) alert tcp $HOME_NET any -> [61.69.245.176] 42069 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201588; rev:1;) alert tcp $HOME_NET any -> [20.199.121.197] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201589; rev:1;) alert tcp $HOME_NET any -> [45.146.253.103] 420 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201590; rev:1;) alert tcp $HOME_NET any -> [18.189.143.187] 7777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201591; rev:1;) alert tcp $HOME_NET any -> [99.75.73.147] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201592; rev:1;) alert tcp $HOME_NET any -> [88.99.219.185] 4041 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201593; rev:1;) alert tcp $HOME_NET any -> [45.137.22.104] 1190 (msg:"SSLBL: Traffic to malicious host (likely Vjw0rm C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201594; rev:1;) alert tcp $HOME_NET any -> [185.33.234.96] 2306 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201595; rev:1;) alert tcp $HOME_NET any -> [47.94.3.159] 4455 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201596; rev:1;) alert tcp $HOME_NET any -> [136.244.94.164] 3132 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201597; rev:1;) alert tcp $HOME_NET any -> [37.0.10.63] 6236 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201598; rev:1;) alert tcp $HOME_NET any -> [91.241.48.250] 2001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201599; rev:1;) alert tcp $HOME_NET any -> [84.38.129.118] 43413 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201600; rev:1;) alert tcp $HOME_NET any -> [46.166.173.94] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201601; rev:1;) alert tcp $HOME_NET any -> [37.0.11.183] 4444 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201602; rev:1;) alert tcp $HOME_NET any -> [144.126.129.113] 27742 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201603; rev:1;) alert tcp $HOME_NET any -> [179.43.187.144] 1111 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201604; rev:1;) alert tcp $HOME_NET any -> [79.134.225.103] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201605; rev:1;) alert tcp $HOME_NET any -> [179.43.141.103] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201606; rev:1;) alert tcp $HOME_NET any -> [79.134.225.103] 6443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201607; rev:1;) alert tcp $HOME_NET any -> [213.152.162.154] 43763 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201608; rev:1;) alert tcp $HOME_NET any -> [13.213.3.159] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201609; rev:1;) alert tcp $HOME_NET any -> [195.133.40.51] 5867 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201610; rev:1;) alert tcp $HOME_NET any -> [20.197.177.229] 6821 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201611; rev:1;) alert tcp $HOME_NET any -> [45.9.148.138] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201612; rev:1;) alert tcp $HOME_NET any -> [18.133.124.202] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201613; rev:1;) alert tcp $HOME_NET any -> [37.0.8.220] 161 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201614; rev:1;) alert tcp $HOME_NET any -> [37.0.11.221] 4444 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201615; rev:1;) alert tcp $HOME_NET any -> [179.43.141.119] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201616; rev:1;) alert tcp $HOME_NET any -> [213.152.162.15] 6751 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201617; rev:1;) alert tcp $HOME_NET any -> [185.215.113.102] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201618; rev:1;) alert tcp $HOME_NET any -> [85.23.139.64] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201619; rev:1;) alert tcp $HOME_NET any -> [185.157.161.53] 97 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201620; rev:1;) alert tcp $HOME_NET any -> [172.81.61.36] 5656 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201621; rev:1;) alert tcp $HOME_NET any -> [3.131.147.49] 11296 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201622; rev:1;) alert tcp $HOME_NET any -> [184.90.251.249] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201623; rev:1;) alert tcp $HOME_NET any -> [13.53.37.168] 777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201624; rev:1;) alert tcp $HOME_NET any -> [93.108.180.0] 4444 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201625; rev:1;) alert tcp $HOME_NET any -> [94.60.124.63] 4444 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201626; rev:1;) alert tcp $HOME_NET any -> [5.181.234.150] 9090 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201627; rev:1;) alert tcp $HOME_NET any -> [139.28.218.235] 62316 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201628; rev:1;) alert tcp $HOME_NET any -> [3.21.21.95] 6518 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201629; rev:1;) alert tcp $HOME_NET any -> [145.249.106.195] 7355 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201630; rev:1;) alert tcp $HOME_NET any -> [185.157.161.248] 1975 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201631; rev:1;) alert tcp $HOME_NET any -> [185.163.204.212] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201632; rev:1;) alert tcp $HOME_NET any -> [212.192.246.250] 4480 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201633; rev:1;) alert tcp $HOME_NET any -> [5.253.84.122] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201634; rev:1;) alert tcp $HOME_NET any -> [179.43.187.188] 4056 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201635; rev:1;) alert tcp $HOME_NET any -> [148.251.67.180] 5505 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201636; rev:1;) alert tcp $HOME_NET any -> [185.163.45.186] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201637; rev:1;) alert tcp $HOME_NET any -> [51.254.31.10] 1718 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201638; rev:1;) alert tcp $HOME_NET any -> [23.105.131.217] 83 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201639; rev:1;) alert tcp $HOME_NET any -> [185.140.53.134] 7565 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201640; rev:1;) alert tcp $HOME_NET any -> [103.195.239.218] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201641; rev:1;) alert tcp $HOME_NET any -> [194.33.45.44] 1414 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201642; rev:1;) alert tcp $HOME_NET any -> [45.147.230.80] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201643; rev:1;) alert tcp $HOME_NET any -> [112.126.60.177] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201644; rev:1;) alert tcp $HOME_NET any -> [194.5.97.107] 8921 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201645; rev:1;) alert tcp $HOME_NET any -> [13.76.94.179] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201646; rev:1;) alert tcp $HOME_NET any -> [185.244.36.230] 1236 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201647; rev:1;) alert tcp $HOME_NET any -> [115.79.199.11] 4444 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201648; rev:1;) alert tcp $HOME_NET any -> [192.121.245.48] 9083 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201649; rev:1;) alert tcp $HOME_NET any -> [8.39.147.87] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201650; rev:1;) alert tcp $HOME_NET any -> [188.120.251.116] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201651; rev:1;) alert tcp $HOME_NET any -> [194.180.174.56] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201652; rev:1;) alert tcp $HOME_NET any -> [45.153.241.244] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201653; rev:1;) alert tcp $HOME_NET any -> [31.210.21.114] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201654; rev:1;) alert tcp $HOME_NET any -> [54.209.199.171] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201655; rev:1;) alert tcp $HOME_NET any -> [194.5.97.94] 7116 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201656; rev:1;) alert tcp $HOME_NET any -> [34.125.20.14] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201657; rev:1;) alert tcp $HOME_NET any -> [79.134.225.90] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201658; rev:1;) alert tcp $HOME_NET any -> [3.142.129.56] 12750 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201659; rev:1;) alert tcp $HOME_NET any -> [109.248.201.153] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201660; rev:1;) alert tcp $HOME_NET any -> [109.248.201.153] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201661; rev:1;) alert tcp $HOME_NET any -> [37.0.10.19] 5678 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201662; rev:1;) alert tcp $HOME_NET any -> [192.227.128.168] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201663; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 3050 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201664; rev:1;) alert tcp $HOME_NET any -> [194.180.174.20] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201665; rev:1;) alert tcp $HOME_NET any -> [43.224.33.42] 8888 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201666; rev:1;) alert tcp $HOME_NET any -> [141.101.134.51] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201667; rev:1;) alert tcp $HOME_NET any -> [103.140.250.132] 9178 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201668; rev:1;) alert tcp $HOME_NET any -> [147.182.222.233] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201669; rev:1;) alert tcp $HOME_NET any -> [3.139.72.79] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201670; rev:1;) alert tcp $HOME_NET any -> [185.186.244.200] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201671; rev:1;) alert tcp $HOME_NET any -> [203.145.171.102] 9999 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201672; rev:1;) alert tcp $HOME_NET any -> [185.19.85.177] 1981 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201673; rev:1;) alert tcp $HOME_NET any -> [51.75.191.89] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201674; rev:1;) alert tcp $HOME_NET any -> [52.252.234.34] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201675; rev:1;) alert tcp $HOME_NET any -> [37.0.10.62] 6992 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201676; rev:1;) alert tcp $HOME_NET any -> [5.63.154.248] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201677; rev:1;) alert tcp $HOME_NET any -> [91.109.180.7] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201678; rev:1;) alert tcp $HOME_NET any -> [91.109.190.5] 2002 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201679; rev:1;) alert tcp $HOME_NET any -> [91.121.214.19] 1605 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201680; rev:1;) alert tcp $HOME_NET any -> [213.238.172.124] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201681; rev:1;) alert tcp $HOME_NET any -> [91.109.180.10] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201682; rev:1;) alert tcp $HOME_NET any -> [217.146.88.139] 5220 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201683; rev:1;) alert tcp $HOME_NET any -> [213.152.162.170] 55928 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201684; rev:1;) alert tcp $HOME_NET any -> [166.62.33.218] 6624 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201685; rev:1;) alert tcp $HOME_NET any -> [185.157.161.248] 1973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201686; rev:1;) alert tcp $HOME_NET any -> [185.29.11.39] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201687; rev:1;) alert tcp $HOME_NET any -> [23.95.13.189] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201688; rev:1;) alert tcp $HOME_NET any -> [194.5.98.105] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201689; rev:1;) alert tcp $HOME_NET any -> [194.58.108.89] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201690; rev:1;) alert tcp $HOME_NET any -> [8.208.102.114] 80 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201691; rev:1;) alert tcp $HOME_NET any -> [18.185.84.88] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201692; rev:1;) alert tcp $HOME_NET any -> [120.26.87.95] 9999 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201693; rev:1;) alert tcp $HOME_NET any -> [5.181.156.15] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201694; rev:1;) alert tcp $HOME_NET any -> [5.181.156.15] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201695; rev:1;) alert tcp $HOME_NET any -> [8.209.67.224] 80 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201696; rev:1;) alert tcp $HOME_NET any -> [177.126.146.148] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201697; rev:1;) alert tcp $HOME_NET any -> [94.158.245.250] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201698; rev:1;) alert tcp $HOME_NET any -> [31.14.40.172] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201699; rev:1;) alert tcp $HOME_NET any -> [37.0.8.248] 5900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201700; rev:1;) alert tcp $HOME_NET any -> [37.0.8.248] 18 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201701; rev:1;) alert tcp $HOME_NET any -> [61.14.233.111] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201702; rev:1;) alert tcp $HOME_NET any -> [194.5.97.150] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201703; rev:1;) alert tcp $HOME_NET any -> [45.137.22.58] 1780 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201704; rev:1;) alert tcp $HOME_NET any -> [103.73.64.115] 9700 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201705; rev:1;) alert tcp $HOME_NET any -> [194.5.98.72] 2405 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201706; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 26369 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201707; rev:1;) alert tcp $HOME_NET any -> [37.221.121.20] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201708; rev:1;) alert tcp $HOME_NET any -> [185.140.53.6] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201709; rev:1;) alert tcp $HOME_NET any -> [143.198.58.231] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201710; rev:1;) alert tcp $HOME_NET any -> [143.198.78.177] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201711; rev:1;) alert tcp $HOME_NET any -> [45.140.17.75] 10443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201712; rev:1;) alert tcp $HOME_NET any -> [185.87.51.159] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201713; rev:1;) alert tcp $HOME_NET any -> [5.180.107.130] 1234 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201714; rev:1;) alert tcp $HOME_NET any -> [91.109.180.8] 25874 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201715; rev:1;) alert tcp $HOME_NET any -> [8.208.27.150] 4550 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201716; rev:1;) alert tcp $HOME_NET any -> [198.244.169.192] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201717; rev:1;) alert tcp $HOME_NET any -> [45.14.50.120] 8808 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201718; rev:1;) alert tcp $HOME_NET any -> [54.37.125.37] 1111 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201719; rev:1;) alert tcp $HOME_NET any -> [77.136.120.46] 4783 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201720; rev:1;) alert tcp $HOME_NET any -> [194.5.97.223] 1981 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201721; rev:1;) alert tcp $HOME_NET any -> [84.38.129.103] 43413 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201722; rev:1;) alert tcp $HOME_NET any -> [162.244.82.93] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201723; rev:1;) alert tcp $HOME_NET any -> [74.201.28.134] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201724; rev:1;) alert tcp $HOME_NET any -> [5.196.153.54] 4204 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201725; rev:1;) alert tcp $HOME_NET any -> [20.69.152.28] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201726; rev:1;) alert tcp $HOME_NET any -> [20.98.203.218] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201727; rev:1;) alert tcp $HOME_NET any -> [195.123.233.106] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201728; rev:1;) alert tcp $HOME_NET any -> [13.52.241.196] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201729; rev:1;) alert tcp $HOME_NET any -> [185.244.30.143] 31337 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201730; rev:1;) alert tcp $HOME_NET any -> [52.27.77.148] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201731; rev:1;) alert tcp $HOME_NET any -> [13.52.98.56] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201732; rev:1;) alert tcp $HOME_NET any -> [34.79.1.9] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201733; rev:1;) alert tcp $HOME_NET any -> [216.250.252.218] 5505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201734; rev:1;) alert tcp $HOME_NET any -> [191.101.130.145] 2880 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201735; rev:1;) alert tcp $HOME_NET any -> [142.44.145.208] 6060 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201736; rev:1;) alert tcp $HOME_NET any -> [45.119.84.166] 3303 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201737; rev:1;) alert tcp $HOME_NET any -> [172.241.29.21] 3389 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201738; rev:1;) alert tcp $HOME_NET any -> [37.0.10.6] 6620 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201739; rev:1;) alert tcp $HOME_NET any -> [45.140.17.74] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201740; rev:1;) alert tcp $HOME_NET any -> [79.134.225.22] 7890 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201741; rev:1;) alert tcp $HOME_NET any -> [185.29.11.40] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201742; rev:1;) alert tcp $HOME_NET any -> [91.109.186.4] 25874 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201743; rev:1;) alert tcp $HOME_NET any -> [212.192.241.41] 6841 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201744; rev:1;) alert tcp $HOME_NET any -> [91.109.190.7] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201745; rev:1;) alert tcp $HOME_NET any -> [211.152.146.87] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201746; rev:1;) alert tcp $HOME_NET any -> [20.52.33.123] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201747; rev:1;) alert tcp $HOME_NET any -> [80.209.229.141] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201748; rev:1;) alert tcp $HOME_NET any -> [77.204.204.154] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201749; rev:1;) alert tcp $HOME_NET any -> [213.226.119.176] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201750; rev:1;) alert tcp $HOME_NET any -> [103.147.184.73] 7920 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201751; rev:1;) alert tcp $HOME_NET any -> [212.192.241.19] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201752; rev:1;) alert tcp $HOME_NET any -> [193.32.219.170] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201753; rev:1;) alert tcp $HOME_NET any -> [147.189.171.186] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201754; rev:1;) alert tcp $HOME_NET any -> [178.238.8.174] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201755; rev:1;) alert tcp $HOME_NET any -> [79.134.225.35] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201756; rev:1;) alert tcp $HOME_NET any -> [61.14.233.111] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201757; rev:1;) alert tcp $HOME_NET any -> [185.140.53.192] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201758; rev:1;) alert tcp $HOME_NET any -> [151.106.56.110] 36000 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201759; rev:1;) alert tcp $HOME_NET any -> [212.129.4.112] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201760; rev:1;) alert tcp $HOME_NET any -> [37.0.8.108] 8080 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201761; rev:1;) alert tcp $HOME_NET any -> [79.134.225.44] 7450 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201762; rev:1;) alert tcp $HOME_NET any -> [82.118.22.1] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201763; rev:1;) alert tcp $HOME_NET any -> [182.186.23.252] 6905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201764; rev:1;) alert tcp $HOME_NET any -> [35.223.81.165] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201765; rev:1;) alert tcp $HOME_NET any -> [79.134.225.52] 600 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201766; rev:1;) alert tcp $HOME_NET any -> [185.87.51.159] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201767; rev:1;) alert tcp $HOME_NET any -> [185.14.31.245] 443 (msg:"SSLBL: Traffic to malicious host (likely RedLineStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201768; rev:1;) alert tcp $HOME_NET any -> [142.4.200.50] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201769; rev:1;) alert tcp $HOME_NET any -> [37.0.11.99] 6620 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201770; rev:1;) alert tcp $HOME_NET any -> [74.201.28.32] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201771; rev:1;) alert tcp $HOME_NET any -> [20.88.54.36] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201772; rev:1;) alert tcp $HOME_NET any -> [211.152.146.73] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201773; rev:1;) alert tcp $HOME_NET any -> [94.158.245.113] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201774; rev:1;) alert tcp $HOME_NET any -> [203.205.191.21] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201775; rev:1;) alert tcp $HOME_NET any -> [91.216.190.111] 4433 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201776; rev:1;) alert tcp $HOME_NET any -> [54.185.45.48] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201777; rev:1;) alert tcp $HOME_NET any -> [185.244.30.28] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201778; rev:1;) alert tcp $HOME_NET any -> [35.165.197.209] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201779; rev:1;) alert tcp $HOME_NET any -> [3.101.57.185] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201780; rev:1;) alert tcp $HOME_NET any -> [178.79.130.185] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201781; rev:1;) alert tcp $HOME_NET any -> [160.176.133.93] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201782; rev:1;) alert tcp $HOME_NET any -> [185.64.106.64] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201783; rev:1;) alert tcp $HOME_NET any -> [91.109.180.3] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201784; rev:1;) alert tcp $HOME_NET any -> [91.109.190.9] 25874 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201785; rev:1;) alert tcp $HOME_NET any -> [45.155.205.208] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201786; rev:1;) alert tcp $HOME_NET any -> [45.195.8.100] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201787; rev:1;) alert tcp $HOME_NET any -> [67.242.2.35] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201788; rev:1;) alert tcp $HOME_NET any -> [67.242.2.35] 8808 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201789; rev:1;) alert tcp $HOME_NET any -> [194.5.98.15] 5162 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201790; rev:1;) alert tcp $HOME_NET any -> [91.193.75.202] 11011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201791; rev:1;) alert tcp $HOME_NET any -> [37.0.8.191] 55714 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201792; rev:1;) alert tcp $HOME_NET any -> [80.253.247.232] 1638 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201793; rev:1;) alert tcp $HOME_NET any -> [185.163.45.90] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201794; rev:1;) alert tcp $HOME_NET any -> [13.56.160.68] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201795; rev:1;) alert tcp $HOME_NET any -> [18.237.106.160] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201796; rev:1;) alert tcp $HOME_NET any -> [185.244.30.19] 1120 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201797; rev:1;) alert tcp $HOME_NET any -> [103.158.190.58] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201798; rev:1;) alert tcp $HOME_NET any -> [91.109.190.4] 25874 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201799; rev:1;) alert tcp $HOME_NET any -> [37.0.8.93] 7050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201800; rev:1;) alert tcp $HOME_NET any -> [188.34.203.105] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201801; rev:1;) alert tcp $HOME_NET any -> [105.155.110.220] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201802; rev:1;) alert tcp $HOME_NET any -> [188.255.114.14] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201803; rev:1;) alert tcp $HOME_NET any -> [107.182.237.15] 55736 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201804; rev:1;) alert tcp $HOME_NET any -> [212.192.241.89] 3309 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201805; rev:1;) alert tcp $HOME_NET any -> [51.38.19.195] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201806; rev:1;) alert tcp $HOME_NET any -> [45.147.198.125] 8848 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201807; rev:1;) alert tcp $HOME_NET any -> [103.150.8.21] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201808; rev:1;) alert tcp $HOME_NET any -> [37.120.206.86] 1738 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201809; rev:1;) alert tcp $HOME_NET any -> [37.0.11.45] 448 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201810; rev:1;) alert tcp $HOME_NET any -> [20.80.51.178] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201811; rev:1;) alert tcp $HOME_NET any -> [134.195.89.8] 6666 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201812; rev:1;) alert tcp $HOME_NET any -> [73.138.124.217] 8808 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201813; rev:1;) alert tcp $HOME_NET any -> [185.140.53.194] 1002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201814; rev:1;) alert tcp $HOME_NET any -> [37.0.11.215] 6666 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201815; rev:1;) alert tcp $HOME_NET any -> [79.134.225.22] 7734 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201816; rev:1;) alert tcp $HOME_NET any -> [193.239.85.45] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201817; rev:1;) alert tcp $HOME_NET any -> [45.15.143.171] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201818; rev:1;) alert tcp $HOME_NET any -> [198.23.212.148] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201819; rev:1;) alert tcp $HOME_NET any -> [142.202.189.75] 4040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201820; rev:1;) alert tcp $HOME_NET any -> [3.137.146.78] 777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201821; rev:1;) alert tcp $HOME_NET any -> [37.0.8.20] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201822; rev:1;) alert tcp $HOME_NET any -> [2.56.59.48] 7355 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201823; rev:1;) alert tcp $HOME_NET any -> [162.244.82.93] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201824; rev:1;) alert tcp $HOME_NET any -> [3.137.146.78] 6666 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201825; rev:1;) alert tcp $HOME_NET any -> [172.94.109.9] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201826; rev:1;) alert tcp $HOME_NET any -> [121.107.159.240] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201827; rev:1;) alert tcp $HOME_NET any -> [211.152.146.86] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201828; rev:1;) alert tcp $HOME_NET any -> [211.152.136.71] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201829; rev:1;) alert tcp $HOME_NET any -> [101.33.11.48] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201830; rev:1;) alert tcp $HOME_NET any -> [54.219.112.13] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201831; rev:1;) alert tcp $HOME_NET any -> [167.179.64.216] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201832; rev:1;) alert tcp $HOME_NET any -> [34.213.41.242] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201833; rev:1;) alert tcp $HOME_NET any -> [147.189.170.240] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201834; rev:1;) alert tcp $HOME_NET any -> [172.67.160.253] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201835; rev:1;) alert tcp $HOME_NET any -> [192.121.245.44] 9088 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201836; rev:1;) alert tcp $HOME_NET any -> [20.151.200.9] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201837; rev:1;) alert tcp $HOME_NET any -> [94.156.35.37] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201838; rev:1;) alert tcp $HOME_NET any -> [77.247.127.177] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201839; rev:1;) alert tcp $HOME_NET any -> [106.52.168.175] 4782 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201840; rev:1;) alert tcp $HOME_NET any -> [179.43.175.71] 4444 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201841; rev:1;) alert tcp $HOME_NET any -> [185.157.161.63] 1973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201842; rev:1;) alert tcp $HOME_NET any -> [91.109.178.7] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201843; rev:1;) alert tcp $HOME_NET any -> [173.44.50.139] 58440 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201844; rev:1;) alert tcp $HOME_NET any -> [37.0.8.17] 46422 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201845; rev:1;) alert tcp $HOME_NET any -> [185.163.47.171] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201846; rev:1;) alert tcp $HOME_NET any -> [37.0.11.118] 5423 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201847; rev:1;) alert tcp $HOME_NET any -> [142.202.190.36] 4040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201848; rev:1;) alert tcp $HOME_NET any -> [185.215.113.213] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201849; rev:1;) alert tcp $HOME_NET any -> [193.169.105.94] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201850; rev:1;) alert tcp $HOME_NET any -> [37.61.205.212] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201851; rev:1;) alert tcp $HOME_NET any -> [185.153.222.198] 6471 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201852; rev:1;) alert tcp $HOME_NET any -> [18.224.165.22] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201853; rev:1;) alert tcp $HOME_NET any -> [3.223.125.168] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201854; rev:1;) alert tcp $HOME_NET any -> [45.153.230.139] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201855; rev:1;) alert tcp $HOME_NET any -> [20.80.30.45] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201856; rev:1;) alert tcp $HOME_NET any -> [185.19.85.168] 8888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201857; rev:1;) alert tcp $HOME_NET any -> [45.90.58.179] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201858; rev:1;) alert tcp $HOME_NET any -> [217.12.221.28] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201859; rev:1;) alert tcp $HOME_NET any -> [139.99.126.75] 92 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201860; rev:1;) alert tcp $HOME_NET any -> [167.99.117.21] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201861; rev:1;) alert tcp $HOME_NET any -> [194.5.98.5] 1604 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201862; rev:1;) alert tcp $HOME_NET any -> [1.15.227.181] 9998 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201863; rev:1;) alert tcp $HOME_NET any -> [101.33.11.29] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201864; rev:1;) alert tcp $HOME_NET any -> [185.244.26.213] 9872 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201865; rev:1;) alert tcp $HOME_NET any -> [91.109.180.4] 2002 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201866; rev:1;) alert tcp $HOME_NET any -> [79.134.225.27] 5821 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201867; rev:1;) alert tcp $HOME_NET any -> [91.109.190.3] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201868; rev:1;) alert tcp $HOME_NET any -> [185.29.11.26] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201869; rev:1;) alert tcp $HOME_NET any -> [193.29.104.186] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201870; rev:1;) alert tcp $HOME_NET any -> [91.193.75.199] 11011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201871; rev:1;) alert tcp $HOME_NET any -> [185.163.45.132] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201872; rev:1;) alert tcp $HOME_NET any -> [79.134.225.105] 12123 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201873; rev:1;) alert tcp $HOME_NET any -> [185.163.45.103] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201874; rev:1;) alert tcp $HOME_NET any -> [45.144.154.150] 5900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201875; rev:1;) alert tcp $HOME_NET any -> [112.154.0.240] 3176 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201876; rev:1;) alert tcp $HOME_NET any -> [45.86.163.188] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201877; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 25358 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201878; rev:1;) alert tcp $HOME_NET any -> [203.23.128.143] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201879; rev:1;) alert tcp $HOME_NET any -> [5.189.188.138] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201880; rev:1;) alert tcp $HOME_NET any -> [172.94.109.19] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201881; rev:1;) alert tcp $HOME_NET any -> [91.109.190.12] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201882; rev:1;) alert tcp $HOME_NET any -> [135.148.134.17] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201883; rev:1;) alert tcp $HOME_NET any -> [18.116.230.222] 8787 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201884; rev:1;) alert tcp $HOME_NET any -> [195.133.40.6] 55714 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201885; rev:1;) alert tcp $HOME_NET any -> [45.147.231.41] 5001 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201886; rev:1;) alert tcp $HOME_NET any -> [39.108.60.64] 4443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201887; rev:1;) alert tcp $HOME_NET any -> [206.188.196.143] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201888; rev:1;) alert tcp $HOME_NET any -> [204.16.247.104] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201889; rev:1;) alert tcp $HOME_NET any -> [1.117.154.185] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201890; rev:1;) alert tcp $HOME_NET any -> [194.29.101.219] 9700 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201891; rev:1;) alert tcp $HOME_NET any -> [31.7.63.14] 8957 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201892; rev:1;) alert tcp $HOME_NET any -> [37.0.11.164] 9174 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201893; rev:1;) alert tcp $HOME_NET any -> [216.250.254.208] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201894; rev:1;) alert tcp $HOME_NET any -> [2.56.59.82] 6992 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201895; rev:1;) alert tcp $HOME_NET any -> [185.225.19.100] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201896; rev:1;) alert tcp $HOME_NET any -> [101.33.10.114] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201897; rev:1;) alert tcp $HOME_NET any -> [95.179.142.67] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201898; rev:1;) alert tcp $HOME_NET any -> [23.81.246.58] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201899; rev:1;) alert tcp $HOME_NET any -> [185.140.53.137] 5541 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201900; rev:1;) alert tcp $HOME_NET any -> [209.54.104.73] 8558 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201901; rev:1;) alert tcp $HOME_NET any -> [91.109.190.4] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201902; rev:1;) alert tcp $HOME_NET any -> [91.109.176.4] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201903; rev:1;) alert tcp $HOME_NET any -> [37.221.121.20] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201904; rev:1;) alert tcp $HOME_NET any -> [167.179.90.23] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201905; rev:1;) alert tcp $HOME_NET any -> [74.201.28.127] 9070 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201906; rev:1;) alert tcp $HOME_NET any -> [52.170.189.162] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201907; rev:1;) alert tcp $HOME_NET any -> [45.158.15.231] 1453 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201908; rev:1;) alert tcp $HOME_NET any -> [194.76.226.201] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201909; rev:1;) alert tcp $HOME_NET any -> [51.81.191.248] 1281 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201910; rev:1;) alert tcp $HOME_NET any -> [45.144.154.150] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201911; rev:1;) alert tcp $HOME_NET any -> [107.150.23.186] 8808 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201912; rev:1;) alert tcp $HOME_NET any -> [52.170.189.162] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201913; rev:1;) alert tcp $HOME_NET any -> [31.210.20.167] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201914; rev:1;) alert tcp $HOME_NET any -> [206.166.251.144] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201915; rev:1;) alert tcp $HOME_NET any -> [185.140.53.8] 6060 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201916; rev:1;) alert tcp $HOME_NET any -> [79.134.225.36] 7570 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201917; rev:1;) alert tcp $HOME_NET any -> [74.201.28.60] 4296 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201918; rev:1;) alert tcp $HOME_NET any -> [81.68.105.177] 8848 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201919; rev:1;) alert tcp $HOME_NET any -> [194.5.98.207] 672 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201920; rev:1;) alert tcp $HOME_NET any -> [45.61.137.91] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201921; rev:1;) alert tcp $HOME_NET any -> [8.140.7.162] 48081 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201922; rev:1;) alert tcp $HOME_NET any -> [5.230.84.38] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201923; rev:1;) alert tcp $HOME_NET any -> [185.193.126.226] 8088 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201924; rev:1;) alert tcp $HOME_NET any -> [14.241.72.25] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201925; rev:1;) alert tcp $HOME_NET any -> [185.157.162.119] 57436 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201926; rev:1;) alert tcp $HOME_NET any -> [20.184.2.45] 9208 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201927; rev:1;) alert tcp $HOME_NET any -> [185.244.30.184] 9872 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201928; rev:1;) alert tcp $HOME_NET any -> [54.233.121.202] 8282 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201929; rev:1;) alert tcp $HOME_NET any -> [91.109.190.2] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201930; rev:1;) alert tcp $HOME_NET any -> [45.119.84.166] 5505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201931; rev:1;) alert tcp $HOME_NET any -> [185.163.45.87] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201932; rev:1;) alert tcp $HOME_NET any -> [185.158.113.59] 45324 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201933; rev:1;) alert tcp $HOME_NET any -> [3.143.239.116] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201934; rev:1;) alert tcp $HOME_NET any -> [122.228.4.229] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201935; rev:1;) alert tcp $HOME_NET any -> [206.188.197.49] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201936; rev:1;) alert tcp $HOME_NET any -> [40.118.53.192] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201937; rev:1;) alert tcp $HOME_NET any -> [196.77.30.93] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201938; rev:1;) alert tcp $HOME_NET any -> [104.154.231.62] 5050 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201939; rev:1;) alert tcp $HOME_NET any -> [37.221.121.20] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201940; rev:1;) alert tcp $HOME_NET any -> [203.159.80.216] 8080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201941; rev:1;) alert tcp $HOME_NET any -> [185.244.26.233] 1169 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201942; rev:1;) alert tcp $HOME_NET any -> [18.215.78.203] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201943; rev:1;) alert tcp $HOME_NET any -> [167.99.96.32] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201944; rev:1;) alert tcp $HOME_NET any -> [2.56.59.72] 9264 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201945; rev:1;) alert tcp $HOME_NET any -> [95.111.241.233] 4563 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201946; rev:1;) alert tcp $HOME_NET any -> [185.65.134.182] 15888 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201947; rev:1;) alert tcp $HOME_NET any -> [178.154.244.45] 666 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201948; rev:1;) alert tcp $HOME_NET any -> [91.109.176.5] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201949; rev:1;) alert tcp $HOME_NET any -> [195.133.40.84] 9521 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201950; rev:1;) alert tcp $HOME_NET any -> [103.151.125.18] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201951; rev:1;) alert tcp $HOME_NET any -> [185.222.57.254] 2040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201952; rev:1;) alert tcp $HOME_NET any -> [158.69.138.23] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201953; rev:1;) alert tcp $HOME_NET any -> [34.238.192.43] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201954; rev:1;) alert tcp $HOME_NET any -> [31.7.63.14] 38294 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201955; rev:1;) alert tcp $HOME_NET any -> [176.98.41.115] 1938 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201956; rev:1;) alert tcp $HOME_NET any -> [91.109.188.6] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201957; rev:1;) alert tcp $HOME_NET any -> [136.144.41.46] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201958; rev:1;) alert tcp $HOME_NET any -> [139.99.126.75] 91 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201959; rev:1;) alert tcp $HOME_NET any -> [45.61.137.250] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201960; rev:1;) alert tcp $HOME_NET any -> [45.144.154.150] 59 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201961; rev:1;) alert tcp $HOME_NET any -> [195.133.40.220] 6992 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201962; rev:1;) alert tcp $HOME_NET any -> [45.155.173.48] 5072 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201963; rev:1;) alert tcp $HOME_NET any -> [121.182.123.212] 443 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201964; rev:1;) alert tcp $HOME_NET any -> [91.193.75.135] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201965; rev:1;) alert tcp $HOME_NET any -> [54.37.191.165] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201966; rev:1;) alert tcp $HOME_NET any -> [23.105.131.239] 3861 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201967; rev:1;) alert tcp $HOME_NET any -> [20.98.18.253] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201968; rev:1;) alert tcp $HOME_NET any -> [95.141.215.167] 9009 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201969; rev:1;) alert tcp $HOME_NET any -> [52.221.201.97] 4444 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201970; rev:1;) alert tcp $HOME_NET any -> [185.222.57.233] 2059 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201971; rev:1;) alert tcp $HOME_NET any -> [23.19.227.243] 5505 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201972; rev:1;) alert tcp $HOME_NET any -> [37.120.222.161] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201973; rev:1;) alert tcp $HOME_NET any -> [37.120.222.160] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201974; rev:1;) alert tcp $HOME_NET any -> [158.69.138.23] 5505 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201975; rev:1;) alert tcp $HOME_NET any -> [199.195.253.181] 5200 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201976; rev:1;) alert tcp $HOME_NET any -> [194.5.98.189] 672 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201977; rev:1;) alert tcp $HOME_NET any -> [213.238.172.95] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201978; rev:1;) alert tcp $HOME_NET any -> [37.221.122.76] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201979; rev:1;) alert tcp $HOME_NET any -> [51.89.107.168] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201980; rev:1;) alert tcp $HOME_NET any -> [206.188.196.131] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201981; rev:1;) alert tcp $HOME_NET any -> [212.192.241.59] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201982; rev:1;) alert tcp $HOME_NET any -> [172.94.109.13] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201983; rev:1;) alert tcp $HOME_NET any -> [207.32.218.49] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201984; rev:1;) alert tcp $HOME_NET any -> [139.28.5.19] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201985; rev:1;) alert tcp $HOME_NET any -> [45.131.1.70] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201986; rev:1;) alert tcp $HOME_NET any -> [178.238.8.135] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201987; rev:1;) alert tcp $HOME_NET any -> [178.154.244.45] 777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201988; rev:1;) alert tcp $HOME_NET any -> [178.154.244.45] 2 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201989; rev:1;) alert tcp $HOME_NET any -> [178.20.44.191] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201990; rev:1;) alert tcp $HOME_NET any -> [89.45.6.74] 56060 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201991; rev:1;) alert tcp $HOME_NET any -> [178.154.244.45] 1 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201992; rev:1;) alert tcp $HOME_NET any -> [217.64.151.123] 65431 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201993; rev:1;) alert tcp $HOME_NET any -> [134.122.84.252] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201994; rev:1;) alert tcp $HOME_NET any -> [47.102.37.135] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201995; rev:1;) alert tcp $HOME_NET any -> [193.32.232.64] 7777 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201996; rev:1;) alert tcp $HOME_NET any -> [20.80.31.89] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201997; rev:1;) alert tcp $HOME_NET any -> [212.192.241.225] 5215 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201998; rev:1;) alert tcp $HOME_NET any -> [45.144.154.150] 18 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905201999; rev:1;) alert tcp $HOME_NET any -> [212.114.52.180] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202000; rev:1;) alert tcp $HOME_NET any -> [108.62.118.247] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202001; rev:1;) alert tcp $HOME_NET any -> [45.147.45.184] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202002; rev:1;) alert tcp $HOME_NET any -> [18.117.142.49] 2 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202003; rev:1;) alert tcp $HOME_NET any -> [212.192.241.9] 4455 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202004; rev:1;) alert tcp $HOME_NET any -> [209.126.85.216] 9632 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202005; rev:1;) alert tcp $HOME_NET any -> [95.217.123.5] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202006; rev:1;) alert tcp $HOME_NET any -> [20.199.112.16] 3535 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202007; rev:1;) alert tcp $HOME_NET any -> [216.250.249.156] 1465 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202008; rev:1;) alert tcp $HOME_NET any -> [139.99.126.75] 90 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202009; rev:1;) alert tcp $HOME_NET any -> [192.161.51.191] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202010; rev:1;) alert tcp $HOME_NET any -> [34.216.7.40] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202011; rev:1;) alert tcp $HOME_NET any -> [13.57.228.91] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202012; rev:1;) alert tcp $HOME_NET any -> [91.134.183.121] 4500 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202013; rev:1;) alert tcp $HOME_NET any -> [213.152.161.244] 52090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202014; rev:1;) alert tcp $HOME_NET any -> [138.124.183.144] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202015; rev:1;) alert tcp $HOME_NET any -> [103.151.123.2] 8621 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202016; rev:1;) alert tcp $HOME_NET any -> [103.140.251.225] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202017; rev:1;) alert tcp $HOME_NET any -> [199.195.253.181] 9700 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202018; rev:1;) alert tcp $HOME_NET any -> [138.68.66.197] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202019; rev:1;) alert tcp $HOME_NET any -> [173.44.50.141] 63753 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202020; rev:1;) alert tcp $HOME_NET any -> [136.144.41.246] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202021; rev:1;) alert tcp $HOME_NET any -> [185.100.84.208] 443 (msg:"SSLBL: Traffic to malicious host (likely AceRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202022; rev:1;) alert tcp $HOME_NET any -> [115.78.134.34] 6606 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202023; rev:1;) alert tcp $HOME_NET any -> [176.98.41.49] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202024; rev:1;) alert tcp $HOME_NET any -> [136.144.41.204] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202025; rev:1;) alert tcp $HOME_NET any -> [20.80.15.232] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202026; rev:1;) alert tcp $HOME_NET any -> [194.180.174.41] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202027; rev:1;) alert tcp $HOME_NET any -> [106.15.50.19] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202028; rev:1;) alert tcp $HOME_NET any -> [212.192.241.252] 9264 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202029; rev:1;) alert tcp $HOME_NET any -> [3.68.95.191] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202030; rev:1;) alert tcp $HOME_NET any -> [2.56.212.226] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202031; rev:1;) alert tcp $HOME_NET any -> [45.63.93.115] 4489 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202032; rev:1;) alert tcp $HOME_NET any -> [46.243.150.151] 38259 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202033; rev:1;) alert tcp $HOME_NET any -> [158.69.138.23] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202034; rev:1;) alert tcp $HOME_NET any -> [47.111.13.98] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202035; rev:1;) alert tcp $HOME_NET any -> [31.210.21.21] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202036; rev:1;) alert tcp $HOME_NET any -> [185.186.244.62] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202037; rev:1;) alert tcp $HOME_NET any -> [216.128.183.103] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202038; rev:1;) alert tcp $HOME_NET any -> [91.241.51.141] 2221 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202039; rev:1;) alert tcp $HOME_NET any -> [79.134.225.89] 1991 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202040; rev:1;) alert tcp $HOME_NET any -> [129.151.100.167] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202041; rev:1;) alert tcp $HOME_NET any -> [52.250.60.164] 6821 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202042; rev:1;) alert tcp $HOME_NET any -> [193.169.254.216] 6464 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202043; rev:1;) alert tcp $HOME_NET any -> [152.89.247.208] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202044; rev:1;) alert tcp $HOME_NET any -> [217.165.81.72] 26597 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202045; rev:1;) alert tcp $HOME_NET any -> [160.20.147.106] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202046; rev:1;) alert tcp $HOME_NET any -> [152.89.247.228] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202047; rev:1;) alert tcp $HOME_NET any -> [41.102.231.123] 300 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202048; rev:1;) alert tcp $HOME_NET any -> [103.72.4.166] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202049; rev:1;) alert tcp $HOME_NET any -> [157.230.255.179] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202050; rev:1;) alert tcp $HOME_NET any -> [45.138.157.202] 25565 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202051; rev:1;) alert tcp $HOME_NET any -> [136.144.41.4] 4771 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202052; rev:1;) alert tcp $HOME_NET any -> [3.18.3.168] 963 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202053; rev:1;) alert tcp $HOME_NET any -> [194.5.97.241] 8921 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202054; rev:1;) alert tcp $HOME_NET any -> [212.192.241.42] 4488 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202055; rev:1;) alert tcp $HOME_NET any -> [199.249.230.2] 61653 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202056; rev:1;) alert tcp $HOME_NET any -> [103.89.91.38] 3390 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202057; rev:1;) alert tcp $HOME_NET any -> [91.109.182.3] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202058; rev:1;) alert tcp $HOME_NET any -> [46.243.221.18] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202059; rev:1;) alert tcp $HOME_NET any -> [185.244.26.234] 4675 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202060; rev:1;) alert tcp $HOME_NET any -> [216.230.75.62] 1107 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202061; rev:1;) alert tcp $HOME_NET any -> [158.247.218.177] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202062; rev:1;) alert tcp $HOME_NET any -> [46.243.221.18] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202063; rev:1;) alert tcp $HOME_NET any -> [45.32.120.24] 777 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202064; rev:1;) alert tcp $HOME_NET any -> [158.69.138.23] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202065; rev:1;) alert tcp $HOME_NET any -> [185.244.26.223] 7551 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202066; rev:1;) alert tcp $HOME_NET any -> [193.183.217.83] 5687 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202067; rev:1;) alert tcp $HOME_NET any -> [158.69.138.23] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202068; rev:1;) alert tcp $HOME_NET any -> [188.166.0.235] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202069; rev:1;) alert tcp $HOME_NET any -> [103.149.13.196] 8621 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202070; rev:1;) alert tcp $HOME_NET any -> [176.58.61.217] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202071; rev:1;) alert tcp $HOME_NET any -> [45.155.124.118] 2461 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202072; rev:1;) alert tcp $HOME_NET any -> [212.192.241.187] 5520 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202073; rev:1;) alert tcp $HOME_NET any -> [82.118.22.204] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202074; rev:1;) alert tcp $HOME_NET any -> [82.118.23.74] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202075; rev:1;) alert tcp $HOME_NET any -> [5.180.104.57] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202076; rev:1;) alert tcp $HOME_NET any -> [84.38.134.66] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202077; rev:1;) alert tcp $HOME_NET any -> [45.156.84.158] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202078; rev:1;) alert tcp $HOME_NET any -> [185.136.169.163] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202079; rev:1;) alert tcp $HOME_NET any -> [185.136.169.163] 3480 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202080; rev:1;) alert tcp $HOME_NET any -> [185.136.169.109] 3480 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202081; rev:1;) alert tcp $HOME_NET any -> [173.44.55.155] 52090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202082; rev:1;) alert tcp $HOME_NET any -> [79.134.225.69] 7551 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202083; rev:1;) alert tcp $HOME_NET any -> [45.15.143.199] 5353 (msg:"SSLBL: Traffic to malicious host (likely DCRat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202084; rev:1;) alert tcp $HOME_NET any -> [89.182.63.182] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202085; rev:1;) alert tcp $HOME_NET any -> [212.192.241.95] 45001 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202086; rev:1;) alert tcp $HOME_NET any -> [194.5.97.146] 8850 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202087; rev:1;) alert tcp $HOME_NET any -> [77.247.110.131] 8765 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202088; rev:1;) alert tcp $HOME_NET any -> [195.123.235.25] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202089; rev:1;) alert tcp $HOME_NET any -> [106.55.51.55] 5443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202090; rev:1;) alert tcp $HOME_NET any -> [5.181.80.120] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202091; rev:1;) alert tcp $HOME_NET any -> [185.239.243.112] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202092; rev:1;) alert tcp $HOME_NET any -> [185.206.144.26] 5505 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202093; rev:1;) alert tcp $HOME_NET any -> [45.133.1.212] 50855 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202094; rev:1;) alert tcp $HOME_NET any -> [185.29.9.47] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202095; rev:1;) alert tcp $HOME_NET any -> [194.5.98.8] 3030 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202096; rev:1;) alert tcp $HOME_NET any -> [23.105.131.195] 49645 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202097; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 45642 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202098; rev:1;) alert tcp $HOME_NET any -> [174.138.22.216] 443 (msg:"SSLBL: Traffic to malicious host (likely CloudStalker C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202099; rev:1;) alert tcp $HOME_NET any -> [82.118.22.247] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202100; rev:1;) alert tcp $HOME_NET any -> [101.33.11.110] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202101; rev:1;) alert tcp $HOME_NET any -> [91.109.186.11] 5490 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202102; rev:1;) alert tcp $HOME_NET any -> [45.134.225.35] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202103; rev:1;) alert tcp $HOME_NET any -> [147.124.214.14] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202104; rev:1;) alert tcp $HOME_NET any -> [79.142.76.244] 43147 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202105; rev:1;) alert tcp $HOME_NET any -> [185.29.9.47] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202106; rev:1;) alert tcp $HOME_NET any -> [31.210.21.188] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202107; rev:1;) alert tcp $HOME_NET any -> [160.177.85.21] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202108; rev:1;) alert tcp $HOME_NET any -> [34.195.49.202] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202109; rev:1;) alert tcp $HOME_NET any -> [95.211.26.199] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202110; rev:1;) alert tcp $HOME_NET any -> [104.236.60.185] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202111; rev:1;) alert tcp $HOME_NET any -> [20.98.2.6] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202112; rev:1;) alert tcp $HOME_NET any -> [89.182.137.33] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202113; rev:1;) alert tcp $HOME_NET any -> [23.105.131.173] 5436 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202114; rev:1;) alert tcp $HOME_NET any -> [207.32.218.84] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202115; rev:1;) alert tcp $HOME_NET any -> [95.142.40.241] 443 (msg:"SSLBL: Traffic to malicious host (likely TrickBot malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202116; rev:1;) alert tcp $HOME_NET any -> [95.142.40.220] 443 (msg:"SSLBL: Traffic to malicious host (likely TrickBot malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202117; rev:1;) alert tcp $HOME_NET any -> [185.250.204.130] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202118; rev:1;) alert tcp $HOME_NET any -> [185.250.204.130] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202119; rev:1;) alert tcp $HOME_NET any -> [185.19.85.168] 5946 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202120; rev:1;) alert tcp $HOME_NET any -> [194.5.98.180] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202121; rev:1;) alert tcp $HOME_NET any -> [18.162.200.0] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202122; rev:1;) alert tcp $HOME_NET any -> [147.124.219.204] 3303 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202123; rev:1;) alert tcp $HOME_NET any -> [89.182.123.92] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202124; rev:1;) alert tcp $HOME_NET any -> [46.21.153.207] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202125; rev:1;) alert tcp $HOME_NET any -> [89.248.173.43] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202126; rev:1;) alert tcp $HOME_NET any -> [79.134.225.18] 2455 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202127; rev:1;) alert tcp $HOME_NET any -> [185.22.172.34] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202128; rev:1;) alert tcp $HOME_NET any -> [207.32.217.131] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202129; rev:1;) alert tcp $HOME_NET any -> [207.32.219.26] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202130; rev:1;) alert tcp $HOME_NET any -> [156.247.13.254] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202131; rev:1;) alert tcp $HOME_NET any -> [45.113.1.17] 4435 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202132; rev:1;) alert tcp $HOME_NET any -> [185.51.246.83] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202133; rev:1;) alert tcp $HOME_NET any -> [164.68.122.235] 2021 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202134; rev:1;) alert tcp $HOME_NET any -> [51.81.105.225] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202135; rev:1;) alert tcp $HOME_NET any -> [101.33.11.25] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202136; rev:1;) alert tcp $HOME_NET any -> [45.87.0.187] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202137; rev:1;) alert tcp $HOME_NET any -> [93.115.21.128] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202138; rev:1;) alert tcp $HOME_NET any -> [194.5.98.145] 2405 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202139; rev:1;) alert tcp $HOME_NET any -> [104.208.31.182] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202140; rev:1;) alert tcp $HOME_NET any -> [135.148.12.151] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202141; rev:1;) alert tcp $HOME_NET any -> [203.159.80.37] 4972 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202142; rev:1;) alert tcp $HOME_NET any -> [104.223.76.176] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202143; rev:1;) alert tcp $HOME_NET any -> [213.142.159.41] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202144; rev:1;) alert tcp $HOME_NET any -> [158.69.189.97] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202145; rev:1;) alert tcp $HOME_NET any -> [203.159.80.177] 5025 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202146; rev:1;) alert tcp $HOME_NET any -> [5.181.156.140] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202147; rev:1;) alert tcp $HOME_NET any -> [45.138.157.144] 25565 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202148; rev:1;) alert tcp $HOME_NET any -> [46.183.220.49] 46422 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202149; rev:1;) alert tcp $HOME_NET any -> [46.183.220.49] 6578 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202150; rev:1;) alert tcp $HOME_NET any -> [136.243.191.199] 5900 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202151; rev:1;) alert tcp $HOME_NET any -> [101.33.11.88] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202152; rev:1;) alert tcp $HOME_NET any -> [179.13.6.240] 8057 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202153; rev:1;) alert tcp $HOME_NET any -> [89.182.88.61] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202154; rev:1;) alert tcp $HOME_NET any -> [79.134.225.75] 7739 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202155; rev:1;) alert tcp $HOME_NET any -> [81.163.246.9] 5020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202156; rev:1;) alert tcp $HOME_NET any -> [79.134.225.75] 2050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202157; rev:1;) alert tcp $HOME_NET any -> [147.124.219.204] 9909 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202158; rev:1;) alert tcp $HOME_NET any -> [185.157.161.205] 1973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202159; rev:1;) alert tcp $HOME_NET any -> [185.157.161.205] 1975 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202160; rev:1;) alert tcp $HOME_NET any -> [35.197.240.92] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202161; rev:1;) alert tcp $HOME_NET any -> [31.44.185.19] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202162; rev:1;) alert tcp $HOME_NET any -> [185.50.248.49] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202163; rev:1;) alert tcp $HOME_NET any -> [31.44.185.24] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202164; rev:1;) alert tcp $HOME_NET any -> [1.15.79.166] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202165; rev:1;) alert tcp $HOME_NET any -> [31.210.21.188] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202166; rev:1;) alert tcp $HOME_NET any -> [1.15.128.150] 60001 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202167; rev:1;) alert tcp $HOME_NET any -> [139.99.178.86] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202168; rev:1;) alert tcp $HOME_NET any -> [104.43.200.50] 2222 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202169; rev:1;) alert tcp $HOME_NET any -> [31.210.21.188] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202170; rev:1;) alert tcp $HOME_NET any -> [42.194.199.231] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202171; rev:1;) alert tcp $HOME_NET any -> [62.234.134.62] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202172; rev:1;) alert tcp $HOME_NET any -> [103.234.72.237] 10920 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202173; rev:1;) alert tcp $HOME_NET any -> [79.134.225.91] 1973 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202174; rev:1;) alert tcp $HOME_NET any -> [79.134.225.91] 1975 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202175; rev:1;) alert tcp $HOME_NET any -> [31.44.185.23] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202176; rev:1;) alert tcp $HOME_NET any -> [13.52.231.237] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202177; rev:1;) alert tcp $HOME_NET any -> [34.220.99.248] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202178; rev:1;) alert tcp $HOME_NET any -> [139.45.197.239] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202179; rev:1;) alert tcp $HOME_NET any -> [54.225.218.189] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202180; rev:1;) alert tcp $HOME_NET any -> [185.50.248.47] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202181; rev:1;) alert tcp $HOME_NET any -> [194.5.97.116] 1177 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202182; rev:1;) alert tcp $HOME_NET any -> [120.78.191.11] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202183; rev:1;) alert tcp $HOME_NET any -> [192.243.59.12] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202184; rev:1;) alert tcp $HOME_NET any -> [103.207.36.177] 6204 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202185; rev:1;) alert tcp $HOME_NET any -> [137.74.176.167] 5553 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202186; rev:1;) alert tcp $HOME_NET any -> [79.134.225.92] 9030 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202187; rev:1;) alert tcp $HOME_NET any -> [47.118.62.39] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202188; rev:1;) alert tcp $HOME_NET any -> [88.214.24.59] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202189; rev:1;) alert tcp $HOME_NET any -> [2.207.101.83] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202190; rev:1;) alert tcp $HOME_NET any -> [45.141.84.112] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202191; rev:1;) alert tcp $HOME_NET any -> [192.243.59.20] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202192; rev:1;) alert tcp $HOME_NET any -> [88.214.24.56] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202193; rev:1;) alert tcp $HOME_NET any -> [41.250.187.176] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202194; rev:1;) alert tcp $HOME_NET any -> [136.243.191.199] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202195; rev:1;) alert tcp $HOME_NET any -> [192.227.128.143] 9488 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202196; rev:1;) alert tcp $HOME_NET any -> [89.182.30.194] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202197; rev:1;) alert tcp $HOME_NET any -> [178.33.222.243] 50855 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202198; rev:1;) alert tcp $HOME_NET any -> [103.113.159.7] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202199; rev:1;) alert tcp $HOME_NET any -> [211.152.136.90] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202200; rev:1;) alert tcp $HOME_NET any -> [185.222.57.171] 3678 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202201; rev:1;) alert tcp $HOME_NET any -> [185.157.161.20] 8990 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202202; rev:1;) alert tcp $HOME_NET any -> [211.152.136.88] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202203; rev:1;) alert tcp $HOME_NET any -> [192.243.59.13] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202204; rev:1;) alert tcp $HOME_NET any -> [194.5.98.120] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202205; rev:1;) alert tcp $HOME_NET any -> [3.142.167.4] 18318 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202206; rev:1;) alert tcp $HOME_NET any -> [193.56.29.105] 1982 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202207; rev:1;) alert tcp $HOME_NET any -> [79.137.109.121] 50855 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202208; rev:1;) alert tcp $HOME_NET any -> [193.239.85.9] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202209; rev:1;) alert tcp $HOME_NET any -> [193.239.84.195] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202210; rev:1;) alert tcp $HOME_NET any -> [46.243.221.40] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202211; rev:1;) alert tcp $HOME_NET any -> [72.11.137.166] 55050 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202212; rev:1;) alert tcp $HOME_NET any -> [20.194.35.6] 7904 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202213; rev:1;) alert tcp $HOME_NET any -> [185.197.30.108] 5687 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202214; rev:1;) alert tcp $HOME_NET any -> [185.140.53.137] 5000 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202215; rev:1;) alert tcp $HOME_NET any -> [201.219.204.73] 1884 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202216; rev:1;) alert tcp $HOME_NET any -> [185.163.47.163] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202217; rev:1;) alert tcp $HOME_NET any -> [194.5.98.107] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202218; rev:1;) alert tcp $HOME_NET any -> [193.142.146.202] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202219; rev:1;) alert tcp $HOME_NET any -> [79.134.225.10] 5000 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202220; rev:1;) alert tcp $HOME_NET any -> [84.38.182.88] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202221; rev:1;) alert tcp $HOME_NET any -> [5.2.65.197] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202222; rev:1;) alert tcp $HOME_NET any -> [34.92.115.71] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202223; rev:1;) alert tcp $HOME_NET any -> [136.244.96.52] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202224; rev:1;) alert tcp $HOME_NET any -> [188.34.142.201] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202225; rev:1;) alert tcp $HOME_NET any -> [193.38.55.11] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202226; rev:1;) alert tcp $HOME_NET any -> [107.155.164.5] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202227; rev:1;) alert tcp $HOME_NET any -> [34.105.210.195] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202228; rev:1;) alert tcp $HOME_NET any -> [115.78.134.34] 7707 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202229; rev:1;) alert tcp $HOME_NET any -> [194.5.98.38] 4783 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202230; rev:1;) alert tcp $HOME_NET any -> [176.103.59.173] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202231; rev:1;) alert tcp $HOME_NET any -> [94.158.245.132] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202232; rev:1;) alert tcp $HOME_NET any -> [167.99.184.82] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202233; rev:1;) alert tcp $HOME_NET any -> [193.239.84.194] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202234; rev:1;) alert tcp $HOME_NET any -> [193.239.84.240] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202235; rev:1;) alert tcp $HOME_NET any -> [185.183.162.147] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202236; rev:1;) alert tcp $HOME_NET any -> [179.43.166.32] 10090 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202237; rev:1;) alert tcp $HOME_NET any -> [46.243.250.171] 6381 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202238; rev:1;) alert tcp $HOME_NET any -> [94.176.235.200] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202239; rev:1;) alert tcp $HOME_NET any -> [185.102.136.27] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202240; rev:1;) alert tcp $HOME_NET any -> [172.111.168.19] 6381 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202241; rev:1;) alert tcp $HOME_NET any -> [34.96.156.66] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202242; rev:1;) alert tcp $HOME_NET any -> [107.175.101.209] 7865 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202243; rev:1;) alert tcp $HOME_NET any -> [159.75.110.125] 9102 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202244; rev:1;) alert tcp $HOME_NET any -> [185.201.47.155] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202245; rev:1;) alert tcp $HOME_NET any -> [94.140.114.21] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202246; rev:1;) alert tcp $HOME_NET any -> [82.118.22.118] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202247; rev:1;) alert tcp $HOME_NET any -> [194.127.178.197] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202248; rev:1;) alert tcp $HOME_NET any -> [80.92.206.44] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202249; rev:1;) alert tcp $HOME_NET any -> [112.74.182.201] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202250; rev:1;) alert tcp $HOME_NET any -> [74.119.195.101] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202251; rev:1;) alert tcp $HOME_NET any -> [185.163.47.244] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202252; rev:1;) alert tcp $HOME_NET any -> [91.228.218.43] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202253; rev:1;) alert tcp $HOME_NET any -> [202.168.154.11] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202254; rev:1;) alert tcp $HOME_NET any -> [185.212.131.90] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202255; rev:1;) alert tcp $HOME_NET any -> [141.136.0.105] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202256; rev:1;) alert tcp $HOME_NET any -> [195.54.33.143] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202257; rev:1;) alert tcp $HOME_NET any -> [46.29.167.123] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202258; rev:1;) alert tcp $HOME_NET any -> [185.163.47.254] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202259; rev:1;) alert tcp $HOME_NET any -> [8.140.186.40] 8888 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202260; rev:1;) alert tcp $HOME_NET any -> [116.203.178.81] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202261; rev:1;) alert tcp $HOME_NET any -> [79.134.225.70] 50855 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202262; rev:1;) alert tcp $HOME_NET any -> [185.19.85.152] 3413 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202263; rev:1;) alert tcp $HOME_NET any -> [195.54.33.200] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202264; rev:1;) alert tcp $HOME_NET any -> [79.134.225.62] 4170 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202265; rev:1;) alert tcp $HOME_NET any -> [66.248.206.71] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202266; rev:1;) alert tcp $HOME_NET any -> [117.51.136.152] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202267; rev:1;) alert tcp $HOME_NET any -> [185.234.247.219] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202268; rev:1;) alert tcp $HOME_NET any -> [141.136.0.96] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202269; rev:1;) alert tcp $HOME_NET any -> [204.48.28.130] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202270; rev:1;) alert tcp $HOME_NET any -> [160.124.49.133] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202271; rev:1;) alert tcp $HOME_NET any -> [185.141.26.139] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202272; rev:1;) alert tcp $HOME_NET any -> [213.152.187.210] 42012 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202273; rev:1;) alert tcp $HOME_NET any -> [74.119.195.166] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202274; rev:1;) alert tcp $HOME_NET any -> [5.181.156.75] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202275; rev:1;) alert tcp $HOME_NET any -> [74.119.195.168] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202276; rev:1;) alert tcp $HOME_NET any -> [176.103.61.84] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202277; rev:1;) alert tcp $HOME_NET any -> [195.123.215.115] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202278; rev:1;) alert tcp $HOME_NET any -> [194.127.179.127] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202279; rev:1;) alert tcp $HOME_NET any -> [195.54.33.131] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202280; rev:1;) alert tcp $HOME_NET any -> [74.119.195.167] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202281; rev:1;) alert tcp $HOME_NET any -> [51.89.204.5] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202282; rev:1;) alert tcp $HOME_NET any -> [195.123.215.67] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202283; rev:1;) alert tcp $HOME_NET any -> [5.230.68.40] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202284; rev:1;) alert tcp $HOME_NET any -> [45.139.187.144] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202285; rev:1;) alert tcp $HOME_NET any -> [46.243.217.11] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202286; rev:1;) alert tcp $HOME_NET any -> [185.157.162.75] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202287; rev:1;) alert tcp $HOME_NET any -> [213.152.187.205] 43413 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202288; rev:1;) alert tcp $HOME_NET any -> [185.66.13.246] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202289; rev:1;) alert tcp $HOME_NET any -> [23.238.217.173] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202290; rev:1;) alert tcp $HOME_NET any -> [94.158.245.69] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202291; rev:1;) alert tcp $HOME_NET any -> [185.144.100.9] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202292; rev:1;) alert tcp $HOME_NET any -> [138.197.176.134] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202293; rev:1;) alert tcp $HOME_NET any -> [45.141.37.7] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202294; rev:1;) alert tcp $HOME_NET any -> [193.233.78.102] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202295; rev:1;) alert tcp $HOME_NET any -> [79.134.225.23] 6667 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202296; rev:1;) alert tcp $HOME_NET any -> [91.200.41.42] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202297; rev:1;) alert tcp $HOME_NET any -> [140.82.57.172] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202298; rev:1;) alert tcp $HOME_NET any -> [23.95.0.100] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202299; rev:1;) alert tcp $HOME_NET any -> [92.223.90.242] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202300; rev:1;) alert tcp $HOME_NET any -> [193.142.58.181] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202301; rev:1;) alert tcp $HOME_NET any -> [141.164.36.203] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202302; rev:1;) alert tcp $HOME_NET any -> [207.32.219.41] 1996 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202303; rev:1;) alert tcp $HOME_NET any -> [34.83.147.211] 3741 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202304; rev:1;) alert tcp $HOME_NET any -> [45.144.225.107] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202305; rev:1;) alert tcp $HOME_NET any -> [88.80.186.210] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202306; rev:1;) alert tcp $HOME_NET any -> [3.138.180.119] 11048 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202307; rev:1;) alert tcp $HOME_NET any -> [45.129.137.247] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202308; rev:1;) alert tcp $HOME_NET any -> [46.243.221.41] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202309; rev:1;) alert tcp $HOME_NET any -> [18.224.135.48] 9933 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202310; rev:1;) alert tcp $HOME_NET any -> [45.77.122.108] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202311; rev:1;) alert tcp $HOME_NET any -> [23.105.131.172] 1609 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202312; rev:1;) alert tcp $HOME_NET any -> [89.182.118.216] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202313; rev:1;) alert tcp $HOME_NET any -> [91.203.145.250] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202314; rev:1;) alert tcp $HOME_NET any -> [86.106.131.188] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202315; rev:1;) alert tcp $HOME_NET any -> [104.36.231.42] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202316; rev:1;) alert tcp $HOME_NET any -> [47.243.68.98] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202317; rev:1;) alert tcp $HOME_NET any -> [201.212.118.175] 444 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202318; rev:1;) alert tcp $HOME_NET any -> [5.34.182.123] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202319; rev:1;) alert tcp $HOME_NET any -> [185.82.219.58] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202320; rev:1;) alert tcp $HOME_NET any -> [195.123.219.199] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202321; rev:1;) alert tcp $HOME_NET any -> [193.38.55.77] 38022 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202322; rev:1;) alert tcp $HOME_NET any -> [74.50.60.96] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202323; rev:1;) alert tcp $HOME_NET any -> [47.89.46.44] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202324; rev:1;) alert tcp $HOME_NET any -> [109.232.239.145] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202325; rev:1;) alert tcp $HOME_NET any -> [51.195.134.41] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202326; rev:1;) alert tcp $HOME_NET any -> [185.50.248.46] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202327; rev:1;) alert tcp $HOME_NET any -> [5.181.156.79] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202328; rev:1;) alert tcp $HOME_NET any -> [185.14.28.131] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202329; rev:1;) alert tcp $HOME_NET any -> [18.191.253.86] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202330; rev:1;) alert tcp $HOME_NET any -> [185.222.57.238] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202331; rev:1;) alert tcp $HOME_NET any -> [124.70.89.118] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202332; rev:1;) alert tcp $HOME_NET any -> [18.224.135.48] 1 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202333; rev:1;) alert tcp $HOME_NET any -> [195.58.49.13] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202334; rev:1;) alert tcp $HOME_NET any -> [139.224.118.73] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202335; rev:1;) alert tcp $HOME_NET any -> [193.38.55.33] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202336; rev:1;) alert tcp $HOME_NET any -> [152.89.162.12] 1973 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202337; rev:1;) alert tcp $HOME_NET any -> [179.43.140.164] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202338; rev:1;) alert tcp $HOME_NET any -> [18.224.135.48] 2008 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202339; rev:1;) alert tcp $HOME_NET any -> [51.81.165.158] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202340; rev:1;) alert tcp $HOME_NET any -> [209.249.134.8] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202341; rev:1;) alert tcp $HOME_NET any -> [49.235.187.153] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202342; rev:1;) alert tcp $HOME_NET any -> [185.163.45.229] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202343; rev:1;) alert tcp $HOME_NET any -> [193.135.12.12] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202344; rev:1;) alert tcp $HOME_NET any -> [143.110.180.217] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202345; rev:1;) alert tcp $HOME_NET any -> [193.135.12.10] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202346; rev:1;) alert tcp $HOME_NET any -> [45.77.194.161] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202347; rev:1;) alert tcp $HOME_NET any -> [46.243.221.36] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202348; rev:1;) alert tcp $HOME_NET any -> [54.37.160.138] 6601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202349; rev:1;) alert tcp $HOME_NET any -> [46.243.221.55] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202350; rev:1;) alert tcp $HOME_NET any -> [34.91.189.70] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202351; rev:1;) alert tcp $HOME_NET any -> [5.181.156.3] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202352; rev:1;) alert tcp $HOME_NET any -> [45.139.236.5] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202353; rev:1;) alert tcp $HOME_NET any -> [103.233.195.64] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202354; rev:1;) alert tcp $HOME_NET any -> [91.152.91.234] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202355; rev:1;) alert tcp $HOME_NET any -> [193.135.12.14] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202356; rev:1;) alert tcp $HOME_NET any -> [193.135.12.15] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202357; rev:1;) alert tcp $HOME_NET any -> [198.23.212.148] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202358; rev:1;) alert tcp $HOME_NET any -> [198.23.212.148] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202359; rev:1;) alert tcp $HOME_NET any -> [203.159.80.242] 6805 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202360; rev:1;) alert tcp $HOME_NET any -> [204.236.142.165] 443 (msg:"SSLBL: Traffic to malicious host (likely BazarCall C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202361; rev:1;) alert tcp $HOME_NET any -> [54.218.15.82] 443 (msg:"SSLBL: Traffic to malicious host (likely BazarCall C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202362; rev:1;) alert tcp $HOME_NET any -> [172.94.109.35] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202363; rev:1;) alert tcp $HOME_NET any -> [134.122.134.87] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202364; rev:1;) alert tcp $HOME_NET any -> [185.244.38.80] 50663 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202365; rev:1;) alert tcp $HOME_NET any -> [194.5.98.174] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202366; rev:1;) alert tcp $HOME_NET any -> [46.243.221.30] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202367; rev:1;) alert tcp $HOME_NET any -> [182.92.233.209] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202368; rev:1;) alert tcp $HOME_NET any -> [185.58.92.227] 5353 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202369; rev:1;) alert tcp $HOME_NET any -> [185.189.151.126] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202370; rev:1;) alert tcp $HOME_NET any -> [221.146.229.139] 1002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202371; rev:1;) alert tcp $HOME_NET any -> [103.224.241.225] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202372; rev:1;) alert tcp $HOME_NET any -> [94.158.245.121] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202373; rev:1;) alert tcp $HOME_NET any -> [45.134.169.75] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202374; rev:1;) alert tcp $HOME_NET any -> [95.179.246.182] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202375; rev:1;) alert tcp $HOME_NET any -> [34.76.44.128] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202376; rev:1;) alert tcp $HOME_NET any -> [194.5.97.128] 11011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202377; rev:1;) alert tcp $HOME_NET any -> [103.55.10.39] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202378; rev:1;) alert tcp $HOME_NET any -> [108.61.89.233] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202379; rev:1;) alert tcp $HOME_NET any -> [35.201.213.225] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202380; rev:1;) alert tcp $HOME_NET any -> [112.124.28.213] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202381; rev:1;) alert tcp $HOME_NET any -> [34.91.16.249] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202382; rev:1;) alert tcp $HOME_NET any -> [213.152.162.69] 43413 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202383; rev:1;) alert tcp $HOME_NET any -> [172.111.251.53] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202384; rev:1;) alert tcp $HOME_NET any -> [172.94.50.146] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202385; rev:1;) alert tcp $HOME_NET any -> [47.95.219.96] 3344 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202386; rev:1;) alert tcp $HOME_NET any -> [185.225.19.253] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202387; rev:1;) alert tcp $HOME_NET any -> [45.67.231.247] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202388; rev:1;) alert tcp $HOME_NET any -> [5.181.156.250] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202389; rev:1;) alert tcp $HOME_NET any -> [92.63.99.163] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202390; rev:1;) alert tcp $HOME_NET any -> [185.219.40.40] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202391; rev:1;) alert tcp $HOME_NET any -> [188.127.231.114] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202392; rev:1;) alert tcp $HOME_NET any -> [172.94.50.143] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202393; rev:1;) alert tcp $HOME_NET any -> [34.70.170.220] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202394; rev:1;) alert tcp $HOME_NET any -> [168.119.0.86] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202395; rev:1;) alert tcp $HOME_NET any -> [77.247.127.24] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202396; rev:1;) alert tcp $HOME_NET any -> [140.238.243.50] 2021 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202397; rev:1;) alert tcp $HOME_NET any -> [191.101.130.162] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202398; rev:1;) alert tcp $HOME_NET any -> [18.224.135.48] 1612 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202399; rev:1;) alert tcp $HOME_NET any -> [41.105.23.43] 1231 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202400; rev:1;) alert tcp $HOME_NET any -> [191.101.130.162] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202401; rev:1;) alert tcp $HOME_NET any -> [34.65.142.15] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202402; rev:1;) alert tcp $HOME_NET any -> [35.246.79.214] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202403; rev:1;) alert tcp $HOME_NET any -> [185.163.45.182] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202404; rev:1;) alert tcp $HOME_NET any -> [34.90.118.146] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202405; rev:1;) alert tcp $HOME_NET any -> [8.209.66.127] 443 (msg:"SSLBL: Traffic to malicious host (likely BazarCall malware distribution traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202406; rev:1;) alert tcp $HOME_NET any -> [8.209.66.127] 443 (msg:"SSLBL: Traffic to malicious host (likely BazarCall C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202407; rev:1;) alert tcp $HOME_NET any -> [45.145.36.210] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202408; rev:1;) alert tcp $HOME_NET any -> [172.104.225.210] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202409; rev:1;) alert tcp $HOME_NET any -> [101.200.178.253] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202410; rev:1;) alert tcp $HOME_NET any -> [35.246.130.209] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202411; rev:1;) alert tcp $HOME_NET any -> [185.219.168.29] 2990 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202412; rev:1;) alert tcp $HOME_NET any -> [41.105.114.108] 1231 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202413; rev:1;) alert tcp $HOME_NET any -> [185.163.45.249] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202414; rev:1;) alert tcp $HOME_NET any -> [79.134.225.18] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202415; rev:1;) alert tcp $HOME_NET any -> [172.93.163.101] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202416; rev:1;) alert tcp $HOME_NET any -> [172.93.163.101] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202417; rev:1;) alert tcp $HOME_NET any -> [46.243.221.26] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202418; rev:1;) alert tcp $HOME_NET any -> [152.89.247.74] 7139 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202419; rev:1;) alert tcp $HOME_NET any -> [194.5.98.206] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202420; rev:1;) alert tcp $HOME_NET any -> [23.163.0.12] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202421; rev:1;) alert tcp $HOME_NET any -> [35.204.89.50] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202422; rev:1;) alert tcp $HOME_NET any -> [106.55.62.131] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202423; rev:1;) alert tcp $HOME_NET any -> [185.106.123.114] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202424; rev:1;) alert tcp $HOME_NET any -> [64.225.20.68] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202425; rev:1;) alert tcp $HOME_NET any -> [149.56.80.31] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202426; rev:1;) alert tcp $HOME_NET any -> [5.181.156.126] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202427; rev:1;) alert tcp $HOME_NET any -> [5.181.156.126] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202428; rev:1;) alert tcp $HOME_NET any -> [152.89.247.75] 2810 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202429; rev:1;) alert tcp $HOME_NET any -> [18.223.156.62] 4656 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202430; rev:1;) alert tcp $HOME_NET any -> [158.69.149.45] 53 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202431; rev:1;) alert tcp $HOME_NET any -> [167.114.77.20] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202432; rev:1;) alert tcp $HOME_NET any -> [213.152.161.5] 42012 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202433; rev:1;) alert tcp $HOME_NET any -> [35.232.94.42] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202434; rev:1;) alert tcp $HOME_NET any -> [185.157.161.20] 20058 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202435; rev:1;) alert tcp $HOME_NET any -> [64.225.101.13] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202436; rev:1;) alert tcp $HOME_NET any -> [95.216.105.73] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202437; rev:1;) alert tcp $HOME_NET any -> [185.140.53.133] 1404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202438; rev:1;) alert tcp $HOME_NET any -> [34.91.233.147] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202439; rev:1;) alert tcp $HOME_NET any -> [160.20.147.107] 1508 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202440; rev:1;) alert tcp $HOME_NET any -> [3.20.238.67] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202441; rev:1;) alert tcp $HOME_NET any -> [160.20.145.218] 5072 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202442; rev:1;) alert tcp $HOME_NET any -> [103.151.125.236] 5665 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202443; rev:1;) alert tcp $HOME_NET any -> [203.159.80.241] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202444; rev:1;) alert tcp $HOME_NET any -> [3.12.163.16] 7777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202445; rev:1;) alert tcp $HOME_NET any -> [178.238.8.204] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202446; rev:1;) alert tcp $HOME_NET any -> [51.81.126.20] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202447; rev:1;) alert tcp $HOME_NET any -> [34.91.203.83] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202448; rev:1;) alert tcp $HOME_NET any -> [213.152.161.229] 8746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202449; rev:1;) alert tcp $HOME_NET any -> [41.214.187.35] 1993 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202450; rev:1;) alert tcp $HOME_NET any -> [195.62.33.224] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202451; rev:1;) alert tcp $HOME_NET any -> [152.89.247.27] 1210 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202452; rev:1;) alert tcp $HOME_NET any -> [35.241.172.252] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202453; rev:1;) alert tcp $HOME_NET any -> [185.118.164.167] 2442 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202454; rev:1;) alert tcp $HOME_NET any -> [5.2.68.70] 8070 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202455; rev:1;) alert tcp $HOME_NET any -> [193.42.26.19] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202456; rev:1;) alert tcp $HOME_NET any -> [3.128.190.178] 7777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202457; rev:1;) alert tcp $HOME_NET any -> [42.51.46.58] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202458; rev:1;) alert tcp $HOME_NET any -> [34.107.19.249] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202459; rev:1;) alert tcp $HOME_NET any -> [189.232.4.114] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202460; rev:1;) alert tcp $HOME_NET any -> [45.85.90.192] 44277 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202461; rev:1;) alert tcp $HOME_NET any -> [3.128.190.178] 2403 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202462; rev:1;) alert tcp $HOME_NET any -> [94.103.80.254] 4334 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202463; rev:1;) alert tcp $HOME_NET any -> [154.209.5.14] 10443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202464; rev:1;) alert tcp $HOME_NET any -> [103.212.180.246] 5554 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202465; rev:1;) alert tcp $HOME_NET any -> [45.77.46.72] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202466; rev:1;) alert tcp $HOME_NET any -> [91.243.45.11] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202467; rev:1;) alert tcp $HOME_NET any -> [34.69.90.254] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202468; rev:1;) alert tcp $HOME_NET any -> [185.157.161.223] 1973 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202469; rev:1;) alert tcp $HOME_NET any -> [189.232.49.230] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202470; rev:1;) alert tcp $HOME_NET any -> [35.228.252.199] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202471; rev:1;) alert tcp $HOME_NET any -> [36.110.239.122] 4430 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202472; rev:1;) alert tcp $HOME_NET any -> [46.101.58.213] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202473; rev:1;) alert tcp $HOME_NET any -> [121.37.139.238] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202474; rev:1;) alert tcp $HOME_NET any -> [3.128.190.178] 1488 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202475; rev:1;) alert tcp $HOME_NET any -> [195.123.209.122] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202476; rev:1;) alert tcp $HOME_NET any -> [195.123.213.219] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202477; rev:1;) alert tcp $HOME_NET any -> [104.200.67.118] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202478; rev:1;) alert tcp $HOME_NET any -> [79.134.225.26] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202479; rev:1;) alert tcp $HOME_NET any -> [172.93.201.100] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202480; rev:1;) alert tcp $HOME_NET any -> [3.128.254.246] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202481; rev:1;) alert tcp $HOME_NET any -> [91.109.176.8] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202482; rev:1;) alert tcp $HOME_NET any -> [154.16.67.107] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202483; rev:1;) alert tcp $HOME_NET any -> [3.128.190.178] 1604 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202484; rev:1;) alert tcp $HOME_NET any -> [3.19.75.7] 7777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202485; rev:1;) alert tcp $HOME_NET any -> [3.128.190.178] 1222 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202486; rev:1;) alert tcp $HOME_NET any -> [141.255.155.228] 1188 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202487; rev:1;) alert tcp $HOME_NET any -> [79.134.225.8] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202488; rev:1;) alert tcp $HOME_NET any -> [45.153.203.55] 44277 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202489; rev:1;) alert tcp $HOME_NET any -> [89.182.79.1] 3601 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202490; rev:1;) alert tcp $HOME_NET any -> [107.191.62.88] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202491; rev:1;) alert tcp $HOME_NET any -> [198.102.14.18] 4712 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202492; rev:1;) alert tcp $HOME_NET any -> [185.82.218.53] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202493; rev:1;) alert tcp $HOME_NET any -> [181.141.5.139] 8050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202494; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 26187 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202495; rev:1;) alert tcp $HOME_NET any -> [23.106.160.164] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202496; rev:1;) alert tcp $HOME_NET any -> [172.104.247.192] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202497; rev:1;) alert tcp $HOME_NET any -> [103.151.123.132] 6204 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202498; rev:1;) alert tcp $HOME_NET any -> [88.214.59.150] 9911 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202499; rev:1;) alert tcp $HOME_NET any -> [79.134.225.126] 3000 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202500; rev:1;) alert tcp $HOME_NET any -> [54.84.206.216] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202501; rev:1;) alert tcp $HOME_NET any -> [158.247.220.30] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202502; rev:1;) alert tcp $HOME_NET any -> [195.2.92.62] 443 (msg:"SSLBL: Traffic to malicious host (likely FIN7 traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202503; rev:1;) alert tcp $HOME_NET any -> [18.188.163.174] 45165 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202504; rev:1;) alert tcp $HOME_NET any -> [86.107.197.52] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202505; rev:1;) alert tcp $HOME_NET any -> [104.243.41.123] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202506; rev:1;) alert tcp $HOME_NET any -> [23.146.242.233] 5000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202507; rev:1;) alert tcp $HOME_NET any -> [194.26.29.191] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202508; rev:1;) alert tcp $HOME_NET any -> [79.134.225.53] 8765 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202509; rev:1;) alert tcp $HOME_NET any -> [193.218.118.85] 1781 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202510; rev:1;) alert tcp $HOME_NET any -> [213.217.0.217] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202511; rev:1;) alert tcp $HOME_NET any -> [185.130.213.157] 666 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202512; rev:1;) alert tcp $HOME_NET any -> [185.20.186.108] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202513; rev:1;) alert tcp $HOME_NET any -> [182.186.116.148] 6905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202514; rev:1;) alert tcp $HOME_NET any -> [45.43.2.204] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202515; rev:1;) alert tcp $HOME_NET any -> [139.28.235.223] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202516; rev:1;) alert tcp $HOME_NET any -> [194.127.179.247] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202517; rev:1;) alert tcp $HOME_NET any -> [176.58.112.29] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202518; rev:1;) alert tcp $HOME_NET any -> [54.89.120.178] 1605 (msg:"SSLBL: Traffic to malicious host (likely njrat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202519; rev:1;) alert tcp $HOME_NET any -> [45.153.203.230] 4016 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202520; rev:1;) alert tcp $HOME_NET any -> [76.6.210.168] 1337 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202521; rev:1;) alert tcp $HOME_NET any -> [145.239.145.114] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202522; rev:1;) alert tcp $HOME_NET any -> [185.140.53.134] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202523; rev:1;) alert tcp $HOME_NET any -> [93.95.227.30] 5506 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202524; rev:1;) alert tcp $HOME_NET any -> [185.239.242.118] 4016 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202525; rev:1;) alert tcp $HOME_NET any -> [182.186.40.205] 6905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202526; rev:1;) alert tcp $HOME_NET any -> [91.109.190.2] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202527; rev:1;) alert tcp $HOME_NET any -> [115.220.8.189] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202528; rev:1;) alert tcp $HOME_NET any -> [201.219.204.73] 1881 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202529; rev:1;) alert tcp $HOME_NET any -> [119.45.183.69] 8880 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202530; rev:1;) alert tcp $HOME_NET any -> [139.28.235.223] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202531; rev:1;) alert tcp $HOME_NET any -> [179.43.166.30] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202532; rev:1;) alert tcp $HOME_NET any -> [185.140.53.137] 4723 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202533; rev:1;) alert tcp $HOME_NET any -> [85.143.217.252] 8084 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202534; rev:1;) alert tcp $HOME_NET any -> [142.202.188.249] 2025 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202535; rev:1;) alert tcp $HOME_NET any -> [91.109.176.8] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202536; rev:1;) alert tcp $HOME_NET any -> [192.169.6.68] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202537; rev:1;) alert tcp $HOME_NET any -> [161.129.71.137] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202538; rev:1;) alert tcp $HOME_NET any -> [194.36.191.32] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202539; rev:1;) alert tcp $HOME_NET any -> [172.94.42.34] 8890 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202540; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 50232 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202541; rev:1;) alert tcp $HOME_NET any -> [45.76.177.3] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202542; rev:1;) alert tcp $HOME_NET any -> [122.228.4.170] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202543; rev:1;) alert tcp $HOME_NET any -> [194.5.98.231] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202544; rev:1;) alert tcp $HOME_NET any -> [77.149.2.122] 5552 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202545; rev:1;) alert tcp $HOME_NET any -> [45.141.84.215] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202546; rev:1;) alert tcp $HOME_NET any -> [139.59.162.149] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202547; rev:1;) alert tcp $HOME_NET any -> [51.81.7.200] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202548; rev:1;) alert tcp $HOME_NET any -> [37.46.150.236] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202549; rev:1;) alert tcp $HOME_NET any -> [142.202.191.119] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202550; rev:1;) alert tcp $HOME_NET any -> [13.58.93.231] 7777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202551; rev:1;) alert tcp $HOME_NET any -> [185.150.24.55] 9879 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202552; rev:1;) alert tcp $HOME_NET any -> [3.138.139.210] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202553; rev:1;) alert tcp $HOME_NET any -> [51.81.241.89] 8331 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202554; rev:1;) alert tcp $HOME_NET any -> [5.39.217.241] 4016 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202555; rev:1;) alert tcp $HOME_NET any -> [194.5.98.136] 1177 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202556; rev:1;) alert tcp $HOME_NET any -> [172.93.222.169] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202557; rev:1;) alert tcp $HOME_NET any -> [45.145.185.50] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202558; rev:1;) alert tcp $HOME_NET any -> [161.129.71.135] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202559; rev:1;) alert tcp $HOME_NET any -> [185.244.30.225] 51817 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202560; rev:1;) alert tcp $HOME_NET any -> [185.140.53.224] 9845 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202561; rev:1;) alert tcp $HOME_NET any -> [95.179.211.251] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202562; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 31330 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202563; rev:1;) alert tcp $HOME_NET any -> [172.94.42.34] 4042 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202564; rev:1;) alert tcp $HOME_NET any -> [179.43.140.189] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202565; rev:1;) alert tcp $HOME_NET any -> [101.37.76.168] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202566; rev:1;) alert tcp $HOME_NET any -> [5.189.166.237] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202567; rev:1;) alert tcp $HOME_NET any -> [161.129.71.133] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202568; rev:1;) alert tcp $HOME_NET any -> [141.105.66.243] 4016 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202569; rev:1;) alert tcp $HOME_NET any -> [23.227.202.13] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202570; rev:1;) alert tcp $HOME_NET any -> [103.114.107.184] 7180 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202571; rev:1;) alert tcp $HOME_NET any -> [79.134.225.69] 1973 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202572; rev:1;) alert tcp $HOME_NET any -> [185.157.162.107] 6606 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202573; rev:1;) alert tcp $HOME_NET any -> [185.140.53.131] 2190 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202574; rev:1;) alert tcp $HOME_NET any -> [88.214.59.150] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202575; rev:1;) alert tcp $HOME_NET any -> [119.29.18.190] 8090 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202576; rev:1;) alert tcp $HOME_NET any -> [179.43.140.133] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202577; rev:1;) alert tcp $HOME_NET any -> [193.23.3.13] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202578; rev:1;) alert tcp $HOME_NET any -> [185.140.53.131] 5567 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202579; rev:1;) alert tcp $HOME_NET any -> [80.80.130.110] 644 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202580; rev:1;) alert tcp $HOME_NET any -> [154.16.248.44] 40770 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202581; rev:1;) alert tcp $HOME_NET any -> [134.122.40.38] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202582; rev:1;) alert tcp $HOME_NET any -> [79.134.225.23] 30493 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202583; rev:1;) alert tcp $HOME_NET any -> [185.157.162.107] 4783 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202584; rev:1;) alert tcp $HOME_NET any -> [195.206.105.10] 3988 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202585; rev:1;) alert tcp $HOME_NET any -> [185.200.243.169] 51817 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202586; rev:1;) alert tcp $HOME_NET any -> [91.193.75.189] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202587; rev:1;) alert tcp $HOME_NET any -> [79.134.225.18] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202588; rev:1;) alert tcp $HOME_NET any -> [20.50.121.62] 1604 (msg:"SSLBL: Traffic to malicious host (likely njrat C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202589; rev:1;) alert tcp $HOME_NET any -> [23.105.131.188] 1993 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202590; rev:1;) alert tcp $HOME_NET any -> [91.109.186.3] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202591; rev:1;) alert tcp $HOME_NET any -> [176.43.110.149] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202592; rev:1;) alert tcp $HOME_NET any -> [185.140.53.135] 1010 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202593; rev:1;) alert tcp $HOME_NET any -> [80.209.241.21] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202594; rev:1;) alert tcp $HOME_NET any -> [79.134.225.45] 2233 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202595; rev:1;) alert tcp $HOME_NET any -> [18.188.97.62] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202596; rev:1;) alert tcp $HOME_NET any -> [194.5.97.173] 1993 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202597; rev:1;) alert tcp $HOME_NET any -> [115.126.25.22] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202598; rev:1;) alert tcp $HOME_NET any -> [198.23.212.149] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202599; rev:1;) alert tcp $HOME_NET any -> [13.58.162.35] 1028 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202600; rev:1;) alert tcp $HOME_NET any -> [124.156.187.132] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202601; rev:1;) alert tcp $HOME_NET any -> [136.244.98.158] 1000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202602; rev:1;) alert tcp $HOME_NET any -> [92.185.183.6] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202603; rev:1;) alert tcp $HOME_NET any -> [84.38.180.119] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202604; rev:1;) alert tcp $HOME_NET any -> [103.153.100.248] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202605; rev:1;) alert tcp $HOME_NET any -> [91.193.75.182] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202606; rev:1;) alert tcp $HOME_NET any -> [68.235.43.126] 56927 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202607; rev:1;) alert tcp $HOME_NET any -> [194.33.45.43] 1177 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202608; rev:1;) alert tcp $HOME_NET any -> [85.86.181.192] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202609; rev:1;) alert tcp $HOME_NET any -> [107.172.100.227] 3040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202610; rev:1;) alert tcp $HOME_NET any -> [103.147.184.53] 1991 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202611; rev:1;) alert tcp $HOME_NET any -> [13.58.162.35] 6207 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202612; rev:1;) alert tcp $HOME_NET any -> [218.253.251.89] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202613; rev:1;) alert tcp $HOME_NET any -> [68.235.43.124] 56927 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202614; rev:1;) alert tcp $HOME_NET any -> [3.87.210.81] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202615; rev:1;) alert tcp $HOME_NET any -> [46.243.150.195] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202616; rev:1;) alert tcp $HOME_NET any -> [217.69.0.99] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202617; rev:1;) alert tcp $HOME_NET any -> [41.105.120.192] 1231 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202618; rev:1;) alert tcp $HOME_NET any -> [107.172.100.223] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202619; rev:1;) alert tcp $HOME_NET any -> [91.193.75.122] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202620; rev:1;) alert tcp $HOME_NET any -> [198.23.212.148] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202621; rev:1;) alert tcp $HOME_NET any -> [188.72.124.19] 3310 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202622; rev:1;) alert tcp $HOME_NET any -> [95.179.152.155] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202623; rev:1;) alert tcp $HOME_NET any -> [92.185.183.6] 81 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202624; rev:1;) alert tcp $HOME_NET any -> [182.150.0.31] 19530 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202625; rev:1;) alert tcp $HOME_NET any -> [194.156.98.71] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202626; rev:1;) alert tcp $HOME_NET any -> [168.119.103.207] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202627; rev:1;) alert tcp $HOME_NET any -> [185.58.92.18] 5353 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202628; rev:1;) alert tcp $HOME_NET any -> [135.181.8.164] 4654 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202629; rev:1;) alert tcp $HOME_NET any -> [196.74.226.94] 92 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202630; rev:1;) alert tcp $HOME_NET any -> [45.15.143.216] 5210 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202631; rev:1;) alert tcp $HOME_NET any -> [128.90.108.165] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202632; rev:1;) alert tcp $HOME_NET any -> [103.99.1.128] 9875 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202633; rev:1;) alert tcp $HOME_NET any -> [194.5.98.93] 4545 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202634; rev:1;) alert tcp $HOME_NET any -> [46.31.77.31] 1453 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202635; rev:1;) alert tcp $HOME_NET any -> [38.132.99.154] 1234 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202636; rev:1;) alert tcp $HOME_NET any -> [79.134.225.88] 6458 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202637; rev:1;) alert tcp $HOME_NET any -> [185.140.53.178] 7743 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202638; rev:1;) alert tcp $HOME_NET any -> [45.15.143.234] 5366 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202639; rev:1;) alert tcp $HOME_NET any -> [79.134.225.22] 7898 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202640; rev:1;) alert tcp $HOME_NET any -> [79.134.225.22] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202641; rev:1;) alert tcp $HOME_NET any -> [195.20.109.121] 586 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202642; rev:1;) alert tcp $HOME_NET any -> [92.185.183.6] 14444 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202643; rev:1;) alert tcp $HOME_NET any -> [37.46.150.155] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202644; rev:1;) alert tcp $HOME_NET any -> [23.105.131.186] 9000 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202645; rev:1;) alert tcp $HOME_NET any -> [38.68.46.205] 8950 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202646; rev:1;) alert tcp $HOME_NET any -> [13.58.162.35] 10137 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202647; rev:1;) alert tcp $HOME_NET any -> [196.89.158.176] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202648; rev:1;) alert tcp $HOME_NET any -> [80.89.230.61] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202649; rev:1;) alert tcp $HOME_NET any -> [3.35.158.172] 1199 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202650; rev:1;) alert tcp $HOME_NET any -> [45.15.143.195] 5366 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202651; rev:1;) alert tcp $HOME_NET any -> [206.166.251.173] 5922 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202652; rev:1;) alert tcp $HOME_NET any -> [212.8.246.174] 3465 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202653; rev:1;) alert tcp $HOME_NET any -> [176.48.141.174] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202654; rev:1;) alert tcp $HOME_NET any -> [5.2.68.112] 2442 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202655; rev:1;) alert tcp $HOME_NET any -> [185.140.53.191] 4185 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202656; rev:1;) alert tcp $HOME_NET any -> [168.119.170.202] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202657; rev:1;) alert tcp $HOME_NET any -> [135.181.96.16] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202658; rev:1;) alert tcp $HOME_NET any -> [13.58.162.35] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202659; rev:1;) alert tcp $HOME_NET any -> [82.246.130.70] 4440 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202660; rev:1;) alert tcp $HOME_NET any -> [87.98.245.48] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202661; rev:1;) alert tcp $HOME_NET any -> [185.58.92.18] 4500 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202662; rev:1;) alert tcp $HOME_NET any -> [120.78.194.220] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202663; rev:1;) alert tcp $HOME_NET any -> [185.157.161.86] 20058 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202664; rev:1;) alert tcp $HOME_NET any -> [103.99.1.128] 3071 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202665; rev:1;) alert tcp $HOME_NET any -> [139.155.18.71] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202666; rev:1;) alert tcp $HOME_NET any -> [51.11.247.87] 2053 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202667; rev:1;) alert tcp $HOME_NET any -> [86.137.28.177] 3073 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202668; rev:1;) alert tcp $HOME_NET any -> [141.255.157.36] 10001 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202669; rev:1;) alert tcp $HOME_NET any -> [192.121.102.72] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202670; rev:1;) alert tcp $HOME_NET any -> [154.127.53.5] 4040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202671; rev:1;) alert tcp $HOME_NET any -> [139.59.23.248] 3439 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202672; rev:1;) alert tcp $HOME_NET any -> [88.229.12.141] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202673; rev:1;) alert tcp $HOME_NET any -> [191.88.250.254] 8050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202674; rev:1;) alert tcp $HOME_NET any -> [192.121.102.80] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202675; rev:1;) alert tcp $HOME_NET any -> [88.229.12.141] 222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202676; rev:1;) alert tcp $HOME_NET any -> [3.22.15.135] 14345 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202677; rev:1;) alert tcp $HOME_NET any -> [45.133.216.84] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202678; rev:1;) alert tcp $HOME_NET any -> [8.210.39.131] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202679; rev:1;) alert tcp $HOME_NET any -> [174.138.10.67] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202680; rev:1;) alert tcp $HOME_NET any -> [128.90.115.166] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202681; rev:1;) alert tcp $HOME_NET any -> [41.216.186.241] 443 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202682; rev:1;) alert tcp $HOME_NET any -> [173.234.155.108] 6666 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202683; rev:1;) alert tcp $HOME_NET any -> [45.32.146.181] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202684; rev:1;) alert tcp $HOME_NET any -> [197.207.162.125] 1231 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202685; rev:1;) alert tcp $HOME_NET any -> [185.157.161.86] 9980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202686; rev:1;) alert tcp $HOME_NET any -> [3.95.159.27] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202687; rev:1;) alert tcp $HOME_NET any -> [103.99.1.128] 6204 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202688; rev:1;) alert tcp $HOME_NET any -> [192.119.6.132] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202689; rev:1;) alert tcp $HOME_NET any -> [220.78.86.55] 1324 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202690; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 52297 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202691; rev:1;) alert tcp $HOME_NET any -> [1.54.66.90] 3189 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202692; rev:1;) alert tcp $HOME_NET any -> [85.86.181.192] 3333 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202693; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 56207 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202694; rev:1;) alert tcp $HOME_NET any -> [103.149.27.116] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202695; rev:1;) alert tcp $HOME_NET any -> [178.33.222.243] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202696; rev:1;) alert tcp $HOME_NET any -> [74.124.24.29] 2221 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202697; rev:1;) alert tcp $HOME_NET any -> [220.89.249.206] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202698; rev:1;) alert tcp $HOME_NET any -> [194.5.97.226] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202699; rev:1;) alert tcp $HOME_NET any -> [79.134.225.119] 9030 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202700; rev:1;) alert tcp $HOME_NET any -> [185.244.26.240] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202701; rev:1;) alert tcp $HOME_NET any -> [185.140.53.186] 1604 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202702; rev:1;) alert tcp $HOME_NET any -> [185.118.164.215] 4545 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202703; rev:1;) alert tcp $HOME_NET any -> [185.36.81.30] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202704; rev:1;) alert tcp $HOME_NET any -> [172.245.45.22] 9800 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202705; rev:1;) alert tcp $HOME_NET any -> [54.39.49.150] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202706; rev:1;) alert tcp $HOME_NET any -> [178.62.18.176] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202707; rev:1;) alert tcp $HOME_NET any -> [178.33.222.243] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202708; rev:1;) alert tcp $HOME_NET any -> [79.134.225.46] 7890 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202709; rev:1;) alert tcp $HOME_NET any -> [101.33.11.45] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202710; rev:1;) alert tcp $HOME_NET any -> [104.248.32.109] 22998 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202711; rev:1;) alert tcp $HOME_NET any -> [185.140.53.221] 7743 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202712; rev:1;) alert tcp $HOME_NET any -> [185.140.53.221] 6458 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202713; rev:1;) alert tcp $HOME_NET any -> [179.43.166.54] 8070 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202714; rev:1;) alert tcp $HOME_NET any -> [47.93.122.30] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202715; rev:1;) alert tcp $HOME_NET any -> [142.202.190.30] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202716; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 21457 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202717; rev:1;) alert tcp $HOME_NET any -> [79.134.225.18] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202718; rev:1;) alert tcp $HOME_NET any -> [38.74.14.151] 7832 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202719; rev:1;) alert tcp $HOME_NET any -> [142.202.190.30] 3040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202720; rev:1;) alert tcp $HOME_NET any -> [66.63.162.20] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202721; rev:1;) alert tcp $HOME_NET any -> [35.226.208.32] 4440 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202722; rev:1;) alert tcp $HOME_NET any -> [111.229.83.227] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202723; rev:1;) alert tcp $HOME_NET any -> [45.227.255.74] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202724; rev:1;) alert tcp $HOME_NET any -> [180.214.236.99] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202725; rev:1;) alert tcp $HOME_NET any -> [79.134.225.24] 1800 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202726; rev:1;) alert tcp $HOME_NET any -> [194.5.98.17] 9040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202727; rev:1;) alert tcp $HOME_NET any -> [128.90.108.161] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202728; rev:1;) alert tcp $HOME_NET any -> [86.106.181.177] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202729; rev:1;) alert tcp $HOME_NET any -> [3.19.26.213] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202730; rev:1;) alert tcp $HOME_NET any -> [41.141.241.250] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202731; rev:1;) alert tcp $HOME_NET any -> [23.105.131.129] 3071 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202732; rev:1;) alert tcp $HOME_NET any -> [37.120.208.40] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202733; rev:1;) alert tcp $HOME_NET any -> [185.140.53.211] 5277 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202734; rev:1;) alert tcp $HOME_NET any -> [198.44.97.180] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202735; rev:1;) alert tcp $HOME_NET any -> [45.142.215.100] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202736; rev:1;) alert tcp $HOME_NET any -> [185.82.202.123] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202737; rev:1;) alert tcp $HOME_NET any -> [54.253.227.154] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202738; rev:1;) alert tcp $HOME_NET any -> [185.14.30.217] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202739; rev:1;) alert tcp $HOME_NET any -> [185.128.25.29] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202740; rev:1;) alert tcp $HOME_NET any -> [160.20.146.178] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202741; rev:1;) alert tcp $HOME_NET any -> [39.37.22.52] 6905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202742; rev:1;) alert tcp $HOME_NET any -> [172.86.75.177] 6922 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202743; rev:1;) alert tcp $HOME_NET any -> [185.191.32.180] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202744; rev:1;) alert tcp $HOME_NET any -> [185.144.29.169] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202745; rev:1;) alert tcp $HOME_NET any -> [81.70.2.180] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202746; rev:1;) alert tcp $HOME_NET any -> [185.193.36.73] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202747; rev:1;) alert tcp $HOME_NET any -> [178.128.220.110] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202748; rev:1;) alert tcp $HOME_NET any -> [103.74.192.54] 4443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202749; rev:1;) alert tcp $HOME_NET any -> [3.21.227.133] 3302 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202750; rev:1;) alert tcp $HOME_NET any -> [47.114.39.239] 12345 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202751; rev:1;) alert tcp $HOME_NET any -> [27.22.58.175] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202752; rev:1;) alert tcp $HOME_NET any -> [185.157.162.81] 1973 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202753; rev:1;) alert tcp $HOME_NET any -> [185.157.162.81] 1973 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202754; rev:1;) alert tcp $HOME_NET any -> [185.20.185.96] 9091 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202755; rev:1;) alert tcp $HOME_NET any -> [147.229.68.116] 1268 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202756; rev:1;) alert tcp $HOME_NET any -> [193.239.147.22] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202757; rev:1;) alert tcp $HOME_NET any -> [91.241.19.51] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202758; rev:1;) alert tcp $HOME_NET any -> [103.153.76.244] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202759; rev:1;) alert tcp $HOME_NET any -> [185.157.161.109] 1973 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202760; rev:1;) alert tcp $HOME_NET any -> [171.221.221.25] 2049 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202761; rev:1;) alert tcp $HOME_NET any -> [79.134.225.20] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202762; rev:1;) alert tcp $HOME_NET any -> [45.134.21.8] 72 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202763; rev:1;) alert tcp $HOME_NET any -> [2.56.213.183] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202764; rev:1;) alert tcp $HOME_NET any -> [154.44.177.186] 4433 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202765; rev:1;) alert tcp $HOME_NET any -> [185.19.85.155] 5080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202766; rev:1;) alert tcp $HOME_NET any -> [45.144.30.25] 4404 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202767; rev:1;) alert tcp $HOME_NET any -> [185.105.109.19] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware.DarkSide C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202768; rev:1;) alert tcp $HOME_NET any -> [45.141.59.139] 9898 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202769; rev:1;) alert tcp $HOME_NET any -> [88.119.171.64] 72 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202770; rev:1;) alert tcp $HOME_NET any -> [41.227.47.76] 4898 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202771; rev:1;) alert tcp $HOME_NET any -> [207.148.70.82] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202772; rev:1;) alert tcp $HOME_NET any -> [175.203.53.37] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202773; rev:1;) alert tcp $HOME_NET any -> [160.20.146.178] 5075 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202774; rev:1;) alert tcp $HOME_NET any -> [34.203.235.59] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202775; rev:1;) alert tcp $HOME_NET any -> [80.82.77.164] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202776; rev:1;) alert tcp $HOME_NET any -> [117.51.149.186] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202777; rev:1;) alert tcp $HOME_NET any -> [178.79.134.144] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202778; rev:1;) alert tcp $HOME_NET any -> [194.5.97.249] 9951 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202779; rev:1;) alert tcp $HOME_NET any -> [185.250.242.202] 7000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202780; rev:1;) alert tcp $HOME_NET any -> [185.128.25.29] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202781; rev:1;) alert tcp $HOME_NET any -> [45.144.30.41] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202782; rev:1;) alert tcp $HOME_NET any -> [23.105.131.165] 8094 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202783; rev:1;) alert tcp $HOME_NET any -> [185.58.95.125] 4500 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202784; rev:1;) alert tcp $HOME_NET any -> [45.141.59.139] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202785; rev:1;) alert tcp $HOME_NET any -> [132.232.94.126] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202786; rev:1;) alert tcp $HOME_NET any -> [79.134.225.54] 4545 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202787; rev:1;) alert tcp $HOME_NET any -> [195.123.217.7] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202788; rev:1;) alert tcp $HOME_NET any -> [154.208.76.59] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202789; rev:1;) alert tcp $HOME_NET any -> [161.35.218.255] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202790; rev:1;) alert tcp $HOME_NET any -> [79.134.225.37] 30493 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202791; rev:1;) alert tcp $HOME_NET any -> [79.134.225.50] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202792; rev:1;) alert tcp $HOME_NET any -> [5.230.22.165] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202793; rev:1;) alert tcp $HOME_NET any -> [47.95.37.84] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202794; rev:1;) alert tcp $HOME_NET any -> [34.211.110.219] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202795; rev:1;) alert tcp $HOME_NET any -> [185.128.25.29] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202796; rev:1;) alert tcp $HOME_NET any -> [47.103.212.53] 16777 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202797; rev:1;) alert tcp $HOME_NET any -> [69.51.24.27] 666 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202798; rev:1;) alert tcp $HOME_NET any -> [37.120.208.39] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202799; rev:1;) alert tcp $HOME_NET any -> [37.59.47.123] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202800; rev:1;) alert tcp $HOME_NET any -> [37.120.208.36] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202801; rev:1;) alert tcp $HOME_NET any -> [78.128.113.14] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202802; rev:1;) alert tcp $HOME_NET any -> [45.140.147.167] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202803; rev:1;) alert tcp $HOME_NET any -> [45.140.146.181] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202804; rev:1;) alert tcp $HOME_NET any -> [81.69.14.19] 45832 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202805; rev:1;) alert tcp $HOME_NET any -> [173.234.25.74] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202806; rev:1;) alert tcp $HOME_NET any -> [192.253.244.149] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202807; rev:1;) alert tcp $HOME_NET any -> [119.3.141.162] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202808; rev:1;) alert tcp $HOME_NET any -> [185.153.198.121] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202809; rev:1;) alert tcp $HOME_NET any -> [176.122.152.67] 4433 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202810; rev:1;) alert tcp $HOME_NET any -> [194.113.34.49] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202811; rev:1;) alert tcp $HOME_NET any -> [37.120.208.36] 49703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202812; rev:1;) alert tcp $HOME_NET any -> [47.91.237.42] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202813; rev:1;) alert tcp $HOME_NET any -> [79.134.225.14] 8070 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202814; rev:1;) alert tcp $HOME_NET any -> [172.245.26.140] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202815; rev:1;) alert tcp $HOME_NET any -> [203.115.24.234] 8282 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202816; rev:1;) alert tcp $HOME_NET any -> [185.244.30.253] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202817; rev:1;) alert tcp $HOME_NET any -> [62.102.148.158] 62727 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202818; rev:1;) alert tcp $HOME_NET any -> [45.32.129.110] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202819; rev:1;) alert tcp $HOME_NET any -> [185.244.26.206] 20905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202820; rev:1;) alert tcp $HOME_NET any -> [142.202.190.27] 3040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202821; rev:1;) alert tcp $HOME_NET any -> [79.134.225.99] 4726 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202822; rev:1;) alert tcp $HOME_NET any -> [160.20.146.178] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202823; rev:1;) alert tcp $HOME_NET any -> [185.140.53.234] 2558 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202824; rev:1;) alert tcp $HOME_NET any -> [43.242.201.222] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202825; rev:1;) alert tcp $HOME_NET any -> [79.134.225.104] 20905 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202826; rev:1;) alert tcp $HOME_NET any -> [169.61.11.75] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202827; rev:1;) alert tcp $HOME_NET any -> [91.109.188.7] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202828; rev:1;) alert tcp $HOME_NET any -> [84.38.183.222] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202829; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 57654 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202830; rev:1;) alert tcp $HOME_NET any -> [108.62.118.217] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202831; rev:1;) alert tcp $HOME_NET any -> [8.210.125.201] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202832; rev:1;) alert tcp $HOME_NET any -> [217.12.208.31] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202833; rev:1;) alert tcp $HOME_NET any -> [155.94.198.169] 1990 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202834; rev:1;) alert tcp $HOME_NET any -> [154.127.53.31] 5252 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202835; rev:1;) alert tcp $HOME_NET any -> [194.5.97.177] 10011 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202836; rev:1;) alert tcp $HOME_NET any -> [18.207.200.0] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202837; rev:1;) alert tcp $HOME_NET any -> [3.15.15.105] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202838; rev:1;) alert tcp $HOME_NET any -> [47.242.30.106] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202839; rev:1;) alert tcp $HOME_NET any -> [45.254.64.7] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202840; rev:1;) alert tcp $HOME_NET any -> [18.216.15.65] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202841; rev:1;) alert tcp $HOME_NET any -> [34.204.7.171] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202842; rev:1;) alert tcp $HOME_NET any -> [91.193.75.108] 8070 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202843; rev:1;) alert tcp $HOME_NET any -> [37.120.208.37] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202844; rev:1;) alert tcp $HOME_NET any -> [47.108.129.143] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202845; rev:1;) alert tcp $HOME_NET any -> [95.181.157.49] 1738 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202846; rev:1;) alert tcp $HOME_NET any -> [217.12.218.250] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202847; rev:1;) alert tcp $HOME_NET any -> [188.119.112.174] 8081 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202848; rev:1;) alert tcp $HOME_NET any -> [3.129.73.255] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202849; rev:1;) alert tcp $HOME_NET any -> [185.244.30.185] 9101 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202850; rev:1;) alert tcp $HOME_NET any -> [96.9.241.60] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202851; rev:1;) alert tcp $HOME_NET any -> [18.223.210.216] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202852; rev:1;) alert tcp $HOME_NET any -> [206.166.251.75] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202853; rev:1;) alert tcp $HOME_NET any -> [49.233.89.89] 8443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202854; rev:1;) alert tcp $HOME_NET any -> [185.140.53.186] 2626 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202855; rev:1;) alert tcp $HOME_NET any -> [45.147.229.52] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202856; rev:1;) alert tcp $HOME_NET any -> [91.203.193.163] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202857; rev:1;) alert tcp $HOME_NET any -> [157.230.184.142] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202858; rev:1;) alert tcp $HOME_NET any -> [2.56.213.183] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202859; rev:1;) alert tcp $HOME_NET any -> [79.134.225.99] 4449 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202860; rev:1;) alert tcp $HOME_NET any -> [54.236.241.94] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202861; rev:1;) alert tcp $HOME_NET any -> [35.161.73.88] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202862; rev:1;) alert tcp $HOME_NET any -> [177.255.91.168] 8057 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202863; rev:1;) alert tcp $HOME_NET any -> [62.171.141.54] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202864; rev:1;) alert tcp $HOME_NET any -> [185.140.53.141] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202865; rev:1;) alert tcp $HOME_NET any -> [47.241.25.81] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202866; rev:1;) alert tcp $HOME_NET any -> [185.165.153.249] 4371 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202867; rev:1;) alert tcp $HOME_NET any -> [185.118.167.189] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202868; rev:1;) alert tcp $HOME_NET any -> [47.251.11.230] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202869; rev:1;) alert tcp $HOME_NET any -> [46.166.161.85] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202870; rev:1;) alert tcp $HOME_NET any -> [173.234.155.227] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202871; rev:1;) alert tcp $HOME_NET any -> [207.148.116.8] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202872; rev:1;) alert tcp $HOME_NET any -> [79.134.225.82] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202873; rev:1;) alert tcp $HOME_NET any -> [3.82.47.49] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202874; rev:1;) alert tcp $HOME_NET any -> [35.160.72.225] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202875; rev:1;) alert tcp $HOME_NET any -> [128.90.115.218] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202876; rev:1;) alert tcp $HOME_NET any -> [45.128.206.55] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202877; rev:1;) alert tcp $HOME_NET any -> [74.118.138.139] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202878; rev:1;) alert tcp $HOME_NET any -> [79.134.225.39] 6513 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202879; rev:1;) alert tcp $HOME_NET any -> [3.93.232.10] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202880; rev:1;) alert tcp $HOME_NET any -> [45.147.231.65] 3002 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202881; rev:1;) alert tcp $HOME_NET any -> [45.79.72.33] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202882; rev:1;) alert tcp $HOME_NET any -> [54.224.34.171] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202883; rev:1;) alert tcp $HOME_NET any -> [18.219.29.151] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202884; rev:1;) alert tcp $HOME_NET any -> [34.222.33.48] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202885; rev:1;) alert tcp $HOME_NET any -> [8.209.124.215] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202886; rev:1;) alert tcp $HOME_NET any -> [2.56.62.44] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202887; rev:1;) alert tcp $HOME_NET any -> [128.90.115.47] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202888; rev:1;) alert tcp $HOME_NET any -> [185.19.85.149] 6667 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202889; rev:1;) alert tcp $HOME_NET any -> [188.116.36.154] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202890; rev:1;) alert tcp $HOME_NET any -> [8.208.102.117] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202891; rev:1;) alert tcp $HOME_NET any -> [45.128.207.226] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202892; rev:1;) alert tcp $HOME_NET any -> [91.109.176.2] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202893; rev:1;) alert tcp $HOME_NET any -> [139.155.245.29] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202894; rev:1;) alert tcp $HOME_NET any -> [103.214.165.213] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202895; rev:1;) alert tcp $HOME_NET any -> [93.114.128.73] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202896; rev:1;) alert tcp $HOME_NET any -> [142.93.7.219] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202897; rev:1;) alert tcp $HOME_NET any -> [192.253.244.137] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202898; rev:1;) alert tcp $HOME_NET any -> [45.147.230.131] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202899; rev:1;) alert tcp $HOME_NET any -> [46.173.218.209] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202900; rev:1;) alert tcp $HOME_NET any -> [118.107.41.104] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202901; rev:1;) alert tcp $HOME_NET any -> [118.89.139.166] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202902; rev:1;) alert tcp $HOME_NET any -> [54.245.74.151] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202903; rev:1;) alert tcp $HOME_NET any -> [18.188.194.80] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202904; rev:1;) alert tcp $HOME_NET any -> [156.96.47.42] 586 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202905; rev:1;) alert tcp $HOME_NET any -> [193.218.118.190] 2407 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202906; rev:1;) alert tcp $HOME_NET any -> [185.183.96.173] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202907; rev:1;) alert tcp $HOME_NET any -> [134.19.177.55] 4040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202908; rev:1;) alert tcp $HOME_NET any -> [101.32.183.30] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202909; rev:1;) alert tcp $HOME_NET any -> [79.134.225.15] 43360 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202910; rev:1;) alert tcp $HOME_NET any -> [194.5.97.130] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202911; rev:1;) alert tcp $HOME_NET any -> [103.27.237.75] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202912; rev:1;) alert tcp $HOME_NET any -> [34.221.202.231] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202913; rev:1;) alert tcp $HOME_NET any -> [3.137.180.197] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202914; rev:1;) alert tcp $HOME_NET any -> [185.165.153.249] 4571 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202915; rev:1;) alert tcp $HOME_NET any -> [192.253.244.137] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202916; rev:1;) alert tcp $HOME_NET any -> [37.120.208.36] 49714 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202917; rev:1;) alert tcp $HOME_NET any -> [222.114.199.209] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202918; rev:1;) alert tcp $HOME_NET any -> [8.208.76.109] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202919; rev:1;) alert tcp $HOME_NET any -> [3.15.221.20] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202920; rev:1;) alert tcp $HOME_NET any -> [139.59.230.84] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202921; rev:1;) alert tcp $HOME_NET any -> [101.32.97.85] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202922; rev:1;) alert tcp $HOME_NET any -> [101.32.97.85] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202923; rev:1;) alert tcp $HOME_NET any -> [185.244.30.24] 8913 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202924; rev:1;) alert tcp $HOME_NET any -> [34.205.89.33] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202925; rev:1;) alert tcp $HOME_NET any -> [52.34.17.37] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202926; rev:1;) alert tcp $HOME_NET any -> [47.254.169.137] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202927; rev:1;) alert tcp $HOME_NET any -> [128.90.115.217] 3470 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202928; rev:1;) alert tcp $HOME_NET any -> [54.162.201.128] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202929; rev:1;) alert tcp $HOME_NET any -> [3.81.126.82] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202930; rev:1;) alert tcp $HOME_NET any -> [18.207.182.253] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202931; rev:1;) alert tcp $HOME_NET any -> [3.235.164.215] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202932; rev:1;) alert tcp $HOME_NET any -> [45.128.207.41] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202933; rev:1;) alert tcp $HOME_NET any -> [35.160.125.254] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202934; rev:1;) alert tcp $HOME_NET any -> [52.12.203.202] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202935; rev:1;) alert tcp $HOME_NET any -> [13.58.213.252] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202936; rev:1;) alert tcp $HOME_NET any -> [79.134.225.5] 1221 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202937; rev:1;) alert tcp $HOME_NET any -> [79.134.225.83] 8913 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202938; rev:1;) alert tcp $HOME_NET any -> [202.182.121.93] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202939; rev:1;) alert tcp $HOME_NET any -> [45.128.207.185] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202940; rev:1;) alert tcp $HOME_NET any -> [47.254.26.204] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202941; rev:1;) alert tcp $HOME_NET any -> [178.79.179.200] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202942; rev:1;) alert tcp $HOME_NET any -> [79.134.225.40] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202943; rev:1;) alert tcp $HOME_NET any -> [54.175.34.120] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202944; rev:1;) alert tcp $HOME_NET any -> [18.209.104.208] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202945; rev:1;) alert tcp $HOME_NET any -> [185.165.153.140] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202946; rev:1;) alert tcp $HOME_NET any -> [161.117.254.2] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202947; rev:1;) alert tcp $HOME_NET any -> [205.185.113.54] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202948; rev:1;) alert tcp $HOME_NET any -> [191.88.254.193] 1880 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202949; rev:1;) alert tcp $HOME_NET any -> [172.98.192.91] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202950; rev:1;) alert tcp $HOME_NET any -> [178.33.222.241] 2703 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202951; rev:1;) alert tcp $HOME_NET any -> [185.165.153.251] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202952; rev:1;) alert tcp $HOME_NET any -> [185.140.53.132] 7799 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202953; rev:1;) alert tcp $HOME_NET any -> [23.105.131.174] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202954; rev:1;) alert tcp $HOME_NET any -> [79.134.225.92] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202955; rev:1;) alert tcp $HOME_NET any -> [178.33.222.241] 49746 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202956; rev:1;) alert tcp $HOME_NET any -> [217.8.117.17] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202957; rev:1;) alert tcp $HOME_NET any -> [31.220.4.216] 7010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202958; rev:1;) alert tcp $HOME_NET any -> [104.161.77.84] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202959; rev:1;) alert tcp $HOME_NET any -> [51.79.119.231] 13371 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202960; rev:1;) alert tcp $HOME_NET any -> [51.79.119.231] 13371 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202961; rev:1;) alert tcp $HOME_NET any -> [185.150.117.63] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202962; rev:1;) alert tcp $HOME_NET any -> [194.5.97.21] 7788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202963; rev:1;) alert tcp $HOME_NET any -> [188.166.220.127] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202964; rev:1;) alert tcp $HOME_NET any -> [46.166.161.159] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202965; rev:1;) alert tcp $HOME_NET any -> [46.166.129.195] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202966; rev:1;) alert tcp $HOME_NET any -> [164.90.153.241] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202967; rev:1;) alert tcp $HOME_NET any -> [18.222.171.22] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202968; rev:1;) alert tcp $HOME_NET any -> [137.117.241.192] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202969; rev:1;) alert tcp $HOME_NET any -> [92.38.149.158] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202970; rev:1;) alert tcp $HOME_NET any -> [134.19.177.55] 3040 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202971; rev:1;) alert tcp $HOME_NET any -> [211.152.136.89] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202972; rev:1;) alert tcp $HOME_NET any -> [91.193.75.18] 1313 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202973; rev:1;) alert tcp $HOME_NET any -> [79.134.225.16] 8891 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202974; rev:1;) alert tcp $HOME_NET any -> [94.156.35.109] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202975; rev:1;) alert tcp $HOME_NET any -> [104.168.175.192] 444 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202976; rev:1;) alert tcp $HOME_NET any -> [43.242.201.222] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202977; rev:1;) alert tcp $HOME_NET any -> [91.193.75.225] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202978; rev:1;) alert tcp $HOME_NET any -> [185.244.30.167] 2256 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202979; rev:1;) alert tcp $HOME_NET any -> [5.188.0.82] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202980; rev:1;) alert tcp $HOME_NET any -> [91.193.75.28] 2190 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202981; rev:1;) alert tcp $HOME_NET any -> [211.152.136.77] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202982; rev:1;) alert tcp $HOME_NET any -> [79.134.225.73] 5610 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202983; rev:1;) alert tcp $HOME_NET any -> [185.140.53.138] 1382 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202984; rev:1;) alert tcp $HOME_NET any -> [185.231.113.131] 2016 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202985; rev:1;) alert tcp $HOME_NET any -> [103.207.39.83] 1024 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202986; rev:1;) alert tcp $HOME_NET any -> [91.193.75.171] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202987; rev:1;) alert tcp $HOME_NET any -> [194.5.97.23] 9321 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202988; rev:1;) alert tcp $HOME_NET any -> [91.193.75.35] 1690 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202989; rev:1;) alert tcp $HOME_NET any -> [54.37.36.116] 7866 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202990; rev:1;) alert tcp $HOME_NET any -> [79.134.225.84] 20904 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202991; rev:1;) alert tcp $HOME_NET any -> [66.42.39.79] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202992; rev:1;) alert tcp $HOME_NET any -> [101.226.26.165] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202993; rev:1;) alert tcp $HOME_NET any -> [51.116.230.173] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202994; rev:1;) alert tcp $HOME_NET any -> [179.14.12.213] 8050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202995; rev:1;) alert tcp $HOME_NET any -> [185.140.53.132] 6868 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202996; rev:1;) alert tcp $HOME_NET any -> [194.5.97.15] 8824 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202997; rev:1;) alert tcp $HOME_NET any -> [79.134.225.107] 20923 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202998; rev:1;) alert tcp $HOME_NET any -> [211.152.136.87] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905202999; rev:1;) alert tcp $HOME_NET any -> [134.19.177.55] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203000; rev:1;) alert tcp $HOME_NET any -> [194.5.97.245] 4575 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203001; rev:1;) alert tcp $HOME_NET any -> [128.90.108.105] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203002; rev:1;) alert tcp $HOME_NET any -> [79.134.225.85] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203003; rev:1;) alert tcp $HOME_NET any -> [128.90.115.32] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203004; rev:1;) alert tcp $HOME_NET any -> [185.140.53.145] 2558 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203005; rev:1;) alert tcp $HOME_NET any -> [185.140.53.220] 20986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203006; rev:1;) alert tcp $HOME_NET any -> [128.90.115.83] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203007; rev:1;) alert tcp $HOME_NET any -> [185.244.30.201] 4575 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203008; rev:1;) alert tcp $HOME_NET any -> [185.244.30.130] 20904 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203009; rev:1;) alert tcp $HOME_NET any -> [180.97.251.173] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203010; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 2507 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203011; rev:1;) alert tcp $HOME_NET any -> [104.131.33.128] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203012; rev:1;) alert tcp $HOME_NET any -> [185.165.153.43] 5007 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203013; rev:1;) alert tcp $HOME_NET any -> [185.140.53.132] 5484 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203014; rev:1;) alert tcp $HOME_NET any -> [128.90.115.150] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203015; rev:1;) alert tcp $HOME_NET any -> [77.48.28.230] 20986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203016; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 1506 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203017; rev:1;) alert tcp $HOME_NET any -> [185.193.127.203] 6000 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203018; rev:1;) alert tcp $HOME_NET any -> [91.193.181.158] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203019; rev:1;) alert tcp $HOME_NET any -> [185.140.53.68] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203020; rev:1;) alert tcp $HOME_NET any -> [185.140.53.135] 5484 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203021; rev:1;) alert tcp $HOME_NET any -> [5.149.253.199] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203022; rev:1;) alert tcp $HOME_NET any -> [185.165.153.116] 7866 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203023; rev:1;) alert tcp $HOME_NET any -> [79.134.225.78] 5007 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203024; rev:1;) alert tcp $HOME_NET any -> [128.90.115.41] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203025; rev:1;) alert tcp $HOME_NET any -> [128.90.115.45] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203026; rev:1;) alert tcp $HOME_NET any -> [194.5.97.33] 5200 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203027; rev:1;) alert tcp $HOME_NET any -> [128.90.115.237] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203028; rev:1;) alert tcp $HOME_NET any -> [64.227.103.18] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203029; rev:1;) alert tcp $HOME_NET any -> [45.66.250.145] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203030; rev:1;) alert tcp $HOME_NET any -> [45.143.223.34] 3218 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203031; rev:1;) alert tcp $HOME_NET any -> [185.157.162.81] 9980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203032; rev:1;) alert tcp $HOME_NET any -> [185.140.53.9] 7003 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203033; rev:1;) alert tcp $HOME_NET any -> [192.119.80.53] 4576 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203034; rev:1;) alert tcp $HOME_NET any -> [23.163.0.37] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203035; rev:1;) alert tcp $HOME_NET any -> [185.140.53.7] 2786 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203036; rev:1;) alert tcp $HOME_NET any -> [161.35.174.89] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203037; rev:1;) alert tcp $HOME_NET any -> [157.245.164.207] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203038; rev:1;) alert tcp $HOME_NET any -> [103.89.91.6] 20902 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203039; rev:1;) alert tcp $HOME_NET any -> [79.134.225.84] 3454 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203040; rev:1;) alert tcp $HOME_NET any -> [185.165.153.32] 8824 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203041; rev:1;) alert tcp $HOME_NET any -> [185.165.153.209] 1990 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203042; rev:1;) alert tcp $HOME_NET any -> [185.157.162.81] 20058 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203043; rev:1;) alert tcp $HOME_NET any -> [45.11.19.57] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203044; rev:1;) alert tcp $HOME_NET any -> [194.87.18.22] 2382 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203045; rev:1;) alert tcp $HOME_NET any -> [185.165.153.173] 20986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203046; rev:1;) alert tcp $HOME_NET any -> [194.5.97.33] 1616 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203047; rev:1;) alert tcp $HOME_NET any -> [138.197.175.96] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203048; rev:1;) alert tcp $HOME_NET any -> [194.5.249.199] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203049; rev:1;) alert tcp $HOME_NET any -> [182.92.202.24] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203050; rev:1;) alert tcp $HOME_NET any -> [194.5.97.11] 27031 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203051; rev:1;) alert tcp $HOME_NET any -> [194.5.249.11] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203052; rev:1;) alert tcp $HOME_NET any -> [134.209.160.222] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203053; rev:1;) alert tcp $HOME_NET any -> [160.20.145.14] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203054; rev:1;) alert tcp $HOME_NET any -> [109.248.11.131] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203055; rev:1;) alert tcp $HOME_NET any -> [85.143.223.5] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203056; rev:1;) alert tcp $HOME_NET any -> [89.40.181.108] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203057; rev:1;) alert tcp $HOME_NET any -> [185.140.53.142] 20986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203058; rev:1;) alert tcp $HOME_NET any -> [217.12.218.199] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203059; rev:1;) alert tcp $HOME_NET any -> [206.189.164.25] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203060; rev:1;) alert tcp $HOME_NET any -> [5.34.180.91] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203061; rev:1;) alert tcp $HOME_NET any -> [160.20.145.14] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203062; rev:1;) alert tcp $HOME_NET any -> [185.19.85.155] 2327 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203063; rev:1;) alert tcp $HOME_NET any -> [185.165.153.116] 7896 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203064; rev:1;) alert tcp $HOME_NET any -> [79.134.225.55] 9654 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203065; rev:1;) alert tcp $HOME_NET any -> [159.89.174.73] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203066; rev:1;) alert tcp $HOME_NET any -> [194.5.249.184] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203067; rev:1;) alert tcp $HOME_NET any -> [217.195.153.131] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203068; rev:1;) alert tcp $HOME_NET any -> [79.134.225.51] 2211 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203069; rev:1;) alert tcp $HOME_NET any -> [87.251.70.44] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203070; rev:1;) alert tcp $HOME_NET any -> [194.5.97.4] 8824 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203071; rev:1;) alert tcp $HOME_NET any -> [193.38.51.60] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203072; rev:1;) alert tcp $HOME_NET any -> [51.15.136.48] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203073; rev:1;) alert tcp $HOME_NET any -> [172.111.200.225] 5842 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203074; rev:1;) alert tcp $HOME_NET any -> [192.145.125.42] 4430 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203075; rev:1;) alert tcp $HOME_NET any -> [134.209.191.228] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203076; rev:1;) alert tcp $HOME_NET any -> [111.90.146.85] 1730 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203077; rev:1;) alert tcp $HOME_NET any -> [185.33.86.54] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203078; rev:1;) alert tcp $HOME_NET any -> [122.228.4.169] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203079; rev:1;) alert tcp $HOME_NET any -> [45.66.250.228] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203080; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 30986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203081; rev:1;) alert tcp $HOME_NET any -> [194.187.249.152] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203082; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 1104 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203083; rev:1;) alert tcp $HOME_NET any -> [138.68.50.71] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203084; rev:1;) alert tcp $HOME_NET any -> [194.5.249.122] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203085; rev:1;) alert tcp $HOME_NET any -> [194.5.97.23] 8824 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203086; rev:1;) alert tcp $HOME_NET any -> [91.193.75.59] 20058 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203087; rev:1;) alert tcp $HOME_NET any -> [185.140.53.17] 2211 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203088; rev:1;) alert tcp $HOME_NET any -> [164.90.220.32] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203089; rev:1;) alert tcp $HOME_NET any -> [185.140.53.217] 2123 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203090; rev:1;) alert tcp $HOME_NET any -> [216.230.73.22] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203091; rev:1;) alert tcp $HOME_NET any -> [144.168.224.152] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203092; rev:1;) alert tcp $HOME_NET any -> [45.66.250.229] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203093; rev:1;) alert tcp $HOME_NET any -> [45.66.250.16] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203094; rev:1;) alert tcp $HOME_NET any -> [37.49.230.113] 1524 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203095; rev:1;) alert tcp $HOME_NET any -> [37.49.230.113] 3281 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203096; rev:1;) alert tcp $HOME_NET any -> [194.5.97.58] 20923 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203097; rev:1;) alert tcp $HOME_NET any -> [37.120.146.7] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203098; rev:1;) alert tcp $HOME_NET any -> [103.153.76.133] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203099; rev:1;) alert tcp $HOME_NET any -> [51.75.155.78] 8595 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203100; rev:1;) alert tcp $HOME_NET any -> [95.211.170.243] 1576 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203101; rev:1;) alert tcp $HOME_NET any -> [157.230.17.102] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203102; rev:1;) alert tcp $HOME_NET any -> [146.0.77.108] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203103; rev:1;) alert tcp $HOME_NET any -> [172.94.47.80] 4411 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203104; rev:1;) alert tcp $HOME_NET any -> [82.102.28.107] 62727 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203105; rev:1;) alert tcp $HOME_NET any -> [194.5.98.81] 3434 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203106; rev:1;) alert tcp $HOME_NET any -> [116.203.55.94] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203107; rev:1;) alert tcp $HOME_NET any -> [2.56.214.165] 1234 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203108; rev:1;) alert tcp $HOME_NET any -> [140.82.33.50] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203109; rev:1;) alert tcp $HOME_NET any -> [37.120.146.107] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203110; rev:1;) alert tcp $HOME_NET any -> [161.35.100.78] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203111; rev:1;) alert tcp $HOME_NET any -> [107.148.200.130] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203112; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 46300 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203113; rev:1;) alert tcp $HOME_NET any -> [45.153.240.101] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203114; rev:1;) alert tcp $HOME_NET any -> [103.151.122.113] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203115; rev:1;) alert tcp $HOME_NET any -> [194.5.98.95] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203116; rev:1;) alert tcp $HOME_NET any -> [178.238.8.65] 5055 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203117; rev:1;) alert tcp $HOME_NET any -> [194.5.249.158] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203118; rev:1;) alert tcp $HOME_NET any -> [128.90.108.78] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203119; rev:1;) alert tcp $HOME_NET any -> [91.234.99.15] 443 (msg:"SSLBL: Traffic to malicious host (likely DiamondFox C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203120; rev:1;) alert tcp $HOME_NET any -> [139.59.56.38] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203121; rev:1;) alert tcp $HOME_NET any -> [188.172.80.161] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203122; rev:1;) alert tcp $HOME_NET any -> [78.31.63.30] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203123; rev:1;) alert tcp $HOME_NET any -> [128.90.108.74] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203124; rev:1;) alert tcp $HOME_NET any -> [63.209.33.1] 25980 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203125; rev:1;) alert tcp $HOME_NET any -> [181.52.111.14] 1881 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203126; rev:1;) alert tcp $HOME_NET any -> [185.140.53.130] 6996 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203127; rev:1;) alert tcp $HOME_NET any -> [128.90.108.26] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203128; rev:1;) alert tcp $HOME_NET any -> [185.70.184.88] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203129; rev:1;) alert tcp $HOME_NET any -> [51.161.96.106] 3001 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203130; rev:1;) alert tcp $HOME_NET any -> [51.161.96.106] 3001 (msg:"SSLBL: Traffic to malicious host (likely BitRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203131; rev:1;) alert tcp $HOME_NET any -> [23.254.118.153] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203132; rev:1;) alert tcp $HOME_NET any -> [188.130.138.207] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203133; rev:1;) alert tcp $HOME_NET any -> [142.202.240.110] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203134; rev:1;) alert tcp $HOME_NET any -> [185.22.152.19] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203135; rev:1;) alert tcp $HOME_NET any -> [91.109.176.4] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203136; rev:1;) alert tcp $HOME_NET any -> [51.210.87.65] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203137; rev:1;) alert tcp $HOME_NET any -> [45.153.240.153] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203138; rev:1;) alert tcp $HOME_NET any -> [128.90.108.246] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203139; rev:1;) alert tcp $HOME_NET any -> [91.193.75.93] 20987 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203140; rev:1;) alert tcp $HOME_NET any -> [185.140.53.219] 8891 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203141; rev:1;) alert tcp $HOME_NET any -> [37.49.224.150] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203142; rev:1;) alert tcp $HOME_NET any -> [5.101.51.133] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203143; rev:1;) alert tcp $HOME_NET any -> [45.66.250.148] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203144; rev:1;) alert tcp $HOME_NET any -> [151.106.19.145] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203145; rev:1;) alert tcp $HOME_NET any -> [84.38.183.161] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203146; rev:1;) alert tcp $HOME_NET any -> [194.5.97.49] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203147; rev:1;) alert tcp $HOME_NET any -> [128.90.108.56] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203148; rev:1;) alert tcp $HOME_NET any -> [191.101.130.42] 9931 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203149; rev:1;) alert tcp $HOME_NET any -> [194.5.98.8] 8824 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203150; rev:1;) alert tcp $HOME_NET any -> [149.255.35.92] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203151; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 7071 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203152; rev:1;) alert tcp $HOME_NET any -> [206.123.129.103] 5456 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203153; rev:1;) alert tcp $HOME_NET any -> [46.101.163.251] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203154; rev:1;) alert tcp $HOME_NET any -> [194.5.249.109] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203155; rev:1;) alert tcp $HOME_NET any -> [188.120.255.249] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203156; rev:1;) alert tcp $HOME_NET any -> [35.241.200.200] 10132 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203157; rev:1;) alert tcp $HOME_NET any -> [188.120.255.141] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203158; rev:1;) alert tcp $HOME_NET any -> [185.136.165.173] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203159; rev:1;) alert tcp $HOME_NET any -> [91.245.227.46] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203160; rev:1;) alert tcp $HOME_NET any -> [37.49.224.15] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203161; rev:1;) alert tcp $HOME_NET any -> [185.140.53.11] 9845 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203162; rev:1;) alert tcp $HOME_NET any -> [84.38.181.209] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203163; rev:1;) alert tcp $HOME_NET any -> [37.49.230.114] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203164; rev:1;) alert tcp $HOME_NET any -> [128.90.105.130] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203165; rev:1;) alert tcp $HOME_NET any -> [185.33.85.47] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203166; rev:1;) alert tcp $HOME_NET any -> [45.143.222.153] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203167; rev:1;) alert tcp $HOME_NET any -> [37.49.230.211] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203168; rev:1;) alert tcp $HOME_NET any -> [192.186.183.150] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203169; rev:1;) alert tcp $HOME_NET any -> [37.230.131.83] 9524 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203170; rev:1;) alert tcp $HOME_NET any -> [8.209.102.67] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203171; rev:1;) alert tcp $HOME_NET any -> [203.205.224.59] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203172; rev:1;) alert tcp $HOME_NET any -> [80.85.157.34] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203173; rev:1;) alert tcp $HOME_NET any -> [45.147.231.229] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203174; rev:1;) alert tcp $HOME_NET any -> [188.241.58.228] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203175; rev:1;) alert tcp $HOME_NET any -> [165.227.64.184] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203176; rev:1;) alert tcp $HOME_NET any -> [128.90.112.213] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203177; rev:1;) alert tcp $HOME_NET any -> [5.188.4.174] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203178; rev:1;) alert tcp $HOME_NET any -> [185.33.234.204] 4784 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203179; rev:1;) alert tcp $HOME_NET any -> [185.118.167.4] 8485 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203180; rev:1;) alert tcp $HOME_NET any -> [80.249.146.15] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203181; rev:1;) alert tcp $HOME_NET any -> [128.90.105.75] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203182; rev:1;) alert tcp $HOME_NET any -> [79.141.166.229] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203183; rev:1;) alert tcp $HOME_NET any -> [51.15.21.149] 8080 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203184; rev:1;) alert tcp $HOME_NET any -> [47.254.177.197] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203185; rev:1;) alert tcp $HOME_NET any -> [128.90.107.110] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203186; rev:1;) alert tcp $HOME_NET any -> [161.35.145.71] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203187; rev:1;) alert tcp $HOME_NET any -> [66.228.45.248] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203188; rev:1;) alert tcp $HOME_NET any -> [117.3.216.38] 3589 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203189; rev:1;) alert tcp $HOME_NET any -> [104.168.173.141] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203190; rev:1;) alert tcp $HOME_NET any -> [188.225.78.105] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203191; rev:1;) alert tcp $HOME_NET any -> [178.62.90.125] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203192; rev:1;) alert tcp $HOME_NET any -> [37.49.230.254] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203193; rev:1;) alert tcp $HOME_NET any -> [128.90.112.128] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203194; rev:1;) alert tcp $HOME_NET any -> [128.90.112.171] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203195; rev:1;) alert tcp $HOME_NET any -> [45.153.241.126] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203196; rev:1;) alert tcp $HOME_NET any -> [185.140.53.21] 8991 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203197; rev:1;) alert tcp $HOME_NET any -> [37.49.230.14] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203198; rev:1;) alert tcp $HOME_NET any -> [216.218.208.114] 443 (msg:"SSLBL: Traffic to malicious host (likely Gootkit C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203199; rev:1;) alert tcp $HOME_NET any -> [103.138.108.193] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203200; rev:1;) alert tcp $HOME_NET any -> [62.108.37.200] 4242 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203201; rev:1;) alert tcp $HOME_NET any -> [84.38.180.246] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203202; rev:1;) alert tcp $HOME_NET any -> [185.140.53.6] 270 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203203; rev:1;) alert tcp $HOME_NET any -> [94.100.18.64] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203204; rev:1;) alert tcp $HOME_NET any -> [161.35.228.142] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203205; rev:1;) alert tcp $HOME_NET any -> [79.134.225.19] 5812 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203206; rev:1;) alert tcp $HOME_NET any -> [128.90.112.11] 3468 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203207; rev:1;) alert tcp $HOME_NET any -> [103.151.122.193] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203208; rev:1;) alert tcp $HOME_NET any -> [8.210.57.151] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203209; rev:1;) alert tcp $HOME_NET any -> [37.49.230.86] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203210; rev:1;) alert tcp $HOME_NET any -> [80.249.145.100] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203211; rev:1;) alert tcp $HOME_NET any -> [167.172.216.222] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203212; rev:1;) alert tcp $HOME_NET any -> [103.89.91.6] 20197 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203213; rev:1;) alert tcp $HOME_NET any -> [185.205.210.87] 4848 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203214; rev:1;) alert tcp $HOME_NET any -> [182.92.225.203] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203215; rev:1;) alert tcp $HOME_NET any -> [185.140.53.247] 4723 (msg:"SSLBL: Traffic to malicious host (likely NanoCore C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203216; rev:1;) alert tcp $HOME_NET any -> [194.5.97.24] 6669 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203217; rev:1;) alert tcp $HOME_NET any -> [5.188.228.46] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203218; rev:1;) alert tcp $HOME_NET any -> [157.245.96.68] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203219; rev:1;) alert tcp $HOME_NET any -> [23.227.207.140] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203220; rev:1;) alert tcp $HOME_NET any -> [37.49.230.134] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203221; rev:1;) alert tcp $HOME_NET any -> [74.91.115.145] 9825 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203222; rev:1;) alert tcp $HOME_NET any -> [80.249.144.38] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203223; rev:1;) alert tcp $HOME_NET any -> [79.134.225.19] 8301 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203224; rev:1;) alert tcp $HOME_NET any -> [185.105.1.165] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203225; rev:1;) alert tcp $HOME_NET any -> [159.65.147.133] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203226; rev:1;) alert tcp $HOME_NET any -> [37.49.230.147] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203227; rev:1;) alert tcp $HOME_NET any -> [8.208.26.123] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203228; rev:1;) alert tcp $HOME_NET any -> [167.71.227.19] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203229; rev:1;) alert tcp $HOME_NET any -> [193.38.55.44] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203230; rev:1;) alert tcp $HOME_NET any -> [134.209.204.246] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203231; rev:1;) alert tcp $HOME_NET any -> [156.255.3.231] 444 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203232; rev:1;) alert tcp $HOME_NET any -> [82.53.78.66] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203233; rev:1;) alert tcp $HOME_NET any -> [45.143.222.212] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203234; rev:1;) alert tcp $HOME_NET any -> [185.105.1.161] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203235; rev:1;) alert tcp $HOME_NET any -> [159.203.61.77] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203236; rev:1;) alert tcp $HOME_NET any -> [94.100.18.83] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203237; rev:1;) alert tcp $HOME_NET any -> [79.134.225.82] 54280 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203238; rev:1;) alert tcp $HOME_NET any -> [84.194.102.183] 5781 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203239; rev:1;) alert tcp $HOME_NET any -> [79.134.225.125] 1515 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203240; rev:1;) alert tcp $HOME_NET any -> [185.19.85.161] 3109 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203241; rev:1;) alert tcp $HOME_NET any -> [84.38.183.213] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203242; rev:1;) alert tcp $HOME_NET any -> [51.195.35.9] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203243; rev:1;) alert tcp $HOME_NET any -> [80.249.147.138] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203244; rev:1;) alert tcp $HOME_NET any -> [47.241.35.230] 3333 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203245; rev:1;) alert tcp $HOME_NET any -> [176.107.177.67] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203246; rev:1;) alert tcp $HOME_NET any -> [172.94.19.67] 8482 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203247; rev:1;) alert tcp $HOME_NET any -> [84.38.182.236] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203248; rev:1;) alert tcp $HOME_NET any -> [178.128.213.80] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203249; rev:1;) alert tcp $HOME_NET any -> [185.82.126.221] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203250; rev:1;) alert tcp $HOME_NET any -> [193.203.50.51] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203251; rev:1;) alert tcp $HOME_NET any -> [188.68.220.80] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203252; rev:1;) alert tcp $HOME_NET any -> [45.143.222.142] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203253; rev:1;) alert tcp $HOME_NET any -> [142.93.149.145] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203254; rev:1;) alert tcp $HOME_NET any -> [45.147.230.85] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203255; rev:1;) alert tcp $HOME_NET any -> [23.227.196.40] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203256; rev:1;) alert tcp $HOME_NET any -> [45.113.2.107] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203257; rev:1;) alert tcp $HOME_NET any -> [167.172.149.139] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203258; rev:1;) alert tcp $HOME_NET any -> [188.68.221.93] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203259; rev:1;) alert tcp $HOME_NET any -> [37.72.175.220] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203260; rev:1;) alert tcp $HOME_NET any -> [79.143.31.33] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203261; rev:1;) alert tcp $HOME_NET any -> [64.227.105.16] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203262; rev:1;) alert tcp $HOME_NET any -> [35.188.83.68] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203263; rev:1;) alert tcp $HOME_NET any -> [45.32.137.86] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203264; rev:1;) alert tcp $HOME_NET any -> [80.249.146.167] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203265; rev:1;) alert tcp $HOME_NET any -> [185.244.30.250] 6204 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203266; rev:1;) alert tcp $HOME_NET any -> [161.35.84.5] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203267; rev:1;) alert tcp $HOME_NET any -> [83.171.238.25] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203268; rev:1;) alert tcp $HOME_NET any -> [37.49.224.176] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203269; rev:1;) alert tcp $HOME_NET any -> [51.254.178.24] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203270; rev:1;) alert tcp $HOME_NET any -> [198.50.252.31] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203271; rev:1;) alert tcp $HOME_NET any -> [89.207.129.43] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203272; rev:1;) alert tcp $HOME_NET any -> [185.176.222.156] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203273; rev:1;) alert tcp $HOME_NET any -> [185.244.213.103] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203274; rev:1;) alert tcp $HOME_NET any -> [45.89.175.154] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203275; rev:1;) alert tcp $HOME_NET any -> [118.24.214.63] 5613 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203276; rev:1;) alert tcp $HOME_NET any -> [160.124.140.146] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203277; rev:1;) alert tcp $HOME_NET any -> [84.38.180.125] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203278; rev:1;) alert tcp $HOME_NET any -> [148.0.135.30] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203279; rev:1;) alert tcp $HOME_NET any -> [185.141.33.69] 5052 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203280; rev:1;) alert tcp $HOME_NET any -> [185.65.202.58] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203281; rev:1;) alert tcp $HOME_NET any -> [194.5.250.184] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203282; rev:1;) alert tcp $HOME_NET any -> [62.108.35.175] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203283; rev:1;) alert tcp $HOME_NET any -> [194.5.98.98] 9980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203284; rev:1;) alert tcp $HOME_NET any -> [94.100.18.43] 8443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203285; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 1507 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203286; rev:1;) alert tcp $HOME_NET any -> [199.192.19.38] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203287; rev:1;) alert tcp $HOME_NET any -> [45.147.231.191] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203288; rev:1;) alert tcp $HOME_NET any -> [80.249.146.61] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203289; rev:1;) alert tcp $HOME_NET any -> [195.123.245.187] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203290; rev:1;) alert tcp $HOME_NET any -> [106.54.62.149] 15555 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203291; rev:1;) alert tcp $HOME_NET any -> [45.143.222.115] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203292; rev:1;) alert tcp $HOME_NET any -> [185.140.53.161] 7266 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203293; rev:1;) alert tcp $HOME_NET any -> [80.249.146.101] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203294; rev:1;) alert tcp $HOME_NET any -> [87.255.6.145] 5123 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203295; rev:1;) alert tcp $HOME_NET any -> [45.142.213.203] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203296; rev:1;) alert tcp $HOME_NET any -> [188.68.221.13] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203297; rev:1;) alert tcp $HOME_NET any -> [79.141.166.200] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203298; rev:1;) alert tcp $HOME_NET any -> [117.199.6.72] 443 (msg:"SSLBL: Traffic to malicious host (likely Quakbot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203299; rev:1;) alert tcp $HOME_NET any -> [8.208.28.166] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203300; rev:1;) alert tcp $HOME_NET any -> [45.143.138.16] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203301; rev:1;) alert tcp $HOME_NET any -> [45.55.60.31] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203302; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 21254 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203303; rev:1;) alert tcp $HOME_NET any -> [194.135.93.234] 1349 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203304; rev:1;) alert tcp $HOME_NET any -> [31.184.254.46] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203305; rev:1;) alert tcp $HOME_NET any -> [8.209.79.24] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203306; rev:1;) alert tcp $HOME_NET any -> [157.245.169.70] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203307; rev:1;) alert tcp $HOME_NET any -> [87.255.6.145] 2005 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203308; rev:1;) alert tcp $HOME_NET any -> [185.140.53.219] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203309; rev:1;) alert tcp $HOME_NET any -> [161.35.24.186] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203310; rev:1;) alert tcp $HOME_NET any -> [95.216.251.222] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203311; rev:1;) alert tcp $HOME_NET any -> [101.226.26.166] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203312; rev:1;) alert tcp $HOME_NET any -> [80.249.145.124] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203313; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 48736 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203314; rev:1;) alert tcp $HOME_NET any -> [178.62.15.225] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203315; rev:1;) alert tcp $HOME_NET any -> [205.185.125.93] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203316; rev:1;) alert tcp $HOME_NET any -> [5.149.253.194] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203317; rev:1;) alert tcp $HOME_NET any -> [31.184.254.232] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203318; rev:1;) alert tcp $HOME_NET any -> [84.38.183.210] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203319; rev:1;) alert tcp $HOME_NET any -> [146.0.72.182] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203320; rev:1;) alert tcp $HOME_NET any -> [8.210.77.76] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203321; rev:1;) alert tcp $HOME_NET any -> [8.208.101.150] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203322; rev:1;) alert tcp $HOME_NET any -> [84.38.180.104] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203323; rev:1;) alert tcp $HOME_NET any -> [79.134.225.12] 4567 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203324; rev:1;) alert tcp $HOME_NET any -> [194.5.98.129] 5554 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203325; rev:1;) alert tcp $HOME_NET any -> [195.2.93.77] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203326; rev:1;) alert tcp $HOME_NET any -> [82.148.28.9] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203327; rev:1;) alert tcp $HOME_NET any -> [195.2.93.77] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203328; rev:1;) alert tcp $HOME_NET any -> [66.165.246.89] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203329; rev:1;) alert tcp $HOME_NET any -> [185.49.68.151] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203330; rev:1;) alert tcp $HOME_NET any -> [185.159.82.226] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203331; rev:1;) alert tcp $HOME_NET any -> [107.173.171.162] 1738 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203332; rev:1;) alert tcp $HOME_NET any -> [80.249.146.7] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203333; rev:1;) alert tcp $HOME_NET any -> [185.236.203.192] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203334; rev:1;) alert tcp $HOME_NET any -> [87.255.6.145] 2004 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203335; rev:1;) alert tcp $HOME_NET any -> [93.190.93.29] 4242 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203336; rev:1;) alert tcp $HOME_NET any -> [8.209.96.17] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203337; rev:1;) alert tcp $HOME_NET any -> [45.89.175.151] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203338; rev:1;) alert tcp $HOME_NET any -> [103.147.185.105] 9242 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203339; rev:1;) alert tcp $HOME_NET any -> [46.21.147.169] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203340; rev:1;) alert tcp $HOME_NET any -> [8.209.99.58] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203341; rev:1;) alert tcp $HOME_NET any -> [159.89.139.204] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203342; rev:1;) alert tcp $HOME_NET any -> [159.65.103.89] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203343; rev:1;) alert tcp $HOME_NET any -> [165.22.26.177] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203344; rev:1;) alert tcp $HOME_NET any -> [188.215.229.20] 22 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203345; rev:1;) alert tcp $HOME_NET any -> [103.151.125.141] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203346; rev:1;) alert tcp $HOME_NET any -> [80.249.146.29] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203347; rev:1;) alert tcp $HOME_NET any -> [84.38.180.239] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203348; rev:1;) alert tcp $HOME_NET any -> [38.68.50.180] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203349; rev:1;) alert tcp $HOME_NET any -> [167.71.0.179] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203350; rev:1;) alert tcp $HOME_NET any -> [138.197.144.19] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203351; rev:1;) alert tcp $HOME_NET any -> [185.140.53.129] 7776 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203352; rev:1;) alert tcp $HOME_NET any -> [217.29.53.4] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203353; rev:1;) alert tcp $HOME_NET any -> [47.254.242.30] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203354; rev:1;) alert tcp $HOME_NET any -> [141.255.158.51] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203355; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 21985 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203356; rev:1;) alert tcp $HOME_NET any -> [84.38.183.116] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203357; rev:1;) alert tcp $HOME_NET any -> [45.67.230.56] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203358; rev:1;) alert tcp $HOME_NET any -> [139.60.161.209] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203359; rev:1;) alert tcp $HOME_NET any -> [185.161.208.94] 2222 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203360; rev:1;) alert tcp $HOME_NET any -> [89.105.197.14] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203361; rev:1;) alert tcp $HOME_NET any -> [79.134.225.49] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203362; rev:1;) alert tcp $HOME_NET any -> [23.227.199.112] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203363; rev:1;) alert tcp $HOME_NET any -> [92.204.160.40] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203364; rev:1;) alert tcp $HOME_NET any -> [64.225.65.166] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203365; rev:1;) alert tcp $HOME_NET any -> [38.132.124.231] 443 (msg:"SSLBL: Traffic to malicious host (likely GuLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203366; rev:1;) alert tcp $HOME_NET any -> [149.255.35.163] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203367; rev:1;) alert tcp $HOME_NET any -> [185.236.201.102] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203368; rev:1;) alert tcp $HOME_NET any -> [68.235.48.108] 6250 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203369; rev:1;) alert tcp $HOME_NET any -> [161.35.197.114] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203370; rev:1;) alert tcp $HOME_NET any -> [192.210.237.74] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203371; rev:1;) alert tcp $HOME_NET any -> [185.244.30.180] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203372; rev:1;) alert tcp $HOME_NET any -> [102.130.119.183] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203373; rev:1;) alert tcp $HOME_NET any -> [80.249.147.57] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203374; rev:1;) alert tcp $HOME_NET any -> [45.67.228.170] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203375; rev:1;) alert tcp $HOME_NET any -> [102.130.119.184] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203376; rev:1;) alert tcp $HOME_NET any -> [3.124.197.215] 3333 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203377; rev:1;) alert tcp $HOME_NET any -> [109.230.215.25] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203378; rev:1;) alert tcp $HOME_NET any -> [91.211.246.72] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203379; rev:1;) alert tcp $HOME_NET any -> [93.190.93.152] 4242 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203380; rev:1;) alert tcp $HOME_NET any -> [89.105.194.243] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203381; rev:1;) alert tcp $HOME_NET any -> [139.60.161.57] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203382; rev:1;) alert tcp $HOME_NET any -> [5.101.50.87] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203383; rev:1;) alert tcp $HOME_NET any -> [80.249.146.100] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203384; rev:1;) alert tcp $HOME_NET any -> [80.249.146.100] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203385; rev:1;) alert tcp $HOME_NET any -> [185.140.53.41] 5288 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203386; rev:1;) alert tcp $HOME_NET any -> [45.89.175.161] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203387; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 1501 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203388; rev:1;) alert tcp $HOME_NET any -> [45.147.231.75] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203389; rev:1;) alert tcp $HOME_NET any -> [185.80.128.174] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203390; rev:1;) alert tcp $HOME_NET any -> [199.188.206.68] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203391; rev:1;) alert tcp $HOME_NET any -> [37.221.113.68] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203392; rev:1;) alert tcp $HOME_NET any -> [85.17.26.178] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203393; rev:1;) alert tcp $HOME_NET any -> [84.38.183.227] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203394; rev:1;) alert tcp $HOME_NET any -> [84.38.183.227] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203395; rev:1;) alert tcp $HOME_NET any -> [46.102.153.39] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203396; rev:1;) alert tcp $HOME_NET any -> [185.80.128.112] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203397; rev:1;) alert tcp $HOME_NET any -> [121.42.15.110] 8081 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203398; rev:1;) alert tcp $HOME_NET any -> [23.94.54.199] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203399; rev:1;) alert tcp $HOME_NET any -> [47.53.137.56] 1606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203400; rev:1;) alert tcp $HOME_NET any -> [139.59.28.82] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203401; rev:1;) alert tcp $HOME_NET any -> [5.206.225.37] 5566 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203402; rev:1;) alert tcp $HOME_NET any -> [3.8.93.207] 1337 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203403; rev:1;) alert tcp $HOME_NET any -> [46.21.147.240] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203404; rev:1;) alert tcp $HOME_NET any -> [185.34.52.17] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203405; rev:1;) alert tcp $HOME_NET any -> [79.143.30.10] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203406; rev:1;) alert tcp $HOME_NET any -> [45.66.250.161] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203407; rev:1;) alert tcp $HOME_NET any -> [31.24.224.7] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203408; rev:1;) alert tcp $HOME_NET any -> [167.86.118.236] 1604 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203409; rev:1;) alert tcp $HOME_NET any -> [84.38.180.26] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203410; rev:1;) alert tcp $HOME_NET any -> [178.62.16.209] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203411; rev:1;) alert tcp $HOME_NET any -> [34.70.172.237] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203412; rev:1;) alert tcp $HOME_NET any -> [216.38.8.169] 8153 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203413; rev:1;) alert tcp $HOME_NET any -> [185.41.154.105] 587 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203414; rev:1;) alert tcp $HOME_NET any -> [198.27.105.164] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203415; rev:1;) alert tcp $HOME_NET any -> [185.200.241.77] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203416; rev:1;) alert tcp $HOME_NET any -> [172.104.163.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203417; rev:1;) alert tcp $HOME_NET any -> [185.244.30.202] 2243 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203418; rev:1;) alert tcp $HOME_NET any -> [185.80.129.128] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203419; rev:1;) alert tcp $HOME_NET any -> [79.134.225.47] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203420; rev:1;) alert tcp $HOME_NET any -> [45.11.18.76] 5095 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203421; rev:1;) alert tcp $HOME_NET any -> [5.39.218.178] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203422; rev:1;) alert tcp $HOME_NET any -> [38.132.99.162] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203423; rev:1;) alert tcp $HOME_NET any -> [67.43.239.171] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203424; rev:1;) alert tcp $HOME_NET any -> [37.228.116.200] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203425; rev:1;) alert tcp $HOME_NET any -> [45.58.139.101] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203426; rev:1;) alert tcp $HOME_NET any -> [89.33.246.76] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203427; rev:1;) alert tcp $HOME_NET any -> [91.193.75.163] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203428; rev:1;) alert tcp $HOME_NET any -> [176.123.7.111] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203429; rev:1;) alert tcp $HOME_NET any -> [172.105.52.39] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203430; rev:1;) alert tcp $HOME_NET any -> [185.236.202.149] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203431; rev:1;) alert tcp $HOME_NET any -> [192.188.88.247] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203432; rev:1;) alert tcp $HOME_NET any -> [64.251.28.62] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203433; rev:1;) alert tcp $HOME_NET any -> [91.193.75.145] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203434; rev:1;) alert tcp $HOME_NET any -> [185.34.52.7] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203435; rev:1;) alert tcp $HOME_NET any -> [193.56.28.11] 7870 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203436; rev:1;) alert tcp $HOME_NET any -> [149.255.35.139] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203437; rev:1;) alert tcp $HOME_NET any -> [149.255.35.159] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203438; rev:1;) alert tcp $HOME_NET any -> [94.158.245.4] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203439; rev:1;) alert tcp $HOME_NET any -> [38.68.46.160] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203440; rev:1;) alert tcp $HOME_NET any -> [142.202.190.47] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203441; rev:1;) alert tcp $HOME_NET any -> [185.225.19.97] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203442; rev:1;) alert tcp $HOME_NET any -> [13.82.28.199] 4782 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203443; rev:1;) alert tcp $HOME_NET any -> [80.209.241.84] 56789 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203444; rev:1;) alert tcp $HOME_NET any -> [142.202.188.195] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203445; rev:1;) alert tcp $HOME_NET any -> [5.39.221.45] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203446; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 2786 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203447; rev:1;) alert tcp $HOME_NET any -> [165.227.198.46] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203448; rev:1;) alert tcp $HOME_NET any -> [91.218.66.231] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203449; rev:1;) alert tcp $HOME_NET any -> [139.60.161.95] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203450; rev:1;) alert tcp $HOME_NET any -> [46.17.98.48] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203451; rev:1;) alert tcp $HOME_NET any -> [47.241.116.77] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203452; rev:1;) alert tcp $HOME_NET any -> [23.254.229.35] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203453; rev:1;) alert tcp $HOME_NET any -> [5.39.221.50] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203454; rev:1;) alert tcp $HOME_NET any -> [45.32.128.100] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203455; rev:1;) alert tcp $HOME_NET any -> [142.202.188.216] 443 (msg:"SSLBL: Traffic to malicious host (likely QNodeService C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203456; rev:1;) alert tcp $HOME_NET any -> [167.114.12.200] 443 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203457; rev:1;) alert tcp $HOME_NET any -> [89.163.245.168] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203458; rev:1;) alert tcp $HOME_NET any -> [89.163.253.225] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203459; rev:1;) alert tcp $HOME_NET any -> [95.174.65.212] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203460; rev:1;) alert tcp $HOME_NET any -> [46.183.222.49] 6689 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203461; rev:1;) alert tcp $HOME_NET any -> [46.21.150.151] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203462; rev:1;) alert tcp $HOME_NET any -> [79.134.225.70] 2321 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203463; rev:1;) alert tcp $HOME_NET any -> [8.209.74.159] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203464; rev:1;) alert tcp $HOME_NET any -> [185.244.29.203] 9980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203465; rev:1;) alert tcp $HOME_NET any -> [86.106.20.175] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203466; rev:1;) alert tcp $HOME_NET any -> [172.241.27.37] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203467; rev:1;) alert tcp $HOME_NET any -> [91.132.139.214] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203468; rev:1;) alert tcp $HOME_NET any -> [149.255.36.132] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203469; rev:1;) alert tcp $HOME_NET any -> [91.193.75.7] 1199 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203470; rev:1;) alert tcp $HOME_NET any -> [185.244.30.202] 1139 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203471; rev:1;) alert tcp $HOME_NET any -> [24.185.111.219] 54455 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203472; rev:1;) alert tcp $HOME_NET any -> [54.36.17.100] 5060 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203473; rev:1;) alert tcp $HOME_NET any -> [8.208.9.171] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203474; rev:1;) alert tcp $HOME_NET any -> [190.213.78.26] 5000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203475; rev:1;) alert tcp $HOME_NET any -> [79.134.225.82] 2556 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203476; rev:1;) alert tcp $HOME_NET any -> [178.170.138.217] 3097 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203477; rev:1;) alert tcp $HOME_NET any -> [212.8.247.62] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203478; rev:1;) alert tcp $HOME_NET any -> [114.67.122.133] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203479; rev:1;) alert tcp $HOME_NET any -> [83.11.66.225] 1080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203480; rev:1;) alert tcp $HOME_NET any -> [103.147.184.237] 5010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203481; rev:1;) alert tcp $HOME_NET any -> [91.218.66.231] 18888 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203482; rev:1;) alert tcp $HOME_NET any -> [79.134.225.102] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203483; rev:1;) alert tcp $HOME_NET any -> [47.106.209.173] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203484; rev:1;) alert tcp $HOME_NET any -> [37.120.140.133] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203485; rev:1;) alert tcp $HOME_NET any -> [91.193.75.172] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203486; rev:1;) alert tcp $HOME_NET any -> [203.205.224.29] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203487; rev:1;) alert tcp $HOME_NET any -> [24.31.167.44] 4444 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203488; rev:1;) alert tcp $HOME_NET any -> [185.163.45.109] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203489; rev:1;) alert tcp $HOME_NET any -> [91.92.144.29] 2088 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203490; rev:1;) alert tcp $HOME_NET any -> [47.241.2.255] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203491; rev:1;) alert tcp $HOME_NET any -> [45.32.128.117] 443 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203492; rev:1;) alert tcp $HOME_NET any -> [185.80.130.173] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203493; rev:1;) alert tcp $HOME_NET any -> [194.5.97.223] 6204 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203494; rev:1;) alert tcp $HOME_NET any -> [41.96.194.11] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203495; rev:1;) alert tcp $HOME_NET any -> [185.140.53.154] 2556 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203496; rev:1;) alert tcp $HOME_NET any -> [41.96.193.66] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203497; rev:1;) alert tcp $HOME_NET any -> [185.244.29.129] 9980 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203498; rev:1;) alert tcp $HOME_NET any -> [185.236.202.192] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203499; rev:1;) alert tcp $HOME_NET any -> [120.132.81.251] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203500; rev:1;) alert tcp $HOME_NET any -> [193.56.28.20] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203501; rev:1;) alert tcp $HOME_NET any -> [121.140.64.142] 1002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203502; rev:1;) alert tcp $HOME_NET any -> [92.241.100.83] 25530 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203503; rev:1;) alert tcp $HOME_NET any -> [41.96.30.85] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203504; rev:1;) alert tcp $HOME_NET any -> [198.50.252.26] 1980 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203505; rev:1;) alert tcp $HOME_NET any -> [181.52.111.181] 8015 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203506; rev:1;) alert tcp $HOME_NET any -> [139.60.161.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203507; rev:1;) alert tcp $HOME_NET any -> [217.8.117.41] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203508; rev:1;) alert tcp $HOME_NET any -> [68.235.48.108] 6532 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203509; rev:1;) alert tcp $HOME_NET any -> [104.244.74.228] 7866 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203510; rev:1;) alert tcp $HOME_NET any -> [62.108.37.207] 5252 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203511; rev:1;) alert tcp $HOME_NET any -> [89.182.81.9] 3602 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203512; rev:1;) alert tcp $HOME_NET any -> [194.5.99.111] 17175 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203513; rev:1;) alert tcp $HOME_NET any -> [84.201.188.25] 7007 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203514; rev:1;) alert tcp $HOME_NET any -> [62.108.37.207] 5858 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203515; rev:1;) alert tcp $HOME_NET any -> [64.79.67.69] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203516; rev:1;) alert tcp $HOME_NET any -> [185.163.45.85] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203517; rev:1;) alert tcp $HOME_NET any -> [134.122.98.82] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203518; rev:1;) alert tcp $HOME_NET any -> [172.105.75.242] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203519; rev:1;) alert tcp $HOME_NET any -> [80.83.26.131] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203520; rev:1;) alert tcp $HOME_NET any -> [84.51.52.166] 1002 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203521; rev:1;) alert tcp $HOME_NET any -> [91.211.245.161] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203522; rev:1;) alert tcp $HOME_NET any -> [193.37.214.127] 8891 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203523; rev:1;) alert tcp $HOME_NET any -> [103.147.184.237] 6060 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203524; rev:1;) alert tcp $HOME_NET any -> [8.208.83.31] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203525; rev:1;) alert tcp $HOME_NET any -> [79.134.225.70] 2333 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203526; rev:1;) alert tcp $HOME_NET any -> [41.96.152.168] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203527; rev:1;) alert tcp $HOME_NET any -> [5.45.71.35] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203528; rev:1;) alert tcp $HOME_NET any -> [185.70.184.82] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203529; rev:1;) alert tcp $HOME_NET any -> [62.108.37.206] 6060 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203530; rev:1;) alert tcp $HOME_NET any -> [91.132.139.206] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203531; rev:1;) alert tcp $HOME_NET any -> [185.163.45.194] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203532; rev:1;) alert tcp $HOME_NET any -> [91.193.75.9] 2487 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203533; rev:1;) alert tcp $HOME_NET any -> [101.89.125.173] 443 (msg:"SSLBL: Traffic to malicious host (likely CobaltStrike C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203534; rev:1;) alert tcp $HOME_NET any -> [139.99.122.112] 62 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203535; rev:1;) alert tcp $HOME_NET any -> [104.198.206.229] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203536; rev:1;) alert tcp $HOME_NET any -> [88.198.77.224] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203537; rev:1;) alert tcp $HOME_NET any -> [198.27.77.206] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203538; rev:1;) alert tcp $HOME_NET any -> [102.130.119.142] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203539; rev:1;) alert tcp $HOME_NET any -> [185.140.53.15] 7061 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203540; rev:1;) alert tcp $HOME_NET any -> [161.35.38.118] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203541; rev:1;) alert tcp $HOME_NET any -> [93.190.93.35] 5858 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203542; rev:1;) alert tcp $HOME_NET any -> [107.175.144.243] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203543; rev:1;) alert tcp $HOME_NET any -> [79.134.225.112] 37375 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203544; rev:1;) alert tcp $HOME_NET any -> [139.28.222.104] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203545; rev:1;) alert tcp $HOME_NET any -> [185.80.128.170] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203546; rev:1;) alert tcp $HOME_NET any -> [173.234.155.34] 6060 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203547; rev:1;) alert tcp $HOME_NET any -> [78.217.163.197] 1117 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203548; rev:1;) alert tcp $HOME_NET any -> [185.212.148.63] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203549; rev:1;) alert tcp $HOME_NET any -> [64.225.101.88] 443 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203550; rev:1;) alert tcp $HOME_NET any -> [185.165.153.215] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203551; rev:1;) alert tcp $HOME_NET any -> [185.165.153.215] 6606 (msg:"SSLBL: Traffic to malicious host (likely RevengeRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203552; rev:1;) alert tcp $HOME_NET any -> [82.208.161.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203553; rev:1;) alert tcp $HOME_NET any -> [194.113.235.106] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203554; rev:1;) alert tcp $HOME_NET any -> [185.14.31.168] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203555; rev:1;) alert tcp $HOME_NET any -> [79.134.225.100] 45678 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203556; rev:1;) alert tcp $HOME_NET any -> [180.214.236.107] 6590 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203557; rev:1;) alert tcp $HOME_NET any -> [95.217.81.68] 443 (msg:"SSLBL: Traffic to malicious host (likely BuerLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203558; rev:1;) alert tcp $HOME_NET any -> [182.190.24.221] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203559; rev:1;) alert tcp $HOME_NET any -> [83.97.20.125] 442 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203560; rev:1;) alert tcp $HOME_NET any -> [161.117.87.168] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203561; rev:1;) alert tcp $HOME_NET any -> [104.248.138.198] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203562; rev:1;) alert tcp $HOME_NET any -> [34.222.222.126] 443 (msg:"SSLBL: Traffic to malicious host (likely BazaLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203563; rev:1;) alert tcp $HOME_NET any -> [91.193.75.49] 1952 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203564; rev:1;) alert tcp $HOME_NET any -> [51.15.21.149] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203565; rev:1;) alert tcp $HOME_NET any -> [103.242.134.79] 43 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203566; rev:1;) alert tcp $HOME_NET any -> [45.147.201.55] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203567; rev:1;) alert tcp $HOME_NET any -> [212.114.52.236] 9932 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203568; rev:1;) alert tcp $HOME_NET any -> [64.227.8.3] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203569; rev:1;) alert tcp $HOME_NET any -> [46.183.221.30] 6434 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203570; rev:1;) alert tcp $HOME_NET any -> [172.94.18.253] 6699 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203571; rev:1;) alert tcp $HOME_NET any -> [77.30.145.48] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203572; rev:1;) alert tcp $HOME_NET any -> [23.108.57.5] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203573; rev:1;) alert tcp $HOME_NET any -> [178.48.154.38] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203574; rev:1;) alert tcp $HOME_NET any -> [31.184.253.197] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203575; rev:1;) alert tcp $HOME_NET any -> [172.104.239.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203576; rev:1;) alert tcp $HOME_NET any -> [178.79.158.245] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203577; rev:1;) alert tcp $HOME_NET any -> [91.201.175.46] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203578; rev:1;) alert tcp $HOME_NET any -> [5.56.73.146] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203579; rev:1;) alert tcp $HOME_NET any -> [185.244.29.175] 7071 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203580; rev:1;) alert tcp $HOME_NET any -> [178.238.8.102] 8855 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203581; rev:1;) alert tcp $HOME_NET any -> [23.227.196.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203582; rev:1;) alert tcp $HOME_NET any -> [8.208.80.205] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203583; rev:1;) alert tcp $HOME_NET any -> [8.208.80.205] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203584; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 44137 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203585; rev:1;) alert tcp $HOME_NET any -> [185.140.53.161] 20982 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203586; rev:1;) alert tcp $HOME_NET any -> [194.5.97.75] 20987 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203587; rev:1;) alert tcp $HOME_NET any -> [80.83.26.132] 66 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203588; rev:1;) alert tcp $HOME_NET any -> [84.211.45.238] 1085 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203589; rev:1;) alert tcp $HOME_NET any -> [174.138.59.117] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203590; rev:1;) alert tcp $HOME_NET any -> [185.140.53.92] 2512 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203591; rev:1;) alert tcp $HOME_NET any -> [134.209.172.216] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203592; rev:1;) alert tcp $HOME_NET any -> [190.84.167.48] 1881 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203593; rev:1;) alert tcp $HOME_NET any -> [83.11.162.79] 1080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203594; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203595; rev:1;) alert tcp $HOME_NET any -> [88.218.16.218] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203596; rev:1;) alert tcp $HOME_NET any -> [144.217.211.203] 6714 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203597; rev:1;) alert tcp $HOME_NET any -> [194.5.97.14] 6204 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203598; rev:1;) alert tcp $HOME_NET any -> [104.237.252.50] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203599; rev:1;) alert tcp $HOME_NET any -> [194.5.97.14] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203600; rev:1;) alert tcp $HOME_NET any -> [85.74.134.20] 4782 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203601; rev:1;) alert tcp $HOME_NET any -> [194.5.97.23] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203602; rev:1;) alert tcp $HOME_NET any -> [45.32.167.239] 6606 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203603; rev:1;) alert tcp $HOME_NET any -> [185.244.29.134] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203604; rev:1;) alert tcp $HOME_NET any -> [5.181.156.5] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203605; rev:1;) alert tcp $HOME_NET any -> [5.181.156.5] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203606; rev:1;) alert tcp $HOME_NET any -> [45.153.240.114] 5858 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203607; rev:1;) alert tcp $HOME_NET any -> [192.253.255.182] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203608; rev:1;) alert tcp $HOME_NET any -> [91.218.65.24] 8808 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203609; rev:1;) alert tcp $HOME_NET any -> [194.5.97.58] 20909 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203610; rev:1;) alert tcp $HOME_NET any -> [185.244.29.214] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203611; rev:1;) alert tcp $HOME_NET any -> [185.140.53.190] 586 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203612; rev:1;) alert tcp $HOME_NET any -> [3.17.10.122] 8780 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203613; rev:1;) alert tcp $HOME_NET any -> [94.239.225.11] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203614; rev:1;) alert tcp $HOME_NET any -> [185.140.53.175] 20209 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203615; rev:1;) alert tcp $HOME_NET any -> [194.5.97.75] 20982 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203616; rev:1;) alert tcp $HOME_NET any -> [194.5.97.120] 20986 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203617; rev:1;) alert tcp $HOME_NET any -> [185.140.53.161] 29060 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203618; rev:1;) alert tcp $HOME_NET any -> [46.183.221.31] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203619; rev:1;) alert tcp $HOME_NET any -> [185.140.53.196] 5679 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203620; rev:1;) alert tcp $HOME_NET any -> [185.244.30.71] 8364 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203621; rev:1;) alert tcp $HOME_NET any -> [46.17.96.46] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203622; rev:1;) alert tcp $HOME_NET any -> [45.125.239.247] 6204 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203623; rev:1;) alert tcp $HOME_NET any -> [5.45.68.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203624; rev:1;) alert tcp $HOME_NET any -> [83.11.89.28] 1080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203625; rev:1;) alert tcp $HOME_NET any -> [185.225.17.61] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203626; rev:1;) alert tcp $HOME_NET any -> [8.208.89.223] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203627; rev:1;) alert tcp $HOME_NET any -> [77.247.127.128] 8855 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203628; rev:1;) alert tcp $HOME_NET any -> [176.31.26.213] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203629; rev:1;) alert tcp $HOME_NET any -> [176.31.26.213] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203630; rev:1;) alert tcp $HOME_NET any -> [169.255.59.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Loki C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203631; rev:1;) alert tcp $HOME_NET any -> [143.204.201.33] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203632; rev:1;) alert tcp $HOME_NET any -> [216.170.125.102] 3582 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203633; rev:1;) alert tcp $HOME_NET any -> [217.146.88.66] 9340 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203634; rev:1;) alert tcp $HOME_NET any -> [91.211.246.148] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203635; rev:1;) alert tcp $HOME_NET any -> [188.130.138.126] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203636; rev:1;) alert tcp $HOME_NET any -> [185.140.53.49] 1384 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203637; rev:1;) alert tcp $HOME_NET any -> [45.125.239.219] 6204 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203638; rev:1;) alert tcp $HOME_NET any -> [185.140.53.16] 6403 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203639; rev:1;) alert tcp $HOME_NET any -> [47.89.208.216] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203640; rev:1;) alert tcp $HOME_NET any -> [157.245.11.146] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203641; rev:1;) alert tcp $HOME_NET any -> [43.226.229.97] 8088 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203642; rev:1;) alert tcp $HOME_NET any -> [84.16.248.160] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203643; rev:1;) alert tcp $HOME_NET any -> [93.190.93.23] 8077 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203644; rev:1;) alert tcp $HOME_NET any -> [185.140.53.55] 4040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203645; rev:1;) alert tcp $HOME_NET any -> [149.56.234.156] 1485 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203646; rev:1;) alert tcp $HOME_NET any -> [46.29.165.151] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203647; rev:1;) alert tcp $HOME_NET any -> [91.210.169.101] 6404 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203648; rev:1;) alert tcp $HOME_NET any -> [185.140.53.55] 5541 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203649; rev:1;) alert tcp $HOME_NET any -> [207.246.95.196] 443 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203650; rev:1;) alert tcp $HOME_NET any -> [51.89.201.48] 7866 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203651; rev:1;) alert tcp $HOME_NET any -> [185.140.53.53] 1050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203652; rev:1;) alert tcp $HOME_NET any -> [91.193.75.249] 4590 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203653; rev:1;) alert tcp $HOME_NET any -> [91.193.75.54] 3421 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203654; rev:1;) alert tcp $HOME_NET any -> [89.238.181.103] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203655; rev:1;) alert tcp $HOME_NET any -> [185.225.17.254] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203656; rev:1;) alert tcp $HOME_NET any -> [84.51.52.166] 82 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203657; rev:1;) alert tcp $HOME_NET any -> [45.95.168.130] 2001 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203658; rev:1;) alert tcp $HOME_NET any -> [8.209.77.210] 443 (msg:"SSLBL: Traffic to malicious host (likely DanaBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203659; rev:1;) alert tcp $HOME_NET any -> [103.147.185.179] 5891 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203660; rev:1;) alert tcp $HOME_NET any -> [103.114.105.3] 8780 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203661; rev:1;) alert tcp $HOME_NET any -> [188.130.138.125] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203662; rev:1;) alert tcp $HOME_NET any -> [103.133.107.247] 3310 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203663; rev:1;) alert tcp $HOME_NET any -> [103.141.137.242] 5454 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203664; rev:1;) alert tcp $HOME_NET any -> [161.117.227.195] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203665; rev:1;) alert tcp $HOME_NET any -> [45.129.2.240] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203666; rev:1;) alert tcp $HOME_NET any -> [109.248.11.25] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203667; rev:1;) alert tcp $HOME_NET any -> [103.147.185.179] 5890 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203668; rev:1;) alert tcp $HOME_NET any -> [103.99.1.76] 9087 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203669; rev:1;) alert tcp $HOME_NET any -> [103.125.190.243] 8965 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203670; rev:1;) alert tcp $HOME_NET any -> [119.28.159.130] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203671; rev:1;) alert tcp $HOME_NET any -> [45.125.239.120] 6204 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203672; rev:1;) alert tcp $HOME_NET any -> [45.140.168.169] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203673; rev:1;) alert tcp $HOME_NET any -> [88.119.175.105] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203674; rev:1;) alert tcp $HOME_NET any -> [178.124.140.144] 7866 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203675; rev:1;) alert tcp $HOME_NET any -> [216.38.2.208] 1050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203676; rev:1;) alert tcp $HOME_NET any -> [46.29.167.45] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203677; rev:1;) alert tcp $HOME_NET any -> [105.103.91.155] 5552 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203678; rev:1;) alert tcp $HOME_NET any -> [139.60.161.88] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203679; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 6025 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203680; rev:1;) alert tcp $HOME_NET any -> [45.125.239.253] 6204 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203681; rev:1;) alert tcp $HOME_NET any -> [141.255.156.106] 6606 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203682; rev:1;) alert tcp $HOME_NET any -> [95.211.140.160] 8514 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203683; rev:1;) alert tcp $HOME_NET any -> [45.125.239.50] 10134 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203684; rev:1;) alert tcp $HOME_NET any -> [185.141.61.237] 1010 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203685; rev:1;) alert tcp $HOME_NET any -> [78.108.185.203] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203686; rev:1;) alert tcp $HOME_NET any -> [31.49.13.58] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203687; rev:1;) alert tcp $HOME_NET any -> [89.33.246.107] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203688; rev:1;) alert tcp $HOME_NET any -> [77.48.28.231] 2424 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203689; rev:1;) alert tcp $HOME_NET any -> [84.51.52.166] 2 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203690; rev:1;) alert tcp $HOME_NET any -> [84.51.52.166] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203691; rev:1;) alert tcp $HOME_NET any -> [176.32.35.108] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203692; rev:1;) alert tcp $HOME_NET any -> [45.147.229.106] 8720 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203693; rev:1;) alert tcp $HOME_NET any -> [91.218.65.24] 6178 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203694; rev:1;) alert tcp $HOME_NET any -> [91.218.65.24] 7777 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203695; rev:1;) alert tcp $HOME_NET any -> [84.51.52.166] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203696; rev:1;) alert tcp $HOME_NET any -> [37.72.175.199] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203697; rev:1;) alert tcp $HOME_NET any -> [69.133.56.83] 444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203698; rev:1;) alert tcp $HOME_NET any -> [41.103.199.216] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203699; rev:1;) alert tcp $HOME_NET any -> [176.57.215.142] 443 (msg:"SSLBL: Traffic to malicious host (likely KPOTStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203700; rev:1;) alert tcp $HOME_NET any -> [184.164.139.226] 2020 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203701; rev:1;) alert tcp $HOME_NET any -> [5.188.9.76] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203702; rev:1;) alert tcp $HOME_NET any -> [51.75.154.242] 1515 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203703; rev:1;) alert tcp $HOME_NET any -> [37.228.132.241] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203704; rev:1;) alert tcp $HOME_NET any -> [185.101.93.249] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203705; rev:1;) alert tcp $HOME_NET any -> [195.69.187.142] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203706; rev:1;) alert tcp $HOME_NET any -> [192.95.20.152] 443 (msg:"SSLBL: Traffic to malicious host (likely BlueBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203707; rev:1;) alert tcp $HOME_NET any -> [46.17.47.168] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203708; rev:1;) alert tcp $HOME_NET any -> [195.123.224.47] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203709; rev:1;) alert tcp $HOME_NET any -> [185.140.53.235] 3030 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203710; rev:1;) alert tcp $HOME_NET any -> [47.74.63.135] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203711; rev:1;) alert tcp $HOME_NET any -> [8.208.28.247] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203712; rev:1;) alert tcp $HOME_NET any -> [93.190.93.212] 8890 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203713; rev:1;) alert tcp $HOME_NET any -> [185.140.53.175] 20804 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203714; rev:1;) alert tcp $HOME_NET any -> [192.227.231.18] 1921 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203715; rev:1;) alert tcp $HOME_NET any -> [185.244.30.165] 3434 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203716; rev:1;) alert tcp $HOME_NET any -> [46.29.167.29] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203717; rev:1;) alert tcp $HOME_NET any -> [91.193.75.143] 2128 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203718; rev:1;) alert tcp $HOME_NET any -> [46.21.147.46] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203719; rev:1;) alert tcp $HOME_NET any -> [37.221.114.88] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203720; rev:1;) alert tcp $HOME_NET any -> [94.158.245.225] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203721; rev:1;) alert tcp $HOME_NET any -> [185.244.30.193] 6065 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203722; rev:1;) alert tcp $HOME_NET any -> [185.244.30.21] 3232 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203723; rev:1;) alert tcp $HOME_NET any -> [94.158.245.160] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203724; rev:1;) alert tcp $HOME_NET any -> [94.158.245.160] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203725; rev:1;) alert tcp $HOME_NET any -> [94.158.245.90] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203726; rev:1;) alert tcp $HOME_NET any -> [185.70.186.151] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203727; rev:1;) alert tcp $HOME_NET any -> [216.38.8.168] 3856 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203728; rev:1;) alert tcp $HOME_NET any -> [93.190.93.6] 5934 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203729; rev:1;) alert tcp $HOME_NET any -> [194.33.45.146] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203730; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 3232 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203731; rev:1;) alert tcp $HOME_NET any -> [185.244.30.137] 3030 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203732; rev:1;) alert tcp $HOME_NET any -> [79.134.225.111] 20804 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203733; rev:1;) alert tcp $HOME_NET any -> [185.244.30.137] 9996 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203734; rev:1;) alert tcp $HOME_NET any -> [185.205.210.71] 2020 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203735; rev:1;) alert tcp $HOME_NET any -> [196.229.250.239] 3000 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203736; rev:1;) alert tcp $HOME_NET any -> [88.150.189.98] 1903 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203737; rev:1;) alert tcp $HOME_NET any -> [88.150.189.98] 9956 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203738; rev:1;) alert tcp $HOME_NET any -> [185.244.30.14] 1313 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203739; rev:1;) alert tcp $HOME_NET any -> [43.226.229.83] 8088 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203740; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 4028 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203741; rev:1;) alert tcp $HOME_NET any -> [185.244.30.21] 2526 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203742; rev:1;) alert tcp $HOME_NET any -> [178.124.140.145] 1960 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203743; rev:1;) alert tcp $HOME_NET any -> [46.29.160.64] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203744; rev:1;) alert tcp $HOME_NET any -> [91.215.169.250] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203745; rev:1;) alert tcp $HOME_NET any -> [185.140.53.228] 20908 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203746; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 2034 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203747; rev:1;) alert tcp $HOME_NET any -> [134.19.179.187] 32741 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203748; rev:1;) alert tcp $HOME_NET any -> [43.226.229.110] 8088 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203749; rev:1;) alert tcp $HOME_NET any -> [45.128.133.19] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203750; rev:1;) alert tcp $HOME_NET any -> [82.64.128.42] 5502 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203751; rev:1;) alert tcp $HOME_NET any -> [82.64.128.42] 5501 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203752; rev:1;) alert tcp $HOME_NET any -> [84.38.133.132] 3202 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203753; rev:1;) alert tcp $HOME_NET any -> [184.75.223.219] 32741 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203754; rev:1;) alert tcp $HOME_NET any -> [185.244.30.239] 2091 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203755; rev:1;) alert tcp $HOME_NET any -> [13.224.102.128] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203756; rev:1;) alert tcp $HOME_NET any -> [172.94.100.10] 8088 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203757; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 2022 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203758; rev:1;) alert tcp $HOME_NET any -> [67.43.224.156] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203759; rev:1;) alert tcp $HOME_NET any -> [64.225.74.231] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203760; rev:1;) alert tcp $HOME_NET any -> [144.217.211.203] 1855 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203761; rev:1;) alert tcp $HOME_NET any -> [141.255.147.132] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203762; rev:1;) alert tcp $HOME_NET any -> [185.244.30.13] 7250 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203763; rev:1;) alert tcp $HOME_NET any -> [184.75.223.235] 3460 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203764; rev:1;) alert tcp $HOME_NET any -> [185.244.30.17] 1199 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203765; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 5252 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203766; rev:1;) alert tcp $HOME_NET any -> [79.134.225.109] 4040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203767; rev:1;) alert tcp $HOME_NET any -> [69.65.7.136] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203768; rev:1;) alert tcp $HOME_NET any -> [79.134.225.101] 7872 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203769; rev:1;) alert tcp $HOME_NET any -> [79.134.225.10] 1199 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203770; rev:1;) alert tcp $HOME_NET any -> [79.134.225.99] 20901 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203771; rev:1;) alert tcp $HOME_NET any -> [198.46.141.251] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203772; rev:1;) alert tcp $HOME_NET any -> [128.199.57.93] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203773; rev:1;) alert tcp $HOME_NET any -> [193.37.213.157] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203774; rev:1;) alert tcp $HOME_NET any -> [47.252.2.199] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203775; rev:1;) alert tcp $HOME_NET any -> [168.235.111.253] 56453 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203776; rev:1;) alert tcp $HOME_NET any -> [185.136.163.128] 2020 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203777; rev:1;) alert tcp $HOME_NET any -> [60.51.99.42] 4424 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203778; rev:1;) alert tcp $HOME_NET any -> [212.114.52.84] 2803 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203779; rev:1;) alert tcp $HOME_NET any -> [185.140.53.60] 7071 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203780; rev:1;) alert tcp $HOME_NET any -> [185.243.242.116] 7766 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203781; rev:1;) alert tcp $HOME_NET any -> [111.90.142.123] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203782; rev:1;) alert tcp $HOME_NET any -> [185.183.96.231] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203783; rev:1;) alert tcp $HOME_NET any -> [176.31.88.148] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203784; rev:1;) alert tcp $HOME_NET any -> [185.205.209.223] 1020 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203785; rev:1;) alert tcp $HOME_NET any -> [95.213.195.71] 1788 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203786; rev:1;) alert tcp $HOME_NET any -> [79.134.225.29] 2128 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203787; rev:1;) alert tcp $HOME_NET any -> [79.134.225.5] 1369 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203788; rev:1;) alert tcp $HOME_NET any -> [37.72.175.233] 8080 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203789; rev:1;) alert tcp $HOME_NET any -> [185.203.236.236] 6874 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203790; rev:1;) alert tcp $HOME_NET any -> [142.44.253.233] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203791; rev:1;) alert tcp $HOME_NET any -> [111.90.144.65] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203792; rev:1;) alert tcp $HOME_NET any -> [198.54.115.114] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203793; rev:1;) alert tcp $HOME_NET any -> [45.74.53.124] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203794; rev:1;) alert tcp $HOME_NET any -> [123.240.25.197] 1604 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203795; rev:1;) alert tcp $HOME_NET any -> [185.86.4.70] 4785 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203796; rev:1;) alert tcp $HOME_NET any -> [142.147.97.150] 6084 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203797; rev:1;) alert tcp $HOME_NET any -> [195.123.246.241] 443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203798; rev:1;) alert tcp $HOME_NET any -> [185.159.82.101] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203799; rev:1;) alert tcp $HOME_NET any -> [45.89.230.124] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203800; rev:1;) alert tcp $HOME_NET any -> [47.241.27.57] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203801; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 2121 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203802; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 2121 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203803; rev:1;) alert tcp $HOME_NET any -> [185.203.236.237] 6683 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203804; rev:1;) alert tcp $HOME_NET any -> [35.192.205.70] 6969 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203805; rev:1;) alert tcp $HOME_NET any -> [185.244.30.147] 4789 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203806; rev:1;) alert tcp $HOME_NET any -> [185.140.53.154] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203807; rev:1;) alert tcp $HOME_NET any -> [79.134.225.99] 20908 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203808; rev:1;) alert tcp $HOME_NET any -> [192.3.2.150] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203809; rev:1;) alert tcp $HOME_NET any -> [79.134.225.97] 2016 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203810; rev:1;) alert tcp $HOME_NET any -> [185.244.30.154] 7201 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203811; rev:1;) alert tcp $HOME_NET any -> [46.183.223.29] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203812; rev:1;) alert tcp $HOME_NET any -> [118.100.66.100] 4424 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203813; rev:1;) alert tcp $HOME_NET any -> [95.213.195.71] 17171 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203814; rev:1;) alert tcp $HOME_NET any -> [79.186.190.12] 1080 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203815; rev:1;) alert tcp $HOME_NET any -> [185.98.87.192] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203816; rev:1;) alert tcp $HOME_NET any -> [212.162.150.118] 6874 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203817; rev:1;) alert tcp $HOME_NET any -> [46.17.47.64] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203818; rev:1;) alert tcp $HOME_NET any -> [45.147.200.7] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203819; rev:1;) alert tcp $HOME_NET any -> [46.21.144.10] 8080 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203820; rev:1;) alert tcp $HOME_NET any -> [193.37.213.56] 2040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203821; rev:1;) alert tcp $HOME_NET any -> [195.123.246.12] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203822; rev:1;) alert tcp $HOME_NET any -> [167.99.11.50] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203823; rev:1;) alert tcp $HOME_NET any -> [23.95.94.154] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203824; rev:1;) alert tcp $HOME_NET any -> [91.189.180.195] 7618 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203825; rev:1;) alert tcp $HOME_NET any -> [193.37.213.56] 2030 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203826; rev:1;) alert tcp $HOME_NET any -> [37.120.140.165] 1030 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203827; rev:1;) alert tcp $HOME_NET any -> [185.154.21.193] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203828; rev:1;) alert tcp $HOME_NET any -> [45.66.250.112] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203829; rev:1;) alert tcp $HOME_NET any -> [82.118.22.9] 8085 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203830; rev:1;) alert tcp $HOME_NET any -> [210.183.117.215] 6124 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203831; rev:1;) alert tcp $HOME_NET any -> [193.32.188.136] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203832; rev:1;) alert tcp $HOME_NET any -> [193.37.213.42] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203833; rev:1;) alert tcp $HOME_NET any -> [62.108.37.42] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203834; rev:1;) alert tcp $HOME_NET any -> [175.141.217.222] 4424 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203835; rev:1;) alert tcp $HOME_NET any -> [45.140.169.211] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203836; rev:1;) alert tcp $HOME_NET any -> [47.245.30.255] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203837; rev:1;) alert tcp $HOME_NET any -> [149.167.94.36] 10196 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203838; rev:1;) alert tcp $HOME_NET any -> [23.81.246.113] 6059 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203839; rev:1;) alert tcp $HOME_NET any -> [139.99.122.112] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203840; rev:1;) alert tcp $HOME_NET any -> [190.97.162.37] 443 (msg:"SSLBL: Traffic to malicious host (likely PredatorStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203841; rev:1;) alert tcp $HOME_NET any -> [204.152.201.172] 7707 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203842; rev:1;) alert tcp $HOME_NET any -> [79.134.225.10] 6050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203843; rev:1;) alert tcp $HOME_NET any -> [94.158.245.193] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203844; rev:1;) alert tcp $HOME_NET any -> [94.158.245.180] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203845; rev:1;) alert tcp $HOME_NET any -> [185.225.17.227] 443 (msg:"SSLBL: Traffic to malicious host (likely ServHelper C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203846; rev:1;) alert tcp $HOME_NET any -> [93.190.93.25] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203847; rev:1;) alert tcp $HOME_NET any -> [167.86.106.40] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203848; rev:1;) alert tcp $HOME_NET any -> [217.29.57.164] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203849; rev:1;) alert tcp $HOME_NET any -> [93.190.93.108] 5858 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203850; rev:1;) alert tcp $HOME_NET any -> [92.38.184.121] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203851; rev:1;) alert tcp $HOME_NET any -> [41.46.250.43] 8080 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203852; rev:1;) alert tcp $HOME_NET any -> [82.192.82.102] 5147 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203853; rev:1;) alert tcp $HOME_NET any -> [167.172.164.197] 8443 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203854; rev:1;) alert tcp $HOME_NET any -> [91.215.169.52] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203855; rev:1;) alert tcp $HOME_NET any -> [43.226.229.82] 5288 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203856; rev:1;) alert tcp $HOME_NET any -> [104.129.27.166] 5210 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203857; rev:1;) alert tcp $HOME_NET any -> [144.168.239.42] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203858; rev:1;) alert tcp $HOME_NET any -> [64.225.20.238] 2030 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203859; rev:1;) alert tcp $HOME_NET any -> [82.64.128.42] 6613 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203860; rev:1;) alert tcp $HOME_NET any -> [13.225.78.77] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203861; rev:1;) alert tcp $HOME_NET any -> [51.83.200.181] 1337 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203862; rev:1;) alert tcp $HOME_NET any -> [111.90.156.119] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203863; rev:1;) alert tcp $HOME_NET any -> [217.146.88.175] 4040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203864; rev:1;) alert tcp $HOME_NET any -> [185.176.222.44] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203865; rev:1;) alert tcp $HOME_NET any -> [192.119.71.129] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203866; rev:1;) alert tcp $HOME_NET any -> [151.248.126.195] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203867; rev:1;) alert tcp $HOME_NET any -> [185.10.68.16] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203868; rev:1;) alert tcp $HOME_NET any -> [176.107.160.128] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203869; rev:1;) alert tcp $HOME_NET any -> [181.141.0.182] 1898 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203870; rev:1;) alert tcp $HOME_NET any -> [185.244.30.74] 6970 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203871; rev:1;) alert tcp $HOME_NET any -> [185.209.20.124] 1443 (msg:"SSLBL: Traffic to malicious host (likely Dridex C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203872; rev:1;) alert tcp $HOME_NET any -> [115.134.230.49] 4424 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203873; rev:1;) alert tcp $HOME_NET any -> [95.211.140.172] 6687 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203874; rev:1;) alert tcp $HOME_NET any -> [108.62.141.34] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203875; rev:1;) alert tcp $HOME_NET any -> [82.64.128.42] 6617 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203876; rev:1;) alert tcp $HOME_NET any -> [193.164.150.97] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203877; rev:1;) alert tcp $HOME_NET any -> [185.158.154.218] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203878; rev:1;) alert tcp $HOME_NET any -> [85.143.222.85] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203879; rev:1;) alert tcp $HOME_NET any -> [47.244.208.18] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203880; rev:1;) alert tcp $HOME_NET any -> [91.215.169.244] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203881; rev:1;) alert tcp $HOME_NET any -> [91.215.169.244] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203882; rev:1;) alert tcp $HOME_NET any -> [176.107.160.70] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203883; rev:1;) alert tcp $HOME_NET any -> [176.107.160.70] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203884; rev:1;) alert tcp $HOME_NET any -> [178.124.140.143] 5888 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203885; rev:1;) alert tcp $HOME_NET any -> [47.252.11.17] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203886; rev:1;) alert tcp $HOME_NET any -> [148.72.172.101] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203887; rev:1;) alert tcp $HOME_NET any -> [176.107.160.11] 443 (msg:"SSLBL: Traffic to malicious host (likely PredatorStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203888; rev:1;) alert tcp $HOME_NET any -> [190.211.254.23] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203889; rev:1;) alert tcp $HOME_NET any -> [111.90.156.123] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203890; rev:1;) alert tcp $HOME_NET any -> [46.17.44.169] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203891; rev:1;) alert tcp $HOME_NET any -> [195.123.222.144] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203892; rev:1;) alert tcp $HOME_NET any -> [193.233.149.7] 443 (msg:"SSLBL: Traffic to malicious host (likely RaccoonStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203893; rev:1;) alert tcp $HOME_NET any -> [193.233.149.7] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203894; rev:1;) alert tcp $HOME_NET any -> [188.127.230.203] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203895; rev:1;) alert tcp $HOME_NET any -> [49.51.136.157] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203896; rev:1;) alert tcp $HOME_NET any -> [46.166.173.155] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203897; rev:1;) alert tcp $HOME_NET any -> [5.63.154.250] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203898; rev:1;) alert tcp $HOME_NET any -> [95.217.17.191] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203899; rev:1;) alert tcp $HOME_NET any -> [209.127.19.34] 443 (msg:"SSLBL: Traffic to malicious host (likely AZORult C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203900; rev:1;) alert tcp $HOME_NET any -> [134.0.118.45] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203901; rev:1;) alert tcp $HOME_NET any -> [216.170.126.139] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203902; rev:1;) alert tcp $HOME_NET any -> [45.139.186.90] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203903; rev:1;) alert tcp $HOME_NET any -> [45.143.138.19] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203904; rev:1;) alert tcp $HOME_NET any -> [144.202.5.143] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203905; rev:1;) alert tcp $HOME_NET any -> [179.155.124.71] 15000 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203906; rev:1;) alert tcp $HOME_NET any -> [62.108.37.11] 5252 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203907; rev:1;) alert tcp $HOME_NET any -> [192.3.2.152] 5050 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203908; rev:1;) alert tcp $HOME_NET any -> [216.218.185.162] 443 (msg:"SSLBL: Traffic to malicious host (likely Gootkit C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203909; rev:1;) alert tcp $HOME_NET any -> [45.128.184.104] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203910; rev:1;) alert tcp $HOME_NET any -> [80.85.158.73] 7768 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203911; rev:1;) alert tcp $HOME_NET any -> [185.205.209.194] 1010 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203912; rev:1;) alert tcp $HOME_NET any -> [185.163.47.156] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203913; rev:1;) alert tcp $HOME_NET any -> [49.51.154.98] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203914; rev:1;) alert tcp $HOME_NET any -> [46.29.164.152] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203915; rev:1;) alert tcp $HOME_NET any -> [194.127.179.82] 7575 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203916; rev:1;) alert tcp $HOME_NET any -> [79.174.13.19] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203917; rev:1;) alert tcp $HOME_NET any -> [109.248.222.22] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203918; rev:1;) alert tcp $HOME_NET any -> [45.143.138.27] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203919; rev:1;) alert tcp $HOME_NET any -> [45.143.138.27] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203920; rev:1;) alert tcp $HOME_NET any -> [37.252.1.57] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203921; rev:1;) alert tcp $HOME_NET any -> [188.120.241.68] 443 (msg:"SSLBL: Traffic to malicious host (likely PredatorStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203922; rev:1;) alert tcp $HOME_NET any -> [188.127.227.76] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203923; rev:1;) alert tcp $HOME_NET any -> [95.169.181.90] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203924; rev:1;) alert tcp $HOME_NET any -> [194.58.98.72] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203925; rev:1;) alert tcp $HOME_NET any -> [45.129.2.228] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203926; rev:1;) alert tcp $HOME_NET any -> [176.103.62.240] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203927; rev:1;) alert tcp $HOME_NET any -> [37.48.83.137] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203928; rev:1;) alert tcp $HOME_NET any -> [141.255.154.30] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203929; rev:1;) alert tcp $HOME_NET any -> [45.72.3.132] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203930; rev:1;) alert tcp $HOME_NET any -> [194.67.105.88] 443 (msg:"SSLBL: Traffic to malicious host (likely ZLoader C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203931; rev:1;) alert tcp $HOME_NET any -> [66.154.97.151] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203932; rev:1;) alert tcp $HOME_NET any -> [198.54.125.162] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203933; rev:1;) alert tcp $HOME_NET any -> [108.174.198.213] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203934; rev:1;) alert tcp $HOME_NET any -> [185.189.68.74] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203935; rev:1;) alert tcp $HOME_NET any -> [95.217.99.22] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203936; rev:1;) alert tcp $HOME_NET any -> [95.211.170.231] 1991 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203937; rev:1;) alert tcp $HOME_NET any -> [185.48.56.111] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203938; rev:1;) alert tcp $HOME_NET any -> [69.30.240.82] 4358 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203939; rev:1;) alert tcp $HOME_NET any -> [103.133.109.147] 4434 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203940; rev:1;) alert tcp $HOME_NET any -> [176.10.124.134] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203941; rev:1;) alert tcp $HOME_NET any -> [195.19.192.46] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203942; rev:1;) alert tcp $HOME_NET any -> [45.86.182.200] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203943; rev:1;) alert tcp $HOME_NET any -> [45.137.22.45] 50572 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203944; rev:1;) alert tcp $HOME_NET any -> [45.80.69.34] 443 (msg:"SSLBL: Traffic to malicious host (likely CobInt C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203945; rev:1;) alert tcp $HOME_NET any -> [174.127.99.243] 5888 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203946; rev:1;) alert tcp $HOME_NET any -> [185.202.174.36] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203947; rev:1;) alert tcp $HOME_NET any -> [188.225.38.98] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203948; rev:1;) alert tcp $HOME_NET any -> [62.76.179.117] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203949; rev:1;) alert tcp $HOME_NET any -> [188.225.26.26] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203950; rev:1;) alert tcp $HOME_NET any -> [45.140.168.244] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203951; rev:1;) alert tcp $HOME_NET any -> [46.17.45.99] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203952; rev:1;) alert tcp $HOME_NET any -> [185.140.53.217] 5541 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203953; rev:1;) alert tcp $HOME_NET any -> [176.53.163.150] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203954; rev:1;) alert tcp $HOME_NET any -> [172.247.227.11] 4782 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203955; rev:1;) alert tcp $HOME_NET any -> [31.192.109.47] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203956; rev:1;) alert tcp $HOME_NET any -> [185.244.30.244] 2211 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203957; rev:1;) alert tcp $HOME_NET any -> [104.27.181.27] 443 (msg:"SSLBL: Traffic to malicious host (likely PredatorStealer C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203958; rev:1;) alert tcp $HOME_NET any -> [79.134.225.82] 1112 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203959; rev:1;) alert tcp $HOME_NET any -> [185.140.53.217] 2002 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203960; rev:1;) alert tcp $HOME_NET any -> [37.48.92.195] 1786 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203961; rev:1;) alert tcp $HOME_NET any -> [45.143.138.20] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203962; rev:1;) alert tcp $HOME_NET any -> [37.48.94.115] 1989 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203963; rev:1;) alert tcp $HOME_NET any -> [193.233.78.25] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203964; rev:1;) alert tcp $HOME_NET any -> [62.109.5.243] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203965; rev:1;) alert tcp $HOME_NET any -> [83.166.250.53] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203966; rev:1;) alert tcp $HOME_NET any -> [185.231.245.119] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203967; rev:1;) alert tcp $HOME_NET any -> [185.180.196.30] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203968; rev:1;) alert tcp $HOME_NET any -> [45.128.187.239] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203969; rev:1;) alert tcp $HOME_NET any -> [45.143.138.66] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203970; rev:1;) alert tcp $HOME_NET any -> [185.144.30.54] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203971; rev:1;) alert tcp $HOME_NET any -> [46.8.208.36] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203972; rev:1;) alert tcp $HOME_NET any -> [134.0.116.116] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203973; rev:1;) alert tcp $HOME_NET any -> [37.46.130.73] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203974; rev:1;) alert tcp $HOME_NET any -> [74.36.14.147] 54984 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203975; rev:1;) alert tcp $HOME_NET any -> [185.65.202.7] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203976; rev:1;) alert tcp $HOME_NET any -> [195.69.187.118] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203977; rev:1;) alert tcp $HOME_NET any -> [45.67.229.220] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203978; rev:1;) alert tcp $HOME_NET any -> [94.103.82.31] 443 (msg:"SSLBL: Traffic to malicious host (likely CobInt C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203979; rev:1;) alert tcp $HOME_NET any -> [91.121.235.6] 1515 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203980; rev:1;) alert tcp $HOME_NET any -> [194.5.97.59] 6606 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203981; rev:1;) alert tcp $HOME_NET any -> [185.140.53.6] 1819 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203982; rev:1;) alert tcp $HOME_NET any -> [45.143.138.69] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203983; rev:1;) alert tcp $HOME_NET any -> [83.166.245.47] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203984; rev:1;) alert tcp $HOME_NET any -> [91.214.119.30] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203985; rev:1;) alert tcp $HOME_NET any -> [79.134.225.12] 6036 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203986; rev:1;) alert tcp $HOME_NET any -> [176.32.32.62] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203987; rev:1;) alert tcp $HOME_NET any -> [185.117.155.48] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203988; rev:1;) alert tcp $HOME_NET any -> [176.32.33.203] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203989; rev:1;) alert tcp $HOME_NET any -> [46.29.163.145] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203990; rev:1;) alert tcp $HOME_NET any -> [185.244.30.222] 5200 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203991; rev:1;) alert tcp $HOME_NET any -> [194.61.1.178] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203992; rev:1;) alert tcp $HOME_NET any -> [46.29.161.246] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203993; rev:1;) alert tcp $HOME_NET any -> [95.217.19.128] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203994; rev:1;) alert tcp $HOME_NET any -> [149.154.159.226] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203995; rev:1;) alert tcp $HOME_NET any -> [46.29.161.3] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203996; rev:1;) alert tcp $HOME_NET any -> [185.61.154.7] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203997; rev:1;) alert tcp $HOME_NET any -> [79.134.225.47] 6234 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203998; rev:1;) alert tcp $HOME_NET any -> [83.166.242.144] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905203999; rev:1;) alert tcp $HOME_NET any -> [91.224.22.60] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204000; rev:1;) alert tcp $HOME_NET any -> [141.105.64.132] 1606 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204001; rev:1;) alert tcp $HOME_NET any -> [54.255.139.136] 80 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204002; rev:1;) alert tcp $HOME_NET any -> [84.54.187.24] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204003; rev:1;) alert tcp $HOME_NET any -> [89.35.29.52] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204004; rev:1;) alert tcp $HOME_NET any -> [119.31.127.51] 4444 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204005; rev:1;) alert tcp $HOME_NET any -> [79.134.225.114] 5040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204006; rev:1;) alert tcp $HOME_NET any -> [54.191.72.237] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204007; rev:1;) alert tcp $HOME_NET any -> [193.109.69.17] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204008; rev:1;) alert tcp $HOME_NET any -> [45.89.230.51] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204009; rev:1;) alert tcp $HOME_NET any -> [77.222.63.110] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204010; rev:1;) alert tcp $HOME_NET any -> [173.212.248.28] 8443 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204011; rev:1;) alert tcp $HOME_NET any -> [216.38.2.206] 5252 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204012; rev:1;) alert tcp $HOME_NET any -> [185.165.153.60] 4242 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204013; rev:1;) alert tcp $HOME_NET any -> [185.165.153.27] 44985 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204014; rev:1;) alert tcp $HOME_NET any -> [77.220.205.126] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204015; rev:1;) alert tcp $HOME_NET any -> [45.139.236.3] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204016; rev:1;) alert tcp $HOME_NET any -> [13.69.254.90] 77 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204017; rev:1;) alert tcp $HOME_NET any -> [185.147.15.21] 443 (msg:"SSLBL: Traffic to malicious host (likely AKBuilder C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204018; rev:1;) alert tcp $HOME_NET any -> [185.130.104.152] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204019; rev:1;) alert tcp $HOME_NET any -> [198.50.217.185] 1988 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204020; rev:1;) alert tcp $HOME_NET any -> [45.67.231.175] 443 (msg:"SSLBL: Traffic to malicious host (likely TA505 C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204021; rev:1;) alert tcp $HOME_NET any -> [79.134.225.92] 4040 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204022; rev:1;) alert tcp $HOME_NET any -> [173.249.23.208] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204023; rev:1;) alert tcp $HOME_NET any -> [185.174.172.99] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204024; rev:1;) alert tcp $HOME_NET any -> [81.25.71.88] 443 (msg:"SSLBL: Traffic to malicious host (likely FindPOS C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204025; rev:1;) alert tcp $HOME_NET any -> [185.140.53.135] 7654 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204026; rev:1;) alert tcp $HOME_NET any -> [176.227.191.12] 25530 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204027; rev:1;) alert tcp $HOME_NET any -> [2.91.161.144] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204028; rev:1;) alert tcp $HOME_NET any -> [5.61.40.237] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204029; rev:1;) alert tcp $HOME_NET any -> [185.118.165.109] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204030; rev:1;) alert tcp $HOME_NET any -> [79.134.225.76] 5252 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204031; rev:1;) alert tcp $HOME_NET any -> [176.32.32.15] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204032; rev:1;) alert tcp $HOME_NET any -> [45.144.3.145] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204033; rev:1;) alert tcp $HOME_NET any -> [79.134.225.79] 204 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204034; rev:1;) alert tcp $HOME_NET any -> [51.77.225.5] 7575 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204035; rev:1;) alert tcp $HOME_NET any -> [85.217.171.222] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204036; rev:1;) alert tcp $HOME_NET any -> [37.252.10.127] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204037; rev:1;) alert tcp $HOME_NET any -> [185.130.104.240] 443 (msg:"SSLBL: Traffic to malicious host (likely Ostap C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204038; rev:1;) alert tcp $HOME_NET any -> [46.29.164.66] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204039; rev:1;) alert tcp $HOME_NET any -> [95.110.224.103] 5147 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204040; rev:1;) alert tcp $HOME_NET any -> [83.220.175.116] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204041; rev:1;) alert tcp $HOME_NET any -> [91.218.65.24] 10134 (msg:"SSLBL: Traffic to malicious host (likely OrcusRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204042; rev:1;) alert tcp $HOME_NET any -> [193.29.15.147] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204043; rev:1;) alert tcp $HOME_NET any -> [190.1.237.120] 443 (msg:"SSLBL: Traffic to malicious host (likely Quakbot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204044; rev:1;) alert tcp $HOME_NET any -> [185.113.141.120] 443 (msg:"SSLBL: Traffic to malicious host (likely Ransomware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204045; rev:1;) alert tcp $HOME_NET any -> [195.228.41.2] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204046; rev:1;) alert tcp $HOME_NET any -> [37.75.61.8] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204047; rev:1;) alert tcp $HOME_NET any -> [94.103.82.67] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204048; rev:1;) alert tcp $HOME_NET any -> [185.140.53.78] 4811 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204049; rev:1;) alert tcp $HOME_NET any -> [51.83.18.78] 4358 (msg:"SSLBL: Traffic to malicious host (likely QuasarRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204050; rev:1;) alert tcp $HOME_NET any -> [93.189.149.187] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204051; rev:1;) alert tcp $HOME_NET any -> [185.165.153.199] 5954 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204052; rev:1;) alert tcp $HOME_NET any -> [185.140.53.90] 8585 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204053; rev:1;) alert tcp $HOME_NET any -> [185.165.153.175] 1994 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204054; rev:1;) alert tcp $HOME_NET any -> [213.208.152.216] 5954 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204055; rev:1;) alert tcp $HOME_NET any -> [45.144.2.210] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204056; rev:1;) alert tcp $HOME_NET any -> [185.157.245.59] 4430 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204057; rev:1;) alert tcp $HOME_NET any -> [185.165.153.75] 8585 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204058; rev:1;) alert tcp $HOME_NET any -> [5.188.108.58] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204059; rev:1;) alert tcp $HOME_NET any -> [138.201.6.195] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204060; rev:1;) alert tcp $HOME_NET any -> [194.67.86.241] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204061; rev:1;) alert tcp $HOME_NET any -> [85.143.219.95] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204062; rev:1;) alert tcp $HOME_NET any -> [47.111.114.5] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204063; rev:1;) alert tcp $HOME_NET any -> [194.58.123.243] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204064; rev:1;) alert tcp $HOME_NET any -> [91.77.167.80] 18000 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204065; rev:1;) alert tcp $HOME_NET any -> [45.128.186.79] 443 (msg:"SSLBL: Traffic to malicious host (likely PsiXBot C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204066; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 8808 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204067; rev:1;) alert tcp $HOME_NET any -> [79.134.225.71] 8808 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204068; rev:1;) alert tcp $HOME_NET any -> [91.230.60.107] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204069; rev:1;) alert tcp $HOME_NET any -> [185.253.219.43] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204070; rev:1;) alert tcp $HOME_NET any -> [51.77.225.5] 1960 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204071; rev:1;) alert tcp $HOME_NET any -> [84.38.129.162] 5555 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204072; rev:1;) alert tcp $HOME_NET any -> [188.72.115.200] 24007 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204073; rev:1;) alert tcp $HOME_NET any -> [185.118.66.254] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204074; rev:1;) alert tcp $HOME_NET any -> [90.96.187.205] 4430 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204075; rev:1;) alert tcp $HOME_NET any -> [195.133.146.24] 443 (msg:"SSLBL: Traffic to malicious host (likely Gozi C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204076; rev:1;) alert tcp $HOME_NET any -> [185.165.153.150] 4922 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204077; rev:1;) alert tcp $HOME_NET any -> [45.144.2.212] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204078; rev:1;) alert tcp $HOME_NET any -> [95.213.139.105] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204079; rev:1;) alert tcp $HOME_NET any -> [178.124.140.136] 1819 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204080; rev:1;) alert tcp $HOME_NET any -> [185.140.53.193] 83 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204081; rev:1;) alert tcp $HOME_NET any -> [185.140.53.222] 79 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204082; rev:1;) alert tcp $HOME_NET any -> [95.213.195.71] 3999 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204083; rev:1;) alert tcp $HOME_NET any -> [45.147.200.57] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204084; rev:1;) alert tcp $HOME_NET any -> [45.142.214.21] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204085; rev:1;) alert tcp $HOME_NET any -> [185.156.177.132] 443 (msg:"SSLBL: Traffic to malicious host (likely TinyNuke C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204086; rev:1;) alert tcp $HOME_NET any -> [79.134.225.123] 3930 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204087; rev:1;) alert tcp $HOME_NET any -> [46.148.26.62] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204088; rev:1;) alert tcp $HOME_NET any -> [185.165.153.27] 32765 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204089; rev:1;) alert tcp $HOME_NET any -> [185.163.45.199] 3999 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204090; rev:1;) alert tcp $HOME_NET any -> [194.165.3.1] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204091; rev:1;) alert tcp $HOME_NET any -> [217.182.188.118] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204092; rev:1;) alert tcp $HOME_NET any -> [212.7.208.72] 5567 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204093; rev:1;) alert tcp $HOME_NET any -> [91.193.75.151] 2019 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204094; rev:1;) alert tcp $HOME_NET any -> [185.81.157.122] 5050 (msg:"SSLBL: Traffic to malicious host (likely AsyncRAT C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204095; rev:1;) alert tcp $HOME_NET any -> [103.125.191.106] 7777 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204096; rev:1;) alert tcp $HOME_NET any -> [199.19.224.31] 443 (msg:"SSLBL: Traffic to malicious host (likely Malware C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204097; rev:1;) alert tcp $HOME_NET any -> [91.214.71.123] 443 (msg:"SSLBL: Traffic to malicious host (likely IcedID C&C traffic)"; flow:established,to_server; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; sid:905204098; rev:1;) alert tcp $HOME_NET any -> [185.165.153.28] 20131 (msg:"SSLBL: Traffic to malicious host (likely Adwind C&C traffic)"; fl