Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 11 additions & 11 deletions dyndns-dns.rules
Original file line number Diff line number Diff line change
Expand Up @@ -1067,17 +1067,17 @@ alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query ChangeIP.com d
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query ChangeIP.com domain ygto.com"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|ygto|03|com|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111066; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to DYNU.com domain dynu.com"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|dynu|03|com|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111067; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to DYNU.com domain dynu.net"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|dynu|03|net|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111068; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 6600.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|6600|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111069; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 7766.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|7766|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111070; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 8800.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|8800|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111071; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain webok.net"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|webok|03|net|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111072; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 2288.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|2288|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111073; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 9966.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|9966|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111074; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 8866.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|8866|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111075; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain 3322.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|3322|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111076; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain f3322.net"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|f3322|03|net|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111077; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain eatuo.com"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|eatuo|03|com|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111078; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3222.org domain x3322.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|x3322|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111079; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 6600.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|6600|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111069; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 7766.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|7766|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111070; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 8800.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|8800|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111071; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain webok.net"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|webok|03|net|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111072; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 2288.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|2288|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111073; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 9966.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|9966|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111074; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 8866.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|8866|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111075; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain 3322.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|04|3322|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111076; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain f3322.net"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|f3322|03|net|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111077; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain eatuo.com"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|eatuo|03|com|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111078; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to 3322.org domain x3322.org"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|05|x3322|03|org|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111079; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to Freenom domain co.vu"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|02|co|02|vu|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111080; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to Freenom domain gq"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|02|gq|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111081; rev:1;)
alert udp $HOME_NET any -> any 53 (msg:"ET INFO DYNAMIC_DNS Query to Freenom domain ml"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|02|ml|00|"; nocase; fast_pattern:only; classtype:misc-activity; sid:10111082; rev:1;)
Expand Down
22 changes: 11 additions & 11 deletions dyndns-drop.rules
Original file line number Diff line number Diff line change
Expand Up @@ -1067,17 +1067,17 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Req
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to ChangeIP.com domain ygto.com"; flow:established,to_server; content:".ygto.com"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011066; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to DYNU.com domain dynu.com"; flow:established,to_server; content:".dynu.com"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011067; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to DYNU.com domain dynu.net"; flow:established,to_server; content:".dynu.net"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011068; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 6600.org"; flow:established,to_server; content:".6600.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011069; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 7766.org"; flow:established,to_server; content:".7766.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011070; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 8800.org"; flow:established,to_server; content:".8800.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011071; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain webok.net"; flow:established,to_server; content:".webok.net"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011072; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 2288.org"; flow:established,to_server; content:".2288.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011073; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 9966.org"; flow:established,to_server; content:".9966.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011074; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 8866.org"; flow:established,to_server; content:".8866.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011075; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain 3322.org"; flow:established,to_server; content:".3322.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011076; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain f3322.net"; flow:established,to_server; content:".f3322.net"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011077; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain eatuo.com"; flow:established,to_server; content:".eatuo.com"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011078; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3222.org domain x3322.org"; flow:established,to_server; content:".x3322.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011079; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 6600.org"; flow:established,to_server; content:".6600.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011069; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 7766.org"; flow:established,to_server; content:".7766.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011070; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 8800.org"; flow:established,to_server; content:".8800.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011071; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain webok.net"; flow:established,to_server; content:".webok.net"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011072; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 2288.org"; flow:established,to_server; content:".2288.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011073; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 9966.org"; flow:established,to_server; content:".9966.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011074; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 8866.org"; flow:established,to_server; content:".8866.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011075; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain 3322.org"; flow:established,to_server; content:".3322.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011076; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain f3322.net"; flow:established,to_server; content:".f3322.net"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011077; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain eatuo.com"; flow:established,to_server; content:".eatuo.com"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011078; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to 3322.org domain x3322.org"; flow:established,to_server; content:".x3322.org"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011079; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to Freenom domain co.vu"; flow:established,to_server; content:".co.vu"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011080; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to Freenom domain gq"; flow:established,to_server; content:".gq"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011081; rev:1; classtype:misc-activity;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO DYNAMIC_DNS HTTP Request to Freenom domain ml"; flow:established,to_server; content:".ml"; http_host; isdataat:!1,relative; flowbits:noalert; flowbits:set,ET.DynDNS.HTTP; sid:10011082; rev:1; classtype:misc-activity;)
Expand Down
Loading