# # Emerging Threats RBN rules. # # Rules to detect known Russian Business Network (RBN) hosts. These lists are updated daily or better from many sources # # We do not necessarily declare that these hosts are all bad, or that RBN is inherently an evil organization. Use this # information as you see fit. # # More information available at doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork # # Please submit any feedback or ideas to emerging@emergingthreats.net or the emerging-sigs mailing list # #************************************************************* # # Copyright (c) 2003-2010, Emerging Threats # All rights reserved. # # Redistribution and use in source and binary forms, with or without modification, are permitted provided that the # following conditions are met: # # * Redistributions of source code must retain the above copyright notice, this list of conditions and the following # disclaimer. # * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the # following disclaimer in the documentation and/or other materials provided with the distribution. # * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived # from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES, # INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE # DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR # SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, # WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE # USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # # # VERSION 167 # Updated 2010-03-02 12:59:12 alert tcp [109.196.143.0/24,109.232.225.28,109.232.225.31,109.95.112.0/22,111.111.111.0/24,111.221.47.0/24,112.121.169.186,112.121.173.58,112.121.181.42,112.121.181.82,112.137.162.150,112.137.162.151,112.137.162.91,112.140.184.226,112.159.237.0/24,113.105.152.0/24,113.105.157.0/24,113.105.175.141,113.105.175.142,114.206.14.121] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (1)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407000; rev:167; fwsam: src, 24 hours;) alert udp [109.196.143.0/24,109.232.225.28,109.232.225.31,109.95.112.0/22,111.111.111.0/24,111.221.47.0/24,112.121.169.186,112.121.173.58,112.121.181.42,112.121.181.82,112.137.162.150,112.137.162.151,112.137.162.91,112.140.184.226,112.159.237.0/24,113.105.152.0/24,113.105.157.0/24,113.105.175.141,113.105.175.142,114.206.14.121] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (1)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407001; rev:167; fwsam: src, 24 hours;) alert tcp [114.207.112.16,114.207.112.169,114.207.244.143,114.207.244.146,114.37.101.86,114.42.93.59,114.47.126.158,114.80.209.37,114.80.67.30,114.80.67.32,115.100.250.0/24,115.124.112.159,115.126.2.0/24,115.126.5.0/24,115.238.252.104,115.239.224.234,115.28.82.201,115.29.140.132,115.68.21.172,115.86.180.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (2)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407002; rev:167; fwsam: src, 24 hours;) alert udp [114.207.112.16,114.207.112.169,114.207.244.143,114.207.244.146,114.37.101.86,114.42.93.59,114.47.126.158,114.80.209.37,114.80.67.30,114.80.67.32,115.100.250.0/24,115.124.112.159,115.126.2.0/24,115.126.5.0/24,115.238.252.104,115.239.224.234,115.28.82.201,115.29.140.132,115.68.21.172,115.86.180.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (2)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407003; rev:167; fwsam: src, 24 hours;) alert tcp [116.0.103.115,116.11.252.67,116.123.221.0/24,116.125.130.176,116.125.56.218,116.127.121.26,116.127.121.27,116.199.135.139,116.199.135.238,116.199.136.57,116.208.1.22,116.228.170.3,116.34.65.11,116.34.65.43,116.50.12.0/22,116.50.8.0/24,116.50.9.0/24,116.64.91.168,117.102.44.55,117.135.140.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (3)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407004; rev:167; fwsam: src, 24 hours;) alert udp [116.0.103.115,116.11.252.67,116.123.221.0/24,116.125.130.176,116.125.56.218,116.127.121.26,116.127.121.27,116.199.135.139,116.199.135.238,116.199.136.57,116.208.1.22,116.228.170.3,116.34.65.11,116.34.65.43,116.50.12.0/22,116.50.8.0/24,116.50.9.0/24,116.64.91.168,117.102.44.55,117.135.140.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (3)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407005; rev:167; fwsam: src, 24 hours;) alert tcp [117.20.166.137,117.200.96.105,117.34.74.228,117.41.166.135,117.55.237.193,117.81.132.188,118.122.177.170,118.123.11.29,118.142.9.167,118.171.100.18,118.216.29.81,118.219.232.177,118.219.232.183,118.219.232.197,118.219.234.171,118.220.196.44,118.32.132.193,118.45.190.166,119.110.107.124,119.110.107.125] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (4)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407006; rev:167; fwsam: src, 24 hours;) alert udp [117.20.166.137,117.200.96.105,117.34.74.228,117.41.166.135,117.55.237.193,117.81.132.188,118.122.177.170,118.123.11.29,118.142.9.167,118.171.100.18,118.216.29.81,118.219.232.177,118.219.232.183,118.219.232.197,118.219.234.171,118.220.196.44,118.32.132.193,118.45.190.166,119.110.107.124,119.110.107.125] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (4)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407007; rev:167; fwsam: src, 24 hours;) alert tcp [119.110.107.137,119.110.107.138,119.110.107.155,119.145.146.210,119.146.222.37,119.146.223.175,119.147.114.98,119.147.116.150,119.147.244.201,119.18.201.175,119.202.26.228,119.235.22.26,119.42.225.184,119.47.81.140,119.84.4.43,119.84.4.56,12.46.124.221,120.50.36.100,121.10.105.118,121.10.105.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (5)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407008; rev:167; fwsam: src, 24 hours;) alert udp [119.110.107.137,119.110.107.138,119.110.107.155,119.145.146.210,119.146.222.37,119.146.223.175,119.147.114.98,119.147.116.150,119.147.244.201,119.18.201.175,119.202.26.228,119.235.22.26,119.42.225.184,119.47.81.140,119.84.4.43,119.84.4.56,12.46.124.221,120.50.36.100,121.10.105.118,121.10.105.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (5)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407009; rev:167; fwsam: src, 24 hours;) alert tcp [121.11.152.189,121.11.76.159,121.11.80.216,121.11.85.250,121.11.86.41,121.11.92.211,121.12.104.170,121.12.109.63,121.12.110.50,121.12.117.85,121.12.120.14,121.12.169.179,121.12.170.110,121.12.170.177,121.12.172.172,121.125.75.91,121.14.142.185,121.14.151.77,121.14.152.87,121.14.154.150] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (6)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407010; rev:167; fwsam: src, 24 hours;) alert udp [121.11.152.189,121.11.76.159,121.11.80.216,121.11.85.250,121.11.86.41,121.11.92.211,121.12.104.170,121.12.109.63,121.12.110.50,121.12.117.85,121.12.120.14,121.12.169.179,121.12.170.110,121.12.170.177,121.12.172.172,121.125.75.91,121.14.142.185,121.14.151.77,121.14.152.87,121.14.154.150] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (6)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407011; rev:167; fwsam: src, 24 hours;) alert tcp [121.14.212.238,121.14.229.215,121.14.59.51,121.14.77.159,121.142.142.55,121.15.221.224,121.157.226.157,121.166.234.58,121.176.7.189,121.199.18.43,121.205.91.145,121.254.129.70,121.9.213.170,121.9.213.187,121.9.221.208,121.96.119.92,122.115.63.0/24,122.163.117.150,122.201.81.28,122.203.16.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (7)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407012; rev:167; fwsam: src, 24 hours;) alert udp [121.14.212.238,121.14.229.215,121.14.59.51,121.14.77.159,121.142.142.55,121.15.221.224,121.157.226.157,121.166.234.58,121.176.7.189,121.199.18.43,121.205.91.145,121.254.129.70,121.9.213.170,121.9.213.187,121.9.221.208,121.96.119.92,122.115.63.0/24,122.163.117.150,122.201.81.28,122.203.16.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (7)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407013; rev:167; fwsam: src, 24 hours;) alert tcp [122.218.93.174,122.224.10.105,122.224.186.144,122.224.32.113,122.224.5.189,122.224.5.79,122.224.50.69,122.224.54.202,122.224.54.216,122.224.6.35,122.224.6.48,122.224.9.221,122.224.9.67,122.225.10.234,122.225.117.147,122.225.36.19,122.225.38.32,122.225.56.90,122.225.58.226,122.227.135.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (8)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407014; rev:167; fwsam: src, 24 hours;) alert udp [122.218.93.174,122.224.10.105,122.224.186.144,122.224.32.113,122.224.5.189,122.224.5.79,122.224.50.69,122.224.54.202,122.224.54.216,122.224.6.35,122.224.6.48,122.224.9.221,122.224.9.67,122.225.10.234,122.225.117.147,122.225.36.19,122.225.38.32,122.225.56.90,122.225.58.226,122.227.135.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (8)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407015; rev:167; fwsam: src, 24 hours;) alert tcp [122.227.152.132,122.227.16.187,122.228.201.75,122.70.144.83,122.70.145.130,122.70.145.135,122.70.145.146,122.70.145.148,122.70.145.184,123.123.123.123,123.172.6.202,123.201.38.247,123.236.191.162,123.30.179.163,124.109.3.135,124.11.66.193,124.121.41.198,124.155.149.57,124.172.124.85,124.172.124.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (9)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407016; rev:167; fwsam: src, 24 hours;) alert udp [122.227.152.132,122.227.16.187,122.228.201.75,122.70.144.83,122.70.145.130,122.70.145.135,122.70.145.146,122.70.145.148,122.70.145.184,123.123.123.123,123.172.6.202,123.201.38.247,123.236.191.162,123.30.179.163,124.109.3.135,124.11.66.193,124.121.41.198,124.155.149.57,124.172.124.85,124.172.124.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (9)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407017; rev:167; fwsam: src, 24 hours;) alert tcp [124.217.216.61,124.217.229.237,124.217.229.31,124.217.229.32,124.217.229.48,124.217.238.192,124.217.239.146,124.217.239.156,124.217.239.157,124.217.240.5,124.217.241.142,124.217.247.147,124.217.247.248,124.217.247.249,124.217.251.10,124.217.251.175,124.217.251.182,124.217.251.45,124.217.252.123,124.217.254.59] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (10)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407018; rev:167; fwsam: src, 24 hours;) alert udp [124.217.216.61,124.217.229.237,124.217.229.31,124.217.229.32,124.217.229.48,124.217.238.192,124.217.239.146,124.217.239.156,124.217.239.157,124.217.240.5,124.217.241.142,124.217.247.147,124.217.247.248,124.217.247.249,124.217.251.10,124.217.251.175,124.217.251.182,124.217.251.45,124.217.252.123,124.217.254.59] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (10)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407019; rev:167; fwsam: src, 24 hours;) alert tcp [124.232.132.135,124.232.145.156,124.232.145.164,124.30.182.30,124.42.113.146,124.42.91.162,124.43.65.207,125.139.10.59,125.163.251.219,125.182.109.105,125.211.195.11,125.214.65.244,125.46.1.229,125.46.57.230,125.65.110.105,125.65.110.46,125.65.110.75,125.65.112.10,125.65.112.93,125.65.45.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (11)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407020; rev:167; fwsam: src, 24 hours;) alert udp [124.232.132.135,124.232.145.156,124.232.145.164,124.30.182.30,124.42.113.146,124.42.91.162,124.43.65.207,125.139.10.59,125.163.251.219,125.182.109.105,125.211.195.11,125.214.65.244,125.46.1.229,125.46.57.230,125.65.110.105,125.65.110.46,125.65.110.75,125.65.112.10,125.65.112.93,125.65.45.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (11)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407021; rev:167; fwsam: src, 24 hours;) alert tcp [125.65.46.113,125.68.56.188,125.76.228.26,125.87.0.109,125.87.2.82,125.89.78.200,125.90.88.118,125.91.11.73,128.121.4.11,128.242.120.13,129.44.190.77,130.160.86.220,132.247.8.18,136.145.55.9,139.146.141.147,140.117.43.1,143.225.229.216,144.206.186.112,146.57.249.101,146.82.201.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (12)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407022; rev:167; fwsam: src, 24 hours;) alert udp [125.65.46.113,125.68.56.188,125.76.228.26,125.87.0.109,125.87.2.82,125.89.78.200,125.90.88.118,125.91.11.73,128.121.4.11,128.242.120.13,129.44.190.77,130.160.86.220,132.247.8.18,136.145.55.9,139.146.141.147,140.117.43.1,143.225.229.216,144.206.186.112,146.57.249.101,146.82.201.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (12)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407023; rev:167; fwsam: src, 24 hours;) alert tcp [147.163.1.77,147.202.37.246,147.202.41.44,150.101.216.60,159.226.7.162,161.58.213.81,161.58.56.25,163.121.208.9,165.132.138.50,168.144.247.215,168.187.5.193,173.192.194.192,173.192.194.193,173.192.194.194,173.192.194.195,173.192.194.196,173.192.194.197,173.192.194.198,173.192.194.199,173.192.194.200] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (13)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407024; rev:167; fwsam: src, 24 hours;) alert udp [147.163.1.77,147.202.37.246,147.202.41.44,150.101.216.60,159.226.7.162,161.58.213.81,161.58.56.25,163.121.208.9,165.132.138.50,168.144.247.215,168.187.5.193,173.192.194.192,173.192.194.193,173.192.194.194,173.192.194.195,173.192.194.196,173.192.194.197,173.192.194.198,173.192.194.199,173.192.194.200] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (13)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407025; rev:167; fwsam: src, 24 hours;) alert tcp [173.192.194.201,173.192.194.202,173.192.194.203,173.192.194.204,173.192.194.205,173.192.194.206,173.192.194.207,173.192.194.208,173.192.194.209,173.192.194.210,173.192.194.211,173.192.194.212,173.192.194.213,173.192.194.214,173.192.194.215,173.192.194.216,173.192.194.217,173.192.194.218,173.192.194.219,173.192.194.220] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (14)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407026; rev:167; fwsam: src, 24 hours;) alert udp [173.192.194.201,173.192.194.202,173.192.194.203,173.192.194.204,173.192.194.205,173.192.194.206,173.192.194.207,173.192.194.208,173.192.194.209,173.192.194.210,173.192.194.211,173.192.194.212,173.192.194.213,173.192.194.214,173.192.194.215,173.192.194.216,173.192.194.217,173.192.194.218,173.192.194.219,173.192.194.220] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (14)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407027; rev:167; fwsam: src, 24 hours;) alert tcp [173.192.194.221,173.192.194.222,173.192.194.223,173.20.112.35,173.201.0.128,173.201.6.52,173.212.200.50,173.212.213.137,173.212.228.196,173.212.235.230,173.45.118.58,173.45.126.106,173.45.229.209,173.45.68.170,173.88.23.115,174.101.253.178,174.120.10.253,174.120.118.187,174.120.120.151,174.120.130.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (15)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407028; rev:167; fwsam: src, 24 hours;) alert udp [173.192.194.221,173.192.194.222,173.192.194.223,173.20.112.35,173.201.0.128,173.201.6.52,173.212.200.50,173.212.213.137,173.212.228.196,173.212.235.230,173.45.118.58,173.45.126.106,173.45.229.209,173.45.68.170,173.88.23.115,174.101.253.178,174.120.10.253,174.120.118.187,174.120.120.151,174.120.130.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (15)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407029; rev:167; fwsam: src, 24 hours;) alert tcp [174.120.154.6,174.120.17.226,174.120.18.158,174.120.224.131,174.120.237.23,174.120.30.244,174.120.6.156,174.120.6.7,174.120.61.60,174.120.62.8,174.120.9.91,174.121.10.51,174.121.11.6,174.121.16.9,174.123.158.3,174.123.210.242,174.123.217.34,174.123.249.210,174.129.222.176,174.129.241.185] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (16)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407030; rev:167; fwsam: src, 24 hours;) alert udp [174.120.154.6,174.120.17.226,174.120.18.158,174.120.224.131,174.120.237.23,174.120.30.244,174.120.6.156,174.120.6.7,174.120.61.60,174.120.62.8,174.120.9.91,174.121.10.51,174.121.11.6,174.121.16.9,174.123.158.3,174.123.210.242,174.123.217.34,174.123.249.210,174.129.222.176,174.129.241.185] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (16)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407031; rev:167; fwsam: src, 24 hours;) alert tcp [174.129.244.106,174.132.129.59,174.132.153.57,174.132.154.131,174.132.192.187,174.132.192.9,174.132.250.194,174.132.26.224,174.132.26.225,174.132.26.226,174.132.77.90,174.132.88.66,174.133.104.202,174.133.123.194,174.133.156.2,174.133.18.98,174.133.202.176,174.133.202.177,174.133.202.178,174.133.202.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (17)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407032; rev:167; fwsam: src, 24 hours;) alert udp [174.129.244.106,174.132.129.59,174.132.153.57,174.132.154.131,174.132.192.187,174.132.192.9,174.132.250.194,174.132.26.224,174.132.26.225,174.132.26.226,174.132.77.90,174.132.88.66,174.133.104.202,174.133.123.194,174.133.156.2,174.133.18.98,174.133.202.176,174.133.202.177,174.133.202.178,174.133.202.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (17)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407033; rev:167; fwsam: src, 24 hours;) alert tcp [174.133.202.180,174.133.202.181,174.133.202.182,174.133.202.183,174.133.202.184,174.133.202.185,174.133.202.186,174.133.202.187,174.133.202.188,174.133.202.189,174.133.202.190,174.133.202.191,174.133.34.176,174.133.34.177,174.133.34.178,174.133.34.179,174.133.34.180,174.133.34.181,174.133.34.182,174.133.34.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (18)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407034; rev:167; fwsam: src, 24 hours;) alert udp [174.133.202.180,174.133.202.181,174.133.202.182,174.133.202.183,174.133.202.184,174.133.202.185,174.133.202.186,174.133.202.187,174.133.202.188,174.133.202.189,174.133.202.190,174.133.202.191,174.133.34.176,174.133.34.177,174.133.34.178,174.133.34.179,174.133.34.180,174.133.34.181,174.133.34.182,174.133.34.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (18)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407035; rev:167; fwsam: src, 24 hours;) alert tcp [174.133.5.26,174.133.66.26,174.133.71.200,174.133.71.201,174.133.71.202,174.133.71.203,174.133.71.204,174.133.71.205,174.133.71.206,174.133.71.207,174.133.71.48,174.133.71.49,174.133.71.50,174.133.71.51,174.133.71.52,174.133.71.53,174.133.71.54,174.133.71.55,174.133.71.56,174.133.71.57] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (19)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407036; rev:167; fwsam: src, 24 hours;) alert udp [174.133.5.26,174.133.66.26,174.133.71.200,174.133.71.201,174.133.71.202,174.133.71.203,174.133.71.204,174.133.71.205,174.133.71.206,174.133.71.207,174.133.71.48,174.133.71.49,174.133.71.50,174.133.71.51,174.133.71.52,174.133.71.53,174.133.71.54,174.133.71.55,174.133.71.56,174.133.71.57] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (19)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407037; rev:167; fwsam: src, 24 hours;) alert tcp [174.133.71.58,174.133.71.59,174.133.71.60,174.133.71.61,174.133.71.62,174.133.71.63,174.133.72.248,174.133.72.249,174.133.72.250,174.133.72.251,174.133.72.252,174.133.72.253,174.133.72.254,174.133.72.255,174.133.73.178,174.137.132.21,174.137.132.37,174.137.132.45,174.137.189.38,174.137.189.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (20)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407038; rev:167; fwsam: src, 24 hours;) alert udp [174.133.71.58,174.133.71.59,174.133.71.60,174.133.71.61,174.133.71.62,174.133.71.63,174.133.72.248,174.133.72.249,174.133.72.250,174.133.72.251,174.133.72.252,174.133.72.253,174.133.72.254,174.133.72.255,174.133.73.178,174.137.132.21,174.137.132.37,174.137.132.45,174.137.189.38,174.137.189.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (20)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407039; rev:167; fwsam: src, 24 hours;) alert tcp [174.139.12.202,174.139.16.50,174.139.16.51,174.139.17.140,174.139.240.2,174.139.240.3,174.139.240.4,174.139.241.2,174.139.243.42,174.139.243.43,174.139.243.44,174.139.243.45,174.139.243.46,174.139.255.56,174.139.3.50,174.139.5.51,174.139.7.185,174.142.104.213,174.142.107.97,174.142.109.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (21)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407040; rev:167; fwsam: src, 24 hours;) alert udp [174.139.12.202,174.139.16.50,174.139.16.51,174.139.17.140,174.139.240.2,174.139.240.3,174.139.240.4,174.139.241.2,174.139.243.42,174.139.243.43,174.139.243.44,174.139.243.45,174.139.243.46,174.139.255.56,174.139.3.50,174.139.5.51,174.139.7.185,174.142.104.213,174.142.107.97,174.142.109.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (21)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407041; rev:167; fwsam: src, 24 hours;) alert tcp [174.142.113.202,174.142.113.203,174.142.113.204,174.142.113.205,174.142.113.206,174.142.150.42,174.142.53.148,174.142.9.25,174.142.96.2,174.142.96.3,174.142.96.6,174.143.254.174,174.36.1.27,174.36.105.216,174.36.105.218,174.36.118.235,174.36.118.236,174.36.118.237,174.36.134.200,174.36.158.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (22)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407042; rev:167; fwsam: src, 24 hours;) alert udp [174.142.113.202,174.142.113.203,174.142.113.204,174.142.113.205,174.142.113.206,174.142.150.42,174.142.53.148,174.142.9.25,174.142.96.2,174.142.96.3,174.142.96.6,174.143.254.174,174.36.1.27,174.36.105.216,174.36.105.218,174.36.118.235,174.36.118.236,174.36.118.237,174.36.134.200,174.36.158.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (22)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407043; rev:167; fwsam: src, 24 hours;) alert tcp [174.36.158.89,174.36.167.20,174.36.167.21,174.36.167.22,174.36.167.23,174.36.168.16,174.36.168.17,174.36.168.20,174.36.168.21,174.36.168.22,174.36.180.4,174.36.188.9,174.36.194.154,174.36.194.155,174.36.194.156,174.36.194.157,174.36.194.158,174.36.194.159,174.36.195.192,174.36.196.158] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (23)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407044; rev:167; fwsam: src, 24 hours;) alert udp [174.36.158.89,174.36.167.20,174.36.167.21,174.36.167.22,174.36.167.23,174.36.168.16,174.36.168.17,174.36.168.20,174.36.168.21,174.36.168.22,174.36.180.4,174.36.188.9,174.36.194.154,174.36.194.155,174.36.194.156,174.36.194.157,174.36.194.158,174.36.194.159,174.36.195.192,174.36.196.158] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (23)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407045; rev:167; fwsam: src, 24 hours;) alert tcp [174.36.199.41,174.36.203.117,174.36.214.32,174.36.217.112,174.36.218.194,174.36.218.195,174.36.218.200,174.36.221.128,174.36.230.5,174.36.230.6,174.36.234.248,174.36.235.147,174.36.235.216,174.36.235.243,174.36.236.16,174.36.237.100,174.36.237.84,174.36.243.5,174.36.246.49,174.36.246.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (24)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407046; rev:167; fwsam: src, 24 hours;) alert udp [174.36.199.41,174.36.203.117,174.36.214.32,174.36.217.112,174.36.218.194,174.36.218.195,174.36.218.200,174.36.221.128,174.36.230.5,174.36.230.6,174.36.234.248,174.36.235.147,174.36.235.216,174.36.235.243,174.36.236.16,174.36.237.100,174.36.237.84,174.36.243.5,174.36.246.49,174.36.246.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (24)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407047; rev:167; fwsam: src, 24 hours;) alert tcp [174.36.248.109,174.36.251.247,174.36.46.112,174.36.62.83,174.36.8.173,174.36.80.240,174.36.84.224,174.37.101.85,174.37.101.88,174.37.131.90,174.37.15.12,174.37.152.188,174.37.157.66,174.37.160.242,174.37.163.127,174.37.172.68,174.37.175.229,174.37.175.230,174.37.175.232,174.37.18.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (25)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407048; rev:167; fwsam: src, 24 hours;) alert udp [174.36.248.109,174.36.251.247,174.36.46.112,174.36.62.83,174.36.8.173,174.36.80.240,174.36.84.224,174.37.101.85,174.37.101.88,174.37.131.90,174.37.15.12,174.37.152.188,174.37.157.66,174.37.160.242,174.37.163.127,174.37.172.68,174.37.175.229,174.37.175.230,174.37.175.232,174.37.18.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (25)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407049; rev:167; fwsam: src, 24 hours;) alert tcp [174.37.193.180,174.37.21.130,174.37.216.1,174.37.217.96,174.37.22.173,174.37.222.128,174.37.231.192,174.37.231.193,174.37.231.194,174.37.233.0/24,174.37.235.0/24,174.37.244.32,174.37.244.33,174.37.244.34,174.37.244.35,174.37.244.36,174.37.244.37,174.37.244.38,174.37.244.39,174.37.244.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (26)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407050; rev:167; fwsam: src, 24 hours;) alert udp [174.37.193.180,174.37.21.130,174.37.216.1,174.37.217.96,174.37.22.173,174.37.222.128,174.37.231.192,174.37.231.193,174.37.231.194,174.37.233.0/24,174.37.235.0/24,174.37.244.32,174.37.244.33,174.37.244.34,174.37.244.35,174.37.244.36,174.37.244.37,174.37.244.38,174.37.244.39,174.37.244.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (26)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407051; rev:167; fwsam: src, 24 hours;) alert tcp [174.37.244.41,174.37.244.42,174.37.244.43,174.37.244.44,174.37.244.45,174.37.244.46,174.37.244.47,174.37.244.48,174.37.244.49,174.37.244.50,174.37.244.51,174.37.244.52,174.37.244.53,174.37.244.54,174.37.244.55,174.37.244.56,174.37.244.57,174.37.244.58,174.37.244.59,174.37.244.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (27)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407052; rev:167; fwsam: src, 24 hours;) alert udp [174.37.244.41,174.37.244.42,174.37.244.43,174.37.244.44,174.37.244.45,174.37.244.46,174.37.244.47,174.37.244.48,174.37.244.49,174.37.244.50,174.37.244.51,174.37.244.52,174.37.244.53,174.37.244.54,174.37.244.55,174.37.244.56,174.37.244.57,174.37.244.58,174.37.244.59,174.37.244.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (27)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407053; rev:167; fwsam: src, 24 hours;) alert tcp [174.37.244.61,174.37.244.62,174.37.244.63,174.37.36.170,174.37.88.68,184.73.32.143,186.80.92.113,186.81.205.197,187.10.65.176,187.16.23.139,187.67.255.47,188.120.228.170,188.120.45.160,188.121.46.1,188.124.15.173,188.124.15.229,188.124.15.230,188.124.15.231,188.124.3.225,188.124.5.107] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (28)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407054; rev:167; fwsam: src, 24 hours;) alert udp [174.37.244.61,174.37.244.62,174.37.244.63,174.37.36.170,174.37.88.68,184.73.32.143,186.80.92.113,186.81.205.197,187.10.65.176,187.16.23.139,187.67.255.47,188.120.228.170,188.120.45.160,188.121.46.1,188.124.15.173,188.124.15.229,188.124.15.230,188.124.15.231,188.124.3.225,188.124.5.107] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (28)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407055; rev:167; fwsam: src, 24 hours;) alert tcp [188.124.5.97,188.124.7.241,188.124.7.244,188.124.9.35,188.124.9.37,188.130.176.251,188.130.250.246,188.130.250.248,188.138.24.225,188.162.120.206,188.165.201.16,188.165.65.173,188.40.164.232,188.40.164.233,188.40.164.234,188.40.164.235,188.40.164.236,188.40.164.237,188.40.164.238,188.40.164.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (29)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407056; rev:167; fwsam: src, 24 hours;) alert udp [188.124.5.97,188.124.7.241,188.124.7.244,188.124.9.35,188.124.9.37,188.130.176.251,188.130.250.246,188.130.250.248,188.138.24.225,188.162.120.206,188.165.201.16,188.165.65.173,188.40.164.232,188.40.164.233,188.40.164.234,188.40.164.235,188.40.164.236,188.40.164.237,188.40.164.238,188.40.164.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (29)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407057; rev:167; fwsam: src, 24 hours;) alert tcp [188.40.22.176,188.40.253.34,188.40.36.211,188.40.52.180,188.40.52.181,188.40.61.236,188.40.70.2,188.40.80.120,188.40.86.118,188.58.196.79,188.72.192.129,188.72.205.122,188.72.215.69,188.72.225.208,188.72.225.218,188.72.225.55,188.72.238.69,188.72.243.79,188.72.250.48,188.72.253.141] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (30)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407058; rev:167; fwsam: src, 24 hours;) alert udp [188.40.22.176,188.40.253.34,188.40.36.211,188.40.52.180,188.40.52.181,188.40.61.236,188.40.70.2,188.40.80.120,188.40.86.118,188.58.196.79,188.72.192.129,188.72.205.122,188.72.215.69,188.72.225.208,188.72.225.218,188.72.225.55,188.72.238.69,188.72.243.79,188.72.250.48,188.72.253.141] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (30)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407059; rev:167; fwsam: src, 24 hours;) alert tcp [188.92.73.98,188.93.212.39,188.93.212.50,188.95.48.57,188.95.48.64,188.95.49.0/24,189.101.130.181,189.105.26.64,189.105.69.79,189.14.100.23,189.172.40.250,189.19.60.29,189.19.76.194,189.38.91.30,189.47.38.234,189.68.28.51,189.99.176.72,190.1.35.126,190.120.228.44,190.128.153.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (31)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407060; rev:167; fwsam: src, 24 hours;) alert udp [188.92.73.98,188.93.212.39,188.93.212.50,188.95.48.57,188.95.48.64,188.95.49.0/24,189.101.130.181,189.105.26.64,189.105.69.79,189.14.100.23,189.172.40.250,189.19.60.29,189.19.76.194,189.38.91.30,189.47.38.234,189.68.28.51,189.99.176.72,190.1.35.126,190.120.228.44,190.128.153.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (31)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407061; rev:167; fwsam: src, 24 hours;) alert tcp [190.15.64.203,190.15.72.0/21,190.183.61.41,190.20.51.206,190.210.10.169,190.210.10.242,190.227.44.150,190.228.29.17,190.228.29.81,190.245.105.180,190.245.40.52,190.34.29.179,190.5.236.98,190.81.33.115,192.115.70.0/24,192.118.104.0/22,192.41.60.10,193.104.106.61,193.104.106.62,193.104.110.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (32)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407062; rev:167; fwsam: src, 24 hours;) alert udp [190.15.64.203,190.15.72.0/21,190.183.61.41,190.20.51.206,190.210.10.169,190.210.10.242,190.227.44.150,190.228.29.17,190.228.29.81,190.245.105.180,190.245.40.52,190.34.29.179,190.5.236.98,190.81.33.115,192.115.70.0/24,192.118.104.0/22,192.41.60.10,193.104.106.61,193.104.106.62,193.104.110.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (32)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407063; rev:167; fwsam: src, 24 hours;) alert tcp [193.104.12.11,193.104.12.2,193.104.12.20,193.104.12.21,193.104.153.0/24,193.104.176.0/24,193.104.22.0/24,193.104.27.0/24,193.104.34.98,193.104.41.0/24,193.104.94.0/24,193.105.0.0/24,193.106.32.10,193.106.32.20,193.111.244.118,193.111.244.157,193.111.244.21,193.124.133.160,193.124.133.217,193.124.133.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (33)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407064; rev:167; fwsam: src, 24 hours;) alert udp [193.104.12.11,193.104.12.2,193.104.12.20,193.104.12.21,193.104.153.0/24,193.104.176.0/24,193.104.22.0/24,193.104.27.0/24,193.104.34.98,193.104.41.0/24,193.104.94.0/24,193.105.0.0/24,193.106.32.10,193.106.32.20,193.111.244.118,193.111.244.157,193.111.244.21,193.124.133.160,193.124.133.217,193.124.133.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (33)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407065; rev:167; fwsam: src, 24 hours;) alert tcp [193.124.133.63,193.124.83.95,193.138.172.23,193.138.172.5,193.138.172.6,193.138.172.8,193.138.173.160,193.138.173.251,193.138.228.110,193.138.228.120,193.138.231.80,193.138.231.83,193.138.232.0/22,193.142.244.0/24,193.165.209.3,193.169.12.0/23,193.169.218.150,193.169.234.19,193.169.234.24,193.169.234.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (34)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407066; rev:167; fwsam: src, 24 hours;) alert udp [193.124.133.63,193.124.83.95,193.138.172.23,193.138.172.5,193.138.172.6,193.138.172.8,193.138.173.160,193.138.173.251,193.138.228.110,193.138.228.120,193.138.231.80,193.138.231.83,193.138.232.0/22,193.142.244.0/24,193.165.209.3,193.169.12.0/23,193.169.218.150,193.169.234.19,193.169.234.24,193.169.234.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (34)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407067; rev:167; fwsam: src, 24 hours;) alert tcp [193.169.234.3,193.169.234.31,193.169.235.5,193.169.235.6,193.169.250.20,193.17.41.93,193.178.144.167,193.178.145.167,193.178.145.33,193.178.147.58,193.178.147.6,193.19.138.0/24,193.19.92.222,193.200.173.2,193.200.173.3,193.200.255.18,193.200.255.19,193.200.29.161,193.200.29.177,193.219.5.199] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (35)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407068; rev:167; fwsam: src, 24 hours;) alert udp [193.169.234.3,193.169.234.31,193.169.235.5,193.169.235.6,193.169.250.20,193.17.41.93,193.178.144.167,193.178.145.167,193.178.145.33,193.178.147.58,193.178.147.6,193.19.138.0/24,193.19.92.222,193.200.173.2,193.200.173.3,193.200.255.18,193.200.255.19,193.200.29.161,193.200.29.177,193.219.5.199] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (35)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407069; rev:167; fwsam: src, 24 hours;) alert tcp [193.219.5.200,193.22.244.48,193.22.244.50,193.227.114.2,193.227.240.130,193.227.240.37,193.227.240.38,193.227.241.60,193.232.130.14,193.232.159.1,193.239.4.12,193.27.246.0/23,193.33.128.0/23,193.33.144.226,193.33.170.10,193.33.170.70,193.33.170.75,193.33.61.160,193.33.61.161,193.33.61.188] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (36)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407070; rev:167; fwsam: src, 24 hours;) alert udp [193.219.5.200,193.22.244.48,193.22.244.50,193.227.114.2,193.227.240.130,193.227.240.37,193.227.240.38,193.227.241.60,193.232.130.14,193.232.159.1,193.239.4.12,193.27.246.0/23,193.33.128.0/23,193.33.144.226,193.33.170.10,193.33.170.70,193.33.170.75,193.33.61.160,193.33.61.161,193.33.61.188] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (36)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407071; rev:167; fwsam: src, 24 hours;) alert tcp [193.33.61.224,193.33.61.225,193.34.144.161,193.41.174.99,193.43.92.192,193.86.238.11,193.86.238.12,193.86.238.13,193.86.238.14,193.86.238.19,193.86.238.33,193.9.28.62,194.1.152.1,194.105.21.40,194.105.250.242,194.106.162.116,194.109.11.65,194.109.193.237,194.110.161.0/24,194.110.69.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (37)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407072; rev:167; fwsam: src, 24 hours;) alert udp [193.33.61.224,193.33.61.225,193.34.144.161,193.41.174.99,193.43.92.192,193.86.238.11,193.86.238.12,193.86.238.13,193.86.238.14,193.86.238.19,193.86.238.33,193.9.28.62,194.1.152.1,194.105.21.40,194.105.250.242,194.106.162.116,194.109.11.65,194.109.193.237,194.110.161.0/24,194.110.69.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (37)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407073; rev:167; fwsam: src, 24 hours;) alert tcp [194.116.202.129,194.126.174.124,194.135.103.86,194.135.105.175,194.135.105.203,194.135.105.25,194.135.105.3,194.135.105.48,194.135.105.50,194.135.19.39,194.135.22.0/24,194.135.25.106,194.145.235.0/24,194.146.204.0/22,194.153.188.2,194.154.164.103,194.154.75.191,194.165.4.0/23,194.168.163.56,194.186.45.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (38)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407074; rev:167; fwsam: src, 24 hours;) alert udp [194.116.202.129,194.126.174.124,194.135.103.86,194.135.105.175,194.135.105.203,194.135.105.25,194.135.105.3,194.135.105.48,194.135.105.50,194.135.19.39,194.135.22.0/24,194.135.25.106,194.145.235.0/24,194.146.204.0/22,194.153.188.2,194.154.164.103,194.154.75.191,194.165.4.0/23,194.168.163.56,194.186.45.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (38)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407075; rev:167; fwsam: src, 24 hours;) alert tcp [194.187.103.116,194.187.96.134,194.187.96.151,194.187.98.143,194.187.98.82,194.187.98.83,194.187.99.20,194.187.99.23,194.190.139.249,194.226.127.22,194.226.64.0/20,194.226.96.8,194.242.113.210,194.246.115.221,194.33.180.41,194.42.154.26,194.50.255.226,194.50.255.252,194.50.255.253,194.54.81.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (39)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407076; rev:167; fwsam: src, 24 hours;) alert udp [194.187.103.116,194.187.96.134,194.187.96.151,194.187.98.143,194.187.98.82,194.187.98.83,194.187.99.20,194.187.99.23,194.190.139.249,194.226.127.22,194.226.64.0/20,194.226.96.8,194.242.113.210,194.246.115.221,194.33.180.41,194.42.154.26,194.50.255.226,194.50.255.252,194.50.255.253,194.54.81.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (39)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407077; rev:167; fwsam: src, 24 hours;) alert tcp [194.54.83.163,194.54.88.208,194.54.88.46,194.54.89.12,194.54.90.246,194.58.155.37,194.58.155.38,194.58.78.41,194.58.79.190,194.58.79.80,194.60.205.20,194.67.178.27,194.8.74.227,194.8.75.153,194.8.75.186,194.85.105.17,194.85.61.20,194.85.61.78,194.85.92.136,194.87.50.147] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (40)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407078; rev:167; fwsam: src, 24 hours;) alert udp [194.54.83.163,194.54.88.208,194.54.88.46,194.54.89.12,194.54.90.246,194.58.155.37,194.58.155.38,194.58.78.41,194.58.79.190,194.58.79.80,194.60.205.20,194.67.178.27,194.8.74.227,194.8.75.153,194.8.75.186,194.85.105.17,194.85.61.20,194.85.61.78,194.85.92.136,194.87.50.147] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (40)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407079; rev:167; fwsam: src, 24 hours;) alert tcp [194.90.224.86,195.110.124.133,195.114.16.0/23,195.114.18.144,195.114.18.146,195.114.18.91,195.114.19.183,195.12.48.212,195.12.48.80,195.122.131.8,195.128.174.108,195.130.247.71,195.131.4.189,195.161.0.0/16,195.182.57.36,195.184.195.110,195.186.64.184,195.189.140.137,195.189.226.149,195.189.227.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (41)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407080; rev:167; fwsam: src, 24 hours;) alert udp [194.90.224.86,195.110.124.133,195.114.16.0/23,195.114.18.144,195.114.18.146,195.114.18.91,195.114.19.183,195.12.48.212,195.12.48.80,195.122.131.8,195.128.174.108,195.130.247.71,195.131.4.189,195.161.0.0/16,195.182.57.36,195.184.195.110,195.186.64.184,195.189.140.137,195.189.226.149,195.189.227.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (41)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407081; rev:167; fwsam: src, 24 hours;) alert tcp [195.189.246.35,195.189.247.101,195.190.12.245,195.190.12.246,195.190.13.0/24,195.2.240.147,195.2.240.194,195.2.240.34,195.2.240.58,195.2.252.0/23,195.20.240.114,195.20.9.124,195.207.15.79,195.208.0.4,195.211.101.8,195.216.175.114,195.216.175.115,195.216.175.117,195.216.197.21,195.216.243.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (42)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407082; rev:167; fwsam: src, 24 hours;) alert udp [195.189.246.35,195.189.247.101,195.190.12.245,195.190.12.246,195.190.13.0/24,195.2.240.147,195.2.240.194,195.2.240.34,195.2.240.58,195.2.252.0/23,195.20.240.114,195.20.9.124,195.207.15.79,195.208.0.4,195.211.101.8,195.216.175.114,195.216.175.115,195.216.175.117,195.216.197.21,195.216.243.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (42)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407083; rev:167; fwsam: src, 24 hours;) alert tcp [195.216.243.34,195.22.225.5,195.225.177.0/24,195.225.178.239,195.225.236.90,195.225.58.10,195.228.157.218,195.230.90.19,195.234.159.137,195.24.65.30,195.24.65.50,195.24.77.149,195.24.77.150,195.24.78.182,195.24.78.186,195.24.78.195,195.24.78.242,195.24.78.243,195.242.161.0/24,195.242.98.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (43)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407084; rev:167; fwsam: src, 24 hours;) alert udp [195.216.243.34,195.22.225.5,195.225.177.0/24,195.225.178.239,195.225.236.90,195.225.58.10,195.228.157.218,195.230.90.19,195.234.159.137,195.24.65.30,195.24.65.50,195.24.77.149,195.24.77.150,195.24.78.182,195.24.78.186,195.24.78.195,195.24.78.242,195.24.78.243,195.242.161.0/24,195.242.98.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (43)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407085; rev:167; fwsam: src, 24 hours;) alert tcp [195.242.99.215,195.244.9.20,195.245.119.131,195.245.119.150,195.245.194.22,195.245.194.3,195.248.234.27,195.248.77.45,195.249.40.157,195.250.34.66,195.28.180.122,195.3.136.90,195.3.144.0/22,195.3.192.124,195.3.206.34,195.30.99.152,195.39.196.43,195.42.102.0/23,195.42.120.83,195.47.247.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (44)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407086; rev:167; fwsam: src, 24 hours;) alert udp [195.242.99.215,195.244.9.20,195.245.119.131,195.245.119.150,195.245.194.22,195.245.194.3,195.248.234.27,195.248.77.45,195.249.40.157,195.250.34.66,195.28.180.122,195.3.136.90,195.3.144.0/22,195.3.192.124,195.3.206.34,195.30.99.152,195.39.196.43,195.42.102.0/23,195.42.120.83,195.47.247.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (44)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407087; rev:167; fwsam: src, 24 hours;) alert tcp [195.5.116.0/24,195.5.117.0/24,195.5.161.101,195.5.161.120,195.56.44.203,195.62.37.16,195.62.37.17,195.64.140.0/23,195.64.162.0/23,195.64.190.1,195.66.132.0/24,195.74.37.190,195.78.108.0/23,195.88.190.0/23,195.88.209.0/24,195.88.242.44,195.88.242.83,195.88.33.0/24,195.88.80.0/23,195.9.3.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (45)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407088; rev:167; fwsam: src, 24 hours;) alert udp [195.5.116.0/24,195.5.117.0/24,195.5.161.101,195.5.161.120,195.56.44.203,195.62.37.16,195.62.37.17,195.64.140.0/23,195.64.162.0/23,195.64.190.1,195.66.132.0/24,195.74.37.190,195.78.108.0/23,195.88.190.0/23,195.88.209.0/24,195.88.242.44,195.88.242.83,195.88.33.0/24,195.88.80.0/23,195.9.3.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (45)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407089; rev:167; fwsam: src, 24 hours;) alert tcp [195.93.208.0/23,195.93.218.0/24,195.95.151.138,195.95.151.174,195.95.151.176,195.95.151.184,195.95.155.0/24,195.95.218.0/23,196.2.198.240,196.21.232.104,196.217.228.206,196.218.21.19,196.34.88.6,196.41.6.144,196.41.6.147,198.173.73.9,198.177.253.147,198.177.253.152,198.63.208.35,198.63.210.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (46)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407090; rev:167; fwsam: src, 24 hours;) alert udp [195.93.208.0/23,195.93.218.0/24,195.95.151.138,195.95.151.174,195.95.151.176,195.95.151.184,195.95.155.0/24,195.95.218.0/23,196.2.198.240,196.21.232.104,196.217.228.206,196.218.21.19,196.34.88.6,196.41.6.144,196.41.6.147,198.173.73.9,198.177.253.147,198.177.253.152,198.63.208.35,198.63.210.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (46)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407091; rev:167; fwsam: src, 24 hours;) alert tcp [198.63.210.233,198.63.211.208,198.63.211.8,198.66.255.130,199.102.44.29,199.199.211.35,199.237.229.158,199.237.249.153,199.238.181.158,199.238.181.161,199.238.181.201,199.71.215.171,200.106.145.170,200.106.149.171,200.106.149.172,200.108.36.132,200.111.65.244,200.112.88.97,200.115.160.0/20,200.149.77.224] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (47)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407092; rev:167; fwsam: src, 24 hours;) alert udp [198.63.210.233,198.63.211.208,198.63.211.8,198.66.255.130,199.102.44.29,199.199.211.35,199.237.229.158,199.237.249.153,199.238.181.158,199.238.181.161,199.238.181.201,199.71.215.171,200.106.145.170,200.106.149.171,200.106.149.172,200.108.36.132,200.111.65.244,200.112.88.97,200.115.160.0/20,200.149.77.224] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (47)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407093; rev:167; fwsam: src, 24 hours;) alert tcp [200.149.77.227,200.149.77.228,200.155.17.172,200.160.243.179,200.168.143.247,200.168.150.223,200.171.128.39,200.171.170.10,200.195.192.138,200.203.183.34,200.205.145.90,200.206.191.101,200.207.12.47,200.219.224.4,200.219.224.48,200.219.245.158,200.234.196.118,200.234.196.19,200.234.196.90,200.234.200.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (48)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407094; rev:167; fwsam: src, 24 hours;) alert udp [200.149.77.227,200.149.77.228,200.155.17.172,200.160.243.179,200.168.143.247,200.168.150.223,200.171.128.39,200.171.170.10,200.195.192.138,200.203.183.34,200.205.145.90,200.206.191.101,200.207.12.47,200.219.224.4,200.219.224.48,200.219.245.158,200.234.196.118,200.234.196.19,200.234.196.90,200.234.200.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (48)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407095; rev:167; fwsam: src, 24 hours;) alert tcp [200.234.200.238,200.234.220.18,200.241.52.18,200.35.146.150,200.35.151.36,200.46.83.204,200.46.83.245,200.59.119.132,200.63.42.136,200.63.42.141,200.63.42.81,200.63.44.0/24,200.63.45.0/24,200.63.46.0/24,200.63.48.105,200.63.48.140,200.74.240.97,200.78.235.180,200.86.147.219,200.87.164.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (49)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407096; rev:167; fwsam: src, 24 hours;) alert udp [200.234.200.238,200.234.220.18,200.241.52.18,200.35.146.150,200.35.151.36,200.46.83.204,200.46.83.245,200.59.119.132,200.63.42.136,200.63.42.141,200.63.42.81,200.63.44.0/24,200.63.45.0/24,200.63.46.0/24,200.63.48.105,200.63.48.140,200.74.240.97,200.78.235.180,200.86.147.219,200.87.164.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (49)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407097; rev:167; fwsam: src, 24 hours;) alert tcp [200.98.197.17,200.98.197.28,200.98.251.17,201.134.249.164,201.16.248.189,201.165.241.127,201.17.33.210,201.212.0.243,201.218.198.58,201.218.218.98,201.218.250.124,201.222.251.20,201.224.52.117,201.226.135.11,201.231.44.209,201.232.200.143,201.235.145.105,201.236.86.60,201.239.164.9,201.248.238.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (50)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407098; rev:167; fwsam: src, 24 hours;) alert udp [200.98.197.17,200.98.197.28,200.98.251.17,201.134.249.164,201.16.248.189,201.165.241.127,201.17.33.210,201.212.0.243,201.218.198.58,201.218.218.98,201.218.250.124,201.222.251.20,201.224.52.117,201.226.135.11,201.231.44.209,201.232.200.143,201.235.145.105,201.236.86.60,201.239.164.9,201.248.238.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (50)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407099; rev:167; fwsam: src, 24 hours;) alert tcp [201.43.2.172,201.49.224.134,201.7.103.58,201.76.59.58,201.94.125.1,202.100.91.132,202.103.67.22,202.104.187.86,202.104.236.224,202.104.237.2,202.105.176.76,202.105.179.7,202.107.244.170,202.111.175.126,202.120.2.0/24,202.123.79.15,202.123.79.21,202.123.79.22,202.123.82.7,202.126.109.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (51)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407100; rev:167; fwsam: src, 24 hours;) alert udp [201.43.2.172,201.49.224.134,201.7.103.58,201.76.59.58,201.94.125.1,202.100.91.132,202.103.67.22,202.104.187.86,202.104.236.224,202.104.237.2,202.105.176.76,202.105.179.7,202.107.244.170,202.111.175.126,202.120.2.0/24,202.123.79.15,202.123.79.21,202.123.79.22,202.123.82.7,202.126.109.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (51)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407101; rev:167; fwsam: src, 24 hours;) alert tcp [202.129.187.242,202.130.189.133,202.141.148.29,202.142.20.143,202.142.20.187,202.142.20.188,202.142.20.244,202.144.207.11,202.146.4.119,202.157.51.53,202.162.216.146,202.170.120.71,202.171.157.165,202.172.28.113,202.172.28.38,202.172.32.210,202.174.106.50,202.174.106.51,202.174.106.52,202.175.186.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (52)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407102; rev:167; fwsam: src, 24 hours;) alert udp [202.129.187.242,202.130.189.133,202.141.148.29,202.142.20.143,202.142.20.187,202.142.20.188,202.142.20.244,202.144.207.11,202.146.4.119,202.157.51.53,202.162.216.146,202.170.120.71,202.171.157.165,202.172.28.113,202.172.28.38,202.172.32.210,202.174.106.50,202.174.106.51,202.174.106.52,202.175.186.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (52)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407103; rev:167; fwsam: src, 24 hours;) alert tcp [202.187.140.0/24,202.187.141.0/24,202.190.175.228,202.191.61.27,202.28.117.82,202.39.17.0/24,202.41.215.171,202.44.53.88,202.54.119.132,202.64.251.189,202.65.111.10,202.65.134.102,202.65.207.133,202.67.230.203,202.71.102.0/24,202.71.109.32,202.71.111.196,202.71.111.234,202.73.56.169,202.73.57.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (53)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407104; rev:167; fwsam: src, 24 hours;) alert udp [202.187.140.0/24,202.187.141.0/24,202.190.175.228,202.191.61.27,202.28.117.82,202.39.17.0/24,202.41.215.171,202.44.53.88,202.54.119.132,202.64.251.189,202.65.111.10,202.65.134.102,202.65.207.133,202.67.230.203,202.71.102.0/24,202.71.109.32,202.71.111.196,202.71.111.234,202.73.56.169,202.73.57.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (53)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407105; rev:167; fwsam: src, 24 hours;) alert tcp [202.73.57.20,202.73.57.22,202.73.57.25,202.73.57.6,202.75.35.101,202.75.35.222,202.75.36.22,202.75.38.133,202.75.63.116,202.80.178.128,202.82.11.4,202.83.41.148,202.91.245.221,202.91.251.174,202.93.87.154,202.93.87.249,202.93.91.187,202.95.104.0/24,203.107.164.210,203.110.81.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (54)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407106; rev:167; fwsam: src, 24 hours;) alert udp [202.73.57.20,202.73.57.22,202.73.57.25,202.73.57.6,202.75.35.101,202.75.35.222,202.75.36.22,202.75.38.133,202.75.63.116,202.80.178.128,202.82.11.4,202.83.41.148,202.91.245.221,202.91.251.174,202.93.87.154,202.93.87.249,202.93.91.187,202.95.104.0/24,203.107.164.210,203.110.81.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (54)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407107; rev:167; fwsam: src, 24 hours;) alert tcp [203.116.95.196,203.117.0.0/16,203.119.6.11,203.119.6.16,203.12.234.168,203.121.111.200,203.121.71.180,203.121.73.209,203.121.73.24,203.121.78.148,203.121.79.184,203.121.79.212,203.121.79.71,203.121.79.72,203.121.80.163,203.142.1.10,203.142.19.81,203.146.129.185,203.150.3.230,203.151.234.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (55)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407108; rev:167; fwsam: src, 24 hours;) alert udp [203.116.95.196,203.117.0.0/16,203.119.6.11,203.119.6.16,203.12.234.168,203.121.111.200,203.121.71.180,203.121.73.209,203.121.73.24,203.121.78.148,203.121.79.184,203.121.79.212,203.121.79.71,203.121.79.72,203.121.80.163,203.142.1.10,203.142.19.81,203.146.129.185,203.150.3.230,203.151.234.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (55)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407109; rev:167; fwsam: src, 24 hours;) alert tcp [203.155.56.99,203.156.254.182,203.157.64.24,203.169.164.18,203.169.186.29,203.171.239.91,203.174.83.75,203.174.83.98,203.186.92.84,203.211.143.172,203.211.145.203,203.22.204.226,203.22.204.97,203.251.93.133,203.56.244.21,203.81.50.138,203.81.50.139,203.81.50.140,203.81.50.141,203.81.50.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (56)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407110; rev:167; fwsam: src, 24 hours;) alert udp [203.155.56.99,203.156.254.182,203.157.64.24,203.169.164.18,203.169.186.29,203.171.239.91,203.174.83.75,203.174.83.98,203.186.92.84,203.211.143.172,203.211.145.203,203.22.204.226,203.22.204.97,203.251.93.133,203.56.244.21,203.81.50.138,203.81.50.139,203.81.50.140,203.81.50.141,203.81.50.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (56)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407111; rev:167; fwsam: src, 24 hours;) alert tcp [203.81.50.143,203.86.5.93,203.93.208.86,203.93.212.239,204.118.153.202,204.12.213.179,204.12.213.180,204.12.213.181,204.12.215.18,204.12.215.19,204.12.215.20,204.12.215.21,204.12.216.0/24,204.12.219.0/24,204.12.220.170,204.12.225.83,204.12.226.171,204.12.252.101,204.124.182.250,204.124.182.251] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (57)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407112; rev:167; fwsam: src, 24 hours;) alert udp [203.81.50.143,203.86.5.93,203.93.208.86,203.93.212.239,204.118.153.202,204.12.213.179,204.12.213.180,204.12.213.181,204.12.215.18,204.12.215.19,204.12.215.20,204.12.215.21,204.12.216.0/24,204.12.219.0/24,204.12.220.170,204.12.225.83,204.12.226.171,204.12.252.101,204.124.182.250,204.124.182.251] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (57)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407113; rev:167; fwsam: src, 24 hours;) alert tcp [204.124.182.253,204.124.182.254,204.124.183.53,204.124.183.54,204.13.160.15,204.13.160.38,204.13.161.103,204.13.161.136,204.13.161.177,204.13.64.26,204.13.64.36,204.136.14.181,204.136.14.182,204.14.110.38,204.15.248.80,204.16.199.203,204.16.244.222,204.16.247.230,204.16.252.112,204.188.206.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (58)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407114; rev:167; fwsam: src, 24 hours;) alert udp [204.124.182.253,204.124.182.254,204.124.183.53,204.124.183.54,204.13.160.15,204.13.160.38,204.13.161.103,204.13.161.136,204.13.161.177,204.13.64.26,204.13.64.36,204.136.14.181,204.136.14.182,204.14.110.38,204.15.248.80,204.16.199.203,204.16.244.222,204.16.247.230,204.16.252.112,204.188.206.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (58)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407115; rev:167; fwsam: src, 24 hours;) alert tcp [204.2.183.50,204.225.123.154,204.251.15.190,204.27.56.74,204.27.57.154,204.27.57.210,204.27.57.227,204.27.58.227,204.27.58.228,204.27.58.229,204.27.58.230,204.27.58.231,204.27.58.232,204.27.58.69,204.27.58.75,204.45.1.50,204.8.223.140,204.8.223.249,205.134.162.147,205.134.170.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (59)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407116; rev:167; fwsam: src, 24 hours;) alert udp [204.2.183.50,204.225.123.154,204.251.15.190,204.27.56.74,204.27.57.154,204.27.57.210,204.27.57.227,204.27.58.227,204.27.58.228,204.27.58.229,204.27.58.230,204.27.58.231,204.27.58.232,204.27.58.69,204.27.58.75,204.45.1.50,204.8.223.140,204.8.223.249,205.134.162.147,205.134.170.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (59)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407117; rev:167; fwsam: src, 24 hours;) alert tcp [205.134.191.187,205.134.225.120,205.177.124.46,205.178.144.192,205.178.145.65,205.178.150.185,205.196.212.97,205.209.113.22,205.209.137.109,205.209.137.110,205.209.143.94,205.219.188.169,205.234.140.186,205.234.184.106,205.234.186.234,205.234.197.209,205.234.197.40,205.234.206.30,205.234.222.29,205.234.243.50] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (60)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407118; rev:167; fwsam: src, 24 hours;) alert udp [205.134.191.187,205.134.225.120,205.177.124.46,205.178.144.192,205.178.145.65,205.178.150.185,205.196.212.97,205.209.113.22,205.209.137.109,205.209.137.110,205.209.143.94,205.219.188.169,205.234.140.186,205.234.184.106,205.234.186.234,205.234.197.209,205.234.197.40,205.234.206.30,205.234.222.29,205.234.243.50] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (60)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407119; rev:167; fwsam: src, 24 hours;) alert tcp [205.252.166.58,205.252.166.60,205.252.166.61,205.252.167.72,205.252.24.226,206.123.100.12,206.125.44.28,206.125.44.30,206.161.120.0/24,206.161.121.10,206.161.121.58,206.161.121.82,206.161.126.0/24,206.161.193.131,206.161.200.0/24,206.161.201.180,206.161.201.181,206.161.202.196,206.161.202.198,206.161.202.199] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (61)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407120; rev:167; fwsam: src, 24 hours;) alert udp [205.252.166.58,205.252.166.60,205.252.166.61,205.252.167.72,205.252.24.226,206.123.100.12,206.125.44.28,206.125.44.30,206.161.120.0/24,206.161.121.10,206.161.121.58,206.161.121.82,206.161.126.0/24,206.161.193.131,206.161.200.0/24,206.161.201.180,206.161.201.181,206.161.202.196,206.161.202.198,206.161.202.199] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (61)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407121; rev:167; fwsam: src, 24 hours;) alert tcp [206.161.202.206,206.161.205.52,206.161.206.179,206.161.206.186,206.161.206.187,206.161.206.188,206.217.199.37,206.217.199.4,206.217.201.136,206.217.201.137,206.217.201.240,206.217.201.28,206.217.205.158,206.221.184.140,206.222.31.218,206.222.31.219,206.225.86.123,206.225.94.63,206.251.244.227,206.251.244.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (62)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407122; rev:167; fwsam: src, 24 hours;) alert udp [206.161.202.206,206.161.205.52,206.161.206.179,206.161.206.186,206.161.206.187,206.161.206.188,206.217.199.37,206.217.199.4,206.217.201.136,206.217.201.137,206.217.201.240,206.217.201.28,206.217.205.158,206.221.184.140,206.222.31.218,206.222.31.219,206.225.86.123,206.225.94.63,206.251.244.227,206.251.244.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (62)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407123; rev:167; fwsam: src, 24 hours;) alert tcp [206.251.72.210,206.41.117.254,206.51.225.217,206.51.226.211,206.51.226.78,206.51.234.193,206.51.234.198,206.51.235.12,206.51.235.172,206.51.235.4,206.51.236.150,206.51.236.151,206.51.236.152,206.51.236.153,206.51.236.154,206.51.236.155,206.51.236.156,206.51.236.157,206.51.236.158,206.51.236.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (63)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407124; rev:167; fwsam: src, 24 hours;) alert udp [206.251.72.210,206.41.117.254,206.51.225.217,206.51.226.211,206.51.226.78,206.51.234.193,206.51.234.198,206.51.235.12,206.51.235.172,206.51.235.4,206.51.236.150,206.51.236.151,206.51.236.152,206.51.236.153,206.51.236.154,206.51.236.155,206.51.236.156,206.51.236.157,206.51.236.158,206.51.236.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (63)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407125; rev:167; fwsam: src, 24 hours;) alert tcp [206.51.236.165,206.51.237.93,206.51.238.166,206.51.238.167,206.51.238.200,206.51.238.27,206.51.238.40,206.51.238.41,206.51.238.42,206.51.238.43,206.51.238.44,206.51.238.45,206.51.238.46,206.51.238.47,206.51.238.48,206.51.238.49,206.51.238.5,206.53.48.156,206.53.49.170,206.53.51.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (64)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407126; rev:167; fwsam: src, 24 hours;) alert udp [206.51.236.165,206.51.237.93,206.51.238.166,206.51.238.167,206.51.238.200,206.51.238.27,206.51.238.40,206.51.238.41,206.51.238.42,206.51.238.43,206.51.238.44,206.51.238.45,206.51.238.46,206.51.238.47,206.51.238.48,206.51.238.49,206.51.238.5,206.53.48.156,206.53.49.170,206.53.51.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (64)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407127; rev:167; fwsam: src, 24 hours;) alert tcp [206.53.61.69,206.53.61.70,206.53.61.71,206.53.61.72,206.53.61.73,206.53.61.74,206.53.61.75,206.53.61.76,207.150.191.115,207.150.191.116,207.172.16.150,207.176.7.0/24,207.182.136.106,207.182.136.107,207.182.136.108,207.182.141.42,207.189.104.89,207.189.119.29,207.189.119.30,207.192.234.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (65)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407128; rev:167; fwsam: src, 24 hours;) alert udp [206.53.61.69,206.53.61.70,206.53.61.71,206.53.61.72,206.53.61.73,206.53.61.74,206.53.61.75,206.53.61.76,207.150.191.115,207.150.191.116,207.172.16.150,207.176.7.0/24,207.182.136.106,207.182.136.107,207.182.136.108,207.182.141.42,207.189.104.89,207.189.119.29,207.189.119.30,207.192.234.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (65)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407129; rev:167; fwsam: src, 24 hours;) alert tcp [207.204.9.223,207.210.101.85,207.210.64.174,207.210.69.194,207.210.74.48,207.210.85.61,207.210.88.52,207.226.164.54,207.226.167.94,207.226.168.239,207.226.172.120,207.226.173.0/24,207.226.175.0/24,207.226.178.162,207.226.179.0/24,207.226.182.0/24,207.226.88.123,207.226.88.124,207.246.135.45,207.246.153.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (66)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407130; rev:167; fwsam: src, 24 hours;) alert udp [207.204.9.223,207.210.101.85,207.210.64.174,207.210.69.194,207.210.74.48,207.210.85.61,207.210.88.52,207.226.164.54,207.226.167.94,207.226.168.239,207.226.172.120,207.226.173.0/24,207.226.175.0/24,207.226.178.162,207.226.179.0/24,207.226.182.0/24,207.226.88.123,207.226.88.124,207.246.135.45,207.246.153.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (66)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407131; rev:167; fwsam: src, 24 hours;) alert tcp [207.246.153.236,207.36.232.55,207.44.150.118,207.44.164.50,207.44.178.47,207.45.187.106,207.57.97.233,207.58.145.101,207.58.145.102,207.58.145.103,207.58.145.104,207.58.187.146,207.97.201.192,208.100.0.76,208.100.34.148,208.100.34.94,208.100.5.254,208.100.61.101,208.100.61.2,208.101.0.83] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (67)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407132; rev:167; fwsam: src, 24 hours;) alert udp [207.246.153.236,207.36.232.55,207.44.150.118,207.44.164.50,207.44.178.47,207.45.187.106,207.57.97.233,207.58.145.101,207.58.145.102,207.58.145.103,207.58.145.104,207.58.187.146,207.97.201.192,208.100.0.76,208.100.34.148,208.100.34.94,208.100.5.254,208.100.61.101,208.100.61.2,208.101.0.83] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (67)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407133; rev:167; fwsam: src, 24 hours;) alert tcp [208.101.10.89,208.101.11.160,208.101.11.161,208.101.11.162,208.101.11.163,208.101.11.164,208.101.11.165,208.101.11.166,208.101.11.167,208.101.11.244,208.101.16.180,208.101.17.35,208.101.21.18,208.101.37.227,208.101.41.170,208.101.41.224,208.101.41.225,208.101.41.226,208.101.41.227,208.101.41.228] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (68)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407134; rev:167; fwsam: src, 24 hours;) alert udp [208.101.10.89,208.101.11.160,208.101.11.161,208.101.11.162,208.101.11.163,208.101.11.164,208.101.11.165,208.101.11.166,208.101.11.167,208.101.11.244,208.101.16.180,208.101.17.35,208.101.21.18,208.101.37.227,208.101.41.170,208.101.41.224,208.101.41.225,208.101.41.226,208.101.41.227,208.101.41.228] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (68)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407135; rev:167; fwsam: src, 24 hours;) alert tcp [208.101.41.229,208.101.41.230,208.101.41.231,208.101.43.67,208.101.56.100,208.101.7.96,208.101.9.140,208.109.138.117,208.109.14.114,208.109.181.126,208.109.181.42,208.109.181.58,208.109.189.112,208.109.203.164,208.109.234.133,208.109.50.16,208.110.70.81,208.110.73.34,208.110.80.170,208.110.86.246] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (69)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407136; rev:167; fwsam: src, 24 hours;) alert udp [208.101.41.229,208.101.41.230,208.101.41.231,208.101.43.67,208.101.56.100,208.101.7.96,208.101.9.140,208.109.138.117,208.109.14.114,208.109.181.126,208.109.181.42,208.109.181.58,208.109.189.112,208.109.203.164,208.109.234.133,208.109.50.16,208.110.70.81,208.110.73.34,208.110.80.170,208.110.86.246] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (69)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407137; rev:167; fwsam: src, 24 hours;) alert tcp [208.110.93.90,208.110.93.91,208.110.93.92,208.110.93.93,208.110.93.94,208.112.114.164,208.113.141.194,208.113.153.62,208.113.161.124,208.113.162.113,208.113.168.60,208.116.34.138,208.116.34.139,208.116.34.141,208.116.36.254,208.116.7.242,208.122.40.0/24,208.123.214.220,208.43.105.208,208.43.12.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (70)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407138; rev:167; fwsam: src, 24 hours;) alert udp [208.110.93.90,208.110.93.91,208.110.93.92,208.110.93.93,208.110.93.94,208.112.114.164,208.113.141.194,208.113.153.62,208.113.161.124,208.113.162.113,208.113.168.60,208.116.34.138,208.116.34.139,208.116.34.141,208.116.36.254,208.116.7.242,208.122.40.0/24,208.123.214.220,208.43.105.208,208.43.12.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (70)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407139; rev:167; fwsam: src, 24 hours;) alert tcp [208.43.120.88,208.43.121.156,208.43.124.186,208.43.124.83,208.43.125.104,208.43.125.107,208.43.125.236,208.43.129.120,208.43.129.121,208.43.129.122,208.43.130.19,208.43.132.152,208.43.132.153,208.43.132.154,208.43.132.155,208.43.132.156,208.43.132.157,208.43.146.100,208.43.146.101,208.43.146.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (71)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407140; rev:167; fwsam: src, 24 hours;) alert udp [208.43.120.88,208.43.121.156,208.43.124.186,208.43.124.83,208.43.125.104,208.43.125.107,208.43.125.236,208.43.129.120,208.43.129.121,208.43.129.122,208.43.130.19,208.43.132.152,208.43.132.153,208.43.132.154,208.43.132.155,208.43.132.156,208.43.132.157,208.43.146.100,208.43.146.101,208.43.146.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (71)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407141; rev:167; fwsam: src, 24 hours;) alert tcp [208.43.146.103,208.43.146.96,208.43.146.97,208.43.146.98,208.43.146.99,208.43.155.64,208.43.17.250,208.43.19.64,208.43.194.220,208.43.202.159,208.43.212.208,208.43.229.59,208.43.231.66,208.43.232.224,208.43.232.80,208.43.238.242,208.43.238.251,208.43.242.238,208.43.247.56,208.43.250.121] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (72)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407142; rev:167; fwsam: src, 24 hours;) alert udp [208.43.146.103,208.43.146.96,208.43.146.97,208.43.146.98,208.43.146.99,208.43.155.64,208.43.17.250,208.43.19.64,208.43.194.220,208.43.202.159,208.43.212.208,208.43.229.59,208.43.231.66,208.43.232.224,208.43.232.80,208.43.238.242,208.43.238.251,208.43.242.238,208.43.247.56,208.43.250.121] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (72)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407143; rev:167; fwsam: src, 24 hours;) alert tcp [208.43.27.11,208.43.36.107,208.43.41.0/24,208.43.5.228,208.43.73.230,208.43.79.11,208.43.79.147,208.43.88.188,208.43.92.68,208.50.77.144,208.50.77.161,208.53.137.51,208.53.137.52,208.53.147.189,208.53.148.154,208.53.158.170,208.53.158.84,208.53.168.4,208.66.192.0/22,208.68.104.125] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (73)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407144; rev:167; fwsam: src, 24 hours;) alert udp [208.43.27.11,208.43.36.107,208.43.41.0/24,208.43.5.228,208.43.73.230,208.43.79.11,208.43.79.147,208.43.88.188,208.43.92.68,208.50.77.144,208.50.77.161,208.53.137.51,208.53.137.52,208.53.147.189,208.53.148.154,208.53.158.170,208.53.158.84,208.53.168.4,208.66.192.0/22,208.68.104.125] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (73)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407145; rev:167; fwsam: src, 24 hours;) alert tcp [208.71.106.216,208.72.160.0/20,208.72.168.0/21,208.72.173.0/24,208.73.210.121,208.73.210.32,208.73.210.50,208.74.148.127,208.74.148.203,208.75.183.18,208.75.183.19,208.75.230.43,208.76.80.87,208.76.86.12,208.77.101.104,208.77.40.204,208.77.45.146,208.78.242.184,208.78.242.185,208.79.201.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (74)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407146; rev:167; fwsam: src, 24 hours;) alert udp [208.71.106.216,208.72.160.0/20,208.72.168.0/21,208.72.173.0/24,208.73.210.121,208.73.210.32,208.73.210.50,208.74.148.127,208.74.148.203,208.75.183.18,208.75.183.19,208.75.230.43,208.76.80.87,208.76.86.12,208.77.101.104,208.77.40.204,208.77.45.146,208.78.242.184,208.78.242.185,208.79.201.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (74)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407147; rev:167; fwsam: src, 24 hours;) alert tcp [208.79.82.0/24,208.80.184.202,208.80.184.203,208.81.197.100,208.82.101.81,208.83.224.200,208.85.181.67,208.85.181.68,208.85.181.69,208.85.181.70,208.87.148.0/23,208.87.242.120,208.87.242.130,208.87.243.4,208.87.33.150,208.87.33.151,208.88.224.0/24,208.88.226.199,208.88.226.71,208.88.227.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (75)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407148; rev:167; fwsam: src, 24 hours;) alert udp [208.79.82.0/24,208.80.184.202,208.80.184.203,208.81.197.100,208.82.101.81,208.83.224.200,208.85.181.67,208.85.181.68,208.85.181.69,208.85.181.70,208.87.148.0/23,208.87.242.120,208.87.242.130,208.87.243.4,208.87.33.150,208.87.33.151,208.88.224.0/24,208.88.226.199,208.88.226.71,208.88.227.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (75)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407149; rev:167; fwsam: src, 24 hours;) alert tcp [208.88.51.100,208.88.51.105,208.88.53.0/24,208.93.113.12,208.94.147.65,208.97.177.67,208.97.178.238,208.98.11.187,208.98.22.0/24,208.98.50.221,208.98.6.67,209.114.200.64,209.114.220.8,209.123.181.122,209.123.181.22,209.123.181.85,209.123.181.95,209.123.8.188,209.126.180.172,209.132.28.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (76)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407150; rev:167; fwsam: src, 24 hours;) alert udp [208.88.51.100,208.88.51.105,208.88.53.0/24,208.93.113.12,208.94.147.65,208.97.177.67,208.97.178.238,208.98.11.187,208.98.22.0/24,208.98.50.221,208.98.6.67,209.114.200.64,209.114.220.8,209.123.181.122,209.123.181.22,209.123.181.85,209.123.181.95,209.123.8.188,209.126.180.172,209.132.28.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (76)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407151; rev:167; fwsam: src, 24 hours;) alert tcp [209.150.119.72,209.151.232.35,209.151.236.15,209.151.236.20,209.151.82.2,209.160.20.116,209.160.20.117,209.160.20.24,209.160.21.125,209.160.21.218,209.160.21.51,209.160.21.99,209.160.24.29,209.160.38.125,209.160.65.145,209.160.65.158,209.160.65.62,209.160.66.201,209.160.67.56,209.160.67.74] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (77)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407152; rev:167; fwsam: src, 24 hours;) alert udp [209.150.119.72,209.151.232.35,209.151.236.15,209.151.236.20,209.151.82.2,209.160.20.116,209.160.20.117,209.160.20.24,209.160.21.125,209.160.21.218,209.160.21.51,209.160.21.99,209.160.24.29,209.160.38.125,209.160.65.145,209.160.65.158,209.160.65.62,209.160.66.201,209.160.67.56,209.160.67.74] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (77)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407153; rev:167; fwsam: src, 24 hours;) alert tcp [209.160.68.98,209.160.71.110,209.160.72.174,209.160.73.141,209.160.73.4,209.162.188.225,209.162.189.26,209.172.35.144,209.172.37.190,209.172.41.53,209.172.44.132,209.172.44.212,209.172.57.234,209.172.57.51,209.172.59.133,209.181.247.105,209.188.0.19,209.190.16.82,209.190.24.10,209.190.24.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (78)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407154; rev:167; fwsam: src, 24 hours;) alert udp [209.160.68.98,209.160.71.110,209.160.72.174,209.160.73.141,209.160.73.4,209.162.188.225,209.162.189.26,209.172.35.144,209.172.37.190,209.172.41.53,209.172.44.132,209.172.44.212,209.172.57.234,209.172.57.51,209.172.59.133,209.181.247.105,209.188.0.19,209.190.16.82,209.190.24.10,209.190.24.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (78)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407155; rev:167; fwsam: src, 24 hours;) alert tcp [209.190.24.6,209.190.24.9,209.190.85.36,209.197.3.119,209.20.88.75,209.200.124.200,209.200.162.193,209.200.55.33,209.200.55.60,209.200.60.137,209.200.63.169,209.200.63.179,209.200.63.184,209.200.9.155,209.200.91.44,209.202.252.41,209.202.252.50,209.212.154.223,209.216.193.0/24,209.235.144.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (79)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407156; rev:167; fwsam: src, 24 hours;) alert udp [209.190.24.6,209.190.24.9,209.190.85.36,209.197.3.119,209.20.88.75,209.200.124.200,209.200.162.193,209.200.55.33,209.200.55.60,209.200.60.137,209.200.63.169,209.200.63.179,209.200.63.184,209.200.9.155,209.200.91.44,209.202.252.41,209.202.252.50,209.212.154.223,209.216.193.0/24,209.235.144.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (79)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407157; rev:167; fwsam: src, 24 hours;) alert tcp [209.240.131.94,209.240.137.90,209.249.222.18,209.249.222.37,209.249.222.48,209.25.133.225,209.250.227.0/24,209.250.230.0/24,209.250.232.0/24,209.250.235.0/24,209.250.236.0/24,209.250.237.0/24,209.250.239.17,209.250.240.98,209.250.241.134,209.250.241.141,209.250.241.164,209.250.241.212,209.250.241.240,209.250.241.242] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (80)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407158; rev:167; fwsam: src, 24 hours;) alert udp [209.240.131.94,209.240.137.90,209.249.222.18,209.249.222.37,209.249.222.48,209.25.133.225,209.250.227.0/24,209.250.230.0/24,209.250.232.0/24,209.250.235.0/24,209.250.236.0/24,209.250.237.0/24,209.250.239.17,209.250.240.98,209.250.241.134,209.250.241.141,209.250.241.164,209.250.241.212,209.250.241.240,209.250.241.242] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (80)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407159; rev:167; fwsam: src, 24 hours;) alert tcp [209.250.241.244,209.31.180.130,209.31.180.132,209.31.180.133,209.31.180.135,209.31.180.138,209.31.180.142,209.31.180.144,209.31.180.228,209.31.180.230,209.31.180.232,209.31.180.233,209.31.180.234,209.31.180.235,209.31.180.236,209.31.180.237,209.31.180.238,209.31.180.239,209.31.180.240,209.31.180.241] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (81)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407160; rev:167; fwsam: src, 24 hours;) alert udp [209.250.241.244,209.31.180.130,209.31.180.132,209.31.180.133,209.31.180.135,209.31.180.138,209.31.180.142,209.31.180.144,209.31.180.228,209.31.180.230,209.31.180.232,209.31.180.233,209.31.180.234,209.31.180.235,209.31.180.236,209.31.180.237,209.31.180.238,209.31.180.239,209.31.180.240,209.31.180.241] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (81)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407161; rev:167; fwsam: src, 24 hours;) alert tcp [209.31.180.242,209.31.180.243,209.31.180.248,209.31.180.249,209.31.180.252,209.31.180.28,209.44.111.57,209.44.111.58,209.44.111.59,209.44.111.60,209.44.111.61,209.44.111.62,209.44.114.212,209.44.114.217,209.44.114.218,209.44.114.219,209.44.114.222,209.44.126.0/24,209.51.155.138,209.51.195.116] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (82)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407162; rev:167; fwsam: src, 24 hours;) alert udp [209.31.180.242,209.31.180.243,209.31.180.248,209.31.180.249,209.31.180.252,209.31.180.28,209.44.111.57,209.44.111.58,209.44.111.59,209.44.111.60,209.44.111.61,209.44.111.62,209.44.114.212,209.44.114.217,209.44.114.218,209.44.114.219,209.44.114.222,209.44.126.0/24,209.51.155.138,209.51.195.116] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (82)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407163; rev:167; fwsam: src, 24 hours;) alert tcp [209.51.196.242,209.51.196.247,209.51.196.252,209.59.175.202,209.59.177.9,209.59.179.6,209.59.181.47,209.59.181.48,209.59.194.20,209.59.194.246,209.59.194.250,209.62.105.151,209.62.20.153,209.62.20.163,209.62.20.192,209.62.20.245,209.62.21.201,209.62.27.84,209.62.36.2,209.62.57.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (83)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407164; rev:167; fwsam: src, 24 hours;) alert udp [209.51.196.242,209.51.196.247,209.51.196.252,209.59.175.202,209.59.177.9,209.59.179.6,209.59.181.47,209.59.181.48,209.59.194.20,209.59.194.246,209.59.194.250,209.62.105.151,209.62.20.153,209.62.20.163,209.62.20.192,209.62.20.245,209.62.21.201,209.62.27.84,209.62.36.2,209.62.57.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (83)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407165; rev:167; fwsam: src, 24 hours;) alert tcp [209.62.7.138,209.62.7.250,209.62.7.253,209.62.72.165,209.62.72.169,209.62.72.173,209.62.72.250,209.62.76.10,209.62.85.110,209.62.9.34,209.63.57.10,209.66.114.22,209.66.120.0/24,209.66.123.187,209.66.123.64,209.66.123.65,209.66.123.72,209.66.123.88,209.66.123.93,209.66.124.52] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (84)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407166; rev:167; fwsam: src, 24 hours;) alert udp [209.62.7.138,209.62.7.250,209.62.7.253,209.62.72.165,209.62.72.169,209.62.72.173,209.62.72.250,209.62.76.10,209.62.85.110,209.62.9.34,209.63.57.10,209.66.114.22,209.66.120.0/24,209.66.123.187,209.66.123.64,209.66.123.65,209.66.123.72,209.66.123.88,209.66.123.93,209.66.124.52] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (84)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407167; rev:167; fwsam: src, 24 hours;) alert tcp [209.67.211.122,209.67.211.2,209.67.211.3,209.67.214.194,209.67.214.61,209.67.214.62,209.67.215.178,209.8.151.186,209.8.151.188,209.8.151.190,209.8.19.132,209.8.19.133,209.8.19.213,209.8.20.190,209.8.20.227,209.8.21.202,209.8.23.70,209.8.23.87,209.8.237.142,209.8.24.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (85)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407168; rev:167; fwsam: src, 24 hours;) alert udp [209.67.211.122,209.67.211.2,209.67.211.3,209.67.214.194,209.67.214.61,209.67.214.62,209.67.215.178,209.8.151.186,209.8.151.188,209.8.151.190,209.8.19.132,209.8.19.133,209.8.19.213,209.8.20.190,209.8.20.227,209.8.21.202,209.8.23.70,209.8.23.87,209.8.237.142,209.8.24.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (85)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407169; rev:167; fwsam: src, 24 hours;) alert tcp [209.8.25.114,209.8.25.204,209.8.25.254,209.8.25.66,209.8.45.0/24,209.8.47.0/24,209.81.12.132,209.81.12.133,209.84.29.126,209.85.25.210,209.85.5.16,209.85.51.0/24,209.85.73.222,209.85.84.0/24,209.85.87.42,209.85.97.155,209.85.99.29,209.85.99.30,209.85.99.31,209.85.99.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (86)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407170; rev:167; fwsam: src, 24 hours;) alert udp [209.8.25.114,209.8.25.204,209.8.25.254,209.8.25.66,209.8.45.0/24,209.8.47.0/24,209.81.12.132,209.81.12.133,209.84.29.126,209.85.25.210,209.85.5.16,209.85.51.0/24,209.85.73.222,209.85.84.0/24,209.85.87.42,209.85.97.155,209.85.99.29,209.85.99.30,209.85.99.31,209.85.99.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (86)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407171; rev:167; fwsam: src, 24 hours;) alert tcp [209.85.99.33,209.85.99.34,209.9.170.194,209.9.170.202,209.9.239.108,209.97.196.13,210.1.248.252,210.1.58.38,210.114.175.174,210.128.131.25,210.145.102.19,210.15.254.232,210.188.199.213,210.197.183.47,210.205.6.168,210.205.6.78,210.207.154.2,210.212.30.131,210.228.48.58,210.245.160.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (87)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407172; rev:167; fwsam: src, 24 hours;) alert udp [209.85.99.33,209.85.99.34,209.9.170.194,209.9.170.202,209.9.239.108,209.97.196.13,210.1.248.252,210.1.58.38,210.114.175.174,210.128.131.25,210.145.102.19,210.15.254.232,210.188.199.213,210.197.183.47,210.205.6.168,210.205.6.78,210.207.154.2,210.212.30.131,210.228.48.58,210.245.160.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (87)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407173; rev:167; fwsam: src, 24 hours;) alert tcp [210.245.160.9,210.253.127.9,210.4.118.70,210.48.149.206,210.48.153.232,210.48.154.132,210.48.154.136,210.48.154.208,210.48.157.107,210.51.10.184,210.51.10.189,210.51.166.0/24,210.51.180.239,210.51.181.129,210.51.181.69,210.51.187.44,210.51.187.59,210.51.25.120,210.51.25.206,210.51.36.215] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (88)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407174; rev:167; fwsam: src, 24 hours;) alert udp [210.245.160.9,210.253.127.9,210.4.118.70,210.48.149.206,210.48.153.232,210.48.154.132,210.48.154.136,210.48.154.208,210.48.157.107,210.51.10.184,210.51.10.189,210.51.166.0/24,210.51.180.239,210.51.181.129,210.51.181.69,210.51.187.44,210.51.187.59,210.51.25.120,210.51.25.206,210.51.36.215] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (88)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407175; rev:167; fwsam: src, 24 hours;) alert tcp [210.51.37.113,210.51.51.144,210.51.51.176,210.51.58.103,210.51.58.90,210.72.66.210,210.75.9.70,210.83.80.222,210.83.85.100,210.83.85.101,210.87.160.84,210.93.57.21,211.138.124.238,211.138.124.242,211.139.106.172,211.147.227.243,211.152.33.4,211.154.128.144,211.155.27.250,211.167.67.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (89)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407176; rev:167; fwsam: src, 24 hours;) alert udp [210.51.37.113,210.51.51.144,210.51.51.176,210.51.58.103,210.51.58.90,210.72.66.210,210.75.9.70,210.83.80.222,210.83.85.100,210.83.85.101,210.87.160.84,210.93.57.21,211.138.124.238,211.138.124.242,211.139.106.172,211.147.227.243,211.152.33.4,211.154.128.144,211.155.27.250,211.167.67.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (89)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407177; rev:167; fwsam: src, 24 hours;) alert tcp [211.172.232.237,211.174.178.11,211.174.60.66,211.189.39.242,211.20.210.78,211.20.210.86,211.20.211.98,211.202.2.14,211.202.2.17,211.21.235.21,211.218.126.211,211.218.126.236,211.218.191.247,211.230.122.93,211.233.11.26,211.234.100.137,211.236.244.151,211.238.13.158,211.244.22.196,211.255.23.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (90)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407178; rev:167; fwsam: src, 24 hours;) alert udp [211.172.232.237,211.174.178.11,211.174.60.66,211.189.39.242,211.20.210.78,211.20.210.86,211.20.211.98,211.202.2.14,211.202.2.17,211.21.235.21,211.218.126.211,211.218.126.236,211.218.191.247,211.230.122.93,211.233.11.26,211.234.100.137,211.236.244.151,211.238.13.158,211.244.22.196,211.255.23.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (90)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407179; rev:167; fwsam: src, 24 hours;) alert tcp [211.36.253.32,211.45.0.5,211.46.97.10,211.47.128.229,211.49.99.92,211.52.78.2,211.91.237.3,211.95.72.86,211.95.72.87,211.95.72.88,211.95.72.93,211.95.73.189,211.95.78.0/24,211.95.79.114,211.95.79.115,211.95.79.229,211.95.79.241,211.95.79.242,211.95.79.57,211.95.79.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (91)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407180; rev:167; fwsam: src, 24 hours;) alert udp [211.36.253.32,211.45.0.5,211.46.97.10,211.47.128.229,211.49.99.92,211.52.78.2,211.91.237.3,211.95.72.86,211.95.72.87,211.95.72.88,211.95.72.93,211.95.73.189,211.95.78.0/24,211.95.79.114,211.95.79.115,211.95.79.229,211.95.79.241,211.95.79.242,211.95.79.57,211.95.79.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (91)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407181; rev:167; fwsam: src, 24 hours;) alert tcp [211.95.79.6,212.100.224.219,212.103.194.188,212.115.33.35,212.116.123.4,212.117.160.18,212.117.160.21,212.117.160.22,212.117.162.192,212.117.162.194,212.117.162.51,212.117.162.90,212.117.163.162,212.117.163.164,212.117.163.165,212.117.163.17,212.117.164.120,212.117.164.121,212.117.165.0/24,212.117.166.69] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (92)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407182; rev:167; fwsam: src, 24 hours;) alert udp [211.95.79.6,212.100.224.219,212.103.194.188,212.115.33.35,212.116.123.4,212.117.160.18,212.117.160.21,212.117.160.22,212.117.162.192,212.117.162.194,212.117.162.51,212.117.162.90,212.117.163.162,212.117.163.164,212.117.163.165,212.117.163.17,212.117.164.120,212.117.164.121,212.117.165.0/24,212.117.166.69] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (92)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407183; rev:167; fwsam: src, 24 hours;) alert tcp [212.117.166.70,212.117.166.71,212.117.166.73,212.117.166.74,212.117.166.75,212.117.166.77,212.117.169.163,212.117.170.60,212.117.173.194,212.117.174.14,212.117.174.163,212.117.174.19,212.117.175.218,212.117.175.50,212.117.177.108,212.117.177.18,212.117.177.20,212.117.177.21,212.117.177.23,212.117.177.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (93)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407184; rev:167; fwsam: src, 24 hours;) alert udp [212.117.166.70,212.117.166.71,212.117.166.73,212.117.166.74,212.117.166.75,212.117.166.77,212.117.169.163,212.117.170.60,212.117.173.194,212.117.174.14,212.117.174.163,212.117.174.19,212.117.175.218,212.117.175.50,212.117.177.108,212.117.177.18,212.117.177.20,212.117.177.21,212.117.177.23,212.117.177.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (93)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407185; rev:167; fwsam: src, 24 hours;) alert tcp [212.117.185.0/24,212.118.48.210,212.12.112.25,212.123.6.224,212.150.123.110,212.150.130.183,212.150.164.190,212.150.164.203,212.150.164.74,212.150.164.75,212.150.164.80,212.150.164.81,212.150.164.82,212.150.164.84,212.150.164.85,212.152.181.202,212.154.58.92,212.158.162.5,212.158.167.16,212.174.200.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (94)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407186; rev:167; fwsam: src, 24 hours;) alert udp [212.117.185.0/24,212.118.48.210,212.12.112.25,212.123.6.224,212.150.123.110,212.150.130.183,212.150.164.190,212.150.164.203,212.150.164.74,212.150.164.75,212.150.164.80,212.150.164.81,212.150.164.82,212.150.164.84,212.150.164.85,212.152.181.202,212.154.58.92,212.158.162.5,212.158.167.16,212.174.200.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (94)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407187; rev:167; fwsam: src, 24 hours;) alert tcp [212.174.81.120,212.174.81.122,212.174.81.123,212.174.81.124,212.174.81.19,212.175.158.109,212.175.87.195,212.175.87.196,212.179.35.117,212.186.220.228,212.193.37.141,212.200.56.19,212.227.107.220,212.227.111.21,212.227.32.119,212.227.34.3,212.24.53.0/24,212.24.54.3,212.25.179.97,212.27.63.165] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (95)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407188; rev:167; fwsam: src, 24 hours;) alert udp [212.174.81.120,212.174.81.122,212.174.81.123,212.174.81.124,212.174.81.19,212.175.158.109,212.175.87.195,212.175.87.196,212.179.35.117,212.186.220.228,212.193.37.141,212.200.56.19,212.227.107.220,212.227.111.21,212.227.32.119,212.227.34.3,212.24.53.0/24,212.24.54.3,212.25.179.97,212.27.63.165] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (95)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407189; rev:167; fwsam: src, 24 hours;) alert tcp [212.34.158.97,212.36.9.1,212.36.9.10,212.47.211.166,212.53.64.19,212.58.116.69,212.58.3.24,212.62.98.114,212.63.206.51,212.67.202.83,212.68.141.2,212.77.128.0/20,212.78.89.90,212.84.166.131,212.91.185.27,212.95.32.166,212.95.32.171,212.95.32.26,212.95.33.25,212.95.37.133] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (96)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407190; rev:167; fwsam: src, 24 hours;) alert udp [212.34.158.97,212.36.9.1,212.36.9.10,212.47.211.166,212.53.64.19,212.58.116.69,212.58.3.24,212.62.98.114,212.63.206.51,212.67.202.83,212.68.141.2,212.77.128.0/20,212.78.89.90,212.84.166.131,212.91.185.27,212.95.32.166,212.95.32.171,212.95.32.26,212.95.33.25,212.95.37.133] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (96)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407191; rev:167; fwsam: src, 24 hours;) alert tcp [212.95.37.184,212.95.37.186,212.95.37.211,212.95.38.98,212.95.40.205,212.95.40.44,212.95.41.143,212.95.46.83,212.95.48.51,212.95.49.252,212.95.51.75,212.95.51.76,212.95.53.103,212.95.53.142,212.95.53.143,212.95.54.105,212.95.54.106,212.95.54.113,212.95.54.90,212.95.54.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (97)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407192; rev:167; fwsam: src, 24 hours;) alert udp [212.95.37.184,212.95.37.186,212.95.37.211,212.95.38.98,212.95.40.205,212.95.40.44,212.95.41.143,212.95.46.83,212.95.48.51,212.95.49.252,212.95.51.75,212.95.51.76,212.95.53.103,212.95.53.142,212.95.53.143,212.95.54.105,212.95.54.106,212.95.54.113,212.95.54.90,212.95.54.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (97)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407193; rev:167; fwsam: src, 24 hours;) alert tcp [212.95.55.135,212.95.55.61,212.95.60.233,212.97.132.113,212.97.132.117,212.97.132.132,212.97.132.137,212.97.132.140,212.98.162.59,213.0.109.218,213.108.56.125,213.108.56.140,213.108.56.22,213.108.56.3,213.108.56.99,213.131.252.251,213.133.100.58,213.133.101.7,213.133.110.18,213.133.110.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (98)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407194; rev:167; fwsam: src, 24 hours;) alert udp [212.95.55.135,212.95.55.61,212.95.60.233,212.97.132.113,212.97.132.117,212.97.132.132,212.97.132.137,212.97.132.140,212.98.162.59,213.0.109.218,213.108.56.125,213.108.56.140,213.108.56.22,213.108.56.3,213.108.56.99,213.131.252.251,213.133.100.58,213.133.101.7,213.133.110.18,213.133.110.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (98)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407195; rev:167; fwsam: src, 24 hours;) alert tcp [213.136.106.214,213.136.96.11,213.145.228.120,213.155.0.200,213.155.1.39,213.155.1.46,213.155.10.178,213.155.10.179,213.155.10.181,213.155.10.56,213.155.10.58,213.155.10.63,213.155.11.79,213.155.13.108,213.155.2.104,213.155.2.105,213.155.2.112,213.155.2.37,213.155.22.16,213.155.22.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (99)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407196; rev:167; fwsam: src, 24 hours;) alert udp [213.136.106.214,213.136.96.11,213.145.228.120,213.155.0.200,213.155.1.39,213.155.1.46,213.155.10.178,213.155.10.179,213.155.10.181,213.155.10.56,213.155.10.58,213.155.10.63,213.155.11.79,213.155.13.108,213.155.2.104,213.155.2.105,213.155.2.112,213.155.2.37,213.155.22.16,213.155.22.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (99)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407197; rev:167; fwsam: src, 24 hours;) alert tcp [213.155.22.194,213.155.24.17,213.155.24.22,213.155.24.229,213.155.24.236,213.155.25.184,213.155.29.101,213.155.29.102,213.155.29.56,213.155.29.8,213.155.29.98,213.155.3.117,213.155.3.152,213.155.3.154,213.155.3.240,213.155.3.242,213.155.4.32,213.155.4.72,213.155.4.80,213.155.5.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (100)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407198; rev:167; fwsam: src, 24 hours;) alert udp [213.155.22.194,213.155.24.17,213.155.24.22,213.155.24.229,213.155.24.236,213.155.25.184,213.155.29.101,213.155.29.102,213.155.29.56,213.155.29.8,213.155.29.98,213.155.3.117,213.155.3.152,213.155.3.154,213.155.3.240,213.155.3.242,213.155.4.32,213.155.4.72,213.155.4.80,213.155.5.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (100)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407199; rev:167; fwsam: src, 24 hours;) alert tcp [213.155.5.7,213.155.6.32,213.155.7.0,213.155.7.144,213.155.7.248,213.163.64.37,213.163.64.39,213.163.64.79,213.163.64.81,213.163.64.82,213.163.65.10,213.163.65.2,213.163.65.72,213.163.65.9,213.163.66.241,213.163.67.235,213.163.67.236,213.163.71.207,213.163.84.28,213.163.89.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (101)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407200; rev:167; fwsam: src, 24 hours;) alert udp [213.155.5.7,213.155.6.32,213.155.7.0,213.155.7.144,213.155.7.248,213.163.64.37,213.163.64.39,213.163.64.79,213.163.64.81,213.163.64.82,213.163.65.10,213.163.65.2,213.163.65.72,213.163.65.9,213.163.66.241,213.163.67.235,213.163.67.236,213.163.71.207,213.163.84.28,213.163.89.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (101)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407201; rev:167; fwsam: src, 24 hours;) alert tcp [213.163.90.74,213.163.91.0/24,213.165.80.179,213.171.218.134,213.171.219.234,213.171.222.30,213.172.16.20,213.174.134.1,213.174.134.38,213.174.136.0/22,213.174.141.108,213.174.141.39,213.174.141.47,213.174.142.0/24,213.174.143.196,213.174.152.107,213.174.152.166,213.174.152.2,213.174.153.0/24,213.175.196.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (102)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407202; rev:167; fwsam: src, 24 hours;) alert udp [213.163.90.74,213.163.91.0/24,213.165.80.179,213.171.218.134,213.171.219.234,213.171.222.30,213.172.16.20,213.174.134.1,213.174.134.38,213.174.136.0/22,213.174.141.108,213.174.141.39,213.174.141.47,213.174.142.0/24,213.174.143.196,213.174.152.107,213.174.152.166,213.174.152.2,213.174.153.0/24,213.175.196.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (102)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407203; rev:167; fwsam: src, 24 hours;) alert tcp [213.175.221.46,213.180.199.12,213.180.199.19,213.180.199.24,213.180.199.3,213.180.199.41,213.180.199.44,213.180.199.48,213.180.199.49,213.180.204.8,213.180.79.146,213.180.84.143,213.180.9.66,213.182.197.0/24,213.184.167.220,213.186.116.147,213.186.116.213,213.186.117.200,213.186.126.4,213.186.126.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (103)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407204; rev:167; fwsam: src, 24 hours;) alert udp [213.175.221.46,213.180.199.12,213.180.199.19,213.180.199.24,213.180.199.3,213.180.199.41,213.180.199.44,213.180.199.48,213.180.199.49,213.180.204.8,213.180.79.146,213.180.84.143,213.180.9.66,213.182.197.0/24,213.184.167.220,213.186.116.147,213.186.116.213,213.186.117.200,213.186.126.4,213.186.126.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (103)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407205; rev:167; fwsam: src, 24 hours;) alert tcp [213.186.33.16,213.186.33.2,213.186.33.40,213.186.33.80,213.186.33.87,213.186.40.104,213.189.197.23,213.189.197.241,213.189.197.245,213.189.197.30,213.189.197.5,213.189.213.54,213.189.9.176,213.189.9.228,213.189.9.75,213.192.233.49,213.193.213.123,213.193.4.11,213.201.21.158,213.202.225.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (104)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407206; rev:167; fwsam: src, 24 hours;) alert udp [213.186.33.16,213.186.33.2,213.186.33.40,213.186.33.80,213.186.33.87,213.186.40.104,213.189.197.23,213.189.197.241,213.189.197.245,213.189.197.30,213.189.197.5,213.189.213.54,213.189.9.176,213.189.9.228,213.189.9.75,213.192.233.49,213.193.213.123,213.193.4.11,213.201.21.158,213.202.225.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (104)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407207; rev:167; fwsam: src, 24 hours;) alert tcp [213.202.225.44,213.203.204.50,213.206.254.75,213.206.254.76,213.21.215.187,213.217.48.36,213.220.241.47,213.229.83.152,213.232.249.139,213.235.249.198,213.239.193.162,213.239.201.105,213.239.210.54,213.239.211.251,213.239.234.102,213.242.207.249,213.246.39.102,213.246.56.31,213.251.166.101,213.251.167.153] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (105)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407208; rev:167; fwsam: src, 24 hours;) alert udp [213.202.225.44,213.203.204.50,213.206.254.75,213.206.254.76,213.21.215.187,213.217.48.36,213.220.241.47,213.229.83.152,213.232.249.139,213.235.249.198,213.239.193.162,213.239.201.105,213.239.210.54,213.239.211.251,213.239.234.102,213.242.207.249,213.246.39.102,213.246.56.31,213.251.166.101,213.251.167.153] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (105)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407209; rev:167; fwsam: src, 24 hours;) alert tcp [213.251.170.24,213.251.176.169,213.251.184.114,213.27.4.46,213.5.64.20,213.5.64.30,213.60.233.156,213.81.152.54,213.81.152.60,213.92.95.91,216.104.40.74,216.104.46.58,216.108.235.211,216.108.239.128,216.108.239.62,216.118.117.15,216.118.117.156,216.118.117.160,216.118.117.192,216.118.117.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (106)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407210; rev:167; fwsam: src, 24 hours;) alert udp [213.251.170.24,213.251.176.169,213.251.184.114,213.27.4.46,213.5.64.20,213.5.64.30,213.60.233.156,213.81.152.54,213.81.152.60,213.92.95.91,216.104.40.74,216.104.46.58,216.108.235.211,216.108.239.128,216.108.239.62,216.118.117.15,216.118.117.156,216.118.117.160,216.118.117.192,216.118.117.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (106)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407211; rev:167; fwsam: src, 24 hours;) alert tcp [216.118.117.64,216.12.161.18,216.12.168.138,216.121.82.196,216.122.59.222,216.127.58.55,216.130.168.66,216.130.172.181,216.130.188.207,216.131.127.71,216.139.238.47,216.139.67.20,216.14.113.10,216.14.117.90,216.14.124.11,216.14.80.49,216.146.46.20,216.146.46.8,216.15.150.177,216.15.254.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (107)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407212; rev:167; fwsam: src, 24 hours;) alert udp [216.118.117.64,216.12.161.18,216.12.168.138,216.121.82.196,216.122.59.222,216.127.58.55,216.130.168.66,216.130.172.181,216.130.188.207,216.131.127.71,216.139.238.47,216.139.67.20,216.14.113.10,216.14.117.90,216.14.124.11,216.14.80.49,216.146.46.20,216.146.46.8,216.15.150.177,216.15.254.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (107)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407213; rev:167; fwsam: src, 24 hours;) alert tcp [216.150.65.17,216.150.79.186,216.150.79.74,216.150.79.76,216.150.79.77,216.152.240.12,216.154.218.251,216.154.221.230,216.155.150.165,216.155.150.166,216.155.150.167,216.155.151.142,216.155.153.212,216.157.128.192,216.157.129.2,216.157.132.128,216.157.132.192,216.157.134.64,216.157.136.106,216.157.136.192] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (108)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407214; rev:167; fwsam: src, 24 hours;) alert udp [216.150.65.17,216.150.79.186,216.150.79.74,216.150.79.76,216.150.79.77,216.152.240.12,216.154.218.251,216.154.221.230,216.155.150.165,216.155.150.166,216.155.150.167,216.155.151.142,216.155.153.212,216.157.128.192,216.157.129.2,216.157.132.128,216.157.132.192,216.157.134.64,216.157.136.106,216.157.136.192] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (108)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407215; rev:167; fwsam: src, 24 hours;) alert tcp [216.157.136.2,216.157.136.64,216.157.137.2,216.157.138.2,216.157.138.64,216.157.139.2,216.157.140.103,216.157.140.192,216.157.140.193,216.157.141.2,216.157.146.128,216.157.147.229,216.157.147.69,216.157.148.128,216.157.148.2,216.157.150.128,216.157.150.2,216.157.152.2,216.157.154.192,216.157.154.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (109)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407216; rev:167; fwsam: src, 24 hours;) alert udp [216.157.136.2,216.157.136.64,216.157.137.2,216.157.138.2,216.157.138.64,216.157.139.2,216.157.140.103,216.157.140.192,216.157.140.193,216.157.141.2,216.157.146.128,216.157.147.229,216.157.147.69,216.157.148.128,216.157.148.2,216.157.150.128,216.157.150.2,216.157.152.2,216.157.154.192,216.157.154.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (109)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407217; rev:167; fwsam: src, 24 hours;) alert tcp [216.169.106.222,216.169.99.213,216.177.135.23,216.177.135.4,216.177.137.4,216.177.139.4,216.177.143.4,216.177.193.194,216.177.71.8,216.18.213.202,216.18.239.126,216.180.227.76,216.180.234.3,216.180.241.18,216.187.117.157,216.187.118.219,216.188.26.0/24,216.19.200.237,216.194.67.56,216.195.32.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (110)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407218; rev:167; fwsam: src, 24 hours;) alert udp [216.169.106.222,216.169.99.213,216.177.135.23,216.177.135.4,216.177.137.4,216.177.139.4,216.177.143.4,216.177.193.194,216.177.71.8,216.18.213.202,216.18.239.126,216.180.227.76,216.180.234.3,216.180.241.18,216.187.117.157,216.187.118.219,216.188.26.0/24,216.19.200.237,216.194.67.56,216.195.32.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (110)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407219; rev:167; fwsam: src, 24 hours;) alert tcp [216.195.32.93,216.195.32.94,216.195.33.107,216.195.33.139,216.195.33.141,216.195.33.144,216.195.33.147,216.195.34.0/24,216.195.35.99,216.195.36.123,216.195.36.182,216.195.37.251,216.195.40.0/21,216.195.48.10,216.195.48.113,216.195.48.45,216.195.48.52,216.195.49.0/24,216.195.50.0/24,216.195.52.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (111)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407220; rev:167; fwsam: src, 24 hours;) alert udp [216.195.32.93,216.195.32.94,216.195.33.107,216.195.33.139,216.195.33.141,216.195.33.144,216.195.33.147,216.195.34.0/24,216.195.35.99,216.195.36.123,216.195.36.182,216.195.37.251,216.195.40.0/21,216.195.48.10,216.195.48.113,216.195.48.45,216.195.48.52,216.195.49.0/24,216.195.50.0/24,216.195.52.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (111)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407221; rev:167; fwsam: src, 24 hours;) alert tcp [216.195.52.52,216.195.54.233,216.195.55.0/24,216.195.56.0/24,216.195.57.0/24,216.195.58.0/24,216.195.59.0/24,216.195.60.227,216.195.61.0/24,216.195.62.0/24,216.195.63.0/24,216.199.3.110,216.200.3.163,216.218.162.0/24,216.219.88.42,216.226.131.77,216.227.214.53,216.227.214.83,216.230.250.84,216.24.153.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (112)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407222; rev:167; fwsam: src, 24 hours;) alert udp [216.195.52.52,216.195.54.233,216.195.55.0/24,216.195.56.0/24,216.195.57.0/24,216.195.58.0/24,216.195.59.0/24,216.195.60.227,216.195.61.0/24,216.195.62.0/24,216.195.63.0/24,216.199.3.110,216.200.3.163,216.218.162.0/24,216.219.88.42,216.226.131.77,216.227.214.53,216.227.214.83,216.230.250.84,216.24.153.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (112)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407223; rev:167; fwsam: src, 24 hours;) alert tcp [216.240.131.132,216.240.134.208,216.240.134.211,216.240.134.238,216.240.138.220,216.240.138.221,216.240.139.239,216.240.140.201,216.240.140.202,216.240.143.10,216.240.143.12,216.240.143.16,216.240.143.17,216.240.143.6,216.240.143.7,216.240.143.8,216.240.143.9,216.240.146.119,216.240.146.126,216.240.148.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (113)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407224; rev:167; fwsam: src, 24 hours;) alert udp [216.240.131.132,216.240.134.208,216.240.134.211,216.240.134.238,216.240.138.220,216.240.138.221,216.240.139.239,216.240.140.201,216.240.140.202,216.240.143.10,216.240.143.12,216.240.143.16,216.240.143.17,216.240.143.6,216.240.143.7,216.240.143.8,216.240.143.9,216.240.146.119,216.240.146.126,216.240.148.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (113)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407225; rev:167; fwsam: src, 24 hours;) alert tcp [216.240.148.6,216.240.148.9,216.240.153.223,216.240.157.130,216.240.157.180,216.240.157.88,216.240.157.91,216.240.158.190,216.240.187.102,216.240.187.103,216.240.246.162,216.240.57.210,216.243.10.103,216.245.205.123,216.245.205.60,216.245.208.165,216.245.220.121,216.246.13.87,216.246.20.22,216.246.91.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (114)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407226; rev:167; fwsam: src, 24 hours;) alert udp [216.240.148.6,216.240.148.9,216.240.153.223,216.240.157.130,216.240.157.180,216.240.157.88,216.240.157.91,216.240.158.190,216.240.187.102,216.240.187.103,216.240.246.162,216.240.57.210,216.243.10.103,216.245.205.123,216.245.205.60,216.245.208.165,216.245.220.121,216.246.13.87,216.246.20.22,216.246.91.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (114)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407227; rev:167; fwsam: src, 24 hours;) alert tcp [216.255.176.0/20,216.30.255.200,216.32.75.2,216.32.76.180,216.32.76.6,216.32.76.87,216.32.78.18,216.32.78.50,216.32.83.104,216.32.83.110,216.32.83.111,216.32.86.106,216.32.88.10,216.32.88.11,216.32.95.94,216.34.131.131,216.34.131.135,216.34.94.184,216.40.204.99,216.40.230.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (115)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407228; rev:167; fwsam: src, 24 hours;) alert udp [216.255.176.0/20,216.30.255.200,216.32.75.2,216.32.76.180,216.32.76.6,216.32.76.87,216.32.78.18,216.32.78.50,216.32.83.104,216.32.83.110,216.32.83.111,216.32.86.106,216.32.88.10,216.32.88.11,216.32.95.94,216.34.131.131,216.34.131.135,216.34.94.184,216.40.204.99,216.40.230.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (115)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407229; rev:167; fwsam: src, 24 hours;) alert tcp [216.40.33.252,216.40.33.30,216.40.33.31,216.40.33.35,216.40.7.70,216.45.58.150,216.45.59.32,216.45.59.33,216.45.59.34,216.45.59.35,216.45.59.36,216.45.59.37,216.45.59.38,216.45.59.39,216.55.106.37,216.55.129.189,216.55.142.4,216.55.174.135,216.55.190.112,216.64.158.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (116)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407230; rev:167; fwsam: src, 24 hours;) alert udp [216.40.33.252,216.40.33.30,216.40.33.31,216.40.33.35,216.40.7.70,216.45.58.150,216.45.59.32,216.45.59.33,216.45.59.34,216.45.59.35,216.45.59.36,216.45.59.37,216.45.59.38,216.45.59.39,216.55.106.37,216.55.129.189,216.55.142.4,216.55.174.135,216.55.190.112,216.64.158.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (116)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407231; rev:167; fwsam: src, 24 hours;) alert tcp [216.7.179.100,216.7.89.0/24,216.75.62.101,216.8.179.24,216.81.64.15,216.81.64.192,216.81.64.64,216.81.70.2,216.81.70.64,216.81.71.64,216.81.72.64,216.81.73.2,216.81.74.128,216.81.74.2,216.81.74.64,216.81.77.2,216.81.77.64,216.82.97.111,216.83.44.0/22,216.83.60.0/22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (117)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407232; rev:167; fwsam: src, 24 hours;) alert udp [216.7.179.100,216.7.89.0/24,216.75.62.101,216.8.179.24,216.81.64.15,216.81.64.192,216.81.64.64,216.81.70.2,216.81.70.64,216.81.71.64,216.81.72.64,216.81.73.2,216.81.74.128,216.81.74.2,216.81.74.64,216.81.77.2,216.81.77.64,216.82.97.111,216.83.44.0/22,216.83.60.0/22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (117)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407233; rev:167; fwsam: src, 24 hours;) alert tcp [216.86.144.130,216.86.144.131,216.86.144.134,216.86.144.135,216.86.153.116,216.86.155.41,216.97.230.35,216.97.230.60,216.97.237.20,216.98.141.250,217.106.233.10,217.106.233.9,217.106.234.193,217.106.237.23,217.107.217.167,217.107.217.27,217.107.217.29,217.107.218.70,217.107.219.0/24,217.107.34.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (118)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407234; rev:167; fwsam: src, 24 hours;) alert udp [216.86.144.130,216.86.144.131,216.86.144.134,216.86.144.135,216.86.153.116,216.86.155.41,216.97.230.35,216.97.230.60,216.97.237.20,216.98.141.250,217.106.233.10,217.106.233.9,217.106.234.193,217.106.237.23,217.107.217.167,217.107.217.27,217.107.217.29,217.107.218.70,217.107.219.0/24,217.107.34.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (118)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407235; rev:167; fwsam: src, 24 hours;) alert tcp [217.107.34.119,217.107.34.217,217.107.34.4,217.107.34.6,217.107.34.7,217.109.176.37,217.112.35.59,217.112.37.30,217.112.37.31,217.112.83.151,217.112.94.230,217.112.94.231,217.114.0.67,217.114.108.43,217.117.28.211,217.124.41.76,217.129.215.160,217.13.199.34,217.132.13.196,217.132.43.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (119)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407236; rev:167; fwsam: src, 24 hours;) alert udp [217.107.34.119,217.107.34.217,217.107.34.4,217.107.34.6,217.107.34.7,217.109.176.37,217.112.35.59,217.112.37.30,217.112.37.31,217.112.83.151,217.112.94.230,217.112.94.231,217.114.0.67,217.114.108.43,217.117.28.211,217.124.41.76,217.129.215.160,217.13.199.34,217.132.13.196,217.132.43.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (119)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407237; rev:167; fwsam: src, 24 hours;) alert tcp [217.145.83.229,217.146.87.0/24,217.147.30.100,217.15.81.18,217.15.81.8,217.159.201.18,217.16.16.0/20,217.170.64.0/20,217.171.66.245,217.174.241.205,217.174.254.75,217.188.214.198,217.188.246.105,217.197.114.18,217.197.114.20,217.197.114.22,217.199.217.14,217.199.217.196,217.199.217.3,217.199.217.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (120)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407238; rev:167; fwsam: src, 24 hours;) alert udp [217.145.83.229,217.146.87.0/24,217.147.30.100,217.15.81.18,217.15.81.8,217.159.201.18,217.16.16.0/20,217.170.64.0/20,217.171.66.245,217.174.241.205,217.174.254.75,217.188.214.198,217.188.246.105,217.197.114.18,217.197.114.20,217.197.114.22,217.199.217.14,217.199.217.196,217.199.217.3,217.199.217.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (120)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407239; rev:167; fwsam: src, 24 hours;) alert tcp [217.199.218.50,217.199.218.7,217.199.218.9,217.20.112.96,217.20.112.98,217.20.113.236,217.20.115.72,217.20.115.89,217.20.121.38,217.20.126.120,217.20.175.74,217.20.210.6,217.20.211.0/24,217.218.225.2,217.23.1.11,217.23.1.12,217.23.1.13,217.23.10.19,217.23.10.68,217.23.12.147] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (121)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407240; rev:167; fwsam: src, 24 hours;) alert udp [217.199.218.50,217.199.218.7,217.199.218.9,217.20.112.96,217.20.112.98,217.20.113.236,217.20.115.72,217.20.115.89,217.20.121.38,217.20.126.120,217.20.175.74,217.20.210.6,217.20.211.0/24,217.218.225.2,217.23.1.11,217.23.1.12,217.23.1.13,217.23.10.19,217.23.10.68,217.23.12.147] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (121)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407241; rev:167; fwsam: src, 24 hours;) alert tcp [217.23.12.168,217.23.12.219,217.23.12.79,217.23.12.82,217.23.12.88,217.23.13.45,217.23.3.109,217.23.3.110,217.23.3.127,217.23.3.139,217.23.4.76,217.23.5.219,217.23.5.27,217.23.6.157,217.23.6.17,217.23.6.200,217.23.7.120,217.23.7.161,217.23.7.162,217.23.7.163] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (122)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407242; rev:167; fwsam: src, 24 hours;) alert udp [217.23.12.168,217.23.12.219,217.23.12.79,217.23.12.82,217.23.12.88,217.23.13.45,217.23.3.109,217.23.3.110,217.23.3.127,217.23.3.139,217.23.4.76,217.23.5.219,217.23.5.27,217.23.6.157,217.23.6.17,217.23.6.200,217.23.7.120,217.23.7.161,217.23.7.162,217.23.7.163] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (122)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407243; rev:167; fwsam: src, 24 hours;) alert tcp [217.23.7.183,217.23.7.6,217.23.8.149,217.23.8.214,217.23.8.40,217.23.8.74,217.23.9.133,217.23.9.2,217.23.9.43,217.25.236.12,217.26.144.122,217.26.168.135,217.26.70.81,217.28.146.253,217.64.195.220,217.65.6.113,217.67.22.67,217.67.22.83,217.67.30.22,217.68.153.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (123)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407244; rev:167; fwsam: src, 24 hours;) alert udp [217.23.7.183,217.23.7.6,217.23.8.149,217.23.8.214,217.23.8.40,217.23.8.74,217.23.9.133,217.23.9.2,217.23.9.43,217.25.236.12,217.26.144.122,217.26.168.135,217.26.70.81,217.28.146.253,217.64.195.220,217.65.6.113,217.67.22.67,217.67.22.83,217.67.30.22,217.68.153.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (123)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407245; rev:167; fwsam: src, 24 hours;) alert tcp [217.75.203.10,217.75.98.213,217.77.152.28,217.77.223.20,217.79.190.28,217.8.240.22,218.10.16.199,218.10.16.239,218.10.16.49,218.10.18.76,218.106.254.159,218.106.90.227,218.107.207.150,218.107.207.40,218.108.84.72,218.16.120.253,218.16.224.73,218.16.225.50,218.206.241.178,218.213.77.96] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (124)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407246; rev:167; fwsam: src, 24 hours;) alert udp [217.75.203.10,217.75.98.213,217.77.152.28,217.77.223.20,217.79.190.28,217.8.240.22,218.10.16.199,218.10.16.239,218.10.16.49,218.10.18.76,218.106.254.159,218.106.90.227,218.107.207.150,218.107.207.40,218.108.84.72,218.16.120.253,218.16.224.73,218.16.225.50,218.206.241.178,218.213.77.96] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (124)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407247; rev:167; fwsam: src, 24 hours;) alert tcp [218.23.233.178,218.232.109.134,218.239.45.132,218.24.43.14,218.240.39.141,218.244.147.129,218.246.20.221,218.25.203.5,218.27.203.98,218.28.226.72,218.3.114.57,218.32.192.12,218.5.112.43,218.5.74.92,218.5.76.219,218.5.77.19,218.5.77.28,218.5.79.63,218.5.81.148,218.56.37.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (125)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407248; rev:167; fwsam: src, 24 hours;) alert udp [218.23.233.178,218.232.109.134,218.239.45.132,218.24.43.14,218.240.39.141,218.244.147.129,218.246.20.221,218.25.203.5,218.27.203.98,218.28.226.72,218.3.114.57,218.32.192.12,218.5.112.43,218.5.74.92,218.5.76.219,218.5.77.19,218.5.77.28,218.5.79.63,218.5.81.148,218.56.37.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (125)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407249; rev:167; fwsam: src, 24 hours;) alert tcp [218.6.12.73,218.6.12.82,218.6.15.135,218.6.15.99,218.6.19.3,218.6.2.195,218.6.2.77,218.6.8.247,218.61.126.20,218.61.126.28,218.61.126.9,218.61.204.206,218.61.204.214,218.61.204.215,218.63.200.196,218.75.110.152,218.75.144.4,218.75.149.155,218.75.149.210,218.75.159.148] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (126)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407250; rev:167; fwsam: src, 24 hours;) alert udp [218.6.12.73,218.6.12.82,218.6.15.135,218.6.15.99,218.6.19.3,218.6.2.195,218.6.2.77,218.6.8.247,218.61.126.20,218.61.126.28,218.61.126.9,218.61.204.206,218.61.204.214,218.61.204.215,218.63.200.196,218.75.110.152,218.75.144.4,218.75.149.155,218.75.149.210,218.75.159.148] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (126)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407251; rev:167; fwsam: src, 24 hours;) alert tcp [218.83.161.104,218.85.132.203,218.85.134.171,218.85.136.50,218.85.136.7,218.85.139.33,218.93.202.100,218.93.202.102,218.93.202.114,218.93.202.50,218.93.205.0/24,218.93.248.226,218.93.248.232,218.93.248.238,218.95.37.113,219.129.21.108,219.133.34.70,219.139.76.173,219.139.81.6,219.140.165.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (127)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407252; rev:167; fwsam: src, 24 hours;) alert udp [218.83.161.104,218.85.132.203,218.85.134.171,218.85.136.50,218.85.136.7,218.85.139.33,218.93.202.100,218.93.202.102,218.93.202.114,218.93.202.50,218.93.205.0/24,218.93.248.226,218.93.248.232,218.93.248.238,218.95.37.113,219.129.21.108,219.133.34.70,219.139.76.173,219.139.81.6,219.140.165.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (127)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407253; rev:167; fwsam: src, 24 hours;) alert tcp [219.148.34.10,219.148.34.7,219.148.34.9,219.152.120.116,219.152.120.118,219.152.120.119,219.153.22.196,219.153.41.195,219.153.48.163,219.232.253.135,219.232.253.138,219.232.253.144,219.232.253.164,219.232.253.250,219.240.39.230,219.241.220.152,219.72.238.100,220.164.144.249,220.180.182.143,220.189.253.170] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (128)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407254; rev:167; fwsam: src, 24 hours;) alert udp [219.148.34.10,219.148.34.7,219.148.34.9,219.152.120.116,219.152.120.118,219.152.120.119,219.153.22.196,219.153.41.195,219.153.48.163,219.232.253.135,219.232.253.138,219.232.253.144,219.232.253.164,219.232.253.250,219.240.39.230,219.241.220.152,219.72.238.100,220.164.144.249,220.180.182.143,220.189.253.170] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (128)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407255; rev:167; fwsam: src, 24 hours;) alert tcp [220.194.44.67,220.194.54.153,220.196.42.218,220.196.42.220,220.196.59.0/24,220.227.165.14,220.232.237.32,220.248.167.110,220.248.184.7,220.248.186.106,220.66.118.214,220.90.213.20,221.1.204.243,221.1.204.245,221.1.222.109,221.10.252.244,221.12.89.139,221.122.64.42,221.139.0.44,221.143.43.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (129)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407256; rev:167; fwsam: src, 24 hours;) alert udp [220.194.44.67,220.194.54.153,220.196.42.218,220.196.42.220,220.196.59.0/24,220.227.165.14,220.232.237.32,220.248.167.110,220.248.184.7,220.248.186.106,220.66.118.214,220.90.213.20,221.1.204.243,221.1.204.245,221.1.222.109,221.10.252.244,221.12.89.139,221.122.64.42,221.139.0.44,221.143.43.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (129)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407257; rev:167; fwsam: src, 24 hours;) alert tcp [221.143.51.115,221.163.26.185,221.192.8.90,221.230.140.98,221.5.74.0/24,221.6.181.152,222.103.205.149,222.122.20.228,222.122.56.164,222.122.60.186,222.124.128.149,222.124.24.7,222.170.127.100,222.177.79.137,222.186.12.137,222.186.13.219,222.186.223.92,222.186.23.106,222.186.30.239,222.186.31.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (130)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407258; rev:167; fwsam: src, 24 hours;) alert udp [221.143.51.115,221.163.26.185,221.192.8.90,221.230.140.98,221.5.74.0/24,221.6.181.152,222.103.205.149,222.122.20.228,222.122.56.164,222.122.60.186,222.124.128.149,222.124.24.7,222.170.127.100,222.177.79.137,222.186.12.137,222.186.13.219,222.186.223.92,222.186.23.106,222.186.30.239,222.186.31.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (130)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407259; rev:167; fwsam: src, 24 hours;) alert tcp [222.186.31.11,222.186.31.169,222.186.31.183,222.186.36.70,222.186.9.187,222.188.0.25,222.189.228.27,222.189.228.74,222.189.239.3,222.191.251.115,222.208.183.211,222.214.216.73,222.214.218.61,222.216.222.15,222.219.29.81,222.222.222.222,222.231.1.201,222.236.44.69,222.240.184.62,222.241.12.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (131)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407260; rev:167; fwsam: src, 24 hours;) alert udp [222.186.31.11,222.186.31.169,222.186.31.183,222.186.36.70,222.186.9.187,222.188.0.25,222.189.228.27,222.189.228.74,222.189.239.3,222.191.251.115,222.208.183.211,222.214.216.73,222.214.218.61,222.216.222.15,222.219.29.81,222.222.222.222,222.231.1.201,222.236.44.69,222.240.184.62,222.241.12.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (131)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407261; rev:167; fwsam: src, 24 hours;) alert tcp [222.35.137.0/24,222.35.139.198,222.35.139.206,222.35.139.242,222.35.140.235,222.35.142.60,222.73.173.25,222.73.219.143,222.73.219.58,222.73.219.74,222.73.219.87,222.73.37.203,222.73.37.250,222.73.37.253,222.73.37.78,222.73.91.203,222.76.214.205,222.76.215.12,222.76.215.24,222.76.217.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (132)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407262; rev:167; fwsam: src, 24 hours;) alert udp [222.35.137.0/24,222.35.139.198,222.35.139.206,222.35.139.242,222.35.140.235,222.35.142.60,222.73.173.25,222.73.219.143,222.73.219.58,222.73.219.74,222.73.219.87,222.73.37.203,222.73.37.250,222.73.37.253,222.73.37.78,222.73.91.203,222.76.214.205,222.76.215.12,222.76.215.24,222.76.217.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (132)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407263; rev:167; fwsam: src, 24 hours;) alert tcp [222.76.217.235,222.76.219.140,222.77.178.165,222.92.116.64,23.23.23.23,24.139.111.53,24.21.179.248,24.237.89.77,24.244.141.80,24.244.171.69,24.42.38.115,24.77.22.109,32.97.40.4,38.100.10.144,38.100.93.0/24,38.103.173.98,38.105.19.27,38.105.19.28,38.105.19.29,38.113.1.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (133)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407264; rev:167; fwsam: src, 24 hours;) alert udp [222.76.217.235,222.76.219.140,222.77.178.165,222.92.116.64,23.23.23.23,24.139.111.53,24.21.179.248,24.237.89.77,24.244.141.80,24.244.171.69,24.42.38.115,24.77.22.109,32.97.40.4,38.100.10.144,38.100.93.0/24,38.103.173.98,38.105.19.27,38.105.19.28,38.105.19.29,38.113.1.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (133)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407265; rev:167; fwsam: src, 24 hours;) alert tcp [38.117.90.45,38.97.225.166,38.99.169.206,38.99.169.207,38.99.169.208,38.99.169.209,38.99.169.210,38.99.169.211,38.99.170.187,38.99.170.210,38.99.170.9,38.99.186.27,4.16.224.183,41.141.70.180,41.141.81.117,41.249.1.157,41.249.3.188,41.249.45.60,42.233.79.18,45.137.79.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (134)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407266; rev:167; fwsam: src, 24 hours;) alert udp [38.117.90.45,38.97.225.166,38.99.169.206,38.99.169.207,38.99.169.208,38.99.169.209,38.99.169.210,38.99.169.211,38.99.170.187,38.99.170.210,38.99.170.9,38.99.186.27,4.16.224.183,41.141.70.180,41.141.81.117,41.249.1.157,41.249.3.188,41.249.45.60,42.233.79.18,45.137.79.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (134)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407267; rev:167; fwsam: src, 24 hours;) alert tcp [5.5.5.5,58.138.144.10,58.17.3.35,58.180.222.100,58.211.66.248,58.215.240.36,58.215.240.37,58.215.240.97,58.215.241.41,58.215.75.31,58.215.79.176,58.218.199.0/24,58.218.250.107,58.221.35.208,58.221.38.155,58.225.75.168,58.23.64.240,58.241.255.34,58.241.255.37,58.51.90.219] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (135)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407268; rev:167; fwsam: src, 24 hours;) alert udp [5.5.5.5,58.138.144.10,58.17.3.35,58.180.222.100,58.211.66.248,58.215.240.36,58.215.240.37,58.215.240.97,58.215.241.41,58.215.75.31,58.215.79.176,58.218.199.0/24,58.218.250.107,58.221.35.208,58.221.38.155,58.225.75.168,58.23.64.240,58.241.255.34,58.241.255.37,58.51.90.219] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (135)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407269; rev:167; fwsam: src, 24 hours;) alert tcp [58.51.95.218,58.52.161.100,58.55.127.24,58.64.130.11,58.64.148.54,58.65.232.0/21,58.8.28.201,58.83.8.19,58.83.8.45,58.86.43.35,59.124.195.244,59.125.229.0/24,59.125.231.241,59.125.231.242,59.125.231.252,59.147.102.72,59.147.12.68,59.148.221.79,59.148.221.89,59.175.230.51] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (136)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407270; rev:167; fwsam: src, 24 hours;) alert udp [58.51.95.218,58.52.161.100,58.55.127.24,58.64.130.11,58.64.148.54,58.65.232.0/21,58.8.28.201,58.83.8.19,58.83.8.45,58.86.43.35,59.124.195.244,59.125.229.0/24,59.125.231.241,59.125.231.242,59.125.231.252,59.147.102.72,59.147.12.68,59.148.221.79,59.148.221.89,59.175.230.51] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (136)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407271; rev:167; fwsam: src, 24 hours;) alert tcp [59.188.29.228,59.30.220.137,59.34.197.133,59.34.197.154,59.34.197.64,59.34.198.110,59.34.198.113,59.34.198.31,59.34.198.91,59.34.216.143,59.50.112.20,59.53.88.132,59.53.91.102,59.53.91.106,59.53.91.123,59.53.91.124,59.63.157.207,59.94.104.36,59.95.168.192,59.95.34.57] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (137)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407272; rev:167; fwsam: src, 24 hours;) alert udp [59.188.29.228,59.30.220.137,59.34.197.133,59.34.197.154,59.34.197.64,59.34.198.110,59.34.198.113,59.34.198.31,59.34.198.91,59.34.216.143,59.50.112.20,59.53.88.132,59.53.91.102,59.53.91.106,59.53.91.123,59.53.91.124,59.63.157.207,59.94.104.36,59.95.168.192,59.95.34.57] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (137)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407273; rev:167; fwsam: src, 24 hours;) alert tcp [60.12.117.145,60.12.117.147,60.169.0.2,60.170.241.23,60.171.150.6,60.172.190.185,60.172.229.101,60.172.229.102,60.173.10.68,60.173.11.155,60.173.12.44,60.190.2.41,60.190.203.89,60.190.243.3,60.190.93.178,60.191.124.195,60.191.129.150,60.191.187.14,60.191.223.2,60.191.239.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (138)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407274; rev:167; fwsam: src, 24 hours;) alert udp [60.12.117.145,60.12.117.147,60.169.0.2,60.170.241.23,60.171.150.6,60.172.190.185,60.172.229.101,60.172.229.102,60.173.10.68,60.173.11.155,60.173.12.44,60.190.2.41,60.190.203.89,60.190.243.3,60.190.93.178,60.191.124.195,60.191.129.150,60.191.187.14,60.191.223.2,60.191.239.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (138)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407275; rev:167; fwsam: src, 24 hours;) alert tcp [60.191.239.244,60.191.252.68,60.191.254.251,60.191.72.55,60.220.248.57,60.251.4.82,60.253.96.9,60.29.232.31,60.29.232.32,61.110.25.63,61.129.57.103,61.132.133.21,61.133.234.105,61.134.43.215,61.134.84.76,61.139.126.15,61.139.126.37,61.139.126.53,61.139.126.91,61.141.5.53] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (139)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407276; rev:167; fwsam: src, 24 hours;) alert udp [60.191.239.244,60.191.252.68,60.191.254.251,60.191.72.55,60.220.248.57,60.251.4.82,60.253.96.9,60.29.232.31,60.29.232.32,61.110.25.63,61.129.57.103,61.132.133.21,61.133.234.105,61.134.43.215,61.134.84.76,61.139.126.15,61.139.126.37,61.139.126.53,61.139.126.91,61.141.5.53] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (139)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407277; rev:167; fwsam: src, 24 hours;) alert tcp [61.145.112.39,61.147.109.80,61.147.119.194,61.147.119.207,61.147.67.186,61.150.100.48,61.150.91.14,61.150.91.30,61.152.95.193,61.155.170.30,61.156.242.119,61.156.8.141,61.158.163.83,61.158.219.2,61.160.232.114,61.160.247.37,61.164.109.105,61.164.110.117,61.164.110.166,61.164.117.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (140)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407278; rev:167; fwsam: src, 24 hours;) alert udp [61.145.112.39,61.147.109.80,61.147.119.194,61.147.119.207,61.147.67.186,61.150.100.48,61.150.91.14,61.150.91.30,61.152.95.193,61.155.170.30,61.156.242.119,61.156.8.141,61.158.163.83,61.158.219.2,61.160.232.114,61.160.247.37,61.164.109.105,61.164.110.117,61.164.110.166,61.164.117.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (140)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407279; rev:167; fwsam: src, 24 hours;) alert tcp [61.164.40.53,61.164.44.6,61.174.59.9,61.175.193.50,61.177.120.254,61.185.20.73,61.185.44.19,61.188.87.138,61.188.87.143,61.188.87.230,61.19.251.235,61.191.191.125,61.191.191.61,61.191.52.61,61.191.62.56,61.191.63.149,61.191.63.153,61.191.63.23,61.221.40.63,61.235.117.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (141)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407280; rev:167; fwsam: src, 24 hours;) alert udp [61.164.40.53,61.164.44.6,61.174.59.9,61.175.193.50,61.177.120.254,61.185.20.73,61.185.44.19,61.188.87.138,61.188.87.143,61.188.87.230,61.19.251.235,61.191.191.125,61.191.191.61,61.191.52.61,61.191.62.56,61.191.63.149,61.191.63.153,61.191.63.23,61.221.40.63,61.235.117.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (141)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407281; rev:167; fwsam: src, 24 hours;) alert tcp [61.33.191.132,61.4.190.206,61.4.82.210,61.4.82.211,61.4.82.212,61.4.82.213,61.4.82.214,61.4.82.216,61.4.82.218,61.4.82.222,61.4.82.223,61.4.82.224,61.59.24.45,61.59.24.55,61.61.20.133,61.61.20.134,61.61.20.136,61.61.61.61,61.63.3.40,61.67.193.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (142)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407282; rev:167; fwsam: src, 24 hours;) alert udp [61.33.191.132,61.4.190.206,61.4.82.210,61.4.82.211,61.4.82.212,61.4.82.213,61.4.82.214,61.4.82.216,61.4.82.218,61.4.82.222,61.4.82.223,61.4.82.224,61.59.24.45,61.59.24.55,61.61.20.133,61.61.20.134,61.61.20.136,61.61.61.61,61.63.3.40,61.67.193.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (142)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407283; rev:167; fwsam: src, 24 hours;) alert tcp [61.7.235.227,61.78.58.153,62.101.38.133,62.109.15.163,62.109.15.59,62.109.16.208,62.109.16.28,62.109.19.71,62.109.2.227,62.109.2.32,62.109.4.197,62.112.155.45,62.118.252.230,62.118.254.152,62.118.254.157,62.128.52.211,62.140.23.135,62.140.23.24,62.140.23.52,62.140.23.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (143)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407284; rev:167; fwsam: src, 24 hours;) alert udp [61.7.235.227,61.78.58.153,62.101.38.133,62.109.15.163,62.109.15.59,62.109.16.208,62.109.16.28,62.109.19.71,62.109.2.227,62.109.2.32,62.109.4.197,62.112.155.45,62.118.252.230,62.118.254.152,62.118.254.157,62.128.52.211,62.140.23.135,62.140.23.24,62.140.23.52,62.140.23.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (143)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407285; rev:167; fwsam: src, 24 hours;) alert tcp [62.141.49.229,62.141.52.99,62.146.61.200,62.149.12.191,62.149.140.20,62.149.140.93,62.149.16.49,62.149.165.114,62.149.165.29,62.149.175.39,62.149.18.11,62.149.18.21,62.149.18.34,62.149.23.191,62.149.27.117,62.149.28.166,62.149.28.27,62.152.34.5,62.152.69.195,62.16.112.29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (144)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407286; rev:167; fwsam: src, 24 hours;) alert udp [62.141.49.229,62.141.52.99,62.146.61.200,62.149.12.191,62.149.140.20,62.149.140.93,62.149.16.49,62.149.165.114,62.149.165.29,62.149.175.39,62.149.18.11,62.149.18.21,62.149.18.34,62.149.23.191,62.149.27.117,62.149.28.166,62.149.28.27,62.152.34.5,62.152.69.195,62.16.112.29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (144)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407287; rev:167; fwsam: src, 24 hours;) alert tcp [62.16.112.72,62.16.115.157,62.16.115.84,62.168.168.9,62.175.249.135,62.176.16.0/22,62.176.16.0/23,62.178.239.217,62.182.66.154,62.193.203.13,62.193.226.58,62.193.229.83,62.193.230.10,62.193.242.95,62.193.249.21,62.211.68.58,62.212.130.107,62.212.66.108,62.212.66.109,62.212.66.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (145)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407288; rev:167; fwsam: src, 24 hours;) alert udp [62.16.112.72,62.16.115.157,62.16.115.84,62.168.168.9,62.175.249.135,62.176.16.0/22,62.176.16.0/23,62.178.239.217,62.182.66.154,62.193.203.13,62.193.226.58,62.193.229.83,62.193.230.10,62.193.242.95,62.193.249.21,62.211.68.58,62.212.130.107,62.212.66.108,62.212.66.109,62.212.66.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (145)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407289; rev:167; fwsam: src, 24 hours;) alert tcp [62.212.66.20,62.212.66.75,62.212.67.146,62.212.67.170,62.212.67.19,62.212.74.148,62.213.74.8,62.221.197.18,62.248.107.21,62.250.4.168,62.37.237.16,62.4.83.129,62.4.83.231,62.4.83.242,62.4.85.229,62.75.184.40,62.75.202.206,62.75.218.192,62.75.240.188,62.75.246.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (146)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407290; rev:167; fwsam: src, 24 hours;) alert udp [62.212.66.20,62.212.66.75,62.212.67.146,62.212.67.170,62.212.67.19,62.212.74.148,62.213.74.8,62.221.197.18,62.248.107.21,62.250.4.168,62.37.237.16,62.4.83.129,62.4.83.231,62.4.83.242,62.4.85.229,62.75.184.40,62.75.202.206,62.75.218.192,62.75.240.188,62.75.246.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (146)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407291; rev:167; fwsam: src, 24 hours;) alert tcp [62.77.69.102,62.80.102.253,62.80.127.193,62.90.136.210,62.90.136.237,62.93.229.15,63.119.44.197,63.134.239.75,63.146.2.22,63.146.2.92,63.146.2.93,63.165.0.134,63.214.247.170,63.216.57.68,63.217.28.226,63.217.29.114,63.217.30.58,63.217.31.45,63.217.31.46,63.217.31.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (147)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407292; rev:167; fwsam: src, 24 hours;) alert udp [62.77.69.102,62.80.102.253,62.80.127.193,62.90.136.210,62.90.136.237,62.93.229.15,63.119.44.197,63.134.239.75,63.146.2.22,63.146.2.92,63.146.2.93,63.165.0.134,63.214.247.170,63.216.57.68,63.217.28.226,63.217.29.114,63.217.30.58,63.217.31.45,63.217.31.46,63.217.31.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (147)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407293; rev:167; fwsam: src, 24 hours;) alert tcp [63.217.31.48,63.218.226.243,63.218.226.67,63.218.71.115,63.219.176.162,63.219.178.186,63.219.178.190,63.219.178.218,63.219.178.227,63.219.178.82,63.219.178.85,63.219.178.89,63.219.178.90,63.223.110.177,63.227.18.137,63.243.173.162,63.243.188.37,63.247.141.192,63.251.171.0/24,63.251.83.74] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (148)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407294; rev:167; fwsam: src, 24 hours;) alert udp [63.217.31.48,63.218.226.243,63.218.226.67,63.218.71.115,63.219.176.162,63.219.178.186,63.219.178.190,63.219.178.218,63.219.178.227,63.219.178.82,63.219.178.85,63.219.178.89,63.219.178.90,63.223.110.177,63.227.18.137,63.243.173.162,63.243.188.37,63.247.141.192,63.251.171.0/24,63.251.83.74] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (148)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407295; rev:167; fwsam: src, 24 hours;) alert tcp [63.251.92.0/24,64.111.196.0/24,64.111.197.0/24,64.111.199.221,64.111.207.2,64.111.207.3,64.111.207.5,64.111.207.67,64.111.214.2,64.118.84.7,64.120.141.3,64.120.141.5,64.120.141.58,64.120.141.99,64.120.152.152,64.120.169.149,64.120.170.213,64.120.173.118,64.120.225.18,64.120.227.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (149)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407296; rev:167; fwsam: src, 24 hours;) alert udp [63.251.92.0/24,64.111.196.0/24,64.111.197.0/24,64.111.199.221,64.111.207.2,64.111.207.3,64.111.207.5,64.111.207.67,64.111.214.2,64.118.84.7,64.120.141.3,64.120.141.5,64.120.141.58,64.120.141.99,64.120.152.152,64.120.169.149,64.120.170.213,64.120.173.118,64.120.225.18,64.120.227.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (149)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407297; rev:167; fwsam: src, 24 hours;) alert tcp [64.124.113.236,64.124.210.59,64.124.210.60,64.124.222.0/24,64.13.227.66,64.13.253.153,64.131.76.231,64.14.244.60,64.14.68.27,64.15.138.13,64.15.147.204,64.15.155.240,64.15.72.80,64.150.176.14,64.150.177.215,64.150.177.217,64.150.177.247,64.151.87.9,64.18.144.0/24,64.187.109.136] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (150)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407298; rev:167; fwsam: src, 24 hours;) alert udp [64.124.113.236,64.124.210.59,64.124.210.60,64.124.222.0/24,64.13.227.66,64.13.253.153,64.131.76.231,64.14.244.60,64.14.68.27,64.15.138.13,64.15.147.204,64.15.155.240,64.15.72.80,64.150.176.14,64.150.177.215,64.150.177.217,64.150.177.247,64.151.87.9,64.18.144.0/24,64.187.109.136] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (150)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407299; rev:167; fwsam: src, 24 hours;) alert tcp [64.187.125.173,64.191.100.101,64.191.102.134,64.191.102.135,64.191.102.136,64.191.102.137,64.191.102.229,64.191.103.86,64.191.112.54,64.191.118.248,64.191.12.37,64.191.12.38,64.191.12.53,64.191.123.37,64.191.125.151,64.191.13.164,64.191.16.149,64.191.22.150,64.191.22.21,64.191.25.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (151)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407300; rev:167; fwsam: src, 24 hours;) alert udp [64.187.125.173,64.191.100.101,64.191.102.134,64.191.102.135,64.191.102.136,64.191.102.137,64.191.102.229,64.191.103.86,64.191.112.54,64.191.118.248,64.191.12.37,64.191.12.38,64.191.12.53,64.191.123.37,64.191.125.151,64.191.13.164,64.191.16.149,64.191.22.150,64.191.22.21,64.191.25.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (151)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407301; rev:167; fwsam: src, 24 hours;) alert tcp [64.191.25.245,64.191.3.53,64.191.30.160,64.191.30.181,64.191.38.197,64.191.38.198,64.191.38.199,64.191.40.182,64.191.44.5,64.191.44.8,64.191.47.213,64.191.50.8,64.191.53.230,64.191.64.246,64.191.75.69,64.191.78.0/24,64.191.80.23,64.191.81.245,64.191.89.229,64.191.90.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (152)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407302; rev:167; fwsam: src, 24 hours;) alert udp [64.191.25.245,64.191.3.53,64.191.30.160,64.191.30.181,64.191.38.197,64.191.38.198,64.191.38.199,64.191.40.182,64.191.44.5,64.191.44.8,64.191.47.213,64.191.50.8,64.191.53.230,64.191.64.246,64.191.75.69,64.191.78.0/24,64.191.80.23,64.191.81.245,64.191.89.229,64.191.90.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (152)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407303; rev:167; fwsam: src, 24 hours;) alert tcp [64.191.90.214,64.191.91.200,64.191.91.230,64.191.92.197,64.20.33.156,64.20.36.218,64.20.38.171,64.20.38.172,64.20.38.242,64.20.38.90,64.20.38.91,64.20.53.82,64.20.55.163,64.20.56.138,64.202.107.23,64.208.226.72,64.208.226.93,64.21.100.203,64.21.100.205,64.21.129.136] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (153)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407304; rev:167; fwsam: src, 24 hours;) alert udp [64.191.90.214,64.191.91.200,64.191.91.230,64.191.92.197,64.20.33.156,64.20.36.218,64.20.38.171,64.20.38.172,64.20.38.242,64.20.38.90,64.20.38.91,64.20.53.82,64.20.55.163,64.20.56.138,64.202.107.23,64.208.226.72,64.208.226.93,64.21.100.203,64.21.100.205,64.21.129.136] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (153)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407305; rev:167; fwsam: src, 24 hours;) alert tcp [64.21.144.140,64.21.182.152,64.21.182.153,64.21.182.154,64.21.182.155,64.21.182.156,64.21.182.157,64.21.182.158,64.21.182.159,64.21.182.160,64.21.21.0/24,64.21.37.41,64.21.37.43,64.21.37.47,64.21.37.88,64.21.37.89,64.21.37.90,64.21.37.91,64.21.37.92,64.21.37.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (154)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407306; rev:167; fwsam: src, 24 hours;) alert udp [64.21.144.140,64.21.182.152,64.21.182.153,64.21.182.154,64.21.182.155,64.21.182.156,64.21.182.157,64.21.182.158,64.21.182.159,64.21.182.160,64.21.21.0/24,64.21.37.41,64.21.37.43,64.21.37.47,64.21.37.88,64.21.37.89,64.21.37.90,64.21.37.91,64.21.37.92,64.21.37.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (154)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407307; rev:167; fwsam: src, 24 hours;) alert tcp [64.21.37.94,64.21.37.98,64.21.43.179,64.21.43.183,64.21.86.16,64.213.140.68,64.213.140.69,64.213.140.70,64.213.140.71,64.22.106.107,64.22.119.118,64.235.47.58,64.235.47.65,64.235.52.240,64.235.54.100,64.235.57.21,64.245.136.30,64.247.16.208,64.247.16.215,64.247.49.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (155)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407308; rev:167; fwsam: src, 24 hours;) alert udp [64.21.37.94,64.21.37.98,64.21.43.179,64.21.43.183,64.21.86.16,64.213.140.68,64.213.140.69,64.213.140.70,64.213.140.71,64.22.106.107,64.22.119.118,64.235.47.58,64.235.47.65,64.235.52.240,64.235.54.100,64.235.57.21,64.245.136.30,64.247.16.208,64.247.16.215,64.247.49.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (155)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407309; rev:167; fwsam: src, 24 hours;) alert tcp [64.247.58.168,64.251.10.77,64.251.28.222,64.255.172.50,64.26.155.161,64.27.13.111,64.27.13.94,64.27.16.138,64.27.17.197,64.27.18.53,64.27.18.54,64.27.24.153,64.27.28.224,64.27.28.225,64.27.29.101,64.27.5.163,64.27.5.202,64.27.5.204,64.27.5.63,64.27.52.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (156)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407310; rev:167; fwsam: src, 24 hours;) alert udp [64.247.58.168,64.251.10.77,64.251.28.222,64.255.172.50,64.26.155.161,64.27.13.111,64.27.13.94,64.27.16.138,64.27.17.197,64.27.18.53,64.27.18.54,64.27.24.153,64.27.28.224,64.27.28.225,64.27.29.101,64.27.5.163,64.27.5.202,64.27.5.204,64.27.5.63,64.27.52.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (156)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407311; rev:167; fwsam: src, 24 hours;) alert tcp [64.28.176.0/20,64.28.187.0/24,64.29.151.221,64.32.13.153,64.32.21.3,64.32.29.107,64.32.5.0/24,64.34.211.111,64.34.228.126,64.34.253.46,64.34.255.92,64.34.46.254,64.34.46.60,64.38.232.160,64.38.232.180,64.40.103.249,64.40.117.19,64.40.117.34,64.40.118.10,64.40.118.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (157)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407312; rev:167; fwsam: src, 24 hours;) alert udp [64.28.176.0/20,64.28.187.0/24,64.29.151.221,64.32.13.153,64.32.21.3,64.32.29.107,64.32.5.0/24,64.34.211.111,64.34.228.126,64.34.253.46,64.34.255.92,64.34.46.254,64.34.46.60,64.38.232.160,64.38.232.180,64.40.103.249,64.40.117.19,64.40.117.34,64.40.118.10,64.40.118.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (157)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407313; rev:167; fwsam: src, 24 hours;) alert tcp [64.40.118.8,64.41.84.97,64.46.38.133,64.56.64.130,64.57.252.112,64.6.241.17,64.6.241.26,64.6.243.205,64.62.171.193,64.62.181.43,64.62.181.46,64.69.32.189,64.69.32.202,64.69.32.203,64.69.32.204,64.69.32.206,64.69.32.219,64.69.32.220,64.69.41.18,64.69.46.61] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (158)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407314; rev:167; fwsam: src, 24 hours;) alert udp [64.40.118.8,64.41.84.97,64.46.38.133,64.56.64.130,64.57.252.112,64.6.241.17,64.6.241.26,64.6.243.205,64.62.171.193,64.62.181.43,64.62.181.46,64.69.32.189,64.69.32.202,64.69.32.203,64.69.32.204,64.69.32.206,64.69.32.219,64.69.32.220,64.69.41.18,64.69.46.61] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (158)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407315; rev:167; fwsam: src, 24 hours;) alert tcp [64.69.68.0/24,64.70.19.33,64.71.33.124,64.71.33.35,64.71.33.65,64.71.33.74,64.71.35.17,64.79.79.227,64.8.104.24,64.84.20.166,64.85.168.251,64.86.133.220,64.86.133.221,64.86.133.222,64.86.133.224,64.86.133.225,64.86.133.37,64.86.133.51,64.86.133.58,64.86.133.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (159)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407316; rev:167; fwsam: src, 24 hours;) alert udp [64.69.68.0/24,64.70.19.33,64.71.33.124,64.71.33.35,64.71.33.65,64.71.33.74,64.71.35.17,64.79.79.227,64.8.104.24,64.84.20.166,64.85.168.251,64.86.133.220,64.86.133.221,64.86.133.222,64.86.133.224,64.86.133.225,64.86.133.37,64.86.133.51,64.86.133.58,64.86.133.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (159)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407317; rev:167; fwsam: src, 24 hours;) alert tcp [64.86.133.91,64.86.16.0/24,64.86.17.0/24,64.86.25.200,64.86.25.201,64.86.25.202,64.90.182.182,64.90.182.185,64.91.241.34,64.91.254.69,64.92.105.16,64.92.166.251,64.92.166.252,64.92.166.254,64.92.170.128,64.92.170.134,64.92.170.135,64.92.170.144,64.92.170.145,64.92.170.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (160)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407318; rev:167; fwsam: src, 24 hours;) alert udp [64.86.133.91,64.86.16.0/24,64.86.17.0/24,64.86.25.200,64.86.25.201,64.86.25.202,64.90.182.182,64.90.182.185,64.91.241.34,64.91.254.69,64.92.105.16,64.92.166.251,64.92.166.252,64.92.166.254,64.92.170.128,64.92.170.134,64.92.170.135,64.92.170.144,64.92.170.145,64.92.170.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (160)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407319; rev:167; fwsam: src, 24 hours;) alert tcp [64.92.170.147,64.92.170.148,64.92.170.149,64.92.170.150,64.92.170.151,64.92.173.179,64.92.174.218,64.92.174.70,64.94.117.193,64.94.137.41,65.110.50.141,65.110.60.122,65.110.60.123,65.110.60.70,65.111.162.94,65.135.199.108,65.135.199.21,65.135.99.23,65.182.100.196,65.23.153.152] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (161)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407320; rev:167; fwsam: src, 24 hours;) alert udp [64.92.170.147,64.92.170.148,64.92.170.149,64.92.170.150,64.92.170.151,64.92.173.179,64.92.174.218,64.92.174.70,64.94.117.193,64.94.137.41,65.110.50.141,65.110.60.122,65.110.60.123,65.110.60.70,65.111.162.94,65.135.199.108,65.135.199.21,65.135.99.23,65.182.100.196,65.23.153.152] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (161)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407321; rev:167; fwsam: src, 24 hours;) alert tcp [65.23.153.197,65.23.153.78,65.243.103.0/24,65.247.182.200,65.254.254.34,65.254.51.163,65.254.54.178,65.254.54.179,65.254.55.3,65.60.158.68,65.60.36.50,65.60.44.194,65.60.49.242,65.60.54.58,65.60.6.116,65.60.6.176,65.60.6.178,65.75.169.178,65.75.169.179,65.98.15.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (162)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407322; rev:167; fwsam: src, 24 hours;) alert udp [65.23.153.197,65.23.153.78,65.243.103.0/24,65.247.182.200,65.254.254.34,65.254.51.163,65.254.54.178,65.254.54.179,65.254.55.3,65.60.158.68,65.60.36.50,65.60.44.194,65.60.49.242,65.60.54.58,65.60.6.116,65.60.6.176,65.60.6.178,65.75.169.178,65.75.169.179,65.98.15.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (162)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407323; rev:167; fwsam: src, 24 hours;) alert tcp [65.98.19.103,65.98.3.74,65.99.230.107,66.102.100.70,66.103.128.137,66.11.154.210,66.11.230.67,66.112.221.139,66.113.163.254,66.114.72.115,66.114.72.117,66.115.136.52,66.115.146.145,66.115.174.134,66.116.188.175,66.117.40.216,66.118.146.67,66.118.146.69,66.118.146.84,66.128.62.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (163)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407324; rev:167; fwsam: src, 24 hours;) alert udp [65.98.19.103,65.98.3.74,65.99.230.107,66.102.100.70,66.103.128.137,66.11.154.210,66.11.230.67,66.112.221.139,66.113.163.254,66.114.72.115,66.114.72.117,66.115.136.52,66.115.146.145,66.115.174.134,66.116.188.175,66.117.40.216,66.118.146.67,66.118.146.69,66.118.146.84,66.128.62.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (163)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407325; rev:167; fwsam: src, 24 hours;) alert tcp [66.129.68.65,66.135.41.29,66.135.61.77,66.147.237.116,66.147.237.142,66.147.240.152,66.147.240.157,66.147.242.97,66.148.71.9,66.148.80.4,66.150.120.131,66.150.161.136,66.150.161.137,66.150.161.140,66.150.161.141,66.152.166.189,66.152.78.69,66.152.78.70,66.152.78.75,66.154.108.118] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (164)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407326; rev:167; fwsam: src, 24 hours;) alert udp [66.129.68.65,66.135.41.29,66.135.61.77,66.147.237.116,66.147.237.142,66.147.240.152,66.147.240.157,66.147.242.97,66.148.71.9,66.148.80.4,66.150.120.131,66.150.161.136,66.150.161.137,66.150.161.140,66.150.161.141,66.152.166.189,66.152.78.69,66.152.78.70,66.152.78.75,66.154.108.118] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (164)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407327; rev:167; fwsam: src, 24 hours;) alert tcp [66.154.75.63,66.160.197.20,66.172.83.223,66.172.83.224,66.180.193.210,66.180.193.211,66.185.24.80,66.197.132.22,66.197.139.245,66.197.144.197,66.197.148.103,66.197.148.104,66.197.148.105,66.197.148.106,66.197.148.107,66.197.149.38,66.197.154.198,66.197.154.199,66.197.154.200,66.197.154.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (165)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407328; rev:167; fwsam: src, 24 hours;) alert udp [66.154.75.63,66.160.197.20,66.172.83.223,66.172.83.224,66.180.193.210,66.180.193.211,66.185.24.80,66.197.132.22,66.197.139.245,66.197.144.197,66.197.148.103,66.197.148.104,66.197.148.105,66.197.148.106,66.197.148.107,66.197.149.38,66.197.154.198,66.197.154.199,66.197.154.200,66.197.154.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (165)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407329; rev:167; fwsam: src, 24 hours;) alert tcp [66.197.163.85,66.197.165.41,66.197.165.50,66.197.165.55,66.197.168.21,66.197.168.38,66.197.168.39,66.197.168.40,66.197.170.5,66.197.171.37,66.197.171.6,66.197.186.37,66.197.187.5,66.197.205.133,66.197.207.37,66.197.209.69,66.197.213.117,66.197.224.66,66.197.230.50,66.197.237.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (166)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407330; rev:167; fwsam: src, 24 hours;) alert udp [66.197.163.85,66.197.165.41,66.197.165.50,66.197.165.55,66.197.168.21,66.197.168.38,66.197.168.39,66.197.168.40,66.197.170.5,66.197.171.37,66.197.171.6,66.197.186.37,66.197.187.5,66.197.205.133,66.197.207.37,66.197.209.69,66.197.213.117,66.197.224.66,66.197.230.50,66.197.237.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (166)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407331; rev:167; fwsam: src, 24 hours;) alert tcp [66.197.238.154,66.197.240.165,66.197.68.184,66.197.94.155,66.199.152.4,66.199.229.229,66.199.229.230,66.199.229.253,66.199.232.222,66.199.237.10,66.199.237.127,66.199.237.36,66.199.242.18,66.199.242.19,66.199.248.195,66.199.251.162,66.206.17.28,66.206.17.29,66.206.17.30,66.206.17.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (167)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407332; rev:167; fwsam: src, 24 hours;) alert udp [66.197.238.154,66.197.240.165,66.197.68.184,66.197.94.155,66.199.152.4,66.199.229.229,66.199.229.230,66.199.229.253,66.199.232.222,66.199.237.10,66.199.237.127,66.199.237.36,66.199.242.18,66.199.242.19,66.199.248.195,66.199.251.162,66.206.17.28,66.206.17.29,66.206.17.30,66.206.17.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (167)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407333; rev:167; fwsam: src, 24 hours;) alert tcp [66.212.155.140,66.212.19.146,66.219.22.51,66.220.17.153,66.220.17.157,66.220.17.200,66.220.17.5,66.220.17.6,66.223.111.166,66.225.192.23,66.225.215.231,66.225.217.71,66.225.241.14,66.226.20.41,66.226.75.118,66.226.87.107,66.228.122.240,66.228.122.241,66.228.122.242,66.228.122.243] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (168)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407334; rev:167; fwsam: src, 24 hours;) alert udp [66.212.155.140,66.212.19.146,66.219.22.51,66.220.17.153,66.220.17.157,66.220.17.200,66.220.17.5,66.220.17.6,66.223.111.166,66.225.192.23,66.225.215.231,66.225.217.71,66.225.241.14,66.226.20.41,66.226.75.118,66.226.87.107,66.228.122.240,66.228.122.241,66.228.122.242,66.228.122.243] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (168)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407335; rev:167; fwsam: src, 24 hours;) alert tcp [66.228.122.244,66.228.122.245,66.230.133.40,66.230.155.157,66.230.161.0/24,66.230.167.0/24,66.230.174.60,66.230.175.0/24,66.230.208.19,66.232.102.69,66.232.105.0/24,66.232.106.77,66.232.106.86,66.232.106.90,66.232.106.92,66.232.106.93,66.232.108.154,66.232.109.120,66.232.109.121,66.232.109.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (169)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407336; rev:167; fwsam: src, 24 hours;) alert udp [66.228.122.244,66.228.122.245,66.230.133.40,66.230.155.157,66.230.161.0/24,66.230.167.0/24,66.230.174.60,66.230.175.0/24,66.230.208.19,66.232.102.69,66.232.105.0/24,66.232.106.77,66.232.106.86,66.232.106.90,66.232.106.92,66.232.106.93,66.232.108.154,66.232.109.120,66.232.109.121,66.232.109.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (169)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407337; rev:167; fwsam: src, 24 hours;) alert tcp [66.232.109.123,66.232.109.124,66.232.109.125,66.232.109.126,66.232.109.127,66.232.109.128,66.232.109.129,66.232.109.130,66.232.109.131,66.232.109.249,66.232.109.250,66.232.111.112,66.232.112.86,66.232.113.44,66.232.113.45,66.232.113.46,66.232.113.48,66.232.113.49,66.232.113.57,66.232.113.62] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (170)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407338; rev:167; fwsam: src, 24 hours;) alert udp [66.232.109.123,66.232.109.124,66.232.109.125,66.232.109.126,66.232.109.127,66.232.109.128,66.232.109.129,66.232.109.130,66.232.109.131,66.232.109.249,66.232.109.250,66.232.111.112,66.232.112.86,66.232.113.44,66.232.113.45,66.232.113.46,66.232.113.48,66.232.113.49,66.232.113.57,66.232.113.62] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (170)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407339; rev:167; fwsam: src, 24 hours;) alert tcp [66.232.113.63,66.232.113.80,66.232.114.134,66.232.114.152,66.232.114.56,66.232.114.57,66.232.116.2,66.232.116.3,66.232.116.6,66.232.117.33,66.232.117.38,66.232.118.147,66.232.124.38,66.232.124.39,66.232.124.40,66.232.124.41,66.232.124.42,66.232.125.202,66.232.125.208,66.232.125.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (171)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407340; rev:167; fwsam: src, 24 hours;) alert udp [66.232.113.63,66.232.113.80,66.232.114.134,66.232.114.152,66.232.114.56,66.232.114.57,66.232.116.2,66.232.116.3,66.232.116.6,66.232.117.33,66.232.117.38,66.232.118.147,66.232.124.38,66.232.124.39,66.232.124.40,66.232.124.41,66.232.124.42,66.232.125.202,66.232.125.208,66.232.125.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (171)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407341; rev:167; fwsam: src, 24 hours;) alert tcp [66.232.126.189,66.232.126.190,66.232.126.192,66.232.126.193,66.232.126.194,66.232.126.47,66.232.126.48,66.232.126.49,66.232.126.50,66.232.126.51,66.232.126.52,66.232.126.74,66.232.126.75,66.232.126.76,66.232.126.77,66.232.126.78,66.232.126.79,66.232.126.80,66.232.127.127,66.232.127.128] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (172)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407342; rev:167; fwsam: src, 24 hours;) alert udp [66.232.126.189,66.232.126.190,66.232.126.192,66.232.126.193,66.232.126.194,66.232.126.47,66.232.126.48,66.232.126.49,66.232.126.50,66.232.126.51,66.232.126.52,66.232.126.74,66.232.126.75,66.232.126.76,66.232.126.77,66.232.126.78,66.232.126.79,66.232.126.80,66.232.127.127,66.232.127.128] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (172)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407343; rev:167; fwsam: src, 24 hours;) alert tcp [66.232.127.129,66.232.127.130,66.232.127.44,66.232.22.14,66.232.26.91,66.235.160.93,66.235.180.194,66.235.180.238,66.240.163.84,66.241.193.42,66.244.254.0/24,66.246.221.216,66.246.221.217,66.246.221.218,66.246.221.219,66.246.221.220,66.246.221.221,66.246.221.222,66.246.221.223,66.246.222.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (173)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407344; rev:167; fwsam: src, 24 hours;) alert udp [66.232.127.129,66.232.127.130,66.232.127.44,66.232.22.14,66.232.26.91,66.235.160.93,66.235.180.194,66.235.180.238,66.240.163.84,66.241.193.42,66.244.254.0/24,66.246.221.216,66.246.221.217,66.246.221.218,66.246.221.219,66.246.221.220,66.246.221.221,66.246.221.222,66.246.221.223,66.246.222.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (173)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407345; rev:167; fwsam: src, 24 hours;) alert tcp [66.246.222.33,66.246.235.32,66.246.235.42,66.246.72.50,66.249.28.153,66.249.5.0/24,66.25.227.224,66.252.14.44,66.252.21.106,66.252.228.51,66.252.239.235,66.29.11.144,66.29.115.68,66.29.121.58,66.29.15.140,66.29.15.141,66.29.50.174,66.29.50.176,66.29.50.183,66.29.89.64] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (174)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407346; rev:167; fwsam: src, 24 hours;) alert udp [66.246.222.33,66.246.235.32,66.246.235.42,66.246.72.50,66.249.28.153,66.249.5.0/24,66.25.227.224,66.252.14.44,66.252.21.106,66.252.228.51,66.252.239.235,66.29.11.144,66.29.115.68,66.29.121.58,66.29.15.140,66.29.15.141,66.29.50.174,66.29.50.176,66.29.50.183,66.29.89.64] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (174)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407347; rev:167; fwsam: src, 24 hours;) alert tcp [66.33.195.58,66.35.111.73,66.36.241.193,66.36.242.224,66.39.40.155,66.39.5.165,66.40.52.170,66.40.52.175,66.40.52.56,66.40.52.59,66.40.52.62,66.40.52.63,66.40.52.7,66.40.56.10,66.40.56.36,66.40.65.7,66.40.66.171,66.40.7.42,66.45.226.211,66.45.226.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (175)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407348; rev:167; fwsam: src, 24 hours;) alert udp [66.33.195.58,66.35.111.73,66.36.241.193,66.36.242.224,66.39.40.155,66.39.5.165,66.40.52.170,66.40.52.175,66.40.52.56,66.40.52.59,66.40.52.62,66.40.52.63,66.40.52.7,66.40.56.10,66.40.56.36,66.40.65.7,66.40.66.171,66.40.7.42,66.45.226.211,66.45.226.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (175)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407349; rev:167; fwsam: src, 24 hours;) alert tcp [66.45.226.227,66.45.226.26,66.45.226.42,66.45.226.43,66.45.226.44,66.45.226.45,66.45.227.88,66.45.227.89,66.45.227.90,66.45.227.91,66.45.227.92,66.45.227.93,66.45.227.94,66.45.227.95,66.45.229.61,66.45.230.194,66.45.231.208,66.45.231.209,66.45.231.210,66.45.231.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (176)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407350; rev:167; fwsam: src, 24 hours;) alert udp [66.45.226.227,66.45.226.26,66.45.226.42,66.45.226.43,66.45.226.44,66.45.226.45,66.45.227.88,66.45.227.89,66.45.227.90,66.45.227.91,66.45.227.92,66.45.227.93,66.45.227.94,66.45.227.95,66.45.229.61,66.45.230.194,66.45.231.208,66.45.231.209,66.45.231.210,66.45.231.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (176)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407351; rev:167; fwsam: src, 24 hours;) alert tcp [66.45.231.212,66.45.231.213,66.45.231.214,66.45.231.215,66.45.236.162,66.45.237.219,66.45.240.99,66.45.249.66,66.45.249.82,66.45.250.250,66.45.250.251,66.45.255.226,66.48.81.198,66.48.82.31,66.49.202.47,66.49.222.162,66.49.254.254,66.63.167.50,66.7.148.131,66.7.179.198] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (177)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407352; rev:167; fwsam: src, 24 hours;) alert udp [66.45.231.212,66.45.231.213,66.45.231.214,66.45.231.215,66.45.236.162,66.45.237.219,66.45.240.99,66.45.249.66,66.45.249.82,66.45.250.250,66.45.250.251,66.45.255.226,66.48.81.198,66.48.82.31,66.49.202.47,66.49.222.162,66.49.254.254,66.63.167.50,66.7.148.131,66.7.179.198] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (177)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407353; rev:167; fwsam: src, 24 hours;) alert tcp [66.7.194.207,66.7.196.36,66.7.208.222,66.7.209.7,66.7.213.144,66.7.215.209,66.7.216.212,66.7.219.192,66.7.221.173,66.7.221.48,66.7.56.125,66.70.156.114,66.71.188.9,66.71.244.130,66.71.244.69,66.79.163.21,66.79.168.2,66.79.178.199,66.79.178.200,66.79.179.44] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (178)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407354; rev:167; fwsam: src, 24 hours;) alert udp [66.7.194.207,66.7.196.36,66.7.208.222,66.7.209.7,66.7.213.144,66.7.215.209,66.7.216.212,66.7.219.192,66.7.221.173,66.7.221.48,66.7.56.125,66.70.156.114,66.71.188.9,66.71.244.130,66.71.244.69,66.79.163.21,66.79.168.2,66.79.178.199,66.79.178.200,66.79.179.44] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (178)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407355; rev:167; fwsam: src, 24 hours;) alert tcp [66.79.179.45,66.79.179.46,66.79.184.200,66.79.184.201,66.79.184.203,66.79.184.204,66.79.186.146,66.79.186.147,66.79.186.148,66.79.188.115,66.79.188.116,66.79.188.117,66.79.188.88,66.79.188.89,66.79.188.90,66.90.101.177,66.90.101.183,66.90.103.152,66.90.73.152,66.90.78.50] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (179)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407356; rev:167; fwsam: src, 24 hours;) alert udp [66.79.179.45,66.79.179.46,66.79.184.200,66.79.184.201,66.79.184.203,66.79.184.204,66.79.186.146,66.79.186.147,66.79.186.148,66.79.188.115,66.79.188.116,66.79.188.117,66.79.188.88,66.79.188.89,66.79.188.90,66.90.101.177,66.90.101.183,66.90.103.152,66.90.73.152,66.90.78.50] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (179)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407357; rev:167; fwsam: src, 24 hours;) alert tcp [66.90.78.51,66.90.78.52,66.90.81.138,66.94.75.186,66.96.130.38,66.96.130.40,66.96.131.82,66.96.134.53,66.96.143.191,66.96.146.102,66.96.207.35,66.96.208.245,66.96.208.248,66.96.216.215,66.96.219.149,66.96.252.199,66.96.255.69,66.96.85.112,66.96.85.113,66.96.9.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (180)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407358; rev:167; fwsam: src, 24 hours;) alert udp [66.90.78.51,66.90.78.52,66.90.81.138,66.94.75.186,66.96.130.38,66.96.130.40,66.96.131.82,66.96.134.53,66.96.143.191,66.96.146.102,66.96.207.35,66.96.208.245,66.96.208.248,66.96.216.215,66.96.219.149,66.96.252.199,66.96.255.69,66.96.85.112,66.96.85.113,66.96.9.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (180)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407359; rev:167; fwsam: src, 24 hours;) alert tcp [66.98.242.165,66.98.242.18,66.98.252.9,67.100.161.6,67.137.217.219,67.149.126.176,67.15.103.219,67.15.107.168,67.15.107.180,67.15.11.100,67.15.157.10,67.15.203.219,67.15.22.18,67.15.253.241,67.15.56.128,67.15.62.181,67.15.76.243,67.15.77.182,67.15.97.25,67.159.2.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (181)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407360; rev:167; fwsam: src, 24 hours;) alert udp [66.98.242.165,66.98.242.18,66.98.252.9,67.100.161.6,67.137.217.219,67.149.126.176,67.15.103.219,67.15.107.168,67.15.107.180,67.15.11.100,67.15.157.10,67.15.203.219,67.15.22.18,67.15.253.241,67.15.56.128,67.15.62.181,67.15.76.243,67.15.77.182,67.15.97.25,67.159.2.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (181)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407361; rev:167; fwsam: src, 24 hours;) alert tcp [67.159.32.130,67.159.32.131,67.159.32.58,67.159.32.62,67.159.34.162,67.159.34.163,67.159.34.164,67.159.34.186,67.159.34.187,67.159.34.188,67.159.37.2,67.159.37.3,67.159.37.4,67.159.45.3,67.18.129.147,67.18.129.149,67.18.179.0/24,67.18.19.162,67.18.19.226,67.19.113.177] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (182)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407362; rev:167; fwsam: src, 24 hours;) alert udp [67.159.32.130,67.159.32.131,67.159.32.58,67.159.32.62,67.159.34.162,67.159.34.163,67.159.34.164,67.159.34.186,67.159.34.187,67.159.34.188,67.159.37.2,67.159.37.3,67.159.37.4,67.159.45.3,67.18.129.147,67.18.129.149,67.18.179.0/24,67.18.19.162,67.18.19.226,67.19.113.177] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (182)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407363; rev:167; fwsam: src, 24 hours;) alert tcp [67.19.17.210,67.19.171.210,67.19.24.170,67.19.244.4,67.19.244.5,67.19.244.9,67.19.72.201,67.19.72.202,67.196.132.35,67.202.106.108,67.202.88.62,67.205.3.106,67.205.57.64,67.205.59.23,67.205.74.211,67.205.75.0/24,67.205.93.165,67.207.71.171,67.207.71.174,67.208.75.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (183)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407364; rev:167; fwsam: src, 24 hours;) alert udp [67.19.17.210,67.19.171.210,67.19.24.170,67.19.244.4,67.19.244.5,67.19.244.9,67.19.72.201,67.19.72.202,67.196.132.35,67.202.106.108,67.202.88.62,67.205.3.106,67.205.57.64,67.205.59.23,67.205.74.211,67.205.75.0/24,67.205.93.165,67.207.71.171,67.207.71.174,67.208.75.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (183)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407365; rev:167; fwsam: src, 24 hours;) alert tcp [67.21.67.66,67.210.0.0/20,67.210.124.90,67.210.126.50,67.210.127.56,67.211.161.0,67.212.187.114,67.212.187.58,67.212.187.61,67.212.187.62,67.212.188.154,67.212.237.64,67.212.65.112,67.212.65.113,67.212.65.114,67.212.65.115,67.212.65.116,67.212.65.117,67.212.65.118,67.212.65.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (184)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407366; rev:167; fwsam: src, 24 hours;) alert udp [67.21.67.66,67.210.0.0/20,67.210.124.90,67.210.126.50,67.210.127.56,67.211.161.0,67.212.187.114,67.212.187.58,67.212.187.61,67.212.187.62,67.212.188.154,67.212.237.64,67.212.65.112,67.212.65.113,67.212.65.114,67.212.65.115,67.212.65.116,67.212.65.117,67.212.65.118,67.212.65.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (184)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407367; rev:167; fwsam: src, 24 hours;) alert tcp [67.212.71.196,67.212.80.121,67.212.80.124,67.212.80.125,67.212.81.29,67.214.161.149,67.215.1.50,67.215.1.58,67.215.12.140,67.215.231.242,67.215.238.178,67.215.238.190,67.215.238.195,67.215.238.202,67.215.241.202,67.215.243.211,67.215.253.2,67.215.6.202,67.215.66.132,67.220.197.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (185)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407368; rev:167; fwsam: src, 24 hours;) alert udp [67.212.71.196,67.212.80.121,67.212.80.124,67.212.80.125,67.212.81.29,67.214.161.149,67.215.1.50,67.215.1.58,67.215.12.140,67.215.231.242,67.215.238.178,67.215.238.190,67.215.238.195,67.215.238.202,67.215.241.202,67.215.243.211,67.215.253.2,67.215.6.202,67.215.66.132,67.220.197.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (185)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407369; rev:167; fwsam: src, 24 hours;) alert tcp [67.220.197.51,67.220.199.181,67.220.217.230,67.220.66.0/24,67.220.67.0/24,67.220.72.0/24,67.220.73.0/24,67.220.74.0/24,67.220.75.0/24,67.222.128.29,67.222.150.103,67.222.18.113,67.222.37.192,67.222.5.128,67.222.8.68,67.222.97.149,67.225.136.4,67.225.137.254,67.225.145.61,67.225.151.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (186)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407370; rev:167; fwsam: src, 24 hours;) alert udp [67.220.197.51,67.220.199.181,67.220.217.230,67.220.66.0/24,67.220.67.0/24,67.220.72.0/24,67.220.73.0/24,67.220.74.0/24,67.220.75.0/24,67.222.128.29,67.222.150.103,67.222.18.113,67.222.37.192,67.222.5.128,67.222.8.68,67.222.97.149,67.225.136.4,67.225.137.254,67.225.145.61,67.225.151.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (186)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407371; rev:167; fwsam: src, 24 hours;) alert tcp [67.225.151.254,67.225.151.4,67.225.158.16,67.225.158.17,67.225.158.18,67.225.158.19,67.225.168.207,67.225.179.95,67.225.203.66,67.227.134.31,67.228.10.28,67.228.10.29,67.228.101.157,67.228.111.217,67.228.112.232,67.228.112.233,67.228.112.234,67.228.112.235,67.228.120.3,67.228.122.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (187)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407372; rev:167; fwsam: src, 24 hours;) alert udp [67.225.151.254,67.225.151.4,67.225.158.16,67.225.158.17,67.225.158.18,67.225.158.19,67.225.168.207,67.225.179.95,67.225.203.66,67.227.134.31,67.228.10.28,67.228.10.29,67.228.101.157,67.228.111.217,67.228.112.232,67.228.112.233,67.228.112.234,67.228.112.235,67.228.120.3,67.228.122.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (187)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407373; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.128.55,67.228.137.255,67.228.139.19,67.228.139.205,67.228.139.26,67.228.144.205,67.228.144.211,67.228.144.253,67.228.144.26,67.228.164.196,67.228.174.51,67.228.174.57,67.228.175.180,67.228.177.112,67.228.177.178,67.228.177.181,67.228.177.219,67.228.177.240,67.228.186.114,67.228.187.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (188)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407374; rev:167; fwsam: src, 24 hours;) alert udp [67.228.128.55,67.228.137.255,67.228.139.19,67.228.139.205,67.228.139.26,67.228.144.205,67.228.144.211,67.228.144.253,67.228.144.26,67.228.164.196,67.228.174.51,67.228.174.57,67.228.175.180,67.228.177.112,67.228.177.178,67.228.177.181,67.228.177.219,67.228.177.240,67.228.186.114,67.228.187.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (188)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407375; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.188.64,67.228.189.128,67.228.189.192,67.228.194.20,67.228.194.237,67.228.200.14,67.228.216.5,67.228.216.9,67.228.22.132,67.228.22.133,67.228.22.134,67.228.22.135,67.228.222.240,67.228.222.241,67.228.222.242,67.228.222.243,67.228.222.244,67.228.222.245,67.228.222.246,67.228.222.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (189)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407376; rev:167; fwsam: src, 24 hours;) alert udp [67.228.188.64,67.228.189.128,67.228.189.192,67.228.194.20,67.228.194.237,67.228.200.14,67.228.216.5,67.228.216.9,67.228.22.132,67.228.22.133,67.228.22.134,67.228.22.135,67.228.222.240,67.228.222.241,67.228.222.242,67.228.222.243,67.228.222.244,67.228.222.245,67.228.222.246,67.228.222.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (189)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407377; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.224.78,67.228.23.52,67.228.237.248,67.228.237.249,67.228.237.251,67.228.244.248,67.228.250.128,67.228.250.129,67.228.250.130,67.228.250.131,67.228.250.132,67.228.250.133,67.228.250.134,67.228.250.135,67.228.250.136,67.228.250.137,67.228.250.138,67.228.250.139,67.228.250.140,67.228.250.141] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (190)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407378; rev:167; fwsam: src, 24 hours;) alert udp [67.228.224.78,67.228.23.52,67.228.237.248,67.228.237.249,67.228.237.251,67.228.244.248,67.228.250.128,67.228.250.129,67.228.250.130,67.228.250.131,67.228.250.132,67.228.250.133,67.228.250.134,67.228.250.135,67.228.250.136,67.228.250.137,67.228.250.138,67.228.250.139,67.228.250.140,67.228.250.141] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (190)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407379; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.250.142,67.228.250.143,67.228.250.144,67.228.250.145,67.228.250.146,67.228.250.147,67.228.250.148,67.228.250.149,67.228.250.150,67.228.250.151,67.228.250.152,67.228.250.153,67.228.250.154,67.228.250.155,67.228.250.156,67.228.250.157,67.228.250.158,67.228.250.159,67.228.26.116,67.228.3.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (191)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407380; rev:167; fwsam: src, 24 hours;) alert udp [67.228.250.142,67.228.250.143,67.228.250.144,67.228.250.145,67.228.250.146,67.228.250.147,67.228.250.148,67.228.250.149,67.228.250.150,67.228.250.151,67.228.250.152,67.228.250.153,67.228.250.154,67.228.250.155,67.228.250.156,67.228.250.157,67.228.250.158,67.228.250.159,67.228.26.116,67.228.3.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (191)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407381; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.3.140,67.228.37.8,67.228.38.114,67.228.39.206,67.228.47.0,67.228.50.241,67.228.53.176,67.228.53.177,67.228.53.178,67.228.53.179,67.228.53.180,67.228.53.181,67.228.53.182,67.228.53.183,67.228.60.152,67.228.60.153,67.228.60.154,67.228.60.155,67.228.77.0,67.228.77.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (192)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407382; rev:167; fwsam: src, 24 hours;) alert udp [67.228.3.140,67.228.37.8,67.228.38.114,67.228.39.206,67.228.47.0,67.228.50.241,67.228.53.176,67.228.53.177,67.228.53.178,67.228.53.179,67.228.53.180,67.228.53.181,67.228.53.182,67.228.53.183,67.228.60.152,67.228.60.153,67.228.60.154,67.228.60.155,67.228.77.0,67.228.77.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (192)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407383; rev:167; fwsam: src, 24 hours;) alert tcp [67.228.77.2,67.228.77.3,67.228.77.4,67.228.77.5,67.228.77.6,67.228.77.7,67.228.86.33,67.23.11.229,67.30.129.201,67.43.12.241,67.43.224.213,67.43.224.216,67.43.226.154,67.43.226.242,67.43.230.125,67.43.230.98,67.43.230.99,67.43.236.0/24,67.43.237.75,67.43.237.77] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (193)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407384; rev:167; fwsam: src, 24 hours;) alert udp [67.228.77.2,67.228.77.3,67.228.77.4,67.228.77.5,67.228.77.6,67.228.77.7,67.228.86.33,67.23.11.229,67.30.129.201,67.43.12.241,67.43.224.213,67.43.224.216,67.43.226.154,67.43.226.242,67.43.230.125,67.43.230.98,67.43.230.99,67.43.236.0/24,67.43.237.75,67.43.237.77] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (193)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407385; rev:167; fwsam: src, 24 hours;) alert tcp [67.43.237.78,67.43.239.57,67.43.239.58,67.43.3.69,67.43.62.54,67.55.51.116,67.55.63.238,67.55.79.181,67.55.81.0/24,68.154.37.89,68.168.212.142,68.169.42.25,68.173.95.152,68.174.23.154,68.178.254.234,68.180.151.74,68.233.192.223,68.47.99.249,69.1.2.202,69.1.78.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (194)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407386; rev:167; fwsam: src, 24 hours;) alert udp [67.43.237.78,67.43.239.57,67.43.239.58,67.43.3.69,67.43.62.54,67.55.51.116,67.55.63.238,67.55.79.181,67.55.81.0/24,68.154.37.89,68.168.212.142,68.169.42.25,68.173.95.152,68.174.23.154,68.178.254.234,68.180.151.74,68.233.192.223,68.47.99.249,69.1.2.202,69.1.78.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (194)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407387; rev:167; fwsam: src, 24 hours;) alert tcp [69.10.32.154,69.10.32.155,69.10.34.48,69.10.34.49,69.10.34.50,69.10.34.51,69.10.34.52,69.10.34.53,69.10.34.54,69.10.34.55,69.10.35.251,69.10.35.82,69.10.40.162,69.10.40.163,69.10.41.147,69.10.46.117,69.10.49.193,69.10.52.11,69.10.52.12,69.10.52.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (195)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407388; rev:167; fwsam: src, 24 hours;) alert udp [69.10.32.154,69.10.32.155,69.10.34.48,69.10.34.49,69.10.34.50,69.10.34.51,69.10.34.52,69.10.34.53,69.10.34.54,69.10.34.55,69.10.35.251,69.10.35.82,69.10.40.162,69.10.40.163,69.10.41.147,69.10.46.117,69.10.49.193,69.10.52.11,69.10.52.12,69.10.52.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (195)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407389; rev:167; fwsam: src, 24 hours;) alert tcp [69.10.52.14,69.10.57.194,69.10.59.34,69.10.61.243,69.10.61.244,69.10.61.245,69.10.61.246,69.10.62.2,69.136.229.57,69.14.164.117,69.147.239.106,69.154.143.170,69.156.240.29,69.16.137.252,69.16.229.102,69.161.130.233,69.162.111.26,69.162.114.62,69.162.138.142,69.162.66.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (196)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407390; rev:167; fwsam: src, 24 hours;) alert udp [69.10.52.14,69.10.57.194,69.10.59.34,69.10.61.243,69.10.61.244,69.10.61.245,69.10.61.246,69.10.62.2,69.136.229.57,69.14.164.117,69.147.239.106,69.154.143.170,69.156.240.29,69.16.137.252,69.16.229.102,69.161.130.233,69.162.111.26,69.162.114.62,69.162.138.142,69.162.66.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (196)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407391; rev:167; fwsam: src, 24 hours;) alert tcp [69.162.75.30,69.162.76.170,69.162.76.42,69.162.76.43,69.162.80.146,69.162.86.210,69.162.93.12,69.162.93.15,69.162.93.8,69.163.128.127,69.163.129.151,69.163.140.87,69.163.168.34,69.163.177.125,69.163.181.121,69.163.223.158,69.163.223.171,69.163.39.107,69.163.39.108,69.163.39.109] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (197)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407392; rev:167; fwsam: src, 24 hours;) alert udp [69.162.75.30,69.162.76.170,69.162.76.42,69.162.76.43,69.162.80.146,69.162.86.210,69.162.93.12,69.162.93.15,69.162.93.8,69.163.128.127,69.163.129.151,69.163.140.87,69.163.168.34,69.163.177.125,69.163.181.121,69.163.223.158,69.163.223.171,69.163.39.107,69.163.39.108,69.163.39.109] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (197)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407393; rev:167; fwsam: src, 24 hours;) alert tcp [69.172.129.154,69.174.245.145,69.174.245.147,69.174.245.148,69.175.10.74,69.197.128.203,69.197.128.26,69.197.144.178,69.20.104.139,69.20.104.41,69.20.117.228,69.20.68.36,69.20.68.41,69.20.71.82,69.20.71.83,69.22.168.0/21,69.22.184.0/22,69.237.82.158,69.249.213.188,69.251.151.205] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (198)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407394; rev:167; fwsam: src, 24 hours;) alert udp [69.172.129.154,69.174.245.145,69.174.245.147,69.174.245.148,69.175.10.74,69.197.128.203,69.197.128.26,69.197.144.178,69.20.104.139,69.20.104.41,69.20.117.228,69.20.68.36,69.20.68.41,69.20.71.82,69.20.71.83,69.22.168.0/21,69.22.184.0/22,69.237.82.158,69.249.213.188,69.251.151.205] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (198)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407395; rev:167; fwsam: src, 24 hours;) alert tcp [69.253.217.224,69.28.252.35,69.30.192.58,69.31.115.113,69.31.115.235,69.31.115.75,69.31.115.76,69.31.128.0/24,69.31.40.0/21,69.31.52.156,69.31.64.0/20,69.31.80.0/21,69.31.91.46,69.39.224.85,69.39.232.82,69.4.224.242,69.4.227.252,69.4.227.92,69.4.229.56,69.4.230.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (199)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407396; rev:167; fwsam: src, 24 hours;) alert udp [69.253.217.224,69.28.252.35,69.30.192.58,69.31.115.113,69.31.115.235,69.31.115.75,69.31.115.76,69.31.128.0/24,69.31.40.0/21,69.31.52.156,69.31.64.0/20,69.31.80.0/21,69.31.91.46,69.39.224.85,69.39.232.82,69.4.224.242,69.4.227.252,69.4.227.92,69.4.229.56,69.4.230.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (199)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407397; rev:167; fwsam: src, 24 hours;) alert tcp [69.4.232.241,69.4.232.81,69.4.32.137,69.41.183.0/24,69.42.216.0/24,69.42.65.148,69.42.83.68,69.46.16.254,69.46.16.99,69.46.20.189,69.46.228.171,69.46.228.231,69.46.228.36,69.46.228.45,69.46.228.55,69.46.230.60,69.46.25.35,69.50.134.34,69.50.160.0/19,69.50.193.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (200)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407398; rev:167; fwsam: src, 24 hours;) alert udp [69.4.232.241,69.4.232.81,69.4.32.137,69.41.183.0/24,69.42.216.0/24,69.42.65.148,69.42.83.68,69.46.16.254,69.46.16.99,69.46.20.189,69.46.228.171,69.46.228.231,69.46.228.36,69.46.228.45,69.46.228.55,69.46.230.60,69.46.25.35,69.50.134.34,69.50.160.0/19,69.50.193.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (200)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407399; rev:167; fwsam: src, 24 hours;) alert tcp [69.50.193.169,69.50.195.69,69.50.198.18,69.50.198.57,69.50.198.72,69.50.205.53,69.50.214.13,69.50.214.14,69.50.218.132,69.50.218.133,69.50.218.134,69.50.221.214,69.50.221.216,69.50.221.217,69.50.221.218,69.50.221.219,69.50.221.220,69.50.221.222,69.55.51.5,69.56.237.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (201)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407400; rev:167; fwsam: src, 24 hours;) alert udp [69.50.193.169,69.50.195.69,69.50.198.18,69.50.198.57,69.50.198.72,69.50.205.53,69.50.214.13,69.50.214.14,69.50.218.132,69.50.218.133,69.50.218.134,69.50.221.214,69.50.221.216,69.50.221.217,69.50.221.218,69.50.221.219,69.50.221.220,69.50.221.222,69.55.51.5,69.56.237.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (201)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407401; rev:167; fwsam: src, 24 hours;) alert tcp [69.57.168.194,69.57.172.37,69.57.174.58,69.57.174.59,69.57.174.62,69.57.174.67,69.57.174.68,69.57.174.69,69.57.175.202,69.57.175.203,69.57.175.204,69.57.175.205,69.57.180.67,69.59.17.194,69.59.17.195,69.59.17.196,69.59.17.202,69.59.17.203,69.59.17.5,69.59.17.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (202)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407402; rev:167; fwsam: src, 24 hours;) alert udp [69.57.168.194,69.57.172.37,69.57.174.58,69.57.174.59,69.57.174.62,69.57.174.67,69.57.174.68,69.57.174.69,69.57.175.202,69.57.175.203,69.57.175.204,69.57.175.205,69.57.180.67,69.59.17.194,69.59.17.195,69.59.17.196,69.59.17.202,69.59.17.203,69.59.17.5,69.59.17.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (202)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407403; rev:167; fwsam: src, 24 hours;) alert tcp [69.59.21.247,69.59.21.248,69.59.26.51,69.59.26.52,69.60.114.44,69.64.145.0/24,69.64.147.0/24,69.64.155.0/24,69.64.159.1,69.64.33.149,69.64.33.24,69.64.33.242,69.64.42.172,69.64.42.206,69.64.42.226,69.64.42.241,69.64.50.161,69.64.52.70,69.64.59.172,69.64.67.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (203)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407404; rev:167; fwsam: src, 24 hours;) alert udp [69.59.21.247,69.59.21.248,69.59.26.51,69.59.26.52,69.60.114.44,69.64.145.0/24,69.64.147.0/24,69.64.155.0/24,69.64.159.1,69.64.33.149,69.64.33.24,69.64.33.242,69.64.42.172,69.64.42.206,69.64.42.226,69.64.42.241,69.64.50.161,69.64.52.70,69.64.59.172,69.64.67.194] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (203)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407405; rev:167; fwsam: src, 24 hours;) alert tcp [69.64.81.149,69.65.27.133,69.65.31.110,69.65.31.113,69.65.40.26,69.65.42.149,69.65.48.216,69.65.5.122,69.65.60.193,69.65.96.217,69.72.142.98,69.72.172.10,69.72.180.194,69.72.255.8,69.73.129.21,69.73.158.14,69.73.181.159,69.73.191.7,69.89.17.18,69.89.20.48] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (204)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407406; rev:167; fwsam: src, 24 hours;) alert udp [69.64.81.149,69.65.27.133,69.65.31.110,69.65.31.113,69.65.40.26,69.65.42.149,69.65.48.216,69.65.5.122,69.65.60.193,69.65.96.217,69.72.142.98,69.72.172.10,69.72.180.194,69.72.255.8,69.73.129.21,69.73.158.14,69.73.181.159,69.73.191.7,69.89.17.18,69.89.20.48] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (204)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407407; rev:167; fwsam: src, 24 hours;) alert tcp [69.89.22.108,69.89.27.211,69.89.27.240,69.89.31.107,69.89.31.120,69.89.31.169,69.89.31.180,69.89.31.230,69.89.31.74,69.90.81.133,69.93.106.11,69.93.226.154,69.93.64.230,70.125.102.130,70.137.21.203,70.164.70.82,70.176.110.44,70.32.72.149,70.32.93.225,70.35.16.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (205)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407408; rev:167; fwsam: src, 24 hours;) alert udp [69.89.22.108,69.89.27.211,69.89.27.240,69.89.31.107,69.89.31.120,69.89.31.169,69.89.31.180,69.89.31.230,69.89.31.74,69.90.81.133,69.93.106.11,69.93.226.154,69.93.64.230,70.125.102.130,70.137.21.203,70.164.70.82,70.176.110.44,70.32.72.149,70.32.93.225,70.35.16.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (205)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407409; rev:167; fwsam: src, 24 hours;) alert tcp [70.35.16.23,70.35.16.245,70.35.29.174,70.35.29.8,70.35.30.113,70.35.30.26,70.35.30.66,70.38.11.165,70.38.11.171,70.38.11.184,70.38.11.59,70.38.19.201,70.38.19.202,70.38.19.203,70.38.19.204,70.38.19.205,70.38.19.206,70.38.19.250,70.38.2.33,70.38.2.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (206)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407410; rev:167; fwsam: src, 24 hours;) alert udp [70.35.16.23,70.35.16.245,70.35.29.174,70.35.29.8,70.35.30.113,70.35.30.26,70.35.30.66,70.38.11.165,70.38.11.171,70.38.11.184,70.38.11.59,70.38.19.201,70.38.19.202,70.38.19.203,70.38.19.204,70.38.19.205,70.38.19.206,70.38.19.250,70.38.2.33,70.38.2.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (206)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407411; rev:167; fwsam: src, 24 hours;) alert tcp [70.38.2.37,70.38.29.81,70.38.29.82,70.38.29.84,70.38.29.85,70.38.31.183,70.38.35.162,70.38.35.164,70.38.35.166,70.38.48.41,70.38.71.118,70.38.71.47,70.38.73.25,70.38.73.26,70.38.73.28,70.38.90.254,70.84.1.4,70.84.195.170,70.84.196.30,70.84.2.244] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (207)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407412; rev:167; fwsam: src, 24 hours;) alert udp [70.38.2.37,70.38.29.81,70.38.29.82,70.38.29.84,70.38.29.85,70.38.31.183,70.38.35.162,70.38.35.164,70.38.35.166,70.38.48.41,70.38.71.118,70.38.71.47,70.38.73.25,70.38.73.26,70.38.73.28,70.38.90.254,70.84.1.4,70.84.195.170,70.84.196.30,70.84.2.244] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (207)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407413; rev:167; fwsam: src, 24 hours;) alert tcp [70.84.201.130,70.84.32.114,70.85.114.186,70.85.142.250,70.85.227.66,70.85.236.206,70.85.249.98,70.85.25.254,70.85.52.99,70.85.95.140,70.86.103.194,70.86.12.226,70.86.161.14,70.86.182.194,70.86.196.66,70.86.54.100,70.86.54.101,70.86.54.98,70.86.54.99,70.86.91.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (208)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407414; rev:167; fwsam: src, 24 hours;) alert udp [70.84.201.130,70.84.32.114,70.85.114.186,70.85.142.250,70.85.227.66,70.85.236.206,70.85.249.98,70.85.25.254,70.85.52.99,70.85.95.140,70.86.103.194,70.86.12.226,70.86.161.14,70.86.182.194,70.86.196.66,70.86.54.100,70.86.54.101,70.86.54.98,70.86.54.99,70.86.91.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (208)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407415; rev:167; fwsam: src, 24 hours;) alert tcp [70.87.105.194,70.87.14.10,70.87.14.11,70.87.14.12,70.87.14.13,70.87.14.14,70.87.222.138,71.174.51.86,71.18.0.6,71.18.129.30,71.18.138.87,71.6.202.216,71.6.202.217,71.60.24.87,72.0.255.141,72.10.160.2,72.10.166.195,72.10.172.0/24,72.10.173.139,72.14.183.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (209)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407416; rev:167; fwsam: src, 24 hours;) alert udp [70.87.105.194,70.87.14.10,70.87.14.11,70.87.14.12,70.87.14.13,70.87.14.14,70.87.222.138,71.174.51.86,71.18.0.6,71.18.129.30,71.18.138.87,71.6.202.216,71.6.202.217,71.60.24.87,72.0.255.141,72.10.160.2,72.10.166.195,72.10.172.0/24,72.10.173.139,72.14.183.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (209)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407417; rev:167; fwsam: src, 24 hours;) alert tcp [72.14.187.85,72.14.213.191,72.167.121.94,72.167.131.114,72.167.131.145,72.167.131.174,72.167.131.40,72.167.195.124,72.167.195.125,72.167.232.152,72.167.232.171,72.167.232.200,72.167.232.205,72.167.232.209,72.167.232.42,72.167.232.8,72.18.135.82,72.18.141.26,72.18.156.50,72.20.26.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (210)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407418; rev:167; fwsam: src, 24 hours;) alert udp [72.14.187.85,72.14.213.191,72.167.121.94,72.167.131.114,72.167.131.145,72.167.131.174,72.167.131.40,72.167.195.124,72.167.195.125,72.167.232.152,72.167.232.171,72.167.232.200,72.167.232.205,72.167.232.209,72.167.232.42,72.167.232.8,72.18.135.82,72.18.141.26,72.18.156.50,72.20.26.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (210)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407419; rev:167; fwsam: src, 24 hours;) alert tcp [72.20.33.49,72.21.41.194,72.21.45.234,72.21.45.235,72.21.45.237,72.21.45.238,72.21.46.98,72.21.46.99,72.21.62.101,72.21.62.74,72.21.62.75,72.22.80.163,72.232.107.24,72.232.107.25,72.232.107.26,72.232.107.27,72.232.107.28,72.232.107.29,72.232.107.30,72.232.107.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (211)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407420; rev:167; fwsam: src, 24 hours;) alert udp [72.20.33.49,72.21.41.194,72.21.45.234,72.21.45.235,72.21.45.237,72.21.45.238,72.21.46.98,72.21.46.99,72.21.62.101,72.21.62.74,72.21.62.75,72.22.80.163,72.232.107.24,72.232.107.25,72.232.107.26,72.232.107.27,72.232.107.28,72.232.107.29,72.232.107.30,72.232.107.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (211)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407421; rev:167; fwsam: src, 24 hours;) alert tcp [72.232.107.33,72.232.107.34,72.232.107.35,72.232.107.36,72.232.107.37,72.232.107.38,72.232.107.39,72.232.116.36,72.232.116.39,72.232.116.51,72.232.116.77,72.232.116.84,72.232.117.65,72.232.117.84,72.232.163.171,72.232.184.11,72.232.184.251,72.232.184.252,72.232.184.253,72.232.184.254] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (212)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407422; rev:167; fwsam: src, 24 hours;) alert udp [72.232.107.33,72.232.107.34,72.232.107.35,72.232.107.36,72.232.107.37,72.232.107.38,72.232.107.39,72.232.116.36,72.232.116.39,72.232.116.51,72.232.116.77,72.232.116.84,72.232.117.65,72.232.117.84,72.232.163.171,72.232.184.11,72.232.184.251,72.232.184.252,72.232.184.253,72.232.184.254] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (212)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407423; rev:167; fwsam: src, 24 hours;) alert tcp [72.232.186.18,72.232.186.19,72.232.186.20,72.232.186.21,72.232.187.197,72.232.187.198,72.232.191.48,72.232.197.82,72.232.200.210,72.232.200.211,72.232.201.252,72.232.202.162,72.232.202.163,72.232.203.90,72.232.220.34,72.232.220.35,72.232.229.26,72.232.233.178,72.232.234.130,72.232.234.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (213)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407424; rev:167; fwsam: src, 24 hours;) alert udp [72.232.186.18,72.232.186.19,72.232.186.20,72.232.186.21,72.232.187.197,72.232.187.198,72.232.191.48,72.232.197.82,72.232.200.210,72.232.200.211,72.232.201.252,72.232.202.162,72.232.202.163,72.232.203.90,72.232.220.34,72.232.220.35,72.232.229.26,72.232.233.178,72.232.234.130,72.232.234.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (213)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407425; rev:167; fwsam: src, 24 hours;) alert tcp [72.232.237.202,72.232.237.226,72.232.242.250,72.232.242.82,72.232.242.86,72.232.245.114,72.232.245.98,72.232.254.170,72.232.8.202,72.232.8.203,72.232.84.186,72.232.97.234,72.232.97.235,72.233.114.126,72.233.114.90,72.233.115.169,72.233.28.210,72.233.29.122,72.233.29.123,72.233.29.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (214)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407426; rev:167; fwsam: src, 24 hours;) alert udp [72.232.237.202,72.232.237.226,72.232.242.250,72.232.242.82,72.232.242.86,72.232.245.114,72.232.245.98,72.232.254.170,72.232.8.202,72.232.8.203,72.232.84.186,72.232.97.234,72.232.97.235,72.233.114.126,72.233.114.90,72.233.115.169,72.233.28.210,72.233.29.122,72.233.29.123,72.233.29.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (214)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407427; rev:167; fwsam: src, 24 hours;) alert tcp [72.233.29.125,72.233.29.126,72.233.34.6,72.233.43.2,72.233.50.129,72.233.50.145,72.233.50.151,72.233.50.154,72.233.57.250,72.233.60.0/24,72.233.62.19,72.233.63.90,72.233.63.94,72.233.64.146,72.233.76.10,72.233.79.146,72.233.79.16,72.233.79.17,72.233.79.18,72.233.79.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (215)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407428; rev:167; fwsam: src, 24 hours;) alert udp [72.233.29.125,72.233.29.126,72.233.34.6,72.233.43.2,72.233.50.129,72.233.50.145,72.233.50.151,72.233.50.154,72.233.57.250,72.233.60.0/24,72.233.62.19,72.233.63.90,72.233.63.94,72.233.64.146,72.233.76.10,72.233.79.146,72.233.79.16,72.233.79.17,72.233.79.18,72.233.79.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (215)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407429; rev:167; fwsam: src, 24 hours;) alert tcp [72.233.79.20,72.233.79.21,72.233.79.22,72.233.79.23,72.233.89.148,72.233.89.151,72.249.105.234,72.249.108.120,72.249.144.130,72.249.191.123,72.249.61.36,72.26.101.150,72.26.145.118,72.29.67.139,72.29.70.127,72.29.83.197,72.29.87.105,72.3.182.114,72.32.134.197,72.32.242.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (216)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407430; rev:167; fwsam: src, 24 hours;) alert udp [72.233.79.20,72.233.79.21,72.233.79.22,72.233.79.23,72.233.89.148,72.233.89.151,72.249.105.234,72.249.108.120,72.249.144.130,72.249.191.123,72.249.61.36,72.26.101.150,72.26.145.118,72.29.67.139,72.29.70.127,72.29.83.197,72.29.87.105,72.3.182.114,72.32.134.197,72.32.242.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (216)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407431; rev:167; fwsam: src, 24 hours;) alert tcp [72.32.242.170,72.32.48.189,72.34.46.233,72.35.84.6,72.36.131.100,72.36.133.170,72.36.153.133,72.36.153.62,72.36.174.82,72.36.219.162,72.41.23.75,72.44.67.30,72.44.67.5,72.44.67.7,72.44.67.8,72.44.94.217,72.46.130.169,72.46.130.170,72.46.131.40,72.46.131.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (217)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407432; rev:167; fwsam: src, 24 hours;) alert udp [72.32.242.170,72.32.48.189,72.34.46.233,72.35.84.6,72.36.131.100,72.36.133.170,72.36.153.133,72.36.153.62,72.36.174.82,72.36.219.162,72.41.23.75,72.44.67.30,72.44.67.5,72.44.67.7,72.44.67.8,72.44.94.217,72.46.130.169,72.46.130.170,72.46.131.40,72.46.131.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (217)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407433; rev:167; fwsam: src, 24 hours;) alert tcp [72.46.131.45,72.47.202.204,72.47.203.130,72.47.208.234,72.47.221.40,72.5.169.70,72.51.38.101,72.51.41.155,72.51.41.229,72.51.47.21,72.52.133.217,72.52.140.4,72.52.158.105,72.52.180.18,72.52.210.130,72.52.210.131,72.52.210.132,72.52.210.133,72.55.146.80,72.55.165.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (218)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407434; rev:167; fwsam: src, 24 hours;) alert udp [72.46.131.45,72.47.202.204,72.47.203.130,72.47.208.234,72.47.221.40,72.5.169.70,72.51.38.101,72.51.41.155,72.51.41.229,72.51.47.21,72.52.133.217,72.52.140.4,72.52.158.105,72.52.180.18,72.52.210.130,72.52.210.131,72.52.210.132,72.52.210.133,72.55.146.80,72.55.165.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (218)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407435; rev:167; fwsam: src, 24 hours;) alert tcp [72.55.168.4,72.55.176.232,72.55.186.13,72.55.186.46,72.55.186.59,72.9.100.114,72.9.100.115,72.9.108.26,72.9.145.84,72.9.145.85,72.9.233.117,72.9.235.98,72.9.250.162,72.9.98.0/24,72.9.99.157,74.114.116.101,74.114.116.103,74.114.116.117,74.117.116.89,74.117.222.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (219)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407436; rev:167; fwsam: src, 24 hours;) alert udp [72.55.168.4,72.55.176.232,72.55.186.13,72.55.186.46,72.55.186.59,72.9.100.114,72.9.100.115,72.9.108.26,72.9.145.84,72.9.145.85,72.9.233.117,72.9.235.98,72.9.250.162,72.9.98.0/24,72.9.99.157,74.114.116.101,74.114.116.103,74.114.116.117,74.117.116.89,74.117.222.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (219)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407437; rev:167; fwsam: src, 24 hours;) alert tcp [74.117.222.42,74.118.192.19,74.118.192.20,74.118.192.21,74.118.192.23,74.118.192.25,74.118.192.26,74.118.192.27,74.118.192.28,74.118.192.29,74.118.192.30,74.118.192.31,74.118.192.32,74.200.196.100,74.200.220.211,74.200.220.212,74.200.220.213,74.200.220.214,74.200.220.215,74.200.66.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (220)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407438; rev:167; fwsam: src, 24 hours;) alert udp [74.117.222.42,74.118.192.19,74.118.192.20,74.118.192.21,74.118.192.23,74.118.192.25,74.118.192.26,74.118.192.27,74.118.192.28,74.118.192.29,74.118.192.30,74.118.192.31,74.118.192.32,74.200.196.100,74.200.220.211,74.200.220.212,74.200.220.213,74.200.220.214,74.200.220.215,74.200.66.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (220)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407439; rev:167; fwsam: src, 24 hours;) alert tcp [74.200.69.177,74.200.69.178,74.200.69.226,74.200.71.22,74.200.72.198,74.200.80.10,74.200.80.101,74.200.89.54,74.203.214.93,74.204.161.50,74.204.170.230,74.205.8.2,74.205.8.5,74.205.8.6,74.207.250.121,74.208.121.49,74.208.128.155,74.208.138.91,74.208.150.209,74.208.159.222] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (221)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407440; rev:167; fwsam: src, 24 hours;) alert udp [74.200.69.177,74.200.69.178,74.200.69.226,74.200.71.22,74.200.72.198,74.200.80.10,74.200.80.101,74.200.89.54,74.203.214.93,74.204.161.50,74.204.170.230,74.205.8.2,74.205.8.5,74.205.8.6,74.207.250.121,74.208.121.49,74.208.128.155,74.208.138.91,74.208.150.209,74.208.159.222] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (221)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407441; rev:167; fwsam: src, 24 hours;) alert tcp [74.208.165.187,74.208.165.216,74.208.169.14,74.208.169.94,74.208.182.6,74.208.186.187,74.208.26.93,74.208.28.131,74.208.28.195,74.208.29.179,74.208.30.100,74.208.30.208,74.208.58.228,74.208.84.159,74.208.85.223,74.208.89.200,74.213.167.190,74.213.167.191,74.213.179.102,74.213.179.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (222)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407442; rev:167; fwsam: src, 24 hours;) alert udp [74.208.165.187,74.208.165.216,74.208.169.14,74.208.169.94,74.208.182.6,74.208.186.187,74.208.26.93,74.208.28.131,74.208.28.195,74.208.29.179,74.208.30.100,74.208.30.208,74.208.58.228,74.208.84.159,74.208.85.223,74.208.89.200,74.213.167.190,74.213.167.191,74.213.179.102,74.213.179.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (222)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407443; rev:167; fwsam: src, 24 hours;) alert tcp [74.217.128.3,74.217.128.66,74.220.202.45,74.220.215.220,74.220.215.232,74.220.215.54,74.220.215.56,74.220.215.91,74.221.208.104,74.222.134.20,74.222.6.53,74.50.100.117,74.50.104.114,74.50.107.165,74.50.108.226,74.50.109.254,74.50.110.184,74.50.110.20,74.50.110.21,74.50.110.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (223)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407444; rev:167; fwsam: src, 24 hours;) alert udp [74.217.128.3,74.217.128.66,74.220.202.45,74.220.215.220,74.220.215.232,74.220.215.54,74.220.215.56,74.220.215.91,74.221.208.104,74.222.134.20,74.222.6.53,74.50.100.117,74.50.104.114,74.50.107.165,74.50.108.226,74.50.109.254,74.50.110.184,74.50.110.20,74.50.110.21,74.50.110.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (223)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407445; rev:167; fwsam: src, 24 hours;) alert tcp [74.50.110.226,74.50.110.23,74.50.110.24,74.50.113.0/24,74.50.117.66,74.50.117.67,74.50.117.68,74.50.117.70,74.50.117.71,74.50.117.84,74.50.117.86,74.50.117.87,74.50.117.88,74.50.117.89,74.50.117.95,74.50.119.187,74.50.119.70,74.50.119.94,74.50.120.150,74.50.120.68] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (224)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407446; rev:167; fwsam: src, 24 hours;) alert udp [74.50.110.226,74.50.110.23,74.50.110.24,74.50.113.0/24,74.50.117.66,74.50.117.67,74.50.117.68,74.50.117.70,74.50.117.71,74.50.117.84,74.50.117.86,74.50.117.87,74.50.117.88,74.50.117.89,74.50.117.95,74.50.119.187,74.50.119.70,74.50.119.94,74.50.120.150,74.50.120.68] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (224)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407447; rev:167; fwsam: src, 24 hours;) alert tcp [74.50.120.71,74.50.120.75,74.50.120.87,74.50.125.0/24,74.50.21.225,74.50.26.20,74.50.97.51,74.50.98.132,74.50.98.152,74.50.98.156,74.50.98.158,74.50.98.162,74.50.98.219,74.50.99.236,74.52.111.226,74.52.118.178,74.52.119.146,74.52.124.2,74.52.126.2,74.52.128.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (225)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407448; rev:167; fwsam: src, 24 hours;) alert udp [74.50.120.71,74.50.120.75,74.50.120.87,74.50.125.0/24,74.50.21.225,74.50.26.20,74.50.97.51,74.50.98.132,74.50.98.152,74.50.98.156,74.50.98.158,74.50.98.162,74.50.98.219,74.50.99.236,74.52.111.226,74.52.118.178,74.52.119.146,74.52.124.2,74.52.126.2,74.52.128.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (225)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407449; rev:167; fwsam: src, 24 hours;) alert tcp [74.52.144.66,74.52.16.154,74.52.164.210,74.52.179.179,74.52.212.235,74.52.238.242,74.52.238.243,74.52.32.0/24,74.52.35.85,74.52.35.86,74.52.35.87,74.52.59.66,74.52.59.67,74.52.78.234,74.52.94.178,74.53.108.50,74.53.128.243,74.53.128.246,74.53.169.2,74.53.184.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (226)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407450; rev:167; fwsam: src, 24 hours;) alert udp [74.52.144.66,74.52.16.154,74.52.164.210,74.52.179.179,74.52.212.235,74.52.238.242,74.52.238.243,74.52.32.0/24,74.52.35.85,74.52.35.86,74.52.35.87,74.52.59.66,74.52.59.67,74.52.78.234,74.52.94.178,74.53.108.50,74.53.128.243,74.53.128.246,74.53.169.2,74.53.184.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (226)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407451; rev:167; fwsam: src, 24 hours;) alert tcp [74.53.251.34,74.53.26.178,74.53.28.210,74.53.60.228,74.53.60.234,74.53.83.18,74.53.96.138,74.54.132.2,74.54.143.242,74.54.156.234,74.54.156.235,74.54.176.162,74.54.176.50,74.54.191.130,74.54.219.98,74.54.22.195,74.54.241.100,74.54.255.138,74.54.27.197,74.54.29.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (227)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407452; rev:167; fwsam: src, 24 hours;) alert udp [74.53.251.34,74.53.26.178,74.53.28.210,74.53.60.228,74.53.60.234,74.53.83.18,74.53.96.138,74.54.132.2,74.54.143.242,74.54.156.234,74.54.156.235,74.54.176.162,74.54.176.50,74.54.191.130,74.54.219.98,74.54.22.195,74.54.241.100,74.54.255.138,74.54.27.197,74.54.29.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (227)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407453; rev:167; fwsam: src, 24 hours;) alert tcp [74.54.29.70,74.54.81.147,74.54.82.0/24,74.54.93.130,74.55.100.8,74.55.113.34,74.55.116.90,74.55.136.64,74.55.136.65,74.55.136.66,74.55.136.67,74.55.136.68,74.55.136.69,74.55.136.70,74.55.136.71,74.55.136.72,74.55.136.73,74.55.136.74,74.55.136.75,74.55.136.76] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (228)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407454; rev:167; fwsam: src, 24 hours;) alert udp [74.54.29.70,74.54.81.147,74.54.82.0/24,74.54.93.130,74.55.100.8,74.55.113.34,74.55.116.90,74.55.136.64,74.55.136.65,74.55.136.66,74.55.136.67,74.55.136.68,74.55.136.69,74.55.136.70,74.55.136.71,74.55.136.72,74.55.136.73,74.55.136.74,74.55.136.75,74.55.136.76] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (228)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407455; rev:167; fwsam: src, 24 hours;) alert tcp [74.55.136.77,74.55.136.78,74.55.136.79,74.55.158.58,74.55.180.123,74.55.212.55,74.55.39.10,74.55.39.12,74.55.47.88,74.55.47.89,74.55.47.90,74.55.47.91,74.55.47.92,74.55.47.93,74.55.47.94,74.55.47.95,74.55.98.12,74.62.194.200,74.63.217.6,74.63.217.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (229)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407456; rev:167; fwsam: src, 24 hours;) alert udp [74.55.136.77,74.55.136.78,74.55.136.79,74.55.158.58,74.55.180.123,74.55.212.55,74.55.39.10,74.55.39.12,74.55.47.88,74.55.47.89,74.55.47.90,74.55.47.91,74.55.47.92,74.55.47.93,74.55.47.94,74.55.47.95,74.55.98.12,74.62.194.200,74.63.217.6,74.63.217.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (229)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407457; rev:167; fwsam: src, 24 hours;) alert tcp [74.63.35.204,74.63.78.3,74.63.80.50,74.81.78.68,74.81.81.84,74.86.100.164,74.86.100.165,74.86.100.166,74.86.100.167,74.86.115.0/24,74.86.132.176,74.86.132.177,74.86.132.178,74.86.132.179,74.86.134.37,74.86.147.0/24,74.86.154.0/24,74.86.158.8,74.86.160.56,74.86.187.24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (230)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407458; rev:167; fwsam: src, 24 hours;) alert udp [74.63.35.204,74.63.78.3,74.63.80.50,74.81.78.68,74.81.81.84,74.86.100.164,74.86.100.165,74.86.100.166,74.86.100.167,74.86.115.0/24,74.86.132.176,74.86.132.177,74.86.132.178,74.86.132.179,74.86.134.37,74.86.147.0/24,74.86.154.0/24,74.86.158.8,74.86.160.56,74.86.187.24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (230)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407459; rev:167; fwsam: src, 24 hours;) alert tcp [74.86.207.103,74.86.22.177,74.86.229.248,74.86.30.186,74.86.40.35,74.86.40.37,74.86.40.38,74.86.77.82,74.86.80.19,74.9.2.85,75.101.129.55,75.101.226.170,75.101.230.112,75.102.17.5,75.102.24.14,75.102.9.7,75.119.198.55,75.119.216.186,75.125.132.0,75.125.132.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (231)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407460; rev:167; fwsam: src, 24 hours;) alert udp [74.86.207.103,74.86.22.177,74.86.229.248,74.86.30.186,74.86.40.35,74.86.40.37,74.86.40.38,74.86.77.82,74.86.80.19,74.9.2.85,75.101.129.55,75.101.226.170,75.101.230.112,75.102.17.5,75.102.24.14,75.102.9.7,75.119.198.55,75.119.216.186,75.125.132.0,75.125.132.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (231)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407461; rev:167; fwsam: src, 24 hours;) alert tcp [75.125.132.3,75.125.132.5,75.125.135.195,75.125.135.196,75.125.135.202,75.125.135.205,75.125.148.76,75.125.150.218,75.125.156.78,75.125.158.66,75.125.162.114,75.125.162.115,75.125.164.240,75.125.164.241,75.125.164.242,75.125.164.243,75.125.164.246,75.125.164.247,75.125.178.144,75.125.178.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (232)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407462; rev:167; fwsam: src, 24 hours;) alert udp [75.125.132.3,75.125.132.5,75.125.135.195,75.125.135.196,75.125.135.202,75.125.135.205,75.125.148.76,75.125.150.218,75.125.156.78,75.125.158.66,75.125.162.114,75.125.162.115,75.125.164.240,75.125.164.241,75.125.164.242,75.125.164.243,75.125.164.246,75.125.164.247,75.125.178.144,75.125.178.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (232)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407463; rev:167; fwsam: src, 24 hours;) alert tcp [75.125.178.146,75.125.178.147,75.125.178.148,75.125.178.149,75.125.178.150,75.125.178.151,75.125.178.152,75.125.178.153,75.125.178.154,75.125.178.155,75.125.178.156,75.125.178.157,75.125.178.158,75.125.178.159,75.125.183.50,75.125.200.226,75.125.215.50,75.125.215.51,75.125.230.50,75.125.239.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (233)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407464; rev:167; fwsam: src, 24 hours;) alert udp [75.125.178.146,75.125.178.147,75.125.178.148,75.125.178.149,75.125.178.150,75.125.178.151,75.125.178.152,75.125.178.153,75.125.178.154,75.125.178.155,75.125.178.156,75.125.178.157,75.125.178.158,75.125.178.159,75.125.183.50,75.125.200.226,75.125.215.50,75.125.215.51,75.125.230.50,75.125.239.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (233)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407465; rev:167; fwsam: src, 24 hours;) alert tcp [75.125.239.41,75.125.239.42,75.125.239.43,75.125.239.44,75.125.239.45,75.125.239.46,75.125.239.47,75.125.241.58,75.125.244.114,75.125.246.34,75.125.61.163,75.126.135.220,75.126.137.166,75.126.142.106,75.126.142.108,75.126.149.156,75.126.206.122,75.126.206.125,75.126.211.148,75.126.22.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (234)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407466; rev:167; fwsam: src, 24 hours;) alert udp [75.125.239.41,75.125.239.42,75.125.239.43,75.125.239.44,75.125.239.45,75.125.239.46,75.125.239.47,75.125.241.58,75.125.244.114,75.125.246.34,75.125.61.163,75.126.135.220,75.126.137.166,75.126.142.106,75.126.142.108,75.126.149.156,75.126.206.122,75.126.206.125,75.126.211.148,75.126.22.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (234)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407467; rev:167; fwsam: src, 24 hours;) alert tcp [75.126.22.190,75.126.25.209,75.126.25.211,75.126.3.176,75.126.3.177,75.126.3.178,75.126.3.181,75.126.3.191,75.126.56.243,75.126.57.16,75.126.75.50,75.126.75.53,75.126.85.199,75.127.101.155,75.127.81.214,75.127.84.101,75.127.91.231,75.141.222.60,75.181.10.124,75.196.211.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (235)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407468; rev:167; fwsam: src, 24 hours;) alert udp [75.126.22.190,75.126.25.209,75.126.25.211,75.126.3.176,75.126.3.177,75.126.3.178,75.126.3.181,75.126.3.191,75.126.56.243,75.126.57.16,75.126.75.50,75.126.75.53,75.126.85.199,75.127.101.155,75.127.81.214,75.127.84.101,75.127.91.231,75.141.222.60,75.181.10.124,75.196.211.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (235)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407469; rev:167; fwsam: src, 24 hours;) alert tcp [75.36.218.139,76.124.90.2,76.127.250.95,76.162.102.189,76.162.108.1,76.162.143.189,76.162.178.195,76.163.188.201,76.163.253.1,76.191.100.17,76.214.53.219,76.225.39.23,76.31.251.157,76.73.12.138,76.73.32.102,76.73.32.147,76.73.35.156,76.73.35.157,76.73.37.250,76.73.43.68] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (236)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407470; rev:167; fwsam: src, 24 hours;) alert udp [75.36.218.139,76.124.90.2,76.127.250.95,76.162.102.189,76.162.108.1,76.162.143.189,76.162.178.195,76.163.188.201,76.163.253.1,76.191.100.17,76.214.53.219,76.225.39.23,76.31.251.157,76.73.12.138,76.73.32.102,76.73.32.147,76.73.35.156,76.73.35.157,76.73.37.250,76.73.43.68] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (236)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407471; rev:167; fwsam: src, 24 hours;) alert tcp [76.73.49.150,76.73.58.234,76.73.68.217,76.73.76.114,76.73.76.74,76.73.77.74,76.73.86.26,76.73.87.3,76.73.9.106,76.74.154.110,76.74.238.75,76.74.239.143,76.74.239.45,76.74.248.31,76.74.249.30,76.74.249.5,76.76.101.74,76.76.101.75,76.76.101.78,76.76.101.84] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (237)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407472; rev:167; fwsam: src, 24 hours;) alert udp [76.73.49.150,76.73.58.234,76.73.68.217,76.73.76.114,76.73.76.74,76.73.77.74,76.73.86.26,76.73.87.3,76.73.9.106,76.74.154.110,76.74.238.75,76.74.239.143,76.74.239.45,76.74.248.31,76.74.249.30,76.74.249.5,76.76.101.74,76.76.101.75,76.76.101.78,76.76.101.84] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (237)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407473; rev:167; fwsam: src, 24 hours;) alert tcp [76.76.101.85,76.76.101.86,76.76.103.162,76.76.103.163,76.76.103.164,76.76.103.166,76.76.103.82,76.76.22.221,76.76.3.154,76.76.99.51,76.76.99.52,76.76.99.53,76.83.51.154,76.9.23.148,77.124.33.174,77.220.177.0/24,77.220.178.56,77.221.128.0/19,77.222.40.0/22,77.222.56.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (238)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407474; rev:167; fwsam: src, 24 hours;) alert udp [76.76.101.85,76.76.101.86,76.76.103.162,76.76.103.163,76.76.103.164,76.76.103.166,76.76.103.82,76.76.22.221,76.76.3.154,76.76.99.51,76.76.99.52,76.76.99.53,76.83.51.154,76.9.23.148,77.124.33.174,77.220.177.0/24,77.220.178.56,77.221.128.0/19,77.222.40.0/22,77.222.56.124] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (238)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407475; rev:167; fwsam: src, 24 hours;) alert tcp [77.222.56.175,77.232.66.18,77.232.66.63,77.232.66.69,77.232.68.218,77.232.68.25,77.232.69.162,77.232.69.30,77.232.72.128,77.232.83.81,77.234.201.66,77.235.43.185,77.239.69.162,77.244.211.0/24,77.244.220.0/24,77.245.146.10,77.245.146.2,77.245.146.3,77.245.146.4,77.245.146.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (239)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407476; rev:167; fwsam: src, 24 hours;) alert udp [77.222.56.175,77.232.66.18,77.232.66.63,77.232.66.69,77.232.68.218,77.232.68.25,77.232.69.162,77.232.69.30,77.232.72.128,77.232.83.81,77.234.201.66,77.235.43.185,77.239.69.162,77.244.211.0/24,77.244.220.0/24,77.245.146.10,77.245.146.2,77.245.146.3,77.245.146.4,77.245.146.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (239)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407477; rev:167; fwsam: src, 24 hours;) alert tcp [77.245.146.6,77.245.146.7,77.245.146.8,77.245.148.54,77.245.61.0/24,77.247.178.40,77.247.178.41,77.247.178.42,77.37.14.18,77.37.18.36,77.37.18.61,77.37.19.173,77.37.19.179,77.37.19.198,77.37.19.43,77.73.98.0/24,77.74.12.60,77.74.197.117,77.74.48.107,77.87.192.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (240)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407478; rev:167; fwsam: src, 24 hours;) alert udp [77.245.146.6,77.245.146.7,77.245.146.8,77.245.148.54,77.245.61.0/24,77.247.178.40,77.247.178.41,77.247.178.42,77.37.14.18,77.37.18.36,77.37.18.61,77.37.19.173,77.37.19.179,77.37.19.198,77.37.19.43,77.73.98.0/24,77.74.12.60,77.74.197.117,77.74.48.107,77.87.192.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (240)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407479; rev:167; fwsam: src, 24 hours;) alert tcp [77.91.224.0/21,77.92.145.10,77.92.145.11,77.92.145.12,77.92.145.13,77.92.145.18,77.92.145.19,77.92.145.20,77.92.145.21,77.92.145.26,77.92.145.27,77.92.145.28,77.92.67.92,77.92.88.0/24,77.93.210.188,78.107.239.134,78.108.177.103,78.108.177.104,78.108.177.2,78.108.177.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (241)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407480; rev:167; fwsam: src, 24 hours;) alert udp [77.91.224.0/21,77.92.145.10,77.92.145.11,77.92.145.12,77.92.145.13,77.92.145.18,77.92.145.19,77.92.145.20,77.92.145.21,77.92.145.26,77.92.145.27,77.92.145.28,77.92.67.92,77.92.88.0/24,77.93.210.188,78.107.239.134,78.108.177.103,78.108.177.104,78.108.177.2,78.108.177.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (241)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407481; rev:167; fwsam: src, 24 hours;) alert tcp [78.108.177.31,78.108.177.32,78.108.177.34,78.108.177.94,78.108.178.208,78.108.178.25,78.108.178.57,78.108.179.100,78.108.179.166,78.108.179.213,78.108.179.222,78.108.179.23,78.108.179.71,78.108.179.73,78.108.179.77,78.108.180.18,78.108.180.233,78.108.180.90,78.108.182.164,78.108.183.227] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (242)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407482; rev:167; fwsam: src, 24 hours;) alert udp [78.108.177.31,78.108.177.32,78.108.177.34,78.108.177.94,78.108.178.208,78.108.178.25,78.108.178.57,78.108.179.100,78.108.179.166,78.108.179.213,78.108.179.222,78.108.179.23,78.108.179.71,78.108.179.73,78.108.179.77,78.108.180.18,78.108.180.233,78.108.180.90,78.108.182.164,78.108.183.227] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (242)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407483; rev:167; fwsam: src, 24 hours;) alert tcp [78.108.184.48,78.108.190.0/24,78.108.81.100,78.108.81.170,78.108.87.119,78.109.16.219,78.109.17.106,78.109.18.10,78.109.18.205,78.109.18.210,78.109.18.234,78.109.18.8,78.109.20.106,78.109.20.154,78.109.20.162,78.109.20.50,78.109.21.186,78.109.22.131,78.109.22.135,78.109.23.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (243)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407484; rev:167; fwsam: src, 24 hours;) alert udp [78.108.184.48,78.108.190.0/24,78.108.81.100,78.108.81.170,78.108.87.119,78.109.16.219,78.109.17.106,78.109.18.10,78.109.18.205,78.109.18.210,78.109.18.234,78.109.18.8,78.109.20.106,78.109.20.154,78.109.20.162,78.109.20.50,78.109.21.186,78.109.22.131,78.109.22.135,78.109.23.1] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (243)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407485; rev:167; fwsam: src, 24 hours;) alert tcp [78.109.23.2,78.109.23.3,78.109.23.4,78.109.23.5,78.109.23.6,78.109.23.64,78.109.23.7,78.109.25.216,78.109.25.217,78.109.25.218,78.109.25.33,78.109.28.144,78.109.28.216,78.109.28.217,78.109.28.41,78.109.28.45,78.109.29.112,78.109.29.114,78.109.29.116,78.109.29.33] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (244)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407486; rev:167; fwsam: src, 24 hours;) alert udp [78.109.23.2,78.109.23.3,78.109.23.4,78.109.23.5,78.109.23.6,78.109.23.64,78.109.23.7,78.109.25.216,78.109.25.217,78.109.25.218,78.109.25.33,78.109.28.144,78.109.28.216,78.109.28.217,78.109.28.41,78.109.28.45,78.109.29.112,78.109.29.114,78.109.29.116,78.109.29.33] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (244)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407487; rev:167; fwsam: src, 24 hours;) alert tcp [78.109.29.40,78.109.30.196,78.109.30.200,78.110.166.108,78.110.166.203,78.110.166.60,78.110.172.15,78.110.174.135,78.110.175.15,78.110.175.21,78.110.50.110,78.110.50.113,78.110.50.119,78.110.50.132,78.111.80.213,78.111.80.65,78.129.134.50,78.129.158.68,78.129.166.0/24,78.129.196.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (245)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407488; rev:167; fwsam: src, 24 hours;) alert udp [78.109.29.40,78.109.30.196,78.109.30.200,78.110.166.108,78.110.166.203,78.110.166.60,78.110.172.15,78.110.174.135,78.110.175.15,78.110.175.21,78.110.50.110,78.110.50.113,78.110.50.119,78.110.50.132,78.111.80.213,78.111.80.65,78.129.134.50,78.129.158.68,78.129.166.0/24,78.129.196.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (245)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407489; rev:167; fwsam: src, 24 hours;) alert tcp [78.129.202.0/24,78.129.205.64,78.129.214.103,78.129.223.19,78.129.233.17,78.137.168.33,78.140.132.11,78.140.133.15,78.140.138.105,78.140.139.105,78.140.141.107,78.140.141.114,78.140.143.103,78.140.143.13,78.140.145.144,78.140.170.164,78.140.23.18,78.143.16.7,78.143.46.124,78.157.129.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (246)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407490; rev:167; fwsam: src, 24 hours;) alert udp [78.129.202.0/24,78.129.205.64,78.129.214.103,78.129.223.19,78.129.233.17,78.137.168.33,78.140.132.11,78.140.133.15,78.140.138.105,78.140.139.105,78.140.141.107,78.140.141.114,78.140.143.103,78.140.143.13,78.140.145.144,78.140.170.164,78.140.23.18,78.143.16.7,78.143.46.124,78.157.129.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (246)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407491; rev:167; fwsam: src, 24 hours;) alert tcp [78.157.141.0/24,78.157.142.0/24,78.157.143.0/24,78.159.101.166,78.159.101.239,78.159.101.27,78.159.101.40,78.159.102.97,78.159.102.99,78.159.106.129,78.159.106.130,78.159.106.158,78.159.106.159,78.159.112.146,78.159.112.200,78.159.112.25,78.159.112.43,78.159.112.98,78.159.114.116,78.159.114.175] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (247)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407492; rev:167; fwsam: src, 24 hours;) alert udp [78.157.141.0/24,78.157.142.0/24,78.157.143.0/24,78.159.101.166,78.159.101.239,78.159.101.27,78.159.101.40,78.159.102.97,78.159.102.99,78.159.106.129,78.159.106.130,78.159.106.158,78.159.106.159,78.159.112.146,78.159.112.200,78.159.112.25,78.159.112.43,78.159.112.98,78.159.114.116,78.159.114.175] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (247)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407493; rev:167; fwsam: src, 24 hours;) alert tcp [78.159.114.189,78.159.115.122,78.159.115.215,78.159.115.216,78.159.117.102,78.159.118.0/24,78.159.119.75,78.159.122.197,78.159.124.235,78.159.124.247,78.159.125.159,78.159.126.199,78.159.96.134,78.159.96.16,78.159.96.42,78.159.96.56,78.159.97.21,78.159.97.49,78.159.98.112,78.159.98.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (248)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407494; rev:167; fwsam: src, 24 hours;) alert udp [78.159.114.189,78.159.115.122,78.159.115.215,78.159.115.216,78.159.117.102,78.159.118.0/24,78.159.119.75,78.159.122.197,78.159.124.235,78.159.124.247,78.159.125.159,78.159.126.199,78.159.96.134,78.159.96.16,78.159.96.42,78.159.96.56,78.159.97.21,78.159.97.49,78.159.98.112,78.159.98.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (248)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407495; rev:167; fwsam: src, 24 hours;) alert tcp [78.159.98.217,78.159.98.70,78.159.98.93,78.159.99.224,78.159.99.52,78.159.99.54,78.159.99.66,78.24.218.89,78.24.219.164,78.25.27.20,78.26.144.206,78.26.179.0/24,78.28.197.90,78.28.197.92,78.28.197.94,78.31.65.216,78.40.227.99,78.41.207.196,78.46.100.211,78.46.118.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (249)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407496; rev:167; fwsam: src, 24 hours;) alert udp [78.159.98.217,78.159.98.70,78.159.98.93,78.159.99.224,78.159.99.52,78.159.99.54,78.159.99.66,78.24.218.89,78.24.219.164,78.25.27.20,78.26.144.206,78.26.179.0/24,78.28.197.90,78.28.197.92,78.28.197.94,78.31.65.216,78.40.227.99,78.41.207.196,78.46.100.211,78.46.118.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (249)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407497; rev:167; fwsam: src, 24 hours;) alert tcp [78.46.129.170,78.46.148.49,78.46.151.181,78.46.152.171,78.46.152.8,78.46.183.24,78.46.183.25,78.46.183.26,78.46.183.30,78.46.183.31,78.46.197.82,78.46.201.89,78.46.201.90,78.46.201.92,78.46.205.65,78.46.205.69,78.46.205.70,78.46.216.233,78.46.216.237,78.46.216.238] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (250)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407498; rev:167; fwsam: src, 24 hours;) alert udp [78.46.129.170,78.46.148.49,78.46.151.181,78.46.152.171,78.46.152.8,78.46.183.24,78.46.183.25,78.46.183.26,78.46.183.30,78.46.183.31,78.46.197.82,78.46.201.89,78.46.201.90,78.46.201.92,78.46.205.65,78.46.205.69,78.46.205.70,78.46.216.233,78.46.216.237,78.46.216.238] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (250)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407499; rev:167; fwsam: src, 24 hours;) alert tcp [78.46.218.254,78.46.251.41,78.46.251.43,78.46.254.17,78.46.254.18,78.46.254.22,78.46.33.111,78.46.67.80,78.46.7.50,78.46.73.197,78.46.86.4,78.46.88.142,78.46.88.202,78.46.90.230,78.46.91.6,78.47.100.189,78.47.127.10,78.47.132.216,78.47.132.220,78.47.132.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (251)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407500; rev:167; fwsam: src, 24 hours;) alert udp [78.46.218.254,78.46.251.41,78.46.251.43,78.46.254.17,78.46.254.18,78.46.254.22,78.46.33.111,78.46.67.80,78.46.7.50,78.46.73.197,78.46.86.4,78.46.88.142,78.46.88.202,78.46.90.230,78.46.91.6,78.47.100.189,78.47.127.10,78.47.132.216,78.47.132.220,78.47.132.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (251)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407501; rev:167; fwsam: src, 24 hours;) alert tcp [78.47.132.222,78.47.159.185,78.47.159.186,78.47.159.189,78.47.159.54,78.47.168.82,78.47.172.66,78.47.172.67,78.47.200.155,78.47.209.65,78.47.222.220,78.47.222.221,78.47.230.33,78.47.230.38,78.47.231.2,78.47.240.106,78.47.248.113,78.47.249.230,78.47.91.153,78.47.91.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (252)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407502; rev:167; fwsam: src, 24 hours;) alert udp [78.47.132.222,78.47.159.185,78.47.159.186,78.47.159.189,78.47.159.54,78.47.168.82,78.47.172.66,78.47.172.67,78.47.200.155,78.47.209.65,78.47.222.220,78.47.222.221,78.47.230.33,78.47.230.38,78.47.231.2,78.47.240.106,78.47.248.113,78.47.249.230,78.47.91.153,78.47.91.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (252)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407503; rev:167; fwsam: src, 24 hours;) alert tcp [78.47.91.155,79.109.152.177,79.112.76.56,79.113.183.19,79.113.23.229,79.113.7.140,79.113.83.13,79.118.122.79,79.132.198.0/24,79.132.211.0/24,79.135.152.5,79.135.160.0/19,79.143.176.0/22,79.170.40.21,79.170.40.230,79.170.40.38,79.174.64.13,79.174.64.217,79.174.64.228,79.174.64.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (253)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407504; rev:167; fwsam: src, 24 hours;) alert udp [78.47.91.155,79.109.152.177,79.112.76.56,79.113.183.19,79.113.23.229,79.113.7.140,79.113.83.13,79.118.122.79,79.132.198.0/24,79.132.211.0/24,79.135.152.5,79.135.160.0/19,79.143.176.0/22,79.170.40.21,79.170.40.230,79.170.40.38,79.174.64.13,79.174.64.217,79.174.64.228,79.174.64.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (253)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407505; rev:167; fwsam: src, 24 hours;) alert tcp [79.174.66.47,79.174.68.34,79.174.72.200,79.174.72.79,79.174.72.85,79.174.73.71,79.176.56.52,79.179.121.249,79.179.70.34,79.71.239.81,79.98.25.99,79.98.27.6,79.99.122.34,79.99.69.135,8.12.35.78,8.21.33.134,80.109.240.72,80.121.47.22,80.156.86.78,80.169.63.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (254)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407506; rev:167; fwsam: src, 24 hours;) alert udp [79.174.66.47,79.174.68.34,79.174.72.200,79.174.72.79,79.174.72.85,79.174.73.71,79.176.56.52,79.179.121.249,79.179.70.34,79.71.239.81,79.98.25.99,79.98.27.6,79.99.122.34,79.99.69.135,8.12.35.78,8.21.33.134,80.109.240.72,80.121.47.22,80.156.86.78,80.169.63.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (254)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407507; rev:167; fwsam: src, 24 hours;) alert tcp [80.172.236.66,80.179.12.15,80.190.54.181,80.196.101.229,80.233.168.21,80.233.221.247,80.233.221.253,80.237.132.56,80.24.176.145,80.247.64.150,80.247.67.231,80.248.208.141,80.248.208.205,80.250.24.17,80.250.24.18,80.251.16.2,80.253.225.12,80.69.74.73,80.69.82.11,80.69.82.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (255)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407508; rev:167; fwsam: src, 24 hours;) alert udp [80.172.236.66,80.179.12.15,80.190.54.181,80.196.101.229,80.233.168.21,80.233.221.247,80.233.221.253,80.237.132.56,80.24.176.145,80.247.64.150,80.247.67.231,80.248.208.141,80.248.208.205,80.250.24.17,80.250.24.18,80.251.16.2,80.253.225.12,80.69.74.73,80.69.82.11,80.69.82.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (255)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407509; rev:167; fwsam: src, 24 hours;) alert tcp [80.70.224.0/20,80.74.157.11,80.77.80.0/20,80.79.118.184,80.79.118.210,80.79.118.211,80.79.119.100,80.79.119.104,80.79.119.138,80.82.114.137,80.83.210.226,80.86.198.13,80.86.87.241,80.86.89.131,80.87.199.13,80.87.199.14,80.87.206.99,80.90.114.11,80.90.114.34,80.90.118.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (256)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407510; rev:167; fwsam: src, 24 hours;) alert udp [80.70.224.0/20,80.74.157.11,80.77.80.0/20,80.79.118.184,80.79.118.210,80.79.118.211,80.79.119.100,80.79.119.104,80.79.119.138,80.82.114.137,80.83.210.226,80.86.198.13,80.86.87.241,80.86.89.131,80.87.199.13,80.87.199.14,80.87.206.99,80.90.114.11,80.90.114.34,80.90.118.102] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (256)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407511; rev:167; fwsam: src, 24 hours;) alert tcp [80.90.118.34,80.90.118.35,80.90.118.37,80.90.160.58,80.91.176.135,80.91.176.174,80.91.177.106,80.91.191.138,80.91.191.156,80.91.191.170,80.91.191.188,80.91.76.147,80.91.76.148,80.91.76.149,80.91.76.150,80.91.76.151,80.91.76.152,80.91.76.153,80.91.76.154,80.92.162.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (257)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407512; rev:167; fwsam: src, 24 hours;) alert udp [80.90.118.34,80.90.118.35,80.90.118.37,80.90.160.58,80.91.176.135,80.91.176.174,80.91.177.106,80.91.191.138,80.91.191.156,80.91.191.170,80.91.191.188,80.91.76.147,80.91.76.148,80.91.76.149,80.91.76.150,80.91.76.151,80.91.76.152,80.91.76.153,80.91.76.154,80.92.162.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (257)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407513; rev:167; fwsam: src, 24 hours;) alert tcp [80.93.216.229,80.93.48.54,80.93.49.141,80.93.49.192,80.93.50.149,80.93.50.78,80.93.51.217,80.93.54.56,80.93.54.57,80.93.54.68,80.93.54.78,80.93.56.4,80.93.57.179,80.93.57.211,80.93.62.112,80.93.62.114,80.93.62.125,80.93.62.127,80.95.160.73,81.169.145.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (258)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407514; rev:167; fwsam: src, 24 hours;) alert udp [80.93.216.229,80.93.48.54,80.93.49.141,80.93.49.192,80.93.50.149,80.93.50.78,80.93.51.217,80.93.54.56,80.93.54.57,80.93.54.68,80.93.54.78,80.93.56.4,80.93.57.179,80.93.57.211,80.93.62.112,80.93.62.114,80.93.62.125,80.93.62.127,80.95.160.73,81.169.145.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (258)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407515; rev:167; fwsam: src, 24 hours;) alert tcp [81.169.145.67,81.169.145.69,81.169.145.70,81.169.145.72,81.169.145.73,81.169.145.74,81.169.145.85,81.174.66.128,81.174.66.26,81.176.224.188,81.176.226.110,81.176.226.166,81.176.226.188,81.176.226.80,81.176.232.102,81.176.232.103,81.176.232.104,81.176.236.12,81.176.68.175,81.176.68.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (259)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407516; rev:167; fwsam: src, 24 hours;) alert udp [81.169.145.67,81.169.145.69,81.169.145.70,81.169.145.72,81.169.145.73,81.169.145.74,81.169.145.85,81.174.66.128,81.174.66.26,81.176.224.188,81.176.226.110,81.176.226.166,81.176.226.188,81.176.226.80,81.176.232.102,81.176.232.103,81.176.232.104,81.176.236.12,81.176.68.175,81.176.68.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (259)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407517; rev:167; fwsam: src, 24 hours;) alert tcp [81.176.68.248,81.176.68.47,81.176.68.61,81.177.14.209,81.177.157.22,81.177.22.144,81.177.23.68,81.177.26.41,81.177.3.211,81.177.3.229,81.177.3.242,81.177.3.88,81.177.3.99,81.177.32.14,81.177.32.250,81.177.6.0/24,81.177.8.0/24,81.177.9.32,81.198.255.197,81.20.97.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (260)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407518; rev:167; fwsam: src, 24 hours;) alert udp [81.176.68.248,81.176.68.47,81.176.68.61,81.177.14.209,81.177.157.22,81.177.22.144,81.177.23.68,81.177.26.41,81.177.3.211,81.177.3.229,81.177.3.242,81.177.3.88,81.177.3.99,81.177.32.14,81.177.32.250,81.177.6.0/24,81.177.8.0/24,81.177.9.32,81.198.255.197,81.20.97.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (260)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407519; rev:167; fwsam: src, 24 hours;) alert tcp [81.209.164.65,81.22.60.153,81.222.2.22,81.222.8.2,81.222.9.2,81.222.9.6,81.223.238.227,81.27.32.145,81.31.152.218,81.31.38.122,81.31.42.131,81.4.97.188,81.4.97.194,81.88.48.95,81.9.5.197,81.94.131.81,81.94.16.0/20,81.94.51.58,81.95.128.0/19,81.95.144.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (261)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407520; rev:167; fwsam: src, 24 hours;) alert udp [81.209.164.65,81.22.60.153,81.222.2.22,81.222.8.2,81.222.9.2,81.222.9.6,81.223.238.227,81.27.32.145,81.31.152.218,81.31.38.122,81.31.42.131,81.4.97.188,81.4.97.194,81.88.48.95,81.9.5.197,81.94.131.81,81.94.16.0/20,81.94.51.58,81.95.128.0/19,81.95.144.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (261)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407521; rev:167; fwsam: src, 24 hours;) alert tcp [81.95.156.0/22,81.95.96.126,82.102.15.48,82.102.6.97,82.103.130.171,82.103.131.211,82.103.132.114,82.103.134.106,82.103.137.14,82.103.138.10,82.103.138.37,82.109.45.51,82.110.105.3,82.119.226.100,82.120.80.136,82.129.13.244,82.131.156.180,82.140.107.46,82.144.222.149,82.144.242.175] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (262)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407522; rev:167; fwsam: src, 24 hours;) alert udp [81.95.156.0/22,81.95.96.126,82.102.15.48,82.102.6.97,82.103.130.171,82.103.131.211,82.103.132.114,82.103.134.106,82.103.137.14,82.103.138.10,82.103.138.37,82.109.45.51,82.110.105.3,82.119.226.100,82.120.80.136,82.129.13.244,82.131.156.180,82.140.107.46,82.144.222.149,82.144.242.175] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (262)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407523; rev:167; fwsam: src, 24 hours;) alert tcp [82.146.32.213,82.146.33.103,82.146.33.243,82.146.35.143,82.146.35.18,82.146.40.34,82.146.42.15,82.146.42.8,82.146.43.173,82.146.43.18,82.146.43.2,82.146.43.3,82.146.49.1,82.146.50.202,82.146.51.126,82.146.51.25,82.146.52.158,82.146.55.23,82.146.55.35,82.146.55.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (263)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407524; rev:167; fwsam: src, 24 hours;) alert udp [82.146.32.213,82.146.33.103,82.146.33.243,82.146.35.143,82.146.35.18,82.146.40.34,82.146.42.15,82.146.42.8,82.146.43.173,82.146.43.18,82.146.43.2,82.146.43.3,82.146.49.1,82.146.50.202,82.146.51.126,82.146.51.25,82.146.52.158,82.146.55.23,82.146.55.35,82.146.55.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (263)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407525; rev:167; fwsam: src, 24 hours;) alert tcp [82.146.56.0/21,82.146.62.64,82.147.88.149,82.150.140.14,82.151.132.40,82.165.111.89,82.165.116.190,82.165.117.22,82.165.118.217,82.165.118.40,82.165.122.104,82.165.180.64,82.165.201.27,82.165.204.43,82.165.205.16,82.165.211.180,82.165.50.57,82.165.53.20,82.165.56.46,82.165.73.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (264)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407526; rev:167; fwsam: src, 24 hours;) alert udp [82.146.56.0/21,82.146.62.64,82.147.88.149,82.150.140.14,82.151.132.40,82.165.111.89,82.165.116.190,82.165.117.22,82.165.118.217,82.165.118.40,82.165.122.104,82.165.180.64,82.165.201.27,82.165.204.43,82.165.205.16,82.165.211.180,82.165.50.57,82.165.53.20,82.165.56.46,82.165.73.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (264)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407527; rev:167; fwsam: src, 24 hours;) alert tcp [82.165.77.218,82.166.132.221,82.192.87.96,82.192.88.109,82.192.88.35,82.194.76.201,82.197.130.134,82.197.131.14,82.197.131.17,82.197.131.21,82.197.146.54,82.198.176.34,82.200.96.0/23,82.204.219.135,82.204.219.208,82.204.219.221,82.204.219.223,82.204.219.224,82.204.219.237,82.204.219.251] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (265)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407528; rev:167; fwsam: src, 24 hours;) alert udp [82.165.77.218,82.166.132.221,82.192.87.96,82.192.88.109,82.192.88.35,82.194.76.201,82.197.130.134,82.197.131.14,82.197.131.17,82.197.131.21,82.197.146.54,82.198.176.34,82.200.96.0/23,82.204.219.135,82.204.219.208,82.204.219.221,82.204.219.223,82.204.219.224,82.204.219.237,82.204.219.251] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (265)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407529; rev:167; fwsam: src, 24 hours;) alert tcp [82.208.46.112,82.208.58.199,82.98.144.14,82.98.193.102,82.98.231.25,82.98.235.155,82.98.235.173,82.98.235.182,82.98.235.187,82.98.235.24,82.98.235.52,82.98.235.66,82.98.235.90,82.98.86.0/24,83.133.113.14,83.133.115.9,83.133.118.67,83.133.118.70,83.133.118.72,83.133.119.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (266)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407530; rev:167; fwsam: src, 24 hours;) alert udp [82.208.46.112,82.208.58.199,82.98.144.14,82.98.193.102,82.98.231.25,82.98.235.155,82.98.235.173,82.98.235.182,82.98.235.187,82.98.235.24,82.98.235.52,82.98.235.66,82.98.235.90,82.98.86.0/24,83.133.113.14,83.133.115.9,83.133.118.67,83.133.118.70,83.133.118.72,83.133.119.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (266)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407531; rev:167; fwsam: src, 24 hours;) alert tcp [83.133.119.155,83.133.119.84,83.133.121.153,83.133.122.158,83.133.122.159,83.133.122.160,83.133.122.211,83.133.123.109,83.133.123.113,83.133.123.139,83.133.123.140,83.133.123.166,83.133.123.174,83.133.123.19,83.133.124.240,83.133.124.44,83.133.124.81,83.133.125.116,83.133.126.155,83.133.126.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (267)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407532; rev:167; fwsam: src, 24 hours;) alert udp [83.133.119.155,83.133.119.84,83.133.121.153,83.133.122.158,83.133.122.159,83.133.122.160,83.133.122.211,83.133.123.109,83.133.123.113,83.133.123.139,83.133.123.140,83.133.123.166,83.133.123.174,83.133.123.19,83.133.124.240,83.133.124.44,83.133.124.81,83.133.125.116,83.133.126.155,83.133.126.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (267)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407533; rev:167; fwsam: src, 24 hours;) alert tcp [83.133.126.46,83.133.126.98,83.133.127.93,83.137.192.222,83.137.194.108,83.140.191.170,83.142.230.169,83.142.230.175,83.142.230.44,83.142.230.45,83.143.81.10,83.149.105.88,83.149.112.111,83.149.112.115,83.149.112.96,83.149.69.46,83.149.69.47,83.149.72.171,83.149.72.172,83.149.74.250] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (268)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407534; rev:167; fwsam: src, 24 hours;) alert udp [83.133.126.46,83.133.126.98,83.133.127.93,83.137.192.222,83.137.194.108,83.140.191.170,83.142.230.169,83.142.230.175,83.142.230.44,83.142.230.45,83.143.81.10,83.149.105.88,83.149.112.111,83.149.112.115,83.149.112.96,83.149.69.46,83.149.69.47,83.149.72.171,83.149.72.172,83.149.74.250] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (268)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407535; rev:167; fwsam: src, 24 hours;) alert tcp [83.149.75.50,83.149.75.56,83.149.82.186,83.149.85.100,83.149.86.132,83.149.87.200,83.149.95.208,83.15.82.74,83.168.205.230,83.168.238.66,83.17.76.98,83.170.116.39,83.170.93.113,83.171.76.98,83.171.76.99,83.172.0.56,83.172.144.47,83.19.144.26,83.211.240.146,83.222.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (269)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407536; rev:167; fwsam: src, 24 hours;) alert udp [83.149.75.50,83.149.75.56,83.149.82.186,83.149.85.100,83.149.86.132,83.149.87.200,83.149.95.208,83.15.82.74,83.168.205.230,83.168.238.66,83.17.76.98,83.170.116.39,83.170.93.113,83.171.76.98,83.171.76.99,83.172.0.56,83.172.144.47,83.19.144.26,83.211.240.146,83.222.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (269)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407537; rev:167; fwsam: src, 24 hours;) alert tcp [83.222.104.73,83.222.112.66,83.229.248.147,83.229.250.27,83.229.251.28,83.229.251.29,83.229.251.37,83.229.252.71,83.233.165.108,83.233.165.205,83.233.165.214,83.233.165.229,83.233.165.245,83.233.165.27,83.233.165.69,83.233.30.101,83.233.30.140,83.233.30.157,83.233.30.159,83.233.30.64] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (270)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407538; rev:167; fwsam: src, 24 hours;) alert udp [83.222.104.73,83.222.112.66,83.229.248.147,83.229.250.27,83.229.251.28,83.229.251.29,83.229.251.37,83.229.252.71,83.233.165.108,83.233.165.205,83.233.165.214,83.233.165.229,83.233.165.245,83.233.165.27,83.233.165.69,83.233.30.101,83.233.30.140,83.233.30.157,83.233.30.159,83.233.30.64] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (270)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407539; rev:167; fwsam: src, 24 hours;) alert tcp [83.233.30.65,83.233.30.66,83.233.30.79,83.243.70.11,83.249.125.230,83.249.135.141,83.30.96.19,83.45.96.101,83.68.16.30,83.68.16.6,84.113.4.128,84.16.224.183,84.16.224.199,84.16.224.55,84.16.227.222,84.16.227.223,84.16.227.72,84.16.228.142,84.16.228.143,84.16.228.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (271)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407540; rev:167; fwsam: src, 24 hours;) alert udp [83.233.30.65,83.233.30.66,83.233.30.79,83.243.70.11,83.249.125.230,83.249.135.141,83.30.96.19,83.45.96.101,83.68.16.30,83.68.16.6,84.113.4.128,84.16.224.183,84.16.224.199,84.16.224.55,84.16.227.222,84.16.227.223,84.16.227.72,84.16.228.142,84.16.228.143,84.16.228.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (271)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407541; rev:167; fwsam: src, 24 hours;) alert tcp [84.16.230.38,84.16.231.198,84.16.233.164,84.16.234.27,84.16.235.187,84.16.236.16,84.16.237.46,84.16.237.52,84.16.240.233,84.16.242.70,84.16.244.114,84.16.244.121,84.16.247.12,84.16.251.238,84.16.252.138,84.16.252.183,84.16.252.73,84.16.252.77,84.16.252.80,84.16.252.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (272)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407542; rev:167; fwsam: src, 24 hours;) alert udp [84.16.230.38,84.16.231.198,84.16.233.164,84.16.234.27,84.16.235.187,84.16.236.16,84.16.237.46,84.16.237.52,84.16.240.233,84.16.242.70,84.16.244.114,84.16.244.121,84.16.247.12,84.16.251.238,84.16.252.138,84.16.252.183,84.16.252.73,84.16.252.77,84.16.252.80,84.16.252.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (272)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407543; rev:167; fwsam: src, 24 hours;) alert tcp [84.16.255.108,84.19.184.160,84.204.200.173,84.204.27.100,84.204.97.114,84.204.97.122,84.204.97.124,84.22.162.57,84.228.136.89,84.232.60.34,84.234.251.35,84.243.196.130,84.243.196.132,84.243.196.136,84.243.196.137,84.243.196.6,84.243.197.10,84.243.197.183,84.243.197.184,84.243.197.191] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (273)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407544; rev:167; fwsam: src, 24 hours;) alert udp [84.16.255.108,84.19.184.160,84.204.200.173,84.204.27.100,84.204.97.114,84.204.97.122,84.204.97.124,84.22.162.57,84.228.136.89,84.232.60.34,84.234.251.35,84.243.196.130,84.243.196.132,84.243.196.136,84.243.196.137,84.243.196.6,84.243.197.10,84.243.197.183,84.243.197.184,84.243.197.191] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (273)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407545; rev:167; fwsam: src, 24 hours;) alert tcp [84.243.197.197,84.243.197.45,84.243.200.143,84.243.200.147,84.243.213.39,84.243.252.160,84.243.252.161,84.243.252.162,84.243.252.163,84.243.252.164,84.243.252.165,84.243.252.166,84.243.252.167,84.243.252.168,84.243.252.169,84.243.252.170,84.243.252.171,84.243.252.172,84.243.252.173,84.243.252.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (274)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407546; rev:167; fwsam: src, 24 hours;) alert udp [84.243.197.197,84.243.197.45,84.243.200.143,84.243.200.147,84.243.213.39,84.243.252.160,84.243.252.161,84.243.252.162,84.243.252.163,84.243.252.164,84.243.252.165,84.243.252.166,84.243.252.167,84.243.252.168,84.243.252.169,84.243.252.170,84.243.252.171,84.243.252.172,84.243.252.173,84.243.252.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (274)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407547; rev:167; fwsam: src, 24 hours;) alert tcp [84.243.252.175,84.243.252.176,84.243.252.177,84.243.252.178,84.243.252.179,84.243.252.180,84.243.252.87,84.243.252.88,84.244.137.173,84.244.138.115,84.244.138.55,84.244.189.87,84.246.134.14,84.255.247.1,84.38.140.252,84.45.45.135,84.47.190.138,84.51.21.132,84.51.21.50,84.95.250.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (275)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407548; rev:167; fwsam: src, 24 hours;) alert udp [84.243.252.175,84.243.252.176,84.243.252.177,84.243.252.178,84.243.252.179,84.243.252.180,84.243.252.87,84.243.252.88,84.244.137.173,84.244.138.115,84.244.138.55,84.244.189.87,84.246.134.14,84.255.247.1,84.38.140.252,84.45.45.135,84.47.190.138,84.51.21.132,84.51.21.50,84.95.250.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (275)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407549; rev:167; fwsam: src, 24 hours;) alert tcp [85.10.194.157,85.10.194.158,85.10.194.162,85.10.208.252,85.10.221.161,85.10.221.164,85.10.243.126,85.108.73.82,85.112.126.15,85.114.131.69,85.114.140.107,85.114.141.207,85.114.143.2,85.117.156.252,85.12.15.147,85.12.24.11,85.12.24.12,85.12.24.14,85.12.24.15,85.12.24.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (276)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407550; rev:167; fwsam: src, 24 hours;) alert udp [85.10.194.157,85.10.194.158,85.10.194.162,85.10.208.252,85.10.221.161,85.10.221.164,85.10.243.126,85.108.73.82,85.112.126.15,85.114.131.69,85.114.140.107,85.114.141.207,85.114.143.2,85.117.156.252,85.12.15.147,85.12.24.11,85.12.24.12,85.12.24.14,85.12.24.15,85.12.24.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (276)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407551; rev:167; fwsam: src, 24 hours;) alert tcp [85.12.24.18,85.12.24.19,85.12.25.110,85.12.25.111,85.12.25.75,85.12.43.141,85.12.43.99,85.12.46.21,85.12.46.6,85.124.3.11,85.13.129.230,85.13.132.129,85.13.135.16,85.13.135.43,85.13.236.154,85.131.154.34,85.133.206.11,85.133.206.115,85.133.206.96,85.14.6.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (277)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407552; rev:167; fwsam: src, 24 hours;) alert udp [85.12.24.18,85.12.24.19,85.12.25.110,85.12.25.111,85.12.25.75,85.12.43.141,85.12.43.99,85.12.46.21,85.12.46.6,85.124.3.11,85.13.129.230,85.13.132.129,85.13.135.16,85.13.135.43,85.13.236.154,85.131.154.34,85.133.206.11,85.133.206.115,85.133.206.96,85.14.6.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (277)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407553; rev:167; fwsam: src, 24 hours;) alert tcp [85.142.1.0/24,85.158.181.11,85.158.181.16,85.159.144.21,85.159.233.233,85.159.233.47,85.159.233.48,85.159.63.145,85.17.103.104,85.17.103.112,85.17.103.113,85.17.103.114,85.17.103.115,85.17.103.116,85.17.103.119,85.17.103.35,85.17.103.47,85.17.136.135,85.17.136.137,85.17.136.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (278)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407554; rev:167; fwsam: src, 24 hours;) alert udp [85.142.1.0/24,85.158.181.11,85.158.181.16,85.159.144.21,85.159.233.233,85.159.233.47,85.159.233.48,85.159.63.145,85.17.103.104,85.17.103.112,85.17.103.113,85.17.103.114,85.17.103.115,85.17.103.116,85.17.103.119,85.17.103.35,85.17.103.47,85.17.136.135,85.17.136.137,85.17.136.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (278)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407555; rev:167; fwsam: src, 24 hours;) alert tcp [85.17.136.140,85.17.136.21,85.17.136.4,85.17.138.27,85.17.138.29,85.17.138.60,85.17.138.61,85.17.139.149,85.17.139.54,85.17.141.20,85.17.142.145,85.17.143.132,85.17.143.201,85.17.144.77,85.17.144.78,85.17.148.49,85.17.159.64,85.17.162.100,85.17.162.165,85.17.162.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (279)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407556; rev:167; fwsam: src, 24 hours;) alert udp [85.17.136.140,85.17.136.21,85.17.136.4,85.17.138.27,85.17.138.29,85.17.138.60,85.17.138.61,85.17.139.149,85.17.139.54,85.17.141.20,85.17.142.145,85.17.143.132,85.17.143.201,85.17.144.77,85.17.144.78,85.17.148.49,85.17.159.64,85.17.162.100,85.17.162.165,85.17.162.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (279)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407557; rev:167; fwsam: src, 24 hours;) alert tcp [85.17.162.217,85.17.162.9,85.17.165.132,85.17.166.135,85.17.166.136,85.17.169.55,85.17.177.223,85.17.184.26,85.17.184.31,85.17.188.91,85.17.19.118,85.17.19.132,85.17.200.82,85.17.201.143,85.17.209.45,85.17.211.20,85.17.216.83,85.17.219.61,85.17.224.149,85.17.231.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (280)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407558; rev:167; fwsam: src, 24 hours;) alert udp [85.17.162.217,85.17.162.9,85.17.165.132,85.17.166.135,85.17.166.136,85.17.169.55,85.17.177.223,85.17.184.26,85.17.184.31,85.17.188.91,85.17.19.118,85.17.19.132,85.17.200.82,85.17.201.143,85.17.209.45,85.17.211.20,85.17.216.83,85.17.219.61,85.17.224.149,85.17.231.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (280)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407559; rev:167; fwsam: src, 24 hours;) alert tcp [85.17.232.198,85.17.237.5,85.17.239.117,85.17.239.118,85.17.239.121,85.17.254.0/24,85.17.3.246,85.17.35.246,85.17.35.27,85.17.4.0/24,85.17.45.0/24,85.17.52.4,85.17.52.47,85.17.52.69,85.17.52.7,85.17.52.77,85.17.52.9,85.17.82.115,85.17.87.159,85.17.90.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (281)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407560; rev:167; fwsam: src, 24 hours;) alert udp [85.17.232.198,85.17.237.5,85.17.239.117,85.17.239.118,85.17.239.121,85.17.254.0/24,85.17.3.246,85.17.35.246,85.17.35.27,85.17.4.0/24,85.17.45.0/24,85.17.52.4,85.17.52.47,85.17.52.69,85.17.52.7,85.17.52.77,85.17.52.9,85.17.82.115,85.17.87.159,85.17.90.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (281)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407561; rev:167; fwsam: src, 24 hours;) alert tcp [85.17.90.204,85.17.93.137,85.17.93.190,85.17.93.37,85.17.93.42,85.17.94.16,85.17.94.3,85.17.94.42,85.181.194.86,85.186.13.60,85.19.64.211,85.192.34.156,85.192.43.102,85.197.99.39,85.21.125.197,85.21.125.203,85.21.68.35,85.214.23.161,85.214.90.254,85.229.184.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (282)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407562; rev:167; fwsam: src, 24 hours;) alert udp [85.17.90.204,85.17.93.137,85.17.93.190,85.17.93.37,85.17.93.42,85.17.94.16,85.17.94.3,85.17.94.42,85.181.194.86,85.186.13.60,85.19.64.211,85.192.34.156,85.192.43.102,85.197.99.39,85.21.125.197,85.21.125.203,85.21.68.35,85.214.23.161,85.214.90.254,85.229.184.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (282)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407563; rev:167; fwsam: src, 24 hours;) alert tcp [85.233.160.70,85.235.208.0/24,85.235.209.2,85.24.148.110,85.25.6.69,85.255.112.0/20,85.255.112.0/21,85.255.120.0/24,85.255.121.0/24,85.255.122.4,85.64.2.247,85.9.56.199,85.92.129.132,85.92.152.43,85.92.86.62,86.109.109.67,86.109.167.134,86.122.151.123,86.17.173.169,86.203.230.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (283)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407564; rev:167; fwsam: src, 24 hours;) alert udp [85.233.160.70,85.235.208.0/24,85.235.209.2,85.24.148.110,85.25.6.69,85.255.112.0/20,85.255.112.0/21,85.255.120.0/24,85.255.121.0/24,85.255.122.4,85.64.2.247,85.9.56.199,85.92.129.132,85.92.152.43,85.92.86.62,86.109.109.67,86.109.167.134,86.122.151.123,86.17.173.169,86.203.230.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (283)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407565; rev:167; fwsam: src, 24 hours;) alert tcp [86.35.15.212,86.57.246.177,86.57.246.186,86.76.210.182,87.102.68.100,87.106.103.122,87.106.104.235,87.106.115.164,87.106.123.8,87.106.220.76,87.106.38.65,87.110.27.215,87.112.23.30,87.117.234.92,87.117.252.0/24,87.117.255.0/24,87.118.116.11,87.118.116.14,87.118.117.11,87.118.118.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (284)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407566; rev:167; fwsam: src, 24 hours;) alert udp [86.35.15.212,86.57.246.177,86.57.246.186,86.76.210.182,87.102.68.100,87.106.103.122,87.106.104.235,87.106.115.164,87.106.123.8,87.106.220.76,87.106.38.65,87.110.27.215,87.112.23.30,87.117.234.92,87.117.252.0/24,87.117.255.0/24,87.118.116.11,87.118.116.14,87.118.117.11,87.118.118.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (284)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407567; rev:167; fwsam: src, 24 hours;) alert tcp [87.118.118.92,87.118.120.71,87.118.125.59,87.118.126.246,87.118.126.30,87.118.69.108,87.118.84.124,87.118.84.219,87.118.84.58,87.118.84.63,87.118.86.16,87.118.96.83,87.118.96.86,87.120.40.138,87.121.76.9,87.230.25.199,87.233.139.100,87.233.159.186,87.236.194.123,87.236.216.149] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (285)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407568; rev:167; fwsam: src, 24 hours;) alert udp [87.118.118.92,87.118.120.71,87.118.125.59,87.118.126.246,87.118.126.30,87.118.69.108,87.118.84.124,87.118.84.219,87.118.84.58,87.118.84.63,87.118.86.16,87.118.96.83,87.118.96.86,87.120.40.138,87.121.76.9,87.230.25.199,87.233.139.100,87.233.159.186,87.236.194.123,87.236.216.149] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (285)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407569; rev:167; fwsam: src, 24 hours;) alert tcp [87.237.13.203,87.238.162.146,87.238.175.38,87.242.115.19,87.242.115.93,87.242.116.123,87.242.126.153,87.242.73.95,87.242.76.68,87.242.78.57,87.242.90.0/24,87.248.163.54,87.248.163.56,87.248.163.58,87.248.180.0/24,87.249.116.188,87.249.98.22,87.251.53.97,87.252.1.21,87.255.54.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (286)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407570; rev:167; fwsam: src, 24 hours;) alert udp [87.237.13.203,87.238.162.146,87.238.175.38,87.242.115.19,87.242.115.93,87.242.116.123,87.242.126.153,87.242.73.95,87.242.76.68,87.242.78.57,87.242.90.0/24,87.248.163.54,87.248.163.56,87.248.163.58,87.248.180.0/24,87.249.116.188,87.249.98.22,87.251.53.97,87.252.1.21,87.255.54.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (286)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407571; rev:167; fwsam: src, 24 hours;) alert tcp [87.3.36.91,87.98.128.146,87.98.149.171,87.98.182.64,87.98.222.197,87.98.234.25,87.98.239.19,87.98.239.2,88.131.75.169,88.153.34.164,88.156.69.141,88.182.125.201,88.191.15.229,88.191.22.55,88.191.35.98,88.191.36.93,88.191.78.48,88.191.98.78,88.198.103.122,88.198.103.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (287)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407572; rev:167; fwsam: src, 24 hours;) alert udp [87.3.36.91,87.98.128.146,87.98.149.171,87.98.182.64,87.98.222.197,87.98.234.25,87.98.239.19,87.98.239.2,88.131.75.169,88.153.34.164,88.156.69.141,88.182.125.201,88.191.15.229,88.191.22.55,88.191.35.98,88.191.36.93,88.191.78.48,88.191.98.78,88.198.103.122,88.198.103.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (287)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407573; rev:167; fwsam: src, 24 hours;) alert tcp [88.198.105.145,88.198.105.149,88.198.107.25,88.198.111.1,88.198.120.177,88.198.122.250,88.198.129.249,88.198.131.169,88.198.15.198,88.198.152.130,88.198.152.131,88.198.152.132,88.198.160.57,88.198.160.58,88.198.160.59,88.198.17.99,88.198.207.4,88.198.233.225,88.198.233.228,88.198.239.161] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (288)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407574; rev:167; fwsam: src, 24 hours;) alert udp [88.198.105.145,88.198.105.149,88.198.107.25,88.198.111.1,88.198.120.177,88.198.122.250,88.198.129.249,88.198.131.169,88.198.15.198,88.198.152.130,88.198.152.131,88.198.152.132,88.198.160.57,88.198.160.58,88.198.160.59,88.198.17.99,88.198.207.4,88.198.233.225,88.198.233.228,88.198.239.161] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (288)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407575; rev:167; fwsam: src, 24 hours;) alert tcp [88.198.239.162,88.198.239.163,88.198.239.164,88.198.239.165,88.198.239.166,88.198.39.195,88.198.40.57,88.198.41.170,88.198.48.247,88.198.58.147,88.198.61.232,88.198.62.170,88.198.62.171,88.198.69.134,88.198.8.15,88.198.81.153,88.201.208.0/20,88.203.163.100,88.208.0.0/21,88.208.118.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (289)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407576; rev:167; fwsam: src, 24 hours;) alert udp [88.198.239.162,88.198.239.163,88.198.239.164,88.198.239.165,88.198.239.166,88.198.39.195,88.198.40.57,88.198.41.170,88.198.48.247,88.198.58.147,88.198.61.232,88.198.62.170,88.198.62.171,88.198.69.134,88.198.8.15,88.198.81.153,88.201.208.0/20,88.203.163.100,88.208.0.0/21,88.208.118.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (289)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407577; rev:167; fwsam: src, 24 hours;) alert tcp [88.208.16.116,88.208.16.144,88.208.16.147,88.208.16.234,88.208.16.235,88.208.17.1,88.208.17.116,88.208.19.153,88.208.19.4,88.208.21.110,88.208.21.16,88.208.21.188,88.208.252.192,88.208.28.0/22,88.208.39.146,88.208.46.232,88.208.46.239,88.212.196.87,88.212.202.56,88.214.192.0/18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (290)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407578; rev:167; fwsam: src, 24 hours;) alert udp [88.208.16.116,88.208.16.144,88.208.16.147,88.208.16.234,88.208.16.235,88.208.17.1,88.208.17.116,88.208.19.153,88.208.19.4,88.208.21.110,88.208.21.16,88.208.21.188,88.208.252.192,88.208.28.0/22,88.208.39.146,88.208.46.232,88.208.46.239,88.212.196.87,88.212.202.56,88.214.192.0/18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (290)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407579; rev:167; fwsam: src, 24 hours;) alert tcp [88.214.192.0/20,88.214.204.221,88.216.136.50,88.243.194.168,88.80.203.162,88.80.208.170,88.80.4.19,88.81.249.200,88.84.128.40,88.84.137.164,88.84.137.166,88.85.65.129,88.85.65.5,88.85.65.6,88.85.66.17,88.85.66.63,88.85.75.140,88.85.78.81,88.85.81.101,88.85.82.148] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (291)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407580; rev:167; fwsam: src, 24 hours;) alert udp [88.214.192.0/20,88.214.204.221,88.216.136.50,88.243.194.168,88.80.203.162,88.80.208.170,88.80.4.19,88.81.249.200,88.84.128.40,88.84.137.164,88.84.137.166,88.85.65.129,88.85.65.5,88.85.65.6,88.85.66.17,88.85.66.63,88.85.75.140,88.85.78.81,88.85.81.101,88.85.82.148] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (291)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407581; rev:167; fwsam: src, 24 hours;) alert tcp [88.85.89.16,88.85.89.5,88.85.89.7,88.86.103.186,88.86.103.242,88.86.113.143,89.103.105.241,89.104.166.52,89.104.71.235,89.104.80.155,89.104.82.198,89.105.159.213,89.106.14.203,89.108.104.38,89.108.104.72,89.108.105.10,89.108.105.11,89.108.120.72,89.108.122.119,89.108.124.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (292)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407582; rev:167; fwsam: src, 24 hours;) alert udp [88.85.89.16,88.85.89.5,88.85.89.7,88.86.103.186,88.86.103.242,88.86.113.143,89.103.105.241,89.104.166.52,89.104.71.235,89.104.80.155,89.104.82.198,89.105.159.213,89.106.14.203,89.108.104.38,89.108.104.72,89.108.105.10,89.108.105.11,89.108.120.72,89.108.122.119,89.108.124.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (292)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407583; rev:167; fwsam: src, 24 hours;) alert tcp [89.108.126.22,89.108.64.0/19,89.111.171.191,89.111.173.65,89.111.173.77,89.111.176.0/24,89.111.188.155,89.114.126.152,89.125.31.83,89.138.7.136,89.143.17.40,89.146.137.0,89.149.194.201,89.149.194.45,89.149.200.153,89.149.200.79,89.149.201.133,89.149.202.115,89.149.202.127,89.149.202.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (293)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407584; rev:167; fwsam: src, 24 hours;) alert udp [89.108.126.22,89.108.64.0/19,89.111.171.191,89.111.173.65,89.111.173.77,89.111.176.0/24,89.111.188.155,89.114.126.152,89.125.31.83,89.138.7.136,89.143.17.40,89.146.137.0,89.149.194.201,89.149.194.45,89.149.200.153,89.149.200.79,89.149.201.133,89.149.202.115,89.149.202.127,89.149.202.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (293)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407585; rev:167; fwsam: src, 24 hours;) alert tcp [89.149.202.254,89.149.202.30,89.149.206.56,89.149.207.114,89.149.207.120,89.149.207.213,89.149.207.56,89.149.208.179,89.149.208.241,89.149.208.29,89.149.208.44,89.149.209.11,89.149.209.117,89.149.209.160,89.149.209.161,89.149.209.225,89.149.209.69,89.149.209.93,89.149.210.147,89.149.210.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (294)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407586; rev:167; fwsam: src, 24 hours;) alert udp [89.149.202.254,89.149.202.30,89.149.206.56,89.149.207.114,89.149.207.120,89.149.207.213,89.149.207.56,89.149.208.179,89.149.208.241,89.149.208.29,89.149.208.44,89.149.209.11,89.149.209.117,89.149.209.160,89.149.209.161,89.149.209.225,89.149.209.69,89.149.209.93,89.149.210.147,89.149.210.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (294)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407587; rev:167; fwsam: src, 24 hours;) alert tcp [89.149.210.44,89.149.212.100,89.149.212.137,89.149.212.151,89.149.212.218,89.149.216.212,89.149.216.213,89.149.217.157,89.149.217.158,89.149.217.205,89.149.220.0/24,89.149.221.182,89.149.221.74,89.149.225.88,89.149.226.0/24,89.149.227.0/24,89.149.228.201,89.149.229.37,89.149.230.73,89.149.235.190] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (295)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407588; rev:167; fwsam: src, 24 hours;) alert udp [89.149.210.44,89.149.212.100,89.149.212.137,89.149.212.151,89.149.212.218,89.149.216.212,89.149.216.213,89.149.217.157,89.149.217.158,89.149.217.205,89.149.220.0/24,89.149.221.182,89.149.221.74,89.149.225.88,89.149.226.0/24,89.149.227.0/24,89.149.228.201,89.149.229.37,89.149.230.73,89.149.235.190] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (295)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407589; rev:167; fwsam: src, 24 hours;) alert tcp [89.149.235.192,89.149.235.235,89.149.236.0/24,89.149.241.0/24,89.149.242.128,89.149.242.134,89.149.242.16,89.149.242.190,89.149.242.191,89.149.242.201,89.149.242.25,89.149.243.28,89.149.244.173,89.149.244.204,89.149.244.211,89.149.244.22,89.149.244.29,89.149.244.83,89.149.247.244,89.149.249.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (296)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407590; rev:167; fwsam: src, 24 hours;) alert udp [89.149.235.192,89.149.235.235,89.149.236.0/24,89.149.241.0/24,89.149.242.128,89.149.242.134,89.149.242.16,89.149.242.190,89.149.242.191,89.149.242.201,89.149.242.25,89.149.243.28,89.149.244.173,89.149.244.204,89.149.244.211,89.149.244.22,89.149.244.29,89.149.244.83,89.149.247.244,89.149.249.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (296)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407591; rev:167; fwsam: src, 24 hours;) alert tcp [89.149.250.12,89.149.251.111,89.149.251.130,89.149.251.203,89.149.251.33,89.149.251.43,89.149.251.44,89.149.251.56,89.149.252.154,89.149.252.155,89.149.252.19,89.149.252.24,89.149.252.252,89.149.253.215,89.149.253.239,89.149.254.12,89.149.254.134,89.149.254.174,89.149.254.182,89.149.254.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (297)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407592; rev:167; fwsam: src, 24 hours;) alert udp [89.149.250.12,89.149.251.111,89.149.251.130,89.149.251.203,89.149.251.33,89.149.251.43,89.149.251.44,89.149.251.56,89.149.252.154,89.149.252.155,89.149.252.19,89.149.252.24,89.149.252.252,89.149.253.215,89.149.253.239,89.149.254.12,89.149.254.134,89.149.254.174,89.149.254.182,89.149.254.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (297)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407593; rev:167; fwsam: src, 24 hours;) alert tcp [89.149.254.55,89.149.255.190,89.149.255.191,89.149.255.34,89.149.255.35,89.149.255.61,89.161.135.107,89.161.169.155,89.161.179.31,89.171.115.10,89.179.247.183,89.18.179.45,89.18.181.0/24,89.18.189.44,89.185.228.12,89.185.228.13,89.185.228.141,89.185.228.17,89.185.228.59,89.185.229.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (298)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407594; rev:167; fwsam: src, 24 hours;) alert udp [89.149.254.55,89.149.255.190,89.149.255.191,89.149.255.34,89.149.255.35,89.149.255.61,89.161.135.107,89.161.169.155,89.161.179.31,89.171.115.10,89.179.247.183,89.18.179.45,89.18.181.0/24,89.18.189.44,89.185.228.12,89.185.228.13,89.185.228.141,89.185.228.17,89.185.228.59,89.185.229.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (298)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407595; rev:167; fwsam: src, 24 hours;) alert tcp [89.185.229.127,89.185.231.103,89.186.5.153,89.187.101.71,89.187.46.254,89.187.48.0/24,89.188.112.0/24,89.188.122.66,89.188.136.89,89.188.16.12,89.19.29.130,89.191.224.28,89.200.170.230,89.200.201.66,89.200.201.67,89.200.201.94,89.208.136.218,89.208.145.148,89.208.176.11,89.208.41.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (299)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407596; rev:167; fwsam: src, 24 hours;) alert udp [89.185.229.127,89.185.231.103,89.186.5.153,89.187.101.71,89.187.46.254,89.187.48.0/24,89.188.112.0/24,89.188.122.66,89.188.136.89,89.188.16.12,89.19.29.130,89.191.224.28,89.200.170.230,89.200.201.66,89.200.201.67,89.200.201.94,89.208.136.218,89.208.145.148,89.208.176.11,89.208.41.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (299)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407597; rev:167; fwsam: src, 24 hours;) alert tcp [89.218.40.131,89.218.85.18,89.222.192.199,89.238.135.227,89.238.162.82,89.248.111.232,89.248.160.154,89.248.160.157,89.248.160.227,89.248.160.231,89.248.162.16,89.248.162.164,89.248.166.45,89.248.166.57,89.248.166.59,89.248.166.60,89.248.168.120,89.248.168.168,89.248.168.22,89.248.168.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (300)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407598; rev:167; fwsam: src, 24 hours;) alert udp [89.218.40.131,89.218.85.18,89.222.192.199,89.238.135.227,89.238.162.82,89.248.111.232,89.248.160.154,89.248.160.157,89.248.160.227,89.248.160.231,89.248.162.16,89.248.162.164,89.248.166.45,89.248.166.57,89.248.166.59,89.248.166.60,89.248.168.120,89.248.168.168,89.248.168.22,89.248.168.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (300)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407599; rev:167; fwsam: src, 24 hours;) alert tcp [89.248.168.49,89.248.168.70,89.248.168.74,89.248.168.79,89.248.171.33,89.248.171.40,89.248.171.48,89.248.171.6,89.248.171.68,89.248.172.0/23,89.248.174.58,89.248.174.61,89.248.174.95,89.249.18.170,89.249.22.196,89.250.63.123,89.254.139.247,89.255.8.114,89.28.13.200,89.28.13.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (301)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407600; rev:167; fwsam: src, 24 hours;) alert udp [89.248.168.49,89.248.168.70,89.248.168.74,89.248.168.79,89.248.171.33,89.248.171.40,89.248.171.48,89.248.171.6,89.248.171.68,89.248.172.0/23,89.248.174.58,89.248.174.61,89.248.174.95,89.249.18.170,89.249.22.196,89.250.63.123,89.254.139.247,89.255.8.114,89.28.13.200,89.28.13.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (301)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407601; rev:167; fwsam: src, 24 hours;) alert tcp [89.31.143.101,89.32.22.215,89.45.97.180,89.46.12.43,89.47.236.152,89.47.236.230,89.47.237.52,89.47.237.55,89.96.184.80,89.96.48.150,90.150.144.50,90.156.144.78,90.156.145.198,90.156.149.33,90.156.153.104,90.156.153.112,90.156.153.34,90.156.153.49,90.156.153.91,90.156.153.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (302)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407602; rev:167; fwsam: src, 24 hours;) alert udp [89.31.143.101,89.32.22.215,89.45.97.180,89.46.12.43,89.47.236.152,89.47.236.230,89.47.237.52,89.47.237.55,89.96.184.80,89.96.48.150,90.150.144.50,90.156.144.78,90.156.145.198,90.156.149.33,90.156.153.104,90.156.153.112,90.156.153.34,90.156.153.49,90.156.153.91,90.156.153.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (302)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407603; rev:167; fwsam: src, 24 hours;) alert tcp [90.156.178.37,90.156.178.40,90.156.178.46,90.156.178.47,90.156.209.115,90.189.132.25,90.5.177.194,91.103.216.240,91.121.1.99,91.121.105.7,91.121.108.53,91.121.112.130,91.121.121.6,91.121.124.22,91.121.132.182,91.121.134.229,91.121.140.44,91.121.142.111,91.121.146.101,91.121.147.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (303)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407604; rev:167; fwsam: src, 24 hours;) alert udp [90.156.178.37,90.156.178.40,90.156.178.46,90.156.178.47,90.156.209.115,90.189.132.25,90.5.177.194,91.103.216.240,91.121.1.99,91.121.105.7,91.121.108.53,91.121.112.130,91.121.121.6,91.121.124.22,91.121.132.182,91.121.134.229,91.121.140.44,91.121.142.111,91.121.146.101,91.121.147.142] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (303)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407605; rev:167; fwsam: src, 24 hours;) alert tcp [91.121.148.73,91.121.167.41,91.121.174.19,91.121.21.162,91.121.24.139,91.121.4.192,91.121.4.99,91.121.45.67,91.121.49.129,91.121.55.177,91.121.7.26,91.121.74.84,91.121.76.11,91.121.79.19,91.121.79.191,91.121.8.105,91.121.86.130,91.121.88.218,91.121.89.185,91.121.95.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (304)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407606; rev:167; fwsam: src, 24 hours;) alert udp [91.121.148.73,91.121.167.41,91.121.174.19,91.121.21.162,91.121.24.139,91.121.4.192,91.121.4.99,91.121.45.67,91.121.49.129,91.121.55.177,91.121.7.26,91.121.74.84,91.121.76.11,91.121.79.19,91.121.79.191,91.121.8.105,91.121.86.130,91.121.88.218,91.121.89.185,91.121.95.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (304)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407607; rev:167; fwsam: src, 24 hours;) alert tcp [91.121.95.136,91.121.97.186,91.142.209.26,91.144.136.26,91.144.144.252,91.149.157.130,91.184.49.170,91.184.56.88,91.186.21.122,91.186.25.40,91.189.113.105,91.189.113.12,91.189.113.210,91.189.81.71,91.191.174.196,91.191.174.199,91.191.174.200,91.192.106.0/23,91.192.117.59,91.192.148.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (305)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407608; rev:167; fwsam: src, 24 hours;) alert udp [91.121.95.136,91.121.97.186,91.142.209.26,91.144.136.26,91.144.144.252,91.149.157.130,91.184.49.170,91.184.56.88,91.186.21.122,91.186.25.40,91.189.113.105,91.189.113.12,91.189.113.210,91.189.81.71,91.191.174.196,91.191.174.199,91.191.174.200,91.192.106.0/23,91.192.117.59,91.192.148.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (305)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407609; rev:167; fwsam: src, 24 hours;) alert tcp [91.192.68.52,91.192.71.7,91.193.108.150,91.193.108.222,91.193.108.239,91.193.108.254,91.193.40.0/22,91.194.10.60,91.194.140.0/23,91.194.250.162,91.194.40.19,91.194.76.0/23,91.195.116.0/23,91.195.118.245,91.196.232.0/22,91.197.130.18,91.197.130.19,91.197.130.20,91.197.130.21,91.197.130.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (306)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407610; rev:167; fwsam: src, 24 hours;) alert udp [91.192.68.52,91.192.71.7,91.193.108.150,91.193.108.222,91.193.108.239,91.193.108.254,91.193.40.0/22,91.194.10.60,91.194.140.0/23,91.194.250.162,91.194.40.19,91.194.76.0/23,91.195.116.0/23,91.195.118.245,91.196.232.0/22,91.197.130.18,91.197.130.19,91.197.130.20,91.197.130.21,91.197.130.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (306)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407611; rev:167; fwsam: src, 24 hours;) alert tcp [91.197.160.20,91.198.109.0/24,91.198.165.243,91.198.71.0/24,91.199.112.0/24,91.199.230.14,91.199.245.101,91.200.122.153,91.200.144.0/23,91.200.146.200,91.200.146.201,91.200.146.4,91.200.146.8,91.200.164.0/22,91.201.196.0/24,91.201.28.0/24,91.201.29.110,91.201.29.123,91.201.29.250,91.201.29.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (307)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407612; rev:167; fwsam: src, 24 hours;) alert udp [91.197.160.20,91.198.109.0/24,91.198.165.243,91.198.71.0/24,91.199.112.0/24,91.199.230.14,91.199.245.101,91.200.122.153,91.200.144.0/23,91.200.146.200,91.200.146.201,91.200.146.4,91.200.146.8,91.200.164.0/22,91.201.196.0/24,91.201.28.0/24,91.201.29.110,91.201.29.123,91.201.29.250,91.201.29.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (307)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407613; rev:167; fwsam: src, 24 hours;) alert tcp [91.201.63.143,91.202.63.96,91.202.63.99,91.203.146.38,91.203.4.112,91.203.4.113,91.203.4.49,91.203.5.111,91.203.5.133,91.203.68.0/22,91.203.92.0/22,91.204.73.5,91.205.172.118,91.205.233.33,91.205.40.5,91.205.96.12,91.206.10.173,91.206.10.190,91.206.14.7,91.206.200.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (308)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407614; rev:167; fwsam: src, 24 hours;) alert udp [91.201.63.143,91.202.63.96,91.202.63.99,91.203.146.38,91.203.4.112,91.203.4.113,91.203.4.49,91.203.5.111,91.203.5.133,91.203.68.0/22,91.203.92.0/22,91.204.73.5,91.205.172.118,91.205.233.33,91.205.40.5,91.205.96.12,91.206.10.173,91.206.10.190,91.206.14.7,91.206.200.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (308)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407615; rev:167; fwsam: src, 24 hours;) alert tcp [91.206.226.41,91.206.226.42,91.206.231.140,91.206.231.189,91.207.116.0/23,91.207.192.23,91.207.4.0/22,91.207.51.208,91.207.60.0/23,91.207.8.252,91.208.0.0/24,91.208.162.9,91.208.228.101,91.209.163.171,91.209.163.178,91.209.163.182,91.209.163.184,91.209.163.201,91.209.163.202,91.209.163.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (309)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407616; rev:167; fwsam: src, 24 hours;) alert udp [91.206.226.41,91.206.226.42,91.206.231.140,91.206.231.189,91.207.116.0/23,91.207.192.23,91.207.4.0/22,91.207.51.208,91.207.60.0/23,91.207.8.252,91.208.0.0/24,91.208.162.9,91.208.228.101,91.209.163.171,91.209.163.178,91.209.163.182,91.209.163.184,91.209.163.201,91.209.163.202,91.209.163.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (309)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407617; rev:167; fwsam: src, 24 hours;) alert tcp [91.209.183.21,91.209.183.56,91.209.183.61,91.21.88.146,91.210.104.70,91.210.189.35,91.210.57.135,91.211.113.221,91.211.117.25,91.211.117.39,91.211.224.168,91.211.64.0/22,91.212.107.103,91.212.107.37,91.212.107.38,91.212.107.5,91.212.107.7,91.212.107.8,91.212.107.9,91.212.127.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (310)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407618; rev:167; fwsam: src, 24 hours;) alert udp [91.209.183.21,91.209.183.56,91.209.183.61,91.21.88.146,91.210.104.70,91.210.189.35,91.210.57.135,91.211.113.221,91.211.117.25,91.211.117.39,91.211.224.168,91.211.64.0/22,91.212.107.103,91.212.107.37,91.212.107.38,91.212.107.5,91.212.107.7,91.212.107.8,91.212.107.9,91.212.127.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (310)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407619; rev:167; fwsam: src, 24 hours;) alert tcp [91.212.132.0/24,91.212.158.5,91.212.198.0/24,91.212.210.75,91.212.220.0/24,91.212.226.0/24,91.212.41.0/24,91.212.65.0/24,91.213.121.180,91.213.121.185,91.213.121.186,91.213.121.39,91.213.121.54,91.213.121.86,91.213.126.0/24,91.213.174.0/24,91.213.175.129,91.213.175.239,91.213.29.0/24,91.213.29.15] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (311)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407620; rev:167; fwsam: src, 24 hours;) alert udp [91.212.132.0/24,91.212.158.5,91.212.198.0/24,91.212.210.75,91.212.220.0/24,91.212.226.0/24,91.212.41.0/24,91.212.65.0/24,91.213.121.180,91.213.121.185,91.213.121.186,91.213.121.39,91.213.121.54,91.213.121.86,91.213.126.0/24,91.213.174.0/24,91.213.175.129,91.213.175.239,91.213.29.0/24,91.213.29.15] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (311)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407621; rev:167; fwsam: src, 24 hours;) alert tcp [91.213.72.0/24,91.213.94.10,91.213.94.130,91.213.94.131,91.214.44.123,91.214.44.181,91.214.44.188,91.214.45.73,91.214.45.75,91.215.156.74,91.215.156.77,91.215.168.18,91.215.170.36,91.215.170.47,91.215.216.19,91.92.165.55,91.93.133.4,92.168.61.133,92.23.158.52,92.241.160.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (312)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407622; rev:167; fwsam: src, 24 hours;) alert udp [91.213.72.0/24,91.213.94.10,91.213.94.130,91.213.94.131,91.214.44.123,91.214.44.181,91.214.44.188,91.214.45.73,91.214.45.75,91.215.156.74,91.215.156.77,91.215.168.18,91.215.170.36,91.215.170.47,91.215.216.19,91.92.165.55,91.93.133.4,92.168.61.133,92.23.158.52,92.241.160.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (312)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407623; rev:167; fwsam: src, 24 hours;) alert tcp [92.243.76.132,92.243.76.135,92.243.76.139,92.38.0.111,92.38.0.41,92.38.0.69,92.38.1.11,92.38.1.12,92.39.48.2,92.42.186.73,92.43.17.136,92.43.18.130,92.43.18.131,92.48.110.155,92.48.112.77,92.48.119.151,92.48.122.144,92.48.122.60,92.48.122.61,92.48.124.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (313)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407624; rev:167; fwsam: src, 24 hours;) alert udp [92.243.76.132,92.243.76.135,92.243.76.139,92.38.0.111,92.38.0.41,92.38.0.69,92.38.1.11,92.38.1.12,92.39.48.2,92.42.186.73,92.43.17.136,92.43.18.130,92.43.18.131,92.48.110.155,92.48.112.77,92.48.119.151,92.48.122.144,92.48.122.60,92.48.122.61,92.48.124.212] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (313)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407625; rev:167; fwsam: src, 24 hours;) alert tcp [92.48.127.134,92.48.192.0/18,92.48.69.13,92.48.78.252,92.48.91.144,92.48.91.146,92.50.143.94,92.50.238.233,92.53.96.0/22,92.60.176.13,92.60.176.33,92.60.176.41,92.60.176.45,92.60.177.230,92.60.177.238,92.60.177.242,92.60.177.245,92.60.184.31,92.61.146.101,92.61.148.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (314)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407626; rev:167; fwsam: src, 24 hours;) alert udp [92.48.127.134,92.48.192.0/18,92.48.69.13,92.48.78.252,92.48.91.144,92.48.91.146,92.50.143.94,92.50.238.233,92.53.96.0/22,92.60.176.13,92.60.176.33,92.60.176.41,92.60.176.45,92.60.177.230,92.60.177.238,92.60.177.242,92.60.177.245,92.60.184.31,92.61.146.101,92.61.148.174] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (314)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407627; rev:167; fwsam: src, 24 hours;) alert tcp [92.61.150.184,92.61.240.22,92.61.248.102,92.61.248.126,92.61.36.93,92.61.38.16,92.61.80.66,92.62.100.0/24,92.62.101.0/24,92.62.98.10,92.63.102.64,92.63.103.97,92.63.104.165,92.63.106.125,92.63.106.185,92.63.96.137,92.63.97.148,92.63.97.192,92.87.67.143,92.96.50.127] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (315)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407628; rev:167; fwsam: src, 24 hours;) alert udp [92.61.150.184,92.61.240.22,92.61.248.102,92.61.248.126,92.61.36.93,92.61.38.16,92.61.80.66,92.62.100.0/24,92.62.101.0/24,92.62.98.10,92.63.102.64,92.63.103.97,92.63.104.165,92.63.106.125,92.63.106.185,92.63.96.137,92.63.97.148,92.63.97.192,92.87.67.143,92.96.50.127] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (315)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407629; rev:167; fwsam: src, 24 hours;) alert tcp [93.103.232.126,93.104.211.71,93.138.227.37,93.158.114.111,93.158.114.132,93.158.114.138,93.158.114.139,93.158.114.163,93.158.114.164,93.170.16.144,93.174.88.27,93.174.90.17,93.174.90.18,93.174.92.197,93.174.92.214,93.174.92.219,93.174.92.220,93.174.92.221,93.174.92.222,93.174.92.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (316)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407630; rev:167; fwsam: src, 24 hours;) alert udp [93.103.232.126,93.104.211.71,93.138.227.37,93.158.114.111,93.158.114.132,93.158.114.138,93.158.114.139,93.158.114.163,93.158.114.164,93.170.16.144,93.174.88.27,93.174.90.17,93.174.90.18,93.174.92.197,93.174.92.214,93.174.92.219,93.174.92.220,93.174.92.221,93.174.92.222,93.174.92.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (316)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407631; rev:167; fwsam: src, 24 hours;) alert tcp [93.174.92.224,93.174.92.225,93.174.92.226,93.174.92.227,93.174.92.228,93.174.92.229,93.174.92.66,93.174.93.110,93.174.93.117,93.174.93.130,93.174.93.137,93.174.93.164,93.174.93.188,93.174.93.36,93.174.94.197,93.174.94.198,93.174.94.229,93.174.95.130,93.174.95.135,93.174.95.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (317)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407632; rev:167; fwsam: src, 24 hours;) alert udp [93.174.92.224,93.174.92.225,93.174.92.226,93.174.92.227,93.174.92.228,93.174.92.229,93.174.92.66,93.174.93.110,93.174.93.117,93.174.93.130,93.174.93.137,93.174.93.164,93.174.93.188,93.174.93.36,93.174.94.197,93.174.94.198,93.174.94.229,93.174.95.130,93.174.95.135,93.174.95.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (317)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407633; rev:167; fwsam: src, 24 hours;) alert tcp [93.174.95.141,93.174.95.153,93.174.95.191,93.174.95.192,93.174.95.193,93.174.95.194,93.174.95.195,93.174.95.196,93.177.237.73,93.182.156.61,93.183.192.0/18,93.184.144.152,93.186.118.53,93.186.164.168,93.186.176.244,93.186.178.76,93.187.200.179,93.187.232.187,93.188.160.0/21,93.189.33.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (318)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407634; rev:167; fwsam: src, 24 hours;) alert udp [93.174.95.141,93.174.95.153,93.174.95.191,93.174.95.192,93.174.95.193,93.174.95.194,93.174.95.195,93.174.95.196,93.177.237.73,93.182.156.61,93.183.192.0/18,93.184.144.152,93.186.118.53,93.186.164.168,93.186.176.244,93.186.178.76,93.187.200.179,93.187.232.187,93.188.160.0/21,93.189.33.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (318)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407635; rev:167; fwsam: src, 24 hours;) alert tcp [93.190.137.180,93.190.137.99,93.190.138.238,93.190.138.239,93.190.138.80,93.190.139.0/24,93.190.140.134,93.190.140.135,93.190.140.165,93.190.140.49,93.190.140.56,93.190.141.102,93.190.141.13,93.190.141.145,93.190.141.146,93.190.141.15,93.190.141.176,93.190.141.40,93.190.141.41,93.190.141.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (319)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407636; rev:167; fwsam: src, 24 hours;) alert udp [93.190.137.180,93.190.137.99,93.190.138.238,93.190.138.239,93.190.138.80,93.190.139.0/24,93.190.140.134,93.190.140.135,93.190.140.165,93.190.140.49,93.190.140.56,93.190.141.102,93.190.141.13,93.190.141.145,93.190.141.146,93.190.141.15,93.190.141.176,93.190.141.40,93.190.141.41,93.190.141.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (319)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407637; rev:167; fwsam: src, 24 hours;) alert tcp [93.190.141.94,93.190.142.134,93.190.142.135,93.88.179.33,94.102.208.74,94.102.216.148,94.102.219.71,94.102.48.0/20,94.103.80.220,94.103.86.94,94.103.88.0/21,94.124.84.10,94.125.71.77,94.125.90.163,94.125.90.164,94.136.35.124,94.142.128.100,94.142.128.41,94.142.129.51,94.198.48.0/21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (320)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407638; rev:167; fwsam: src, 24 hours;) alert udp [93.190.141.94,93.190.142.134,93.190.142.135,93.88.179.33,94.102.208.74,94.102.216.148,94.102.219.71,94.102.48.0/20,94.103.80.220,94.103.86.94,94.103.88.0/21,94.124.84.10,94.125.71.77,94.125.90.163,94.125.90.164,94.136.35.124,94.142.128.100,94.142.128.41,94.142.129.51,94.198.48.0/21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (320)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407639; rev:167; fwsam: src, 24 hours;) alert tcp [94.199.200.125,94.228.208.59,94.228.208.6,94.228.209.0/24,94.228.210.0/24,94.228.211.0/24,94.228.212.0/24,94.228.213.0/24,94.228.215.168,94.229.64.115,94.229.65.172,94.23.11.87,94.23.114.3,94.23.114.70,94.23.114.71,94.23.120.53,94.23.121.234,94.23.14.110,94.23.177.147,94.23.198.97] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (321)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407640; rev:167; fwsam: src, 24 hours;) alert udp [94.199.200.125,94.228.208.59,94.228.208.6,94.228.209.0/24,94.228.210.0/24,94.228.211.0/24,94.228.212.0/24,94.228.213.0/24,94.228.215.168,94.229.64.115,94.229.65.172,94.23.11.87,94.23.114.3,94.23.114.70,94.23.114.71,94.23.120.53,94.23.121.234,94.23.14.110,94.23.177.147,94.23.198.97] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (321)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407641; rev:167; fwsam: src, 24 hours;) alert tcp [94.23.199.154,94.23.199.98,94.23.206.229,94.23.208.11,94.23.211.214,94.23.23.65,94.23.238.202,94.23.34.43,94.23.4.164,94.23.6.43,94.23.89.95,94.232.248.0/24,94.240.225.56,94.243.110.72,94.247.0.0/21,94.247.88.109,94.249.155.5,94.25.224.130,94.25.85.14,94.27.123.227] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (322)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407642; rev:167; fwsam: src, 24 hours;) alert udp [94.23.199.154,94.23.199.98,94.23.206.229,94.23.208.11,94.23.211.214,94.23.23.65,94.23.238.202,94.23.34.43,94.23.4.164,94.23.6.43,94.23.89.95,94.232.248.0/24,94.240.225.56,94.243.110.72,94.247.0.0/21,94.247.88.109,94.249.155.5,94.25.224.130,94.25.85.14,94.27.123.227] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (322)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407643; rev:167; fwsam: src, 24 hours;) alert tcp [94.52.128.126,94.73.6.14,94.75.192.66,94.75.193.14,94.75.193.167,94.75.198.241,94.75.199.168,94.75.199.178,94.75.207.219,94.75.207.64,94.75.209.11,94.75.210.39,94.75.214.117,94.75.214.138,94.75.214.18,94.75.215.3,94.75.215.42,94.75.215.59,94.75.215.8,94.75.215.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (323)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407644; rev:167; fwsam: src, 24 hours;) alert udp [94.52.128.126,94.73.6.14,94.75.192.66,94.75.193.14,94.75.193.167,94.75.198.241,94.75.199.168,94.75.199.178,94.75.207.219,94.75.207.64,94.75.209.11,94.75.210.39,94.75.214.117,94.75.214.138,94.75.214.18,94.75.215.3,94.75.215.42,94.75.215.59,94.75.215.8,94.75.215.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (323)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407645; rev:167; fwsam: src, 24 hours;) alert tcp [94.75.216.155,94.75.216.163,94.75.221.68,94.75.221.70,94.75.221.73,94.75.221.76,94.75.226.73,94.75.227.110,94.75.227.111,94.75.227.80,94.75.228.136,94.75.228.162,94.75.228.245,94.75.228.36,94.75.229.229,94.75.229.249,94.75.229.253,94.75.233.162,94.75.233.192,94.75.233.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (324)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407646; rev:167; fwsam: src, 24 hours;) alert udp [94.75.216.155,94.75.216.163,94.75.221.68,94.75.221.70,94.75.221.73,94.75.221.76,94.75.226.73,94.75.227.110,94.75.227.111,94.75.227.80,94.75.228.136,94.75.228.162,94.75.228.245,94.75.228.36,94.75.229.229,94.75.229.249,94.75.229.253,94.75.233.162,94.75.233.192,94.75.233.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (324)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407647; rev:167; fwsam: src, 24 hours;) alert tcp [94.75.234.35,94.75.234.7,94.75.236.231,94.75.240.242,94.75.243.114,94.75.243.115,94.75.243.117,94.75.253.77,94.75.253.92,94.75.253.97,94.76.194.116,94.76.205.160,94.76.208.43,94.76.212.238,94.76.212.239,94.76.212.241,94.76.213.104,94.76.213.227,94.76.213.234,94.76.220.89] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (325)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407648; rev:167; fwsam: src, 24 hours;) alert udp [94.75.234.35,94.75.234.7,94.75.236.231,94.75.240.242,94.75.243.114,94.75.243.115,94.75.243.117,94.75.253.77,94.75.253.92,94.75.253.97,94.76.194.116,94.76.205.160,94.76.208.43,94.76.212.238,94.76.212.239,94.76.212.241,94.76.213.104,94.76.213.227,94.76.213.234,94.76.220.89] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (325)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407649; rev:167; fwsam: src, 24 hours;) alert tcp [94.76.225.134,94.76.225.98,94.76.235.32,95.104.41.45,95.129.144.0/24,95.129.145.46,95.129.145.58,95.129.146.244,95.142.35.50,95.143.192.198,95.143.192.202,95.143.192.203,95.143.192.23,95.143.192.25,95.143.192.31,95.143.192.33,95.143.192.35,95.143.192.38,95.143.192.41,95.143.192.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (326)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407650; rev:167; fwsam: src, 24 hours;) alert udp [94.76.225.134,94.76.225.98,94.76.235.32,95.104.41.45,95.129.144.0/24,95.129.145.46,95.129.145.58,95.129.146.244,95.142.35.50,95.143.192.198,95.143.192.202,95.143.192.203,95.143.192.23,95.143.192.25,95.143.192.31,95.143.192.33,95.143.192.35,95.143.192.38,95.143.192.41,95.143.192.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (326)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407651; rev:167; fwsam: src, 24 hours;) alert tcp [95.143.192.43,95.143.192.44,95.143.192.51,95.143.192.52,95.143.192.53,95.143.192.58,95.143.192.59,95.143.194.7,95.143.207.0/24,95.168.163.83,95.168.166.62,95.168.173.24,95.168.178.115,95.168.181.221,95.168.182.61,95.168.183.129,95.168.183.130,95.168.183.79,95.168.183.97,95.169.186.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (327)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407652; rev:167; fwsam: src, 24 hours;) alert udp [95.143.192.43,95.143.192.44,95.143.192.51,95.143.192.52,95.143.192.53,95.143.192.58,95.143.192.59,95.143.194.7,95.143.207.0/24,95.168.163.83,95.168.166.62,95.168.173.24,95.168.178.115,95.168.181.221,95.168.182.61,95.168.183.129,95.168.183.130,95.168.183.79,95.168.183.97,95.169.186.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (327)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407653; rev:167; fwsam: src, 24 hours;) alert tcp [95.169.190.147,95.169.190.205,95.169.190.223,95.169.190.55,95.169.191.126,95.169.191.223,95.170.128.227,95.211.1.16,95.211.1.173,95.211.128.237,95.211.13.155,95.211.13.248,95.211.131.68,95.211.14.157,95.211.14.158,95.211.14.162,95.211.14.163,95.211.2.1,95.211.21.86,95.211.24.117] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (328)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407654; rev:167; fwsam: src, 24 hours;) alert udp [95.169.190.147,95.169.190.205,95.169.190.223,95.169.190.55,95.169.191.126,95.169.191.223,95.170.128.227,95.211.1.16,95.211.1.173,95.211.128.237,95.211.13.155,95.211.13.248,95.211.131.68,95.211.14.157,95.211.14.158,95.211.14.162,95.211.14.163,95.211.2.1,95.211.21.86,95.211.24.117] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (328)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407655; rev:167; fwsam: src, 24 hours;) alert tcp [95.211.26.5,95.211.27.211,95.211.53.242,95.211.7.140,95.211.7.183,95.211.7.188,95.211.8.118,95.211.8.12,95.211.8.136,95.211.8.20,95.211.8.21,95.211.8.215,95.211.8.216,95.211.8.61,95.211.8.87,95.211.81.116,95.211.81.121,95.211.81.239,95.211.81.87,95.211.81.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (329)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407656; rev:167; fwsam: src, 24 hours;) alert udp [95.211.26.5,95.211.27.211,95.211.53.242,95.211.7.140,95.211.7.183,95.211.7.188,95.211.8.118,95.211.8.12,95.211.8.136,95.211.8.20,95.211.8.21,95.211.8.215,95.211.8.216,95.211.8.61,95.211.8.87,95.211.81.116,95.211.81.121,95.211.81.239,95.211.81.87,95.211.81.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (329)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407657; rev:167; fwsam: src, 24 hours;) alert tcp [95.211.9.246,95.211.9.25,95.211.9.27,95.211.92.253,95.211.98.159,95.31.234.3,95.58.65.50,95.78.126.195,95.84.203.133,96.0.161.123,96.0.179.224,96.0.25.161,96.0.255.64,96.0.63.107,96.0.75.2,96.27.21.3,96.30.24.92,96.30.27.183,96.31.84.98,96.44.128.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (330)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407658; rev:167; fwsam: src, 24 hours;) alert udp [95.211.9.246,95.211.9.25,95.211.9.27,95.211.92.253,95.211.98.159,95.31.234.3,95.58.65.50,95.78.126.195,95.84.203.133,96.0.161.123,96.0.179.224,96.0.25.161,96.0.255.64,96.0.63.107,96.0.75.2,96.27.21.3,96.30.24.92,96.30.27.183,96.31.84.98,96.44.128.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (330)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407659; rev:167; fwsam: src, 24 hours;) alert tcp [96.44.128.241,96.44.128.242,96.44.128.243,96.44.128.244,96.44.128.245,96.44.128.246,96.44.128.247,96.54.78.212,96.9.131.166,96.9.138.229,96.9.142.101,96.9.159.165,96.9.176.149,96.9.180.102,96.9.188.23,97.107.140.38,97.74.144.118,97.74.144.35,97.74.144.81,97.74.144.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (331)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407660; rev:167; fwsam: src, 24 hours;) alert udp [96.44.128.241,96.44.128.242,96.44.128.243,96.44.128.244,96.44.128.245,96.44.128.246,96.44.128.247,96.54.78.212,96.9.131.166,96.9.138.229,96.9.142.101,96.9.159.165,96.9.176.149,96.9.180.102,96.9.188.23,97.107.140.38,97.74.144.118,97.74.144.35,97.74.144.81,97.74.144.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (331)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407661; rev:167; fwsam: src, 24 hours;) alert tcp [97.74.144.97,97.74.185.234,97.74.215.38,97.74.220.163,97.74.26.128,97.74.28.243,97.74.64.235,97.82.228.202,98.101.93.44,98.121.216.106,98.124.198.1,98.124.199.1,98.126.116.2,98.126.116.90,98.126.119.180,98.126.120.18,98.126.120.19,98.126.120.20,98.126.134.107,98.126.211.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (332)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407662; rev:167; fwsam: src, 24 hours;) alert udp [97.74.144.97,97.74.185.234,97.74.215.38,97.74.220.163,97.74.26.128,97.74.28.243,97.74.64.235,97.82.228.202,98.101.93.44,98.121.216.106,98.124.198.1,98.124.199.1,98.126.116.2,98.126.116.90,98.126.119.180,98.126.120.18,98.126.120.19,98.126.120.20,98.126.134.107,98.126.211.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (332)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407663; rev:167; fwsam: src, 24 hours;) alert tcp [98.126.24.162,98.126.25.234,98.126.28.121,98.126.29.234,98.126.29.78,98.126.3.82,98.126.3.86,98.126.3.87,98.126.3.88,98.126.32.194,98.126.38.28,98.126.46.156,98.126.46.210,98.126.74.154,98.126.74.156,98.126.76.110,98.126.9.218,98.130.73.133,98.131.104.1,98.131.106.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (333)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407664; rev:167; fwsam: src, 24 hours;) alert udp [98.126.24.162,98.126.25.234,98.126.28.121,98.126.29.234,98.126.29.78,98.126.3.82,98.126.3.86,98.126.3.87,98.126.3.88,98.126.32.194,98.126.38.28,98.126.46.156,98.126.46.210,98.126.74.154,98.126.74.156,98.126.76.110,98.126.9.218,98.130.73.133,98.131.104.1,98.131.106.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (333)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407665; rev:167; fwsam: src, 24 hours;)