# # Emerging Threats RBN rules. # # Rules to detect known Russian Business Network (RBN) hosts. These lists are updated daily or better from many sources # # We do not necessarily declare that these hosts are all bad, or that RBN is inherently an evil organization. Use this # information as you see fit. # # More information available at doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork # # Please submit any feedback or ideas to emerging@emergingthreats.net or the emerging-sigs mailing list # #************************************************************* # # Copyright (c) 2003-2009, Emerging Threats # All rights reserved. # # Redistribution and use in source and binary forms, with or without modification, are permitted provided that the # following conditions are met: # # * Redistributions of source code must retain the above copyright notice, this list of conditions and the following # disclaimer. # * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the # following disclaimer in the documentation and/or other materials provided with the distribution. # * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived # from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES, # INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE # DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR # SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, # WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE # USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # # # VERSION 140 # Updated 2009-07-02 16:36:24 alert tcp [114.80.67.30,114.80.67.32,115.126.2.116,115.126.2.117,115.126.2.118,115.126.2.121,115.126.2.140,115.126.2.141,115.126.2.233,115.126.2.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (1)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407000; rev:140; fwsam: src, 24 hours;) alert udp [114.80.67.30,114.80.67.32,115.126.2.116,115.126.2.117,115.126.2.118,115.126.2.121,115.126.2.140,115.126.2.141,115.126.2.233,115.126.2.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (1)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407001; rev:140; fwsam: src, 24 hours;) alert tcp [115.126.5.10,115.126.5.122,115.126.5.50,115.126.5.51,115.126.5.76,115.126.5.92,115.28.82.201,116.0.103.115,116.125.56.218,116.199.135.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (2)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407002; rev:140; fwsam: src, 24 hours;) alert udp [115.126.5.10,115.126.5.122,115.126.5.50,115.126.5.51,115.126.5.76,115.126.5.92,115.28.82.201,116.0.103.115,116.125.56.218,116.199.135.139] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (2)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407003; rev:140; fwsam: src, 24 hours;) alert tcp [116.199.135.238,116.199.136.57,116.50.12.0/22,116.50.8.0/24,116.50.9.0/24,118.126.4.86,118.216.29.81,118.219.232.177,118.219.234.171,118.220.196.44] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (3)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407004; rev:140; fwsam: src, 24 hours;) alert udp [116.199.135.238,116.199.136.57,116.50.12.0/22,116.50.8.0/24,116.50.9.0/24,118.126.4.86,118.216.29.81,118.219.232.177,118.219.234.171,118.220.196.44] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (3)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407005; rev:140; fwsam: src, 24 hours;) alert tcp [118.45.190.166,119.110.107.124,119.110.107.132,119.110.107.136,119.110.107.137,119.235.22.26,119.47.81.140,119.84.4.56,121.10.105.92,121.11.86.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (4)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407006; rev:140; fwsam: src, 24 hours;) alert udp [118.45.190.166,119.110.107.124,119.110.107.132,119.110.107.136,119.110.107.137,119.235.22.26,119.47.81.140,119.84.4.56,121.10.105.92,121.11.86.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (4)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407007; rev:140; fwsam: src, 24 hours;) alert tcp [121.125.75.91,121.14.59.51,121.199.18.43,122.117.35.153,122.224.5.189,122.224.9.221,123.123.123.123,124.155.149.57,124.217.239.146,124.217.247.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (5)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407008; rev:140; fwsam: src, 24 hours;) alert udp [121.125.75.91,121.14.59.51,121.199.18.43,122.117.35.153,122.224.5.189,122.224.9.221,123.123.123.123,124.155.149.57,124.217.239.146,124.217.247.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (5)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407009; rev:140; fwsam: src, 24 hours;) alert tcp [124.217.247.249,124.43.65.207,125.163.251.219,125.211.195.11,125.46.1.229,125.46.57.230,125.65.46.113,128.242.120.13,129.44.190.77,132.247.8.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (6)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407010; rev:140; fwsam: src, 24 hours;) alert udp [124.217.247.249,124.43.65.207,125.163.251.219,125.211.195.11,125.46.1.229,125.46.57.230,125.65.46.113,128.242.120.13,129.44.190.77,132.247.8.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (6)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407011; rev:140; fwsam: src, 24 hours;) alert tcp [133.11.95.99,146.82.201.203,147.202.37.246,157.166.255.25,159.226.7.162,165.254.12.200,168.144.247.215,173.20.112.35,173.45.68.170,174.120.10.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (7)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407012; rev:140; fwsam: src, 24 hours;) alert udp [133.11.95.99,146.82.201.203,147.202.37.246,157.166.255.25,159.226.7.162,165.254.12.200,168.144.247.215,173.20.112.35,173.45.68.170,174.120.10.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (7)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407013; rev:140; fwsam: src, 24 hours;) alert tcp [174.120.18.158,174.120.30.244,174.129.241.185,174.129.244.106,174.132.165.154,174.132.180.98,174.132.192.9,174.132.250.194,174.132.88.66,174.133.156.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (8)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407014; rev:140; fwsam: src, 24 hours;) alert udp [174.120.18.158,174.120.30.244,174.129.241.185,174.129.244.106,174.132.165.154,174.132.180.98,174.132.192.9,174.132.250.194,174.132.88.66,174.133.156.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (8)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407015; rev:140; fwsam: src, 24 hours;) alert tcp [174.133.202.176,174.133.202.176/28,174.133.202.191,174.133.5.26,174.133.66.26,174.133.71.200/29,174.133.71.48/28,174.133.72.250,174.133.73.178,174.137.132.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (9)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407016; rev:140; fwsam: src, 24 hours;) alert udp [174.133.202.176,174.133.202.176/28,174.133.202.191,174.133.5.26,174.133.66.26,174.133.71.200/29,174.133.71.48/28,174.133.72.250,174.133.73.178,174.137.132.21] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (9)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407017; rev:140; fwsam: src, 24 hours;) alert tcp [174.137.132.37,174.137.132.45,174.137.189.38,174.137.189.39,174.139.17.140,174.139.26.172,174.142.109.139,174.142.113.20,174.142.113.203,174.142.113.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (10)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407018; rev:140; fwsam: src, 24 hours;) alert udp [174.137.132.37,174.137.132.45,174.137.189.38,174.137.189.39,174.139.17.140,174.139.26.172,174.142.109.139,174.142.113.20,174.142.113.203,174.142.113.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (10)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407019; rev:140; fwsam: src, 24 hours;) alert tcp [174.142.9.25,174.143.254.174,174.36.1.27,174.36.167.20,174.36.214.32,174.36.217.112,174.36.221.128,174.36.234.248,174.36.243.5,174.36.251.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (11)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407020; rev:140; fwsam: src, 24 hours;) alert udp [174.142.9.25,174.143.254.174,174.36.1.27,174.36.167.20,174.36.214.32,174.36.217.112,174.36.221.128,174.36.234.248,174.36.243.5,174.36.251.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (11)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407021; rev:140; fwsam: src, 24 hours;) alert tcp [174.36.46.112,174.37.217.96,189.14.100.23,189.19.60.29,189.19.76.194,189.38.91.30,190.15.64.203,190.15.72.0/21,190.183.63.0/24,190.20.51.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (12)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407022; rev:140; fwsam: src, 24 hours;) alert udp [174.36.46.112,174.37.217.96,189.14.100.23,189.19.60.29,189.19.76.194,189.38.91.30,190.15.64.203,190.15.72.0/21,190.183.63.0/24,190.20.51.206] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (12)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407023; rev:140; fwsam: src, 24 hours;) alert tcp [190.210.10.169,190.210.10.20,190.210.10.242,190.210.10.30,190.210.10.31,190.210.10.32,190.228.29.17,190.228.29.81,190.5.236.98,192.115.70.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (13)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407024; rev:140; fwsam: src, 24 hours;) alert udp [190.210.10.169,190.210.10.20,190.210.10.242,190.210.10.30,190.210.10.31,190.210.10.32,190.228.29.17,190.228.29.81,190.5.236.98,192.115.70.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (13)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407025; rev:140; fwsam: src, 24 hours;) alert tcp [193.111.244.118,193.111.244.157,193.111.244.21,193.124.133.160,193.124.133.63,193.138.172.23,193.138.172.5,193.138.172.6,193.138.172.8,193.138.173.160] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (14)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407026; rev:140; fwsam: src, 24 hours;) alert udp [193.111.244.118,193.111.244.157,193.111.244.21,193.124.133.160,193.124.133.63,193.138.172.23,193.138.172.5,193.138.172.6,193.138.172.8,193.138.173.160] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (14)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407027; rev:140; fwsam: src, 24 hours;) alert tcp [193.138.173.251,193.138.228.110,193.138.228.120,193.138.232.0/22,193.142.244.0/24,193.178.145.167,193.178.147.58,193.19.138.0/24,193.200.173.2,193.200.173.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (15)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407028; rev:140; fwsam: src, 24 hours;) alert udp [193.138.173.251,193.138.228.110,193.138.228.120,193.138.232.0/22,193.142.244.0/24,193.178.145.167,193.178.147.58,193.19.138.0/24,193.200.173.2,193.200.173.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (15)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407029; rev:140; fwsam: src, 24 hours;) alert tcp [193.200.255.18,193.200.255.19,193.200.29.161,193.200.29.177,193.22.244.48,193.227.240.130,193.227.240.37,193.227.240.38,193.227.241.60,193.232.130.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (16)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407030; rev:140; fwsam: src, 24 hours;) alert udp [193.200.255.18,193.200.255.19,193.200.29.161,193.200.29.177,193.22.244.48,193.227.240.130,193.227.240.37,193.227.240.38,193.227.241.60,193.232.130.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (16)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407031; rev:140; fwsam: src, 24 hours;) alert tcp [193.232.159.1,193.27.246.179,193.27.246.195,193.27.246.237,193.27.246.246,193.27.246.250,193.27.246.35,193.27.246.52,193.27.247.240,193.33.128.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (17)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407032; rev:140; fwsam: src, 24 hours;) alert udp [193.232.159.1,193.27.246.179,193.27.246.195,193.27.246.237,193.27.246.246,193.27.246.250,193.27.246.35,193.27.246.52,193.27.247.240,193.33.128.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (17)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407033; rev:140; fwsam: src, 24 hours;) alert tcp [193.33.144.226,193.33.61.161,193.33.61.224,193.33.61.225,193.41.174.99,193.86.238.12,193.86.238.13,193.86.238.19,194.1.152.1,194.109.11.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (18)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407034; rev:140; fwsam: src, 24 hours;) alert udp [193.33.144.226,193.33.61.161,193.33.61.224,193.33.61.225,193.41.174.99,193.86.238.12,193.86.238.13,193.86.238.19,194.1.152.1,194.109.11.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (18)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407035; rev:140; fwsam: src, 24 hours;) alert tcp [194.110.161.0/24,194.110.69.0/24,194.116.202.129,194.126.174.124,194.135.103.86,194.135.105.203,194.135.19.39,194.135.22.0/24,194.135.25.106,194.145.235.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (19)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407036; rev:140; fwsam: src, 24 hours;) alert udp [194.110.161.0/24,194.110.69.0/24,194.116.202.129,194.126.174.124,194.135.103.86,194.135.105.203,194.135.19.39,194.135.22.0/24,194.135.25.106,194.145.235.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (19)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407037; rev:140; fwsam: src, 24 hours;) alert tcp [194.146.204.0/22,194.154.75.191,194.165.4.0/23,194.187.103.116,194.187.96.134,194.187.96.151,194.187.98.143,194.187.98.82,194.187.98.83,194.187.99.20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (20)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407038; rev:140; fwsam: src, 24 hours;) alert udp [194.146.204.0/22,194.154.75.191,194.165.4.0/23,194.187.103.116,194.187.96.134,194.187.96.151,194.187.98.143,194.187.98.82,194.187.98.83,194.187.99.20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (20)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407039; rev:140; fwsam: src, 24 hours;) alert tcp [194.187.99.23,194.190.139.249,194.226.127.22,194.226.64.0/20,194.226.96.8,194.246.115.221,194.33.180.41,194.42.154.26,194.50.255.226,194.50.255.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (21)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407040; rev:140; fwsam: src, 24 hours;) alert udp [194.187.99.23,194.190.139.249,194.226.127.22,194.226.64.0/20,194.226.96.8,194.246.115.221,194.33.180.41,194.42.154.26,194.50.255.226,194.50.255.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (21)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407041; rev:140; fwsam: src, 24 hours;) alert tcp [194.50.255.253,194.54.88.46,194.54.89.12,194.54.90.246,194.58.155.37,194.58.155.38,194.58.78.41,194.8.74.227,194.85.105.17,194.85.61.20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (22)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407042; rev:140; fwsam: src, 24 hours;) alert udp [194.50.255.253,194.54.88.46,194.54.89.12,194.54.90.246,194.58.155.37,194.58.155.38,194.58.78.41,194.8.74.227,194.85.105.17,194.85.61.20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (22)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407043; rev:140; fwsam: src, 24 hours;) alert tcp [194.85.61.78,194.85.92.136,194.90.224.86,195.110.124.133,195.114.16.0/23,195.114.18.146,195.12.48.212,195.12.48.80,195.131.4.189,195.161.0.0/16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (23)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407044; rev:140; fwsam: src, 24 hours;) alert udp [194.85.61.78,194.85.92.136,194.90.224.86,195.110.124.133,195.114.16.0/23,195.114.18.146,195.12.48.212,195.12.48.80,195.131.4.189,195.161.0.0/16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (23)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407045; rev:140; fwsam: src, 24 hours;) alert tcp [195.161.119.201,195.161.119.240,195.189.226.149,195.189.227.194,195.190.13.10,195.190.13.106,195.190.13.107,195.190.13.11,195.190.13.139,195.190.13.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (24)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407046; rev:140; fwsam: src, 24 hours;) alert udp [195.161.119.201,195.161.119.240,195.189.226.149,195.189.227.194,195.190.13.10,195.190.13.106,195.190.13.107,195.190.13.11,195.190.13.139,195.190.13.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (24)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407047; rev:140; fwsam: src, 24 hours;) alert tcp [195.190.13.163,195.190.13.234,195.190.13.3,195.2.240.147,195.2.240.34,195.2.240.58,195.2.252.0/23,195.2.253.233,195.2.253.237,195.216.175.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (25)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407048; rev:140; fwsam: src, 24 hours;) alert udp [195.190.13.163,195.190.13.234,195.190.13.3,195.2.240.147,195.2.240.34,195.2.240.58,195.2.252.0/23,195.2.253.233,195.2.253.237,195.216.175.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (25)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407049; rev:140; fwsam: src, 24 hours;) alert tcp [195.216.175.115,195.216.175.117,195.222.29.118,195.225.177.0/24,195.225.178.239,195.230.90.19,195.234.159.137,195.24.65.50,195.24.78.182,195.24.78.186] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (26)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407050; rev:140; fwsam: src, 24 hours;) alert udp [195.216.175.115,195.216.175.117,195.222.29.118,195.225.177.0/24,195.225.178.239,195.230.90.19,195.234.159.137,195.24.65.50,195.24.78.182,195.24.78.186] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (26)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407051; rev:140; fwsam: src, 24 hours;) alert tcp [195.24.78.195,195.24.78.242,195.24.78.243,195.242.161.24,195.242.161.45,195.242.99.215,195.244.9.20,195.245.119.131,195.245.119.150,195.245.194.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (27)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407052; rev:140; fwsam: src, 24 hours;) alert udp [195.24.78.195,195.24.78.242,195.24.78.243,195.242.161.24,195.242.161.45,195.242.99.215,195.244.9.20,195.245.119.131,195.245.119.150,195.245.194.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (27)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407053; rev:140; fwsam: src, 24 hours;) alert tcp [195.248.234.27,195.248.77.45,195.3.144.0/22,195.3.206.34,195.39.196.43,195.42.102.27,195.42.103.40,195.42.103.41,195.42.103.80,195.42.103.84] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (28)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407054; rev:140; fwsam: src, 24 hours;) alert udp [195.248.234.27,195.248.77.45,195.3.144.0/22,195.3.206.34,195.39.196.43,195.42.102.27,195.42.103.40,195.42.103.41,195.42.103.80,195.42.103.84] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (28)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407055; rev:140; fwsam: src, 24 hours;) alert tcp [195.42.103.91,195.5.116.0/24,195.5.117.0/24,195.62.37.16,195.62.37.17,195.64.140.0/23,195.64.162.0/23,195.64.190.1,195.66.132.0/24,195.88.209.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (29)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407056; rev:140; fwsam: src, 24 hours;) alert udp [195.42.103.91,195.5.116.0/24,195.5.117.0/24,195.62.37.16,195.62.37.17,195.64.140.0/23,195.64.162.0/23,195.64.190.1,195.66.132.0/24,195.88.209.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (29)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407057; rev:140; fwsam: src, 24 hours;) alert tcp [195.88.209.243,195.88.209.244,195.88.33.54,195.88.33.55,195.88.80.127,195.88.80.177,195.88.80.178,195.88.80.206,195.88.80.207,195.88.80.208] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (30)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407058; rev:140; fwsam: src, 24 hours;) alert udp [195.88.209.243,195.88.209.244,195.88.33.54,195.88.33.55,195.88.80.127,195.88.80.177,195.88.80.178,195.88.80.206,195.88.80.207,195.88.80.208] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (30)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407059; rev:140; fwsam: src, 24 hours;) alert tcp [195.88.80.40,195.88.80.41,195.88.81.11,195.88.81.115,195.88.81.116,195.88.81.117,195.88.81.12,195.88.81.36,195.88.81.37,195.88.81.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (31)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407060; rev:140; fwsam: src, 24 hours;) alert udp [195.88.80.40,195.88.80.41,195.88.81.11,195.88.81.115,195.88.81.116,195.88.81.117,195.88.81.12,195.88.81.36,195.88.81.37,195.88.81.65] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (31)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407061; rev:140; fwsam: src, 24 hours;) alert tcp [195.88.81.73,195.88.81.74,195.88.81.92,195.88.81.93,195.93.218.130,195.93.218.195,195.93.218.196,195.93.218.197,195.93.218.25,195.93.218.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (32)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407062; rev:140; fwsam: src, 24 hours;) alert udp [195.88.81.73,195.88.81.74,195.88.81.92,195.88.81.93,195.93.218.130,195.93.218.195,195.93.218.196,195.93.218.197,195.93.218.25,195.93.218.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (32)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407063; rev:140; fwsam: src, 24 hours;) alert tcp [195.93.218.43,195.93.219.201,195.95.151.138,195.95.151.174,195.95.155.13,195.95.155.4,195.95.218.0/23,196.2.198.240,198.63.210.226,198.63.210.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (33)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407064; rev:140; fwsam: src, 24 hours;) alert udp [195.93.218.43,195.93.219.201,195.95.151.138,195.95.151.174,195.95.155.13,195.95.155.4,195.95.218.0/23,196.2.198.240,198.63.210.226,198.63.210.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (33)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407065; rev:140; fwsam: src, 24 hours;) alert tcp [198.63.211.208,198.63.211.8,198.66.255.130,199.199.211.35,199.237.229.158,200.108.36.132,200.115.160.0/20,200.122.168.229,200.155.17.172,200.168.143.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (34)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407066; rev:140; fwsam: src, 24 hours;) alert udp [198.63.211.208,198.63.211.8,198.66.255.130,199.199.211.35,199.237.229.158,200.108.36.132,200.115.160.0/20,200.122.168.229,200.155.17.172,200.168.143.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (34)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407067; rev:140; fwsam: src, 24 hours;) alert tcp [200.171.128.39,200.171.170.10,200.205.145.90,200.219.224.48,200.234.196.118,200.234.196.19,200.234.196.90,200.234.200.139,200.241.52.18,200.35.146.150] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (35)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407068; rev:140; fwsam: src, 24 hours;) alert udp [200.171.128.39,200.171.170.10,200.205.145.90,200.219.224.48,200.234.196.118,200.234.196.19,200.234.196.90,200.234.200.139,200.241.52.18,200.35.146.150] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (35)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407069; rev:140; fwsam: src, 24 hours;) alert tcp [200.35.151.36,200.46.83.204,200.46.83.245,200.63.42.136,200.63.42.141,200.63.42.81,200.63.44.177,200.63.45.0/24,200.63.48.105,200.63.48.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (36)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407070; rev:140; fwsam: src, 24 hours;) alert udp [200.35.151.36,200.46.83.204,200.46.83.245,200.63.42.136,200.63.42.141,200.63.42.81,200.63.44.177,200.63.45.0/24,200.63.48.105,200.63.48.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (36)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407071; rev:140; fwsam: src, 24 hours;) alert tcp [200.87.164.22,201.134.249.164,201.16.248.189,201.212.0.243,201.218.250.124,201.235.145.105,201.248.238.0/24,201.76.59.58,202.123.79.22,202.172.28.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (37)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407072; rev:140; fwsam: src, 24 hours;) alert udp [200.87.164.22,201.134.249.164,201.16.248.189,201.212.0.243,201.218.250.124,201.235.145.105,201.248.238.0/24,201.76.59.58,202.123.79.22,202.172.28.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (37)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407073; rev:140; fwsam: src, 24 hours;) alert tcp [202.172.28.38,202.174.106.50,202.174.106.51,202.174.106.52,202.187.140.0/24,202.187.141.0/24,202.190.175.228,202.191.61.27,202.28.117.82,202.41.215.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (38)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407074; rev:140; fwsam: src, 24 hours;) alert udp [202.172.28.38,202.174.106.50,202.174.106.51,202.174.106.52,202.187.140.0/24,202.187.141.0/24,202.190.175.228,202.191.61.27,202.28.117.82,202.41.215.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (38)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407075; rev:140; fwsam: src, 24 hours;) alert tcp [202.54.119.132,202.65.111.10,202.67.230.203,202.71.102.0/24,202.71.111.234,202.73.56.169,202.73.57.11,202.73.57.20,202.73.57.22,202.73.57.25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (39)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407076; rev:140; fwsam: src, 24 hours;) alert udp [202.54.119.132,202.65.111.10,202.67.230.203,202.71.102.0/24,202.71.111.234,202.73.56.169,202.73.57.11,202.73.57.20,202.73.57.22,202.73.57.25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (39)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407077; rev:140; fwsam: src, 24 hours;) alert tcp [202.73.57.6,202.75.35.101,202.75.35.222,202.75.36.22,202.75.63.116,202.80.178.128,202.82.11.4,202.91.245.221,202.95.104.0/24,203.116.63.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (40)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407078; rev:140; fwsam: src, 24 hours;) alert udp [202.73.57.6,202.75.35.101,202.75.35.222,202.75.36.22,202.75.63.116,202.80.178.128,202.82.11.4,202.91.245.221,202.95.104.0/24,203.116.63.113] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (40)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407079; rev:140; fwsam: src, 24 hours;) alert tcp [203.117.0.0/16,203.119.6.11,203.121.110.150,203.121.110.151,203.121.110.152,203.121.110.153,203.121.110.154,203.121.110.155,203.121.110.156,203.121.110.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (41)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407080; rev:140; fwsam: src, 24 hours;) alert udp [203.117.0.0/16,203.119.6.11,203.121.110.150,203.121.110.151,203.121.110.152,203.121.110.153,203.121.110.154,203.121.110.155,203.121.110.156,203.121.110.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (41)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407081; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.110.158,203.121.110.159,203.121.110.160,203.121.110.161,203.121.110.162,203.121.110.163,203.121.110.164,203.121.110.165,203.121.110.166,203.121.110.167] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (42)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407082; rev:140; fwsam: src, 24 hours;) alert udp [203.121.110.158,203.121.110.159,203.121.110.160,203.121.110.161,203.121.110.162,203.121.110.163,203.121.110.164,203.121.110.165,203.121.110.166,203.121.110.167] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (42)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407083; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.110.168,203.121.110.169,203.121.110.170,203.121.110.171,203.121.110.172,203.121.110.173,203.121.110.174,203.121.110.175,203.121.110.176,203.121.110.177] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (43)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407084; rev:140; fwsam: src, 24 hours;) alert udp [203.121.110.168,203.121.110.169,203.121.110.170,203.121.110.171,203.121.110.172,203.121.110.173,203.121.110.174,203.121.110.175,203.121.110.176,203.121.110.177] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (43)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407085; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.110.178,203.121.110.179,203.121.110.196,203.121.110.217,203.121.110.221,203.121.110.229,203.121.110.247,203.121.110.36,203.121.110.37,203.121.110.38] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (44)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407086; rev:140; fwsam: src, 24 hours;) alert udp [203.121.110.178,203.121.110.179,203.121.110.196,203.121.110.217,203.121.110.221,203.121.110.229,203.121.110.247,203.121.110.36,203.121.110.37,203.121.110.38] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (44)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407087; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.110.39,203.121.110.40,203.121.110.41,203.121.110.42,203.121.110.43,203.121.110.44,203.121.110.45,203.121.111.200,203.121.67.170,203.121.67.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (45)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407088; rev:140; fwsam: src, 24 hours;) alert udp [203.121.110.39,203.121.110.40,203.121.110.41,203.121.110.42,203.121.110.43,203.121.110.44,203.121.110.45,203.121.111.200,203.121.67.170,203.121.67.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (45)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407089; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.67.230,203.121.67.231,203.121.67.232,203.121.67.233,203.121.67.234,203.121.67.235,203.121.67.236,203.121.67.237,203.121.67.238,203.121.67.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (46)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407090; rev:140; fwsam: src, 24 hours;) alert udp [203.121.67.230,203.121.67.231,203.121.67.232,203.121.67.233,203.121.67.234,203.121.67.235,203.121.67.236,203.121.67.237,203.121.67.238,203.121.67.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (46)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407091; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.67.32,203.121.67.33,203.121.67.34,203.121.67.35,203.121.67.36,203.121.67.37,203.121.67.38,203.121.67.39,203.121.67.40,203.121.67.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (47)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407092; rev:140; fwsam: src, 24 hours;) alert udp [203.121.67.32,203.121.67.33,203.121.67.34,203.121.67.35,203.121.67.36,203.121.67.37,203.121.67.38,203.121.67.39,203.121.67.40,203.121.67.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (47)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407093; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.67.54,203.121.68.18,203.121.69.134,203.121.69.135,203.121.69.136,203.121.69.137,203.121.69.138,203.121.69.143,203.121.69.144,203.121.69.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (48)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407094; rev:140; fwsam: src, 24 hours;) alert udp [203.121.67.54,203.121.68.18,203.121.69.134,203.121.69.135,203.121.69.136,203.121.69.137,203.121.69.138,203.121.69.143,203.121.69.144,203.121.69.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (48)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407095; rev:140; fwsam: src, 24 hours;) alert tcp [203.121.69.146,203.121.71.180,203.121.73.209,203.121.73.24,203.121.78.148,203.121.79.184,203.121.79.212,203.121.79.71,203.121.79.72,203.121.80.163] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (49)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407096; rev:140; fwsam: src, 24 hours;) alert udp [203.121.69.146,203.121.71.180,203.121.73.209,203.121.73.24,203.121.78.148,203.121.79.184,203.121.79.212,203.121.79.71,203.121.79.72,203.121.80.163] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (49)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407097; rev:140; fwsam: src, 24 hours;) alert tcp [203.142.19.81,203.146.129.185,203.157.64.24,203.169.128.0/19,203.169.164.18,203.174.83.75,203.211.145.203,203.22.204.226,203.22.204.97,203.93.212.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (50)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407098; rev:140; fwsam: src, 24 hours;) alert udp [203.142.19.81,203.146.129.185,203.157.64.24,203.169.128.0/19,203.169.164.18,203.174.83.75,203.211.145.203,203.22.204.226,203.22.204.97,203.93.212.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (50)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407099; rev:140; fwsam: src, 24 hours;) alert tcp [204.13.160.15,204.13.160.38,204.13.161.103,204.13.161.136,204.13.161.177,204.14.110.38,204.16.244.155,204.16.244.222,204.16.247.230,204.16.252.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (51)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407100; rev:140; fwsam: src, 24 hours;) alert udp [204.13.160.15,204.13.160.38,204.13.161.103,204.13.161.136,204.13.161.177,204.14.110.38,204.16.244.155,204.16.244.222,204.16.247.230,204.16.252.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (51)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407101; rev:140; fwsam: src, 24 hours;) alert tcp [204.2.183.50,204.225.123.154,204.251.15.190,204.27.56.74,204.27.57.227,204.8.223.140,204.8.223.249,205.134.162.147,205.134.170.131,205.134.191.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (52)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407102; rev:140; fwsam: src, 24 hours;) alert udp [204.2.183.50,204.225.123.154,204.251.15.190,204.27.56.74,204.27.57.227,204.8.223.140,204.8.223.249,205.134.162.147,205.134.170.131,205.134.191.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (52)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407103; rev:140; fwsam: src, 24 hours;) alert tcp [205.134.225.120,205.177.124.46,205.178.145.65,205.178.150.185,205.196.212.97,205.209.137.109,205.209.137.110,205.209.143.94,205.219.188.169,205.234.140.186] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (53)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407104; rev:140; fwsam: src, 24 hours;) alert udp [205.134.225.120,205.177.124.46,205.178.145.65,205.178.150.185,205.196.212.97,205.209.137.109,205.209.137.110,205.209.143.94,205.219.188.169,205.234.140.186] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (53)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407105; rev:140; fwsam: src, 24 hours;) alert tcp [205.234.184.106,205.234.186.234,205.234.197.209,205.234.197.40,205.234.206.30,205.252.166.58,205.252.166.60,205.252.166.61,205.252.167.72,205.252.24.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (54)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407106; rev:140; fwsam: src, 24 hours;) alert udp [205.234.184.106,205.234.186.234,205.234.197.209,205.234.197.40,205.234.206.30,205.252.166.58,205.252.166.60,205.252.166.61,205.252.167.72,205.252.24.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (54)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407107; rev:140; fwsam: src, 24 hours;) alert tcp [206.123.100.12,206.125.44.28,206.125.44.30,206.161.120.0/24,206.161.121.10,206.161.121.58,206.161.121.82,206.161.126.0/24,206.161.193.131,206.161.200.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (55)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407108; rev:140; fwsam: src, 24 hours;) alert udp [206.123.100.12,206.125.44.28,206.125.44.30,206.161.120.0/24,206.161.121.10,206.161.121.58,206.161.121.82,206.161.126.0/24,206.161.193.131,206.161.200.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (55)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407109; rev:140; fwsam: src, 24 hours;) alert tcp [206.161.201.180,206.161.201.181,206.161.202.196,206.161.202.198,206.161.202.199,206.161.202.206,206.161.205.52,206.161.206.186,206.161.206.187,206.221.184.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (56)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407110; rev:140; fwsam: src, 24 hours;) alert udp [206.161.201.180,206.161.201.181,206.161.202.196,206.161.202.198,206.161.202.199,206.161.202.206,206.161.205.52,206.161.206.186,206.161.206.187,206.221.184.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (56)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407111; rev:140; fwsam: src, 24 hours;) alert tcp [206.222.31.218,206.222.31.219,206.225.86.123,206.251.244.227,206.251.244.252,206.51.225.217,206.51.226.211,206.51.226.78,206.51.234.0/24,206.51.235.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (57)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407112; rev:140; fwsam: src, 24 hours;) alert udp [206.222.31.218,206.222.31.219,206.225.86.123,206.251.244.227,206.251.244.252,206.51.225.217,206.51.226.211,206.51.226.78,206.51.234.0/24,206.51.235.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (57)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407113; rev:140; fwsam: src, 24 hours;) alert tcp [206.51.235.172,206.51.235.4,206.51.236.150,206.51.236.151,206.51.236.152,206.51.236.153,206.51.236.154,206.51.236.155,206.51.236.156,206.51.236.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (58)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407114; rev:140; fwsam: src, 24 hours;) alert udp [206.51.235.172,206.51.235.4,206.51.236.150,206.51.236.151,206.51.236.152,206.51.236.153,206.51.236.154,206.51.236.155,206.51.236.156,206.51.236.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (58)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407115; rev:140; fwsam: src, 24 hours;) alert tcp [206.51.236.158,206.51.236.159,206.51.237.93,206.51.238.166,206.51.238.167,206.51.238.200,206.51.238.27,206.51.238.40,206.51.238.41,206.51.238.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (59)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407116; rev:140; fwsam: src, 24 hours;) alert udp [206.51.236.158,206.51.236.159,206.51.237.93,206.51.238.166,206.51.238.167,206.51.238.200,206.51.238.27,206.51.238.40,206.51.238.41,206.51.238.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (59)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407117; rev:140; fwsam: src, 24 hours;) alert tcp [206.51.238.43,206.51.238.44,206.51.238.45,206.51.238.46,206.51.238.47,206.51.238.48,206.51.238.49,206.51.238.5,206.53.48.156,206.53.51.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (60)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407118; rev:140; fwsam: src, 24 hours;) alert udp [206.51.238.43,206.51.238.44,206.51.238.45,206.51.238.46,206.51.238.47,206.51.238.48,206.51.238.49,206.51.238.5,206.53.48.156,206.53.51.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (60)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407119; rev:140; fwsam: src, 24 hours;) alert tcp [206.53.61.71,206.53.61.75,206.53.61.76,207.150.191.115,207.150.191.116,207.176.7.0/24,207.182.136.106,207.182.136.107,207.182.136.108,207.182.141.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (61)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407120; rev:140; fwsam: src, 24 hours;) alert udp [206.53.61.71,206.53.61.75,206.53.61.76,207.150.191.115,207.150.191.116,207.176.7.0/24,207.182.136.106,207.182.136.107,207.182.136.108,207.182.141.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (61)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407121; rev:140; fwsam: src, 24 hours;) alert tcp [207.189.104.89,207.189.119.29,207.189.119.30,207.210.104.106,207.210.112.209,207.210.85.61,207.210.88.52,207.226.164.54,207.226.167.94,207.226.168.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (62)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407122; rev:140; fwsam: src, 24 hours;) alert udp [207.189.104.89,207.189.119.29,207.189.119.30,207.210.104.106,207.210.112.209,207.210.85.61,207.210.88.52,207.226.164.54,207.226.167.94,207.226.168.239] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (62)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407123; rev:140; fwsam: src, 24 hours;) alert tcp [207.226.173.0/24,207.226.175.0/24,207.226.178.149,207.226.178.162,207.226.178.163,207.226.179.0/24,207.226.182.0/24,207.226.88.123,207.226.88.124,207.36.232.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (63)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407124; rev:140; fwsam: src, 24 hours;) alert udp [207.226.173.0/24,207.226.175.0/24,207.226.178.149,207.226.178.162,207.226.178.163,207.226.179.0/24,207.226.182.0/24,207.226.88.123,207.226.88.124,207.36.232.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (63)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407125; rev:140; fwsam: src, 24 hours;) alert tcp [207.44.164.50,207.58.145.101,207.58.145.102,207.58.145.103,207.58.145.104,208.100.34.148,208.100.61.101,208.100.61.2,208.101.11.160,208.101.11.161] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (64)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407126; rev:140; fwsam: src, 24 hours;) alert udp [207.44.164.50,207.58.145.101,207.58.145.102,207.58.145.103,207.58.145.104,208.100.34.148,208.100.61.101,208.100.61.2,208.101.11.160,208.101.11.161] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (64)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407127; rev:140; fwsam: src, 24 hours;) alert tcp [208.101.11.162,208.101.11.163,208.101.11.164,208.101.11.165,208.101.11.166,208.101.11.167,208.101.21.18,208.101.41.224,208.101.41.225,208.101.41.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (65)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407128; rev:140; fwsam: src, 24 hours;) alert udp [208.101.11.162,208.101.11.163,208.101.11.164,208.101.11.165,208.101.11.166,208.101.11.167,208.101.21.18,208.101.41.224,208.101.41.225,208.101.41.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (65)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407129; rev:140; fwsam: src, 24 hours;) alert tcp [208.101.41.227,208.101.41.228,208.101.41.229,208.101.41.230,208.101.41.231,208.101.43.67,208.101.56.100,208.109.181.42,208.109.189.112,208.109.203.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (66)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407130; rev:140; fwsam: src, 24 hours;) alert udp [208.101.41.227,208.101.41.228,208.101.41.229,208.101.41.230,208.101.41.231,208.101.43.67,208.101.56.100,208.109.181.42,208.109.189.112,208.109.203.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (66)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407131; rev:140; fwsam: src, 24 hours;) alert tcp [208.110.70.81,208.110.80.170,208.113.141.194,208.113.153.62,208.113.161.124,208.113.162.113,208.113.168.60,208.122.40.22,208.122.40.253,208.43.120.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (67)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407132; rev:140; fwsam: src, 24 hours;) alert udp [208.110.70.81,208.110.80.170,208.113.141.194,208.113.153.62,208.113.161.124,208.113.162.113,208.113.168.60,208.122.40.22,208.122.40.253,208.43.120.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (67)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407133; rev:140; fwsam: src, 24 hours;) alert tcp [208.43.121.156,208.43.124.186,208.43.125.104,208.43.125.107,208.43.125.236,208.43.130.19,208.43.155.64,208.43.202.159,208.43.231.66,208.43.232.224] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (68)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407134; rev:140; fwsam: src, 24 hours;) alert udp [208.43.121.156,208.43.124.186,208.43.125.104,208.43.125.107,208.43.125.236,208.43.130.19,208.43.155.64,208.43.202.159,208.43.231.66,208.43.232.224] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (68)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407135; rev:140; fwsam: src, 24 hours;) alert tcp [208.43.242.238,208.43.250.121,208.43.27.11,208.43.41.0/24,208.43.73.230,208.43.79.11,208.43.92.68,208.53.147.189,208.66.192.0/22,208.72.160.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (69)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407136; rev:140; fwsam: src, 24 hours;) alert udp [208.43.242.238,208.43.250.121,208.43.27.11,208.43.41.0/24,208.43.73.230,208.43.79.11,208.43.92.68,208.53.147.189,208.66.192.0/22,208.72.160.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (69)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407137; rev:140; fwsam: src, 24 hours;) alert tcp [208.72.168.0/21,208.72.173.0/24,208.73.210.121,208.73.210.32,208.73.210.50,208.75.183.18,208.75.183.19,208.75.230.43,208.77.101.104,208.77.45.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (70)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407138; rev:140; fwsam: src, 24 hours;) alert udp [208.72.168.0/21,208.72.173.0/24,208.73.210.121,208.73.210.32,208.73.210.50,208.75.183.18,208.75.183.19,208.75.230.43,208.77.101.104,208.77.45.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (70)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407139; rev:140; fwsam: src, 24 hours;) alert tcp [208.79.82.0/24,208.80.184.202,208.80.184.203,208.85.181.67,208.85.181.68,208.85.181.69,208.85.181.70,208.87.148.0/23,208.87.242.120,208.87.242.130] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (71)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407140; rev:140; fwsam: src, 24 hours;) alert udp [208.79.82.0/24,208.80.184.202,208.80.184.203,208.85.181.67,208.85.181.68,208.85.181.69,208.85.181.70,208.87.148.0/23,208.87.242.120,208.87.242.130] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (71)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407141; rev:140; fwsam: src, 24 hours;) alert tcp [208.87.243.4,208.87.33.150,208.88.224.0/24,208.88.226.199,208.88.226.71,208.88.227.214,208.88.227.216,208.88.227.234,208.88.227.36,208.88.227.38] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (72)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407142; rev:140; fwsam: src, 24 hours;) alert udp [208.87.243.4,208.87.33.150,208.88.224.0/24,208.88.226.199,208.88.226.71,208.88.227.214,208.88.227.216,208.88.227.234,208.88.227.36,208.88.227.38] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (72)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407143; rev:140; fwsam: src, 24 hours;) alert tcp [208.88.227.39,208.88.227.40,208.88.51.100,208.88.51.105,208.88.53.0/24,208.98.11.187,208.98.22.0/24,208.98.6.67,209.123.181.122,209.123.181.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (73)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407144; rev:140; fwsam: src, 24 hours;) alert udp [208.88.227.39,208.88.227.40,208.88.51.100,208.88.51.105,208.88.53.0/24,208.98.11.187,208.98.22.0/24,208.98.6.67,209.123.181.122,209.123.181.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (73)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407145; rev:140; fwsam: src, 24 hours;) alert tcp [209.123.181.85,209.123.8.188,209.160.20.116,209.160.20.117,209.160.21.125,209.160.21.218,209.160.21.51,209.160.24.29,209.160.38.125,209.160.65.158] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (74)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407146; rev:140; fwsam: src, 24 hours;) alert udp [209.123.181.85,209.123.8.188,209.160.20.116,209.160.20.117,209.160.21.125,209.160.21.218,209.160.21.51,209.160.24.29,209.160.38.125,209.160.65.158] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (74)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407147; rev:140; fwsam: src, 24 hours;) alert tcp [209.160.65.62,209.160.66.201,209.160.67.56,209.160.67.74,209.160.68.98,209.160.71.110,209.160.72.174,209.160.73.141,209.160.73.4,209.162.188.225] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (75)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407148; rev:140; fwsam: src, 24 hours;) alert udp [209.160.65.62,209.160.66.201,209.160.67.56,209.160.67.74,209.160.68.98,209.160.71.110,209.160.72.174,209.160.73.141,209.160.73.4,209.162.188.225] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (75)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407149; rev:140; fwsam: src, 24 hours;) alert tcp [209.162.189.26,209.172.37.190,209.172.41.53,209.172.44.132,209.172.44.212,209.190.16.82,209.190.24.10,209.190.24.3,209.190.24.6,209.190.85.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (76)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407150; rev:140; fwsam: src, 24 hours;) alert udp [209.162.189.26,209.172.37.190,209.172.41.53,209.172.44.132,209.172.44.212,209.190.16.82,209.190.24.10,209.190.24.3,209.190.24.6,209.190.85.36] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (76)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407151; rev:140; fwsam: src, 24 hours;) alert tcp [209.197.3.119,209.20.88.75,209.200.124.200,209.200.162.193,209.200.60.137,209.200.63.169,209.200.63.179,209.200.63.184,209.200.91.44,209.202.252.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (77)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407152; rev:140; fwsam: src, 24 hours;) alert udp [209.197.3.119,209.20.88.75,209.200.124.200,209.200.162.193,209.200.60.137,209.200.63.169,209.200.63.179,209.200.63.184,209.200.91.44,209.202.252.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (77)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407153; rev:140; fwsam: src, 24 hours;) alert tcp [209.202.252.50,209.216.193.100,209.216.193.98,209.249.222.37,209.249.222.48,209.250.227.0/24,209.250.230.0/24,209.250.232.0/24,209.250.235.0/24,209.250.236.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (78)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407154; rev:140; fwsam: src, 24 hours;) alert udp [209.202.252.50,209.216.193.100,209.216.193.98,209.249.222.37,209.249.222.48,209.250.227.0/24,209.250.230.0/24,209.250.232.0/24,209.250.235.0/24,209.250.236.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (78)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407155; rev:140; fwsam: src, 24 hours;) alert tcp [209.250.237.0/24,209.250.239.17,209.250.241.134,209.250.241.141,209.250.241.164,209.250.241.240,209.250.241.244,209.44.100.58,209.44.111.57,209.44.111.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (79)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407156; rev:140; fwsam: src, 24 hours;) alert udp [209.250.237.0/24,209.250.239.17,209.250.241.134,209.250.241.141,209.250.241.164,209.250.241.240,209.250.241.244,209.44.100.58,209.44.111.57,209.44.111.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (79)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407157; rev:140; fwsam: src, 24 hours;) alert tcp [209.44.111.59,209.44.111.60,209.44.115.202,209.44.126.0/24,209.44.126.102,209.44.126.104,209.44.126.22,209.44.126.241,209.44.126.36,209.51.155.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (80)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407158; rev:140; fwsam: src, 24 hours;) alert udp [209.44.111.59,209.44.111.60,209.44.115.202,209.44.126.0/24,209.44.126.102,209.44.126.104,209.44.126.22,209.44.126.241,209.44.126.36,209.51.155.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (80)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407159; rev:140; fwsam: src, 24 hours;) alert tcp [209.51.195.116,209.51.196.240/28,209.51.196.248,209.51.196.250,209.51.196.251,209.51.196.252,209.51.196.253,209.51.196.254,209.59.177.9,209.59.181.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (81)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407160; rev:140; fwsam: src, 24 hours;) alert udp [209.51.195.116,209.51.196.240/28,209.51.196.248,209.51.196.250,209.51.196.251,209.51.196.252,209.51.196.253,209.51.196.254,209.59.177.9,209.59.181.47] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (81)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407161; rev:140; fwsam: src, 24 hours;) alert tcp [209.59.181.48,209.59.194.20,209.59.194.246,209.59.194.250,209.62.105.151,209.62.20.153,209.62.20.163,209.62.20.192,209.62.20.245,209.62.21.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (82)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407162; rev:140; fwsam: src, 24 hours;) alert udp [209.59.181.48,209.59.194.20,209.59.194.246,209.59.194.250,209.62.105.151,209.62.20.153,209.62.20.163,209.62.20.192,209.62.20.245,209.62.21.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (82)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407163; rev:140; fwsam: src, 24 hours;) alert tcp [209.62.27.84,209.62.57.146,209.62.7.138,209.62.7.250,209.62.7.253,209.62.72.165,209.62.72.169,209.62.72.173,209.62.72.250,209.62.76.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (83)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407164; rev:140; fwsam: src, 24 hours;) alert udp [209.62.27.84,209.62.57.146,209.62.7.138,209.62.7.250,209.62.7.253,209.62.72.165,209.62.72.169,209.62.72.173,209.62.72.250,209.62.76.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (83)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407165; rev:140; fwsam: src, 24 hours;) alert tcp [209.62.85.110,209.63.57.10,209.66.114.22,209.66.120.0/24,209.66.123.187,209.66.123.64,209.66.123.65,209.66.123.72,209.66.123.88,209.66.123.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (84)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407166; rev:140; fwsam: src, 24 hours;) alert udp [209.62.85.110,209.63.57.10,209.66.114.22,209.66.120.0/24,209.66.123.187,209.66.123.64,209.66.123.65,209.66.123.72,209.66.123.88,209.66.123.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (84)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407167; rev:140; fwsam: src, 24 hours;) alert tcp [209.66.124.52,209.67.211.122,209.67.211.2,209.67.211.3,209.67.214.194,209.67.214.61,209.67.214.62,209.67.215.178,209.8.151.186,209.8.151.188] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (85)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407168; rev:140; fwsam: src, 24 hours;) alert udp [209.66.124.52,209.67.211.122,209.67.211.2,209.67.211.3,209.67.214.194,209.67.214.61,209.67.214.62,209.67.215.178,209.8.151.186,209.8.151.188] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (85)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407169; rev:140; fwsam: src, 24 hours;) alert tcp [209.8.151.190,209.8.19.133,209.8.19.213,209.8.20.190,209.8.20.227,209.8.23.70,209.8.23.87,209.8.237.142,209.8.24.0/24,209.8.25.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (86)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407170; rev:140; fwsam: src, 24 hours;) alert udp [209.8.151.190,209.8.19.133,209.8.19.213,209.8.20.190,209.8.20.227,209.8.23.70,209.8.23.87,209.8.237.142,209.8.24.0/24,209.8.25.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (86)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407171; rev:140; fwsam: src, 24 hours;) alert tcp [209.8.25.204,209.8.25.254,209.8.25.66,209.8.45.124,209.8.45.147,209.8.45.148,209.8.45.150,209.8.45.153,209.8.47.0/24,209.81.12.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (87)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407172; rev:140; fwsam: src, 24 hours;) alert udp [209.8.25.204,209.8.25.254,209.8.25.66,209.8.45.124,209.8.45.147,209.8.45.148,209.8.45.150,209.8.45.153,209.8.47.0/24,209.81.12.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (87)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407173; rev:140; fwsam: src, 24 hours;) alert tcp [209.81.12.133,209.85.25.210,209.85.51.0/24,209.85.73.222,209.85.84.0/24,209.85.87.42,209.85.97.155,209.85.99.34,209.9.170.194,209.9.170.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (88)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407174; rev:140; fwsam: src, 24 hours;) alert udp [209.81.12.133,209.85.25.210,209.85.51.0/24,209.85.73.222,209.85.84.0/24,209.85.87.42,209.85.97.155,209.85.99.34,209.9.170.194,209.9.170.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (88)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407175; rev:140; fwsam: src, 24 hours;) alert tcp [210.1.248.252,210.114.175.174,210.145.102.19,210.253.127.9,210.48.149.206,210.48.153.232,210.48.154.132,210.48.154.136,210.51.180.239,210.51.25.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (89)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407176; rev:140; fwsam: src, 24 hours;) alert udp [210.1.248.252,210.114.175.174,210.145.102.19,210.253.127.9,210.48.149.206,210.48.153.232,210.48.154.132,210.48.154.136,210.51.180.239,210.51.25.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (89)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407177; rev:140; fwsam: src, 24 hours;) alert tcp [210.51.25.206,210.51.37.113,210.51.51.144,210.51.51.176,210.51.58.103,210.51.58.90,210.83.80.222,210.83.85.100,210.83.85.101,211.139.106.172] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (90)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407178; rev:140; fwsam: src, 24 hours;) alert udp [210.51.25.206,210.51.37.113,210.51.51.144,210.51.51.176,210.51.58.103,210.51.58.90,210.83.80.222,210.83.85.100,210.83.85.101,211.139.106.172] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (90)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407179; rev:140; fwsam: src, 24 hours;) alert tcp [211.147.227.243,211.152.33.4,211.155.27.250,211.167.67.90,211.172.232.237,211.234.100.137,211.238.13.158,211.244.22.196,211.36.253.32,211.49.99.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (91)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407180; rev:140; fwsam: src, 24 hours;) alert udp [211.147.227.243,211.152.33.4,211.155.27.250,211.167.67.90,211.172.232.237,211.234.100.137,211.238.13.158,211.244.22.196,211.36.253.32,211.49.99.92] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (91)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407181; rev:140; fwsam: src, 24 hours;) alert tcp [211.91.237.3,211.95.72.87,211.95.72.88,211.95.72.93,211.95.73.189,211.95.78.104,211.95.78.108,211.95.78.118,211.95.78.119,211.95.78.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (92)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407182; rev:140; fwsam: src, 24 hours;) alert udp [211.91.237.3,211.95.72.87,211.95.72.88,211.95.72.93,211.95.73.189,211.95.78.104,211.95.78.108,211.95.78.118,211.95.78.119,211.95.78.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (92)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407183; rev:140; fwsam: src, 24 hours;) alert tcp [211.95.78.71,211.95.78.73,211.95.78.79,211.95.78.88,211.95.78.99,211.95.79.229,211.95.79.241,211.95.79.242,211.95.79.57,211.95.79.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (93)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407184; rev:140; fwsam: src, 24 hours;) alert udp [211.95.78.71,211.95.78.73,211.95.78.79,211.95.78.88,211.95.78.99,211.95.79.229,211.95.79.241,211.95.79.242,211.95.79.57,211.95.79.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (93)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407185; rev:140; fwsam: src, 24 hours;) alert tcp [211.95.79.6,212.100.224.219,212.117.160.22,212.117.162.192,212.117.162.194,212.117.162.90,212.117.163.162,212.117.163.164,212.117.163.165,212.117.164.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (94)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407186; rev:140; fwsam: src, 24 hours;) alert udp [211.95.79.6,212.100.224.219,212.117.160.22,212.117.162.192,212.117.162.194,212.117.162.90,212.117.163.162,212.117.163.164,212.117.163.165,212.117.164.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (94)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407187; rev:140; fwsam: src, 24 hours;) alert tcp [212.117.164.121,212.117.165.126,212.117.165.127,212.117.165.128,212.117.165.197,212.117.165.237,212.117.175.218,212.117.185.14,212.117.185.18,212.117.185.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (95)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407188; rev:140; fwsam: src, 24 hours;) alert udp [212.117.164.121,212.117.165.126,212.117.165.127,212.117.165.128,212.117.165.197,212.117.165.237,212.117.175.218,212.117.185.14,212.117.185.18,212.117.185.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (95)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407189; rev:140; fwsam: src, 24 hours;) alert tcp [212.117.185.34,212.117.185.40,212.117.185.53,212.118.48.210,212.123.6.224,212.150.130.183,212.150.164.82,212.150.164.84,212.158.162.5,212.158.167.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (96)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407190; rev:140; fwsam: src, 24 hours;) alert udp [212.117.185.34,212.117.185.40,212.117.185.53,212.118.48.210,212.123.6.224,212.150.130.183,212.150.164.82,212.150.164.84,212.158.162.5,212.158.167.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (96)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407191; rev:140; fwsam: src, 24 hours;) alert tcp [212.174.81.120,212.174.81.122,212.174.81.123,212.174.81.124,212.174.81.19,212.179.35.117,212.193.37.141,212.227.111.21,212.227.111.29,212.227.32.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (97)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407192; rev:140; fwsam: src, 24 hours;) alert udp [212.174.81.120,212.174.81.122,212.174.81.123,212.174.81.124,212.174.81.19,212.179.35.117,212.193.37.141,212.227.111.21,212.227.111.29,212.227.32.119] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (97)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407193; rev:140; fwsam: src, 24 hours;) alert tcp [212.227.34.3,212.24.53.0/24,212.24.54.3,212.27.63.165,212.36.9.1,212.47.211.166,212.62.98.114,212.63.206.51,212.77.128.0/20,212.84.166.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (98)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407194; rev:140; fwsam: src, 24 hours;) alert udp [212.227.34.3,212.24.53.0/24,212.24.54.3,212.27.63.165,212.36.9.1,212.47.211.166,212.62.98.114,212.63.206.51,212.77.128.0/20,212.84.166.131] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (98)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407195; rev:140; fwsam: src, 24 hours;) alert tcp [212.91.185.27,212.93.222.10,212.95.32.166,212.95.32.171,212.95.32.26,212.95.33.25,212.95.37.133,212.95.37.184,212.95.37.186,212.95.37.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (99)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407196; rev:140; fwsam: src, 24 hours;) alert udp [212.91.185.27,212.93.222.10,212.95.32.166,212.95.32.171,212.95.32.26,212.95.33.25,212.95.37.133,212.95.37.184,212.95.37.186,212.95.37.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (99)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407197; rev:140; fwsam: src, 24 hours;) alert tcp [212.95.40.205,212.95.40.44,212.95.48.51,212.95.49.252,212.95.51.75,212.95.51.76,212.95.53.103,212.95.53.142,212.95.54.105,212.95.54.106] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (100)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407198; rev:140; fwsam: src, 24 hours;) alert udp [212.95.40.205,212.95.40.44,212.95.48.51,212.95.49.252,212.95.51.75,212.95.51.76,212.95.53.103,212.95.53.142,212.95.54.105,212.95.54.106] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (100)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407199; rev:140; fwsam: src, 24 hours;) alert tcp [212.95.54.113,212.95.55.135,212.97.132.137,212.97.132.140,212.98.162.59,213.131.252.251,213.133.100.58,213.133.101.7,213.133.110.21,213.136.106.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (101)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407200; rev:140; fwsam: src, 24 hours;) alert udp [212.95.54.113,212.95.55.135,212.97.132.137,212.97.132.140,212.98.162.59,213.131.252.251,213.133.100.58,213.133.101.7,213.133.110.21,213.136.106.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (101)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407201; rev:140; fwsam: src, 24 hours;) alert tcp [213.155.0.200,213.155.1.46,213.155.10.178,213.155.10.56,213.155.10.58,213.155.10.63,213.155.13.108,213.155.2.104,213.155.2.105,213.155.2.37] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (102)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407202; rev:140; fwsam: src, 24 hours;) alert udp [213.155.0.200,213.155.1.46,213.155.10.178,213.155.10.56,213.155.10.58,213.155.10.63,213.155.13.108,213.155.2.104,213.155.2.105,213.155.2.37] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (102)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407203; rev:140; fwsam: src, 24 hours;) alert tcp [213.155.29.101,213.155.3.117,213.155.3.152,213.155.3.154,213.155.4.32,213.155.4.72,213.155.4.80,213.155.6.32,213.155.7.144,213.155.7.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (103)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407204; rev:140; fwsam: src, 24 hours;) alert udp [213.155.29.101,213.155.3.117,213.155.3.152,213.155.3.154,213.155.4.32,213.155.4.72,213.155.4.80,213.155.6.32,213.155.7.144,213.155.7.248] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (103)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407205; rev:140; fwsam: src, 24 hours;) alert tcp [213.163.64.79,213.163.64.81,213.163.65.10,213.163.65.9,213.163.91.244,213.163.91.246,213.163.91.91,213.165.80.179,213.171.219.234,213.171.222.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (104)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407206; rev:140; fwsam: src, 24 hours;) alert udp [213.163.64.79,213.163.64.81,213.163.65.10,213.163.65.9,213.163.91.244,213.163.91.246,213.163.91.91,213.165.80.179,213.171.219.234,213.171.222.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (104)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407207; rev:140; fwsam: src, 24 hours;) alert tcp [213.174.134.1,213.174.134.38,213.174.136.0/22,213.174.141.108,213.174.141.39,213.174.142.0/24,213.174.143.196,213.174.152.166,213.174.152.2,213.174.153.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (105)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407208; rev:140; fwsam: src, 24 hours;) alert udp [213.174.134.1,213.174.134.38,213.174.136.0/22,213.174.141.108,213.174.141.39,213.174.142.0/24,213.174.143.196,213.174.152.166,213.174.152.2,213.174.153.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (105)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407209; rev:140; fwsam: src, 24 hours;) alert tcp [213.175.196.80,213.180.199.19,213.180.199.3,213.180.199.48,213.180.204.8,213.180.9.66,213.182.197.0/24,213.186.116.147,213.186.116.213,213.186.33.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (106)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407210; rev:140; fwsam: src, 24 hours;) alert udp [213.175.196.80,213.180.199.19,213.180.199.3,213.180.199.48,213.180.204.8,213.180.9.66,213.182.197.0/24,213.186.116.147,213.186.116.213,213.186.33.19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (106)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407211; rev:140; fwsam: src, 24 hours;) alert tcp [213.186.33.80,213.186.33.87,213.189.213.54,213.189.9.176,213.189.9.75,213.193.4.11,213.202.225.36,213.232.249.139,213.235.249.198,213.239.210.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (107)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407212; rev:140; fwsam: src, 24 hours;) alert udp [213.186.33.80,213.186.33.87,213.189.213.54,213.189.9.176,213.189.9.75,213.193.4.11,213.202.225.36,213.232.249.139,213.235.249.198,213.239.210.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (107)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407213; rev:140; fwsam: src, 24 hours;) alert tcp [213.242.207.249,213.246.56.31,213.251.170.24,213.27.4.46,213.81.152.54,216.104.40.74,216.108.239.128,216.108.239.62,216.118.117.15,216.118.117.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (108)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407214; rev:140; fwsam: src, 24 hours;) alert udp [213.242.207.249,213.246.56.31,213.251.170.24,213.27.4.46,213.81.152.54,216.104.40.74,216.108.239.128,216.108.239.62,216.118.117.15,216.118.117.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (108)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407215; rev:140; fwsam: src, 24 hours;) alert tcp [216.118.117.160,216.118.117.64,216.12.161.18,216.12.168.138,216.122.59.222,216.130.188.207,216.14.124.11,216.14.80.49,216.146.46.20,216.146.46.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (109)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407216; rev:140; fwsam: src, 24 hours;) alert udp [216.118.117.160,216.118.117.64,216.12.161.18,216.12.168.138,216.122.59.222,216.130.188.207,216.14.124.11,216.14.80.49,216.146.46.20,216.146.46.8] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (109)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407217; rev:140; fwsam: src, 24 hours;) alert tcp [216.15.150.177,216.150.79.186,216.150.79.74,216.152.240.12,216.169.106.222,216.180.227.76,216.187.118.219,216.188.26.0/24,216.19.200.237,216.195.32.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (110)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407218; rev:140; fwsam: src, 24 hours;) alert udp [216.15.150.177,216.150.79.186,216.150.79.74,216.152.240.12,216.169.106.222,216.180.227.76,216.187.118.219,216.188.26.0/24,216.19.200.237,216.195.32.90] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (110)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407219; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.32.93,216.195.32.94,216.195.33.107,216.195.33.139,216.195.33.141,216.195.33.144,216.195.33.147,216.195.34.0/24,216.195.35.99,216.195.36.123] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (111)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407220; rev:140; fwsam: src, 24 hours;) alert udp [216.195.32.93,216.195.32.94,216.195.33.107,216.195.33.139,216.195.33.141,216.195.33.144,216.195.33.147,216.195.34.0/24,216.195.35.99,216.195.36.123] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (111)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407221; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.36.182,216.195.37.251,216.195.40.117,216.195.40.120,216.195.40.145,216.195.40.51,216.195.40.64,216.195.42.0/24,216.195.43.0/24,216.195.44.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (112)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407222; rev:140; fwsam: src, 24 hours;) alert udp [216.195.36.182,216.195.37.251,216.195.40.117,216.195.40.120,216.195.40.145,216.195.40.51,216.195.40.64,216.195.42.0/24,216.195.43.0/24,216.195.44.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (112)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407223; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.46.252,216.195.48.10,216.195.48.113,216.195.48.45,216.195.48.52,216.195.49.0/24,216.195.50.0/24,216.195.52.16,216.195.52.52,216.195.54.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (113)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407224; rev:140; fwsam: src, 24 hours;) alert udp [216.195.46.252,216.195.48.10,216.195.48.113,216.195.48.45,216.195.48.52,216.195.49.0/24,216.195.50.0/24,216.195.52.16,216.195.52.52,216.195.54.233] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (113)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407225; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.55.137,216.195.55.139,216.195.55.140,216.195.55.78,216.195.55.80,216.195.56.149,216.195.56.150,216.195.56.234,216.195.56.30,216.195.56.86] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (114)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407226; rev:140; fwsam: src, 24 hours;) alert udp [216.195.55.137,216.195.55.139,216.195.55.140,216.195.55.78,216.195.55.80,216.195.56.149,216.195.56.150,216.195.56.234,216.195.56.30,216.195.56.86] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (114)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407227; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.56.87,216.195.56.88,216.195.57.40,216.195.57.41,216.195.57.43,216.195.57.46,216.195.57.47,216.195.57.49,216.195.57.52,216.195.58.106] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (115)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407228; rev:140; fwsam: src, 24 hours;) alert udp [216.195.56.87,216.195.56.88,216.195.57.40,216.195.57.41,216.195.57.43,216.195.57.46,216.195.57.47,216.195.57.49,216.195.57.52,216.195.58.106] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (115)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407229; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.58.107,216.195.58.11,216.195.58.114,216.195.58.127,216.195.58.169,216.195.58.170,216.195.58.171,216.195.58.172,216.195.58.20,216.195.58.209] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (116)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407230; rev:140; fwsam: src, 24 hours;) alert udp [216.195.58.107,216.195.58.11,216.195.58.114,216.195.58.127,216.195.58.169,216.195.58.170,216.195.58.171,216.195.58.172,216.195.58.20,216.195.58.209] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (116)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407231; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.58.210,216.195.58.211,216.195.58.212,216.195.58.38,216.195.59.112,216.195.59.117,216.195.59.120,216.195.59.144,216.195.59.157,216.195.59.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (117)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407232; rev:140; fwsam: src, 24 hours;) alert udp [216.195.58.210,216.195.58.211,216.195.58.212,216.195.58.38,216.195.59.112,216.195.59.117,216.195.59.120,216.195.59.144,216.195.59.157,216.195.59.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (117)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407233; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.59.77,216.195.59.78,216.195.59.79,216.195.59.80,216.195.59.81,216.195.59.82,216.195.59.83,216.195.59.85,216.195.60.227,216.195.61.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (118)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407234; rev:140; fwsam: src, 24 hours;) alert udp [216.195.59.77,216.195.59.78,216.195.59.79,216.195.59.80,216.195.59.81,216.195.59.82,216.195.59.83,216.195.59.85,216.195.60.227,216.195.61.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (118)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407235; rev:140; fwsam: src, 24 hours;) alert tcp [216.195.62.0/24,216.195.63.0/24,216.200.3.163,216.218.162.0/24,216.226.131.77,216.227.214.53,216.230.250.84,216.240.131.132,216.240.134.208,216.240.134.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (119)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407236; rev:140; fwsam: src, 24 hours;) alert udp [216.195.62.0/24,216.195.63.0/24,216.200.3.163,216.218.162.0/24,216.226.131.77,216.227.214.53,216.230.250.84,216.240.131.132,216.240.134.208,216.240.134.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (119)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407237; rev:140; fwsam: src, 24 hours;) alert tcp [216.240.134.238,216.240.138.220,216.240.138.221,216.240.139.239,216.240.140.201,216.240.143.10,216.240.143.12,216.240.143.16,216.240.143.17,216.240.143.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (120)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407238; rev:140; fwsam: src, 24 hours;) alert udp [216.240.134.238,216.240.138.220,216.240.138.221,216.240.139.239,216.240.140.201,216.240.143.10,216.240.143.12,216.240.143.16,216.240.143.17,216.240.143.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (120)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407239; rev:140; fwsam: src, 24 hours;) alert tcp [216.240.143.7,216.240.143.8,216.240.143.9,216.240.146.119,216.240.148.5,216.240.148.6,216.240.148.9,216.240.157.180,216.240.157.88,216.240.157.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (121)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407240; rev:140; fwsam: src, 24 hours;) alert udp [216.240.143.7,216.240.143.8,216.240.143.9,216.240.146.119,216.240.148.5,216.240.148.6,216.240.148.9,216.240.157.180,216.240.157.88,216.240.157.91] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (121)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407241; rev:140; fwsam: src, 24 hours;) alert tcp [216.240.158.190,216.245.208.165,216.246.91.49,216.255.176.0/20,216.32.75.2,216.32.76.180,216.32.76.6,216.32.76.87,216.32.78.18,216.32.83.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (122)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407242; rev:140; fwsam: src, 24 hours;) alert udp [216.240.158.190,216.245.208.165,216.246.91.49,216.255.176.0/20,216.32.75.2,216.32.76.180,216.32.76.6,216.32.76.87,216.32.78.18,216.32.83.104] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (122)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407243; rev:140; fwsam: src, 24 hours;) alert tcp [216.32.83.110,216.32.83.111,216.32.86.106,216.32.88.10,216.32.88.11,216.32.95.94,216.34.131.131,216.34.131.135,216.34.94.184,216.40.204.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (123)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407244; rev:140; fwsam: src, 24 hours;) alert udp [216.32.83.110,216.32.83.111,216.32.86.106,216.32.88.10,216.32.88.11,216.32.95.94,216.34.131.131,216.34.131.135,216.34.94.184,216.40.204.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (123)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407245; rev:140; fwsam: src, 24 hours;) alert tcp [216.40.230.4,216.40.33.252,216.40.33.30,216.40.33.31,216.40.33.35,216.55.142.4,216.55.163.216,216.64.158.131,216.7.89.0/24,216.75.62.101] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (124)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407246; rev:140; fwsam: src, 24 hours;) alert udp [216.40.230.4,216.40.33.252,216.40.33.30,216.40.33.31,216.40.33.35,216.55.142.4,216.55.163.216,216.64.158.131,216.7.89.0/24,216.75.62.101] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (124)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407247; rev:140; fwsam: src, 24 hours;) alert tcp [216.8.179.24,216.81.64.192,216.83.44.0/22,216.83.60.0/22,216.86.155.41,216.97.230.35,216.97.237.20,217.106.233.10,217.106.233.9,217.106.234.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (125)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407248; rev:140; fwsam: src, 24 hours;) alert udp [216.8.179.24,216.81.64.192,216.83.44.0/22,216.83.60.0/22,216.86.155.41,216.97.230.35,216.97.237.20,217.106.233.10,217.106.233.9,217.106.234.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (125)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407249; rev:140; fwsam: src, 24 hours;) alert tcp [217.107.217.167,217.107.217.27,217.107.217.29,217.107.218.70,217.107.219.112,217.107.219.153,217.107.219.39,217.107.34.119,217.107.34.217,217.107.34.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (126)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407250; rev:140; fwsam: src, 24 hours;) alert udp [217.107.217.167,217.107.217.27,217.107.217.29,217.107.218.70,217.107.219.112,217.107.219.153,217.107.219.39,217.107.34.119,217.107.34.217,217.107.34.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (126)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407251; rev:140; fwsam: src, 24 hours;) alert tcp [217.107.34.7,217.11.54.126,217.112.35.59,217.112.37.30,217.112.37.31,217.112.94.230,217.112.94.231,217.146.87.0/24,217.147.30.100,217.159.201.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (127)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407252; rev:140; fwsam: src, 24 hours;) alert udp [217.107.34.7,217.11.54.126,217.112.35.59,217.112.37.30,217.112.37.31,217.112.94.230,217.112.94.231,217.146.87.0/24,217.147.30.100,217.159.201.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (127)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407253; rev:140; fwsam: src, 24 hours;) alert tcp [217.16.16.0/20,217.170.64.0/20,217.171.66.245,217.188.246.105,217.199.217.3,217.199.217.9,217.199.218.50,217.20.112.96,217.20.112.98,217.20.113.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (128)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407254; rev:140; fwsam: src, 24 hours;) alert udp [217.16.16.0/20,217.170.64.0/20,217.171.66.245,217.188.246.105,217.199.217.3,217.199.217.9,217.199.218.50,217.20.112.96,217.20.112.98,217.20.113.236] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (128)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407255; rev:140; fwsam: src, 24 hours;) alert tcp [217.20.115.72,217.20.115.89,217.20.121.38,217.20.126.120,217.20.210.6,217.20.211.0/24,217.218.225.2,217.26.144.122,217.26.168.135,217.28.146.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (129)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407256; rev:140; fwsam: src, 24 hours;) alert udp [217.20.115.72,217.20.115.89,217.20.121.38,217.20.126.120,217.20.210.6,217.20.211.0/24,217.218.225.2,217.26.144.122,217.26.168.135,217.28.146.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (129)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407257; rev:140; fwsam: src, 24 hours;) alert tcp [217.67.22.83,217.74.66.183,217.75.203.10,217.75.98.213,217.77.152.28,218.10.18.76,218.106.90.227,218.107.207.150,218.107.207.40,218.108.84.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (130)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407258; rev:140; fwsam: src, 24 hours;) alert udp [217.67.22.83,217.74.66.183,217.75.203.10,217.75.98.213,217.77.152.28,218.10.18.76,218.106.90.227,218.107.207.150,218.107.207.40,218.108.84.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (130)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407259; rev:140; fwsam: src, 24 hours;) alert tcp [218.16.224.73,218.16.225.50,218.213.77.96,218.232.109.134,218.239.45.132,218.244.147.129,218.5.74.92,218.5.76.219,218.5.77.19,218.5.79.63] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (131)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407260; rev:140; fwsam: src, 24 hours;) alert udp [218.16.224.73,218.16.225.50,218.213.77.96,218.232.109.134,218.239.45.132,218.244.147.129,218.5.74.92,218.5.76.219,218.5.77.19,218.5.79.63] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (131)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407261; rev:140; fwsam: src, 24 hours;) alert tcp [218.5.81.148,218.56.37.6,218.6.12.82,218.6.2.195,218.61.204.206,218.61.204.214,218.61.204.215,218.83.161.104,218.85.132.203,218.85.139.33] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (132)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407262; rev:140; fwsam: src, 24 hours;) alert udp [218.5.81.148,218.56.37.6,218.6.12.82,218.6.2.195,218.61.204.206,218.61.204.214,218.61.204.215,218.83.161.104,218.85.132.203,218.85.139.33] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (132)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407263; rev:140; fwsam: src, 24 hours;) alert tcp [218.93.202.102,218.93.202.114,218.93.202.50,218.93.205.136,218.93.205.19,218.93.205.242,218.93.205.243,218.93.205.41,219.148.34.10,219.148.34.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (133)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407264; rev:140; fwsam: src, 24 hours;) alert udp [218.93.202.102,218.93.202.114,218.93.202.50,218.93.205.136,218.93.205.19,218.93.205.242,218.93.205.243,218.93.205.41,219.148.34.10,219.148.34.7] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (133)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407265; rev:140; fwsam: src, 24 hours;) alert tcp [219.148.34.9,219.152.120.118,219.153.48.163,219.240.39.230,220.194.44.67,220.196.42.218,220.196.42.220,220.196.59.0/24,220.196.59.23,220.248.167.110] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (134)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407266; rev:140; fwsam: src, 24 hours;) alert udp [219.148.34.9,219.152.120.118,219.153.48.163,219.240.39.230,220.194.44.67,220.196.42.218,220.196.42.220,220.196.59.0/24,220.196.59.23,220.248.167.110] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (134)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407267; rev:140; fwsam: src, 24 hours;) alert tcp [220.248.184.7,220.248.186.106,221.10.252.244,221.12.89.139,221.122.64.42,221.192.8.90,221.5.74.0/24,221.5.74.37,221.6.181.152,222.122.56.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (135)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407268; rev:140; fwsam: src, 24 hours;) alert udp [220.248.184.7,220.248.186.106,221.10.252.244,221.12.89.139,221.122.64.42,221.192.8.90,221.5.74.0/24,221.5.74.37,221.6.181.152,222.122.56.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (135)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407269; rev:140; fwsam: src, 24 hours;) alert tcp [222.124.24.7,222.186.12.137,222.186.13.219,222.186.9.187,222.188.0.25,222.189.228.27,222.189.239.3,222.214.218.61,222.222.222.222,222.231.1.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (136)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407270; rev:140; fwsam: src, 24 hours;) alert udp [222.124.24.7,222.186.12.137,222.186.13.219,222.186.9.187,222.188.0.25,222.189.228.27,222.189.239.3,222.214.218.61,222.222.222.222,222.231.1.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (136)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407271; rev:140; fwsam: src, 24 hours;) alert tcp [222.236.44.69,222.73.219.143,222.73.219.58,222.73.37.203,222.73.37.250,222.73.37.253,222.76.217.174,222.76.217.235,222.77.178.165,23.23.23.23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (137)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407272; rev:140; fwsam: src, 24 hours;) alert udp [222.236.44.69,222.73.219.143,222.73.219.58,222.73.37.203,222.73.37.250,222.73.37.253,222.76.217.174,222.76.217.235,222.77.178.165,23.23.23.23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (137)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407273; rev:140; fwsam: src, 24 hours;) alert tcp [24.244.141.80,24.244.171.69,24.77.22.109,38.100.93.0/24,38.103.173.98,38.105.19.27,38.105.19.28,38.105.19.29,38.113.1.102,38.114.196.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (138)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407274; rev:140; fwsam: src, 24 hours;) alert udp [24.244.141.80,24.244.171.69,24.77.22.109,38.100.93.0/24,38.103.173.98,38.105.19.27,38.105.19.28,38.105.19.29,38.113.1.102,38.114.196.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (138)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407275; rev:140; fwsam: src, 24 hours;) alert tcp [38.117.90.45,38.97.225.166,38.99.170.210,38.99.170.9,4.16.224.183,41.215.241.10,58.17.3.35,58.180.222.100,58.215.79.176,58.225.75.168] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (139)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407276; rev:140; fwsam: src, 24 hours;) alert udp [38.117.90.45,38.97.225.166,38.99.170.210,38.99.170.9,4.16.224.183,41.215.241.10,58.17.3.35,58.180.222.100,58.215.79.176,58.225.75.168] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (139)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407277; rev:140; fwsam: src, 24 hours;) alert tcp [58.241.255.34,58.241.255.37,58.64.130.11,58.65.232.0/21,58.83.8.19,59.125.229.68,59.125.229.74,59.125.231.252,59.148.221.79,59.148.221.89] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (140)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407278; rev:140; fwsam: src, 24 hours;) alert udp [58.241.255.34,58.241.255.37,58.64.130.11,58.65.232.0/21,58.83.8.19,59.125.229.68,59.125.229.74,59.125.231.252,59.148.221.79,59.148.221.89] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (140)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407279; rev:140; fwsam: src, 24 hours;) alert tcp [59.34.197.133,59.34.216.143,60.173.11.155,60.173.12.44,60.190.203.89,60.191.187.14,60.191.252.68,60.191.254.251,60.220.248.57,60.253.96.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (141)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407280; rev:140; fwsam: src, 24 hours;) alert udp [59.34.197.133,59.34.216.143,60.173.11.155,60.173.12.44,60.190.203.89,60.191.187.14,60.191.252.68,60.191.254.251,60.220.248.57,60.253.96.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (141)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407281; rev:140; fwsam: src, 24 hours;) alert tcp [60.29.232.31,60.29.232.32,61.134.43.215,61.139.126.15,61.139.126.91,61.141.5.53,61.150.91.14,61.150.91.30,61.152.95.193,61.160.232.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (142)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407282; rev:140; fwsam: src, 24 hours;) alert udp [60.29.232.31,60.29.232.32,61.134.43.215,61.139.126.15,61.139.126.91,61.141.5.53,61.150.91.14,61.150.91.30,61.152.95.193,61.160.232.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (142)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407283; rev:140; fwsam: src, 24 hours;) alert tcp [61.160.247.37,61.188.87.230,61.191.52.61,61.191.63.153,61.221.40.63,61.235.117.71,61.235.117.74,61.235.117.85,61.235.117.88,61.235.117.88/25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (143)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407284; rev:140; fwsam: src, 24 hours;) alert udp [61.160.247.37,61.188.87.230,61.191.52.61,61.191.63.153,61.221.40.63,61.235.117.71,61.235.117.74,61.235.117.85,61.235.117.88,61.235.117.88/25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (143)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407285; rev:140; fwsam: src, 24 hours;) alert tcp [61.33.191.132,61.59.24.45,61.59.24.55,61.61.61.61,61.67.193.1,61.7.235.227,62.109.16.208,62.109.2.32,62.109.4.197,62.118.252.230] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (144)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407286; rev:140; fwsam: src, 24 hours;) alert udp [61.33.191.132,61.59.24.45,61.59.24.55,61.61.61.61,61.67.193.1,61.7.235.227,62.109.16.208,62.109.2.32,62.109.4.197,62.118.252.230] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (144)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407287; rev:140; fwsam: src, 24 hours;) alert tcp [62.118.254.157,62.140.23.135,62.149.12.191,62.149.140.93,62.149.16.49,62.149.18.11,62.149.18.21,62.149.18.34,62.149.23.191,62.149.27.117] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (145)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407288; rev:140; fwsam: src, 24 hours;) alert udp [62.118.254.157,62.140.23.135,62.149.12.191,62.149.140.93,62.149.16.49,62.149.18.11,62.149.18.21,62.149.18.34,62.149.23.191,62.149.27.117] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (145)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407289; rev:140; fwsam: src, 24 hours;) alert tcp [62.149.28.166,62.149.28.27,62.16.115.84,62.168.168.9,62.175.249.135,62.176.16.0/22,62.176.16.0/23,62.178.239.217,62.193.203.13,62.211.68.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (146)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407290; rev:140; fwsam: src, 24 hours;) alert udp [62.149.28.166,62.149.28.27,62.16.115.84,62.168.168.9,62.175.249.135,62.176.16.0/22,62.176.16.0/23,62.178.239.217,62.193.203.13,62.211.68.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (146)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407291; rev:140; fwsam: src, 24 hours;) alert tcp [62.212.66.20,62.212.66.75,62.212.67.146,62.212.67.170,62.213.74.8,62.250.4.168,62.4.83.129,62.75.202.206,62.80.102.253,62.80.127.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (147)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407292; rev:140; fwsam: src, 24 hours;) alert udp [62.212.66.20,62.212.66.75,62.212.67.146,62.212.67.170,62.213.74.8,62.250.4.168,62.4.83.129,62.75.202.206,62.80.102.253,62.80.127.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (147)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407293; rev:140; fwsam: src, 24 hours;) alert tcp [63.119.44.197,63.146.2.22,63.146.2.92,63.146.2.93,63.214.247.170,63.217.28.226,63.217.29.114,63.217.30.58,63.217.31.45,63.217.31.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (148)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407294; rev:140; fwsam: src, 24 hours;) alert udp [63.119.44.197,63.146.2.22,63.146.2.92,63.146.2.93,63.214.247.170,63.217.28.226,63.217.29.114,63.217.30.58,63.217.31.45,63.217.31.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (148)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407295; rev:140; fwsam: src, 24 hours;) alert tcp [63.217.31.47,63.217.31.48,63.218.226.67,63.219.176.162,63.219.178.186,63.219.178.190,63.219.178.218,63.219.178.227,63.219.178.82,63.219.178.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (149)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407296; rev:140; fwsam: src, 24 hours;) alert udp [63.217.31.47,63.217.31.48,63.218.226.67,63.219.176.162,63.219.178.186,63.219.178.190,63.219.178.218,63.219.178.227,63.219.178.82,63.219.178.85] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (149)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407297; rev:140; fwsam: src, 24 hours;) alert tcp [63.219.178.89,63.219.178.90,63.220.7.82,63.223.110.177,63.227.18.137,63.243.173.162,63.251.171.0/24,63.251.83.74,63.251.92.0/24,64.111.196.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (150)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407298; rev:140; fwsam: src, 24 hours;) alert udp [63.219.178.89,63.219.178.90,63.220.7.82,63.223.110.177,63.227.18.137,63.243.173.162,63.251.171.0/24,63.251.83.74,63.251.92.0/24,64.111.196.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (150)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407299; rev:140; fwsam: src, 24 hours;) alert tcp [64.111.197.0/24,64.111.199.221,64.111.207.5,64.111.214.2,64.120.173.118,64.124.210.59,64.124.210.60,64.124.222.0/24,64.14.244.60,64.15.155.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (151)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407300; rev:140; fwsam: src, 24 hours;) alert udp [64.111.197.0/24,64.111.199.221,64.111.207.5,64.111.214.2,64.120.173.118,64.124.210.59,64.124.210.60,64.124.222.0/24,64.14.244.60,64.15.155.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (151)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407301; rev:140; fwsam: src, 24 hours;) alert tcp [64.15.205.211,64.15.205.212,64.15.72.80,64.150.176.14,64.150.177.215,64.150.177.217,64.150.177.247,64.18.144.0/24,64.191.102.134,64.191.102.135] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (152)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407302; rev:140; fwsam: src, 24 hours;) alert udp [64.15.205.211,64.15.205.212,64.15.72.80,64.150.176.14,64.150.177.215,64.150.177.217,64.150.177.247,64.18.144.0/24,64.191.102.134,64.191.102.135] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (152)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407303; rev:140; fwsam: src, 24 hours;) alert tcp [64.191.102.136,64.191.102.137,64.191.102.229,64.191.12.37,64.191.12.38,64.191.12.53,64.191.123.37,64.191.16.128/27,64.191.16.149,64.191.25.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (153)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407304; rev:140; fwsam: src, 24 hours;) alert udp [64.191.102.136,64.191.102.137,64.191.102.229,64.191.12.37,64.191.12.38,64.191.12.53,64.191.123.37,64.191.16.128/27,64.191.16.149,64.191.25.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (153)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407305; rev:140; fwsam: src, 24 hours;) alert tcp [64.191.3.53,64.191.30.160,64.191.38.197,64.191.38.198,64.191.38.199,64.191.47.213,64.191.64.246,64.191.78.0/24,64.191.90.213,64.191.90.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (154)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407306; rev:140; fwsam: src, 24 hours;) alert udp [64.191.3.53,64.191.30.160,64.191.38.197,64.191.38.198,64.191.38.199,64.191.47.213,64.191.64.246,64.191.78.0/24,64.191.90.213,64.191.90.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (154)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407307; rev:140; fwsam: src, 24 hours;) alert tcp [64.191.91.230,64.191.92.197,64.20.33.156,64.20.36.218,64.20.38.171,64.20.38.172,64.20.38.242,64.20.38.90,64.20.38.91,64.20.56.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (155)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407308; rev:140; fwsam: src, 24 hours;) alert udp [64.191.91.230,64.191.92.197,64.20.33.156,64.20.36.218,64.20.38.171,64.20.38.172,64.20.38.242,64.20.38.90,64.20.38.91,64.20.56.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (155)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407309; rev:140; fwsam: src, 24 hours;) alert tcp [64.202.107.23,64.208.226.72,64.208.226.93,64.21.100.203,64.21.100.205,64.21.129.136,64.21.144.140,64.21.182.152,64.21.182.153,64.21.182.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (156)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407310; rev:140; fwsam: src, 24 hours;) alert udp [64.202.107.23,64.208.226.72,64.208.226.93,64.21.100.203,64.21.100.205,64.21.129.136,64.21.144.140,64.21.182.152,64.21.182.153,64.21.182.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (156)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407311; rev:140; fwsam: src, 24 hours;) alert tcp [64.21.182.155,64.21.182.156,64.21.182.157,64.21.182.158,64.21.182.159,64.21.182.160,64.21.21.128/27,64.21.21.143,64.21.21.148,64.21.37.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (157)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407312; rev:140; fwsam: src, 24 hours;) alert udp [64.21.182.155,64.21.182.156,64.21.182.157,64.21.182.158,64.21.182.159,64.21.182.160,64.21.21.128/27,64.21.21.143,64.21.21.148,64.21.37.41] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (157)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407313; rev:140; fwsam: src, 24 hours;) alert tcp [64.21.37.43,64.21.37.47,64.21.37.88,64.21.37.89,64.21.37.90,64.21.37.91,64.21.37.92,64.21.37.93,64.21.37.94,64.21.37.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (158)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407314; rev:140; fwsam: src, 24 hours;) alert udp [64.21.37.43,64.21.37.47,64.21.37.88,64.21.37.89,64.21.37.90,64.21.37.91,64.21.37.92,64.21.37.93,64.21.37.94,64.21.37.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (158)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407315; rev:140; fwsam: src, 24 hours;) alert tcp [64.21.43.179,64.21.43.183,64.21.86.16,64.213.140.68,64.213.140.69,64.213.140.70,64.213.140.71,64.22.106.107,64.235.47.65,64.235.52.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (159)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407316; rev:140; fwsam: src, 24 hours;) alert udp [64.21.43.179,64.21.43.183,64.21.86.16,64.213.140.68,64.213.140.69,64.213.140.70,64.213.140.71,64.22.106.107,64.235.47.65,64.235.52.240] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (159)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407317; rev:140; fwsam: src, 24 hours;) alert tcp [64.235.57.21,64.247.16.208,64.247.16.215,64.247.49.31,64.247.58.168,64.251.10.77,64.251.28.222,64.255.172.50,64.26.155.161,64.27.13.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (160)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407318; rev:140; fwsam: src, 24 hours;) alert udp [64.235.57.21,64.247.16.208,64.247.16.215,64.247.49.31,64.247.58.168,64.251.10.77,64.251.28.222,64.255.172.50,64.26.155.161,64.27.13.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (160)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407319; rev:140; fwsam: src, 24 hours;) alert tcp [64.27.16.138,64.27.18.53,64.27.18.54,64.27.24.153,64.27.28.224,64.27.28.225,64.27.29.101,64.27.5.163,64.27.5.202,64.27.52.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (161)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407320; rev:140; fwsam: src, 24 hours;) alert udp [64.27.16.138,64.27.18.53,64.27.18.54,64.27.24.153,64.27.28.224,64.27.28.225,64.27.29.101,64.27.5.163,64.27.5.202,64.27.52.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (161)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407321; rev:140; fwsam: src, 24 hours;) alert tcp [64.28.176.0/20,64.28.187.0/24,64.32.13.153,64.32.21.3,64.32.5.0/24,64.34.46.254,64.34.46.60,64.40.103.249,64.40.117.19,64.40.117.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (162)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407322; rev:140; fwsam: src, 24 hours;) alert udp [64.28.176.0/20,64.28.187.0/24,64.32.13.153,64.32.21.3,64.32.5.0/24,64.34.46.254,64.34.46.60,64.40.103.249,64.40.117.19,64.40.117.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (162)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407323; rev:140; fwsam: src, 24 hours;) alert tcp [64.40.118.10,64.40.118.124,64.40.118.8,64.46.38.133,64.62.181.43,64.62.181.46,64.69.32.189,64.69.32.202,64.69.32.203,64.69.32.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (163)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407324; rev:140; fwsam: src, 24 hours;) alert udp [64.40.118.10,64.40.118.124,64.40.118.8,64.46.38.133,64.62.181.43,64.62.181.46,64.69.32.189,64.69.32.202,64.69.32.203,64.69.32.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (163)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407325; rev:140; fwsam: src, 24 hours;) alert tcp [64.69.32.206,64.69.32.219,64.69.32.220,64.69.41.18,64.69.46.61,64.69.68.0/24,64.70.19.33,64.85.168.251,64.86.133.220,64.86.133.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (164)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407326; rev:140; fwsam: src, 24 hours;) alert udp [64.69.32.206,64.69.32.219,64.69.32.220,64.69.41.18,64.69.46.61,64.69.68.0/24,64.70.19.33,64.85.168.251,64.86.133.220,64.86.133.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (164)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407327; rev:140; fwsam: src, 24 hours;) alert tcp [64.86.133.222,64.86.133.224,64.86.133.225,64.86.133.37,64.86.133.51,64.86.133.58,64.86.133.85,64.86.133.91,64.86.16.0/24,64.86.17.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (165)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407328; rev:140; fwsam: src, 24 hours;) alert udp [64.86.133.222,64.86.133.224,64.86.133.225,64.86.133.37,64.86.133.51,64.86.133.58,64.86.133.85,64.86.133.91,64.86.16.0/24,64.86.17.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (165)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407329; rev:140; fwsam: src, 24 hours;) alert tcp [64.86.17.17,64.86.17.2,64.86.17.20,64.86.17.30,64.86.17.43,64.86.17.44,64.86.17.47,64.86.17.5,64.86.17.54,64.86.17.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (166)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407330; rev:140; fwsam: src, 24 hours;) alert udp [64.86.17.17,64.86.17.2,64.86.17.20,64.86.17.30,64.86.17.43,64.86.17.44,64.86.17.47,64.86.17.5,64.86.17.54,64.86.17.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (166)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407331; rev:140; fwsam: src, 24 hours;) alert tcp [64.86.17.9,64.91.254.69,64.92.166.251,64.92.166.252,64.92.166.254,64.92.170.128,64.92.170.134,64.92.170.135,64.92.170.144,64.92.170.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (167)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407332; rev:140; fwsam: src, 24 hours;) alert udp [64.86.17.9,64.91.254.69,64.92.166.251,64.92.166.252,64.92.166.254,64.92.170.128,64.92.170.134,64.92.170.135,64.92.170.144,64.92.170.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (167)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407333; rev:140; fwsam: src, 24 hours;) alert tcp [64.92.170.146,64.92.170.147,64.92.170.148,64.92.170.149,64.92.170.150,64.92.170.151,64.92.173.179,64.92.174.218,64.92.174.70,64.94.117.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (168)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407334; rev:140; fwsam: src, 24 hours;) alert udp [64.92.170.146,64.92.170.147,64.92.170.148,64.92.170.149,64.92.170.150,64.92.170.151,64.92.173.179,64.92.174.218,64.92.174.70,64.94.117.193] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (168)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407335; rev:140; fwsam: src, 24 hours;) alert tcp [64.94.31.67,65.110.50.141,65.110.60.122,65.110.60.123,65.110.60.70,65.111.162.94,65.182.100.196,65.23.153.152,65.23.153.197,65.23.153.78] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (169)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407336; rev:140; fwsam: src, 24 hours;) alert udp [64.94.31.67,65.110.50.141,65.110.60.122,65.110.60.123,65.110.60.70,65.111.162.94,65.182.100.196,65.23.153.152,65.23.153.197,65.23.153.78] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (169)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407337; rev:140; fwsam: src, 24 hours;) alert tcp [65.243.103.0/24,65.247.182.200,65.254.51.163,65.254.54.178,65.254.54.179,65.60.44.194,65.60.54.58,65.60.6.116,65.75.169.178,65.75.169.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (170)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407338; rev:140; fwsam: src, 24 hours;) alert udp [65.243.103.0/24,65.247.182.200,65.254.51.163,65.254.54.178,65.254.54.179,65.60.44.194,65.60.54.58,65.60.6.116,65.75.169.178,65.75.169.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (170)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407339; rev:140; fwsam: src, 24 hours;) alert tcp [65.98.15.47,65.98.19.103,65.99.230.107,66.11.154.210,66.112.221.139,66.113.163.254,66.114.72.115,66.114.72.117,66.115.136.52,66.115.146.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (171)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407340; rev:140; fwsam: src, 24 hours;) alert udp [65.98.15.47,65.98.19.103,65.99.230.107,66.11.154.210,66.112.221.139,66.113.163.254,66.114.72.115,66.114.72.117,66.115.136.52,66.115.146.145] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (171)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407341; rev:140; fwsam: src, 24 hours;) alert tcp [66.116.188.175,66.117.40.216,66.118.146.67,66.118.146.69,66.128.62.124,66.129.68.65,66.135.41.29,66.147.240.152,66.147.240.157,66.148.71.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (172)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407342; rev:140; fwsam: src, 24 hours;) alert udp [66.116.188.175,66.117.40.216,66.118.146.67,66.118.146.69,66.128.62.124,66.129.68.65,66.135.41.29,66.147.240.152,66.147.240.157,66.148.71.9] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (172)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407343; rev:140; fwsam: src, 24 hours;) alert tcp [66.148.80.4,66.150.120.131,66.150.161.136,66.150.161.137,66.150.161.140,66.150.161.141,66.152.166.189,66.152.78.69,66.152.78.70,66.152.78.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (173)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407344; rev:140; fwsam: src, 24 hours;) alert udp [66.148.80.4,66.150.120.131,66.150.161.136,66.150.161.137,66.150.161.140,66.150.161.141,66.152.166.189,66.152.78.69,66.152.78.70,66.152.78.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (173)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407345; rev:140; fwsam: src, 24 hours;) alert tcp [66.154.75.63,66.172.83.223,66.172.83.224,66.197.149.38,66.197.154.198,66.197.154.199,66.197.154.200,66.197.154.201,66.197.165.41,66.197.165.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (174)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407346; rev:140; fwsam: src, 24 hours;) alert udp [66.154.75.63,66.172.83.223,66.172.83.224,66.197.149.38,66.197.154.198,66.197.154.199,66.197.154.200,66.197.154.201,66.197.165.41,66.197.165.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (174)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407347; rev:140; fwsam: src, 24 hours;) alert tcp [66.197.170.5,66.197.171.37,66.197.171.6,66.197.187.5,66.197.213.117,66.197.68.184,66.197.94.155,66.199.152.4,66.199.229.229,66.199.229.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (175)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407348; rev:140; fwsam: src, 24 hours;) alert udp [66.197.170.5,66.197.171.37,66.197.171.6,66.197.187.5,66.197.213.117,66.197.68.184,66.197.94.155,66.199.152.4,66.199.229.229,66.199.229.253] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (175)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407349; rev:140; fwsam: src, 24 hours;) alert tcp [66.199.232.222,66.199.237.127,66.199.242.18,66.199.242.19,66.199.248.195,66.199.251.162,66.206.17.28,66.206.17.29,66.206.17.30,66.206.17.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (176)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407350; rev:140; fwsam: src, 24 hours;) alert udp [66.199.232.222,66.199.237.127,66.199.242.18,66.199.242.19,66.199.248.195,66.199.251.162,66.206.17.28,66.206.17.29,66.206.17.30,66.206.17.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (176)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407351; rev:140; fwsam: src, 24 hours;) alert tcp [66.212.19.146,66.225.215.231,66.225.241.14,66.226.75.118,66.226.87.107,66.230.133.40,66.230.155.157,66.230.161.0/24,66.230.167.0/24,66.230.174.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (177)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407352; rev:140; fwsam: src, 24 hours;) alert udp [66.212.19.146,66.225.215.231,66.225.241.14,66.226.75.118,66.226.87.107,66.230.133.40,66.230.155.157,66.230.161.0/24,66.230.167.0/24,66.230.174.60] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (177)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407353; rev:140; fwsam: src, 24 hours;) alert tcp [66.230.175.0/24,66.230.208.19,66.232.105.0/24,66.232.106.77,66.232.106.86,66.232.106.90,66.232.106.92,66.232.106.93,66.232.108.154,66.232.109.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (178)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407354; rev:140; fwsam: src, 24 hours;) alert udp [66.230.175.0/24,66.230.208.19,66.232.105.0/24,66.232.106.77,66.232.106.86,66.232.106.90,66.232.106.92,66.232.106.93,66.232.108.154,66.232.109.120] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (178)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407355; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.109.121,66.232.109.122,66.232.109.123,66.232.109.124,66.232.109.125,66.232.109.126,66.232.109.127,66.232.109.128,66.232.109.129,66.232.109.130] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (179)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407356; rev:140; fwsam: src, 24 hours;) alert udp [66.232.109.121,66.232.109.122,66.232.109.123,66.232.109.124,66.232.109.125,66.232.109.126,66.232.109.127,66.232.109.128,66.232.109.129,66.232.109.130] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (179)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407357; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.109.131,66.232.109.249,66.232.109.250,66.232.111.112,66.232.112.86,66.232.113.44,66.232.113.45,66.232.113.46,66.232.113.48,66.232.113.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (180)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407358; rev:140; fwsam: src, 24 hours;) alert udp [66.232.109.131,66.232.109.249,66.232.109.250,66.232.111.112,66.232.112.86,66.232.113.44,66.232.113.45,66.232.113.46,66.232.113.48,66.232.113.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (180)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407359; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.113.57,66.232.113.62,66.232.113.63,66.232.113.80,66.232.114.134,66.232.114.152,66.232.114.56,66.232.114.57,66.232.116.2,66.232.116.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (181)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407360; rev:140; fwsam: src, 24 hours;) alert udp [66.232.113.57,66.232.113.62,66.232.113.63,66.232.113.80,66.232.114.134,66.232.114.152,66.232.114.56,66.232.114.57,66.232.116.2,66.232.116.3] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (181)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407361; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.116.6,66.232.117.33,66.232.117.38,66.232.118.147,66.232.124.38,66.232.124.39,66.232.124.40,66.232.124.41,66.232.124.42,66.232.125.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (182)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407362; rev:140; fwsam: src, 24 hours;) alert udp [66.232.116.6,66.232.117.33,66.232.117.38,66.232.118.147,66.232.124.38,66.232.124.39,66.232.124.40,66.232.124.41,66.232.124.42,66.232.125.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (182)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407363; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.125.208,66.232.125.223,66.232.126.189,66.232.126.190,66.232.126.192,66.232.126.193,66.232.126.194,66.232.126.47,66.232.126.48,66.232.126.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (183)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407364; rev:140; fwsam: src, 24 hours;) alert udp [66.232.125.208,66.232.125.223,66.232.126.189,66.232.126.190,66.232.126.192,66.232.126.193,66.232.126.194,66.232.126.47,66.232.126.48,66.232.126.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (183)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407365; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.126.50,66.232.126.51,66.232.126.52,66.232.126.74,66.232.126.75,66.232.126.76,66.232.126.77,66.232.126.78,66.232.126.79,66.232.126.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (184)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407366; rev:140; fwsam: src, 24 hours;) alert udp [66.232.126.50,66.232.126.51,66.232.126.52,66.232.126.74,66.232.126.75,66.232.126.76,66.232.126.77,66.232.126.78,66.232.126.79,66.232.126.80] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (184)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407367; rev:140; fwsam: src, 24 hours;) alert tcp [66.232.127.127,66.232.127.128,66.232.127.129,66.232.127.130,66.232.127.44,66.232.26.91,66.235.160.93,66.235.180.194,66.235.180.238,66.241.193.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (185)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407368; rev:140; fwsam: src, 24 hours;) alert udp [66.232.127.127,66.232.127.128,66.232.127.129,66.232.127.130,66.232.127.44,66.232.26.91,66.235.160.93,66.235.180.194,66.235.180.238,66.241.193.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (185)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407369; rev:140; fwsam: src, 24 hours;) alert tcp [66.244.254.0/24,66.246.222.32,66.246.222.33,66.246.235.32,66.246.235.42,66.246.237.0/27,66.246.72.50,66.249.28.153,66.249.5.0/24,66.252.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (186)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407370; rev:140; fwsam: src, 24 hours;) alert udp [66.244.254.0/24,66.246.222.32,66.246.222.33,66.246.235.32,66.246.235.42,66.246.237.0/27,66.246.72.50,66.249.28.153,66.249.5.0/24,66.252.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (186)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407371; rev:140; fwsam: src, 24 hours;) alert tcp [66.29.11.144,66.29.115.68,66.29.121.58,66.29.15.140,66.29.15.141,66.29.50.174,66.29.50.176,66.29.50.183,66.29.89.64,66.33.195.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (187)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407372; rev:140; fwsam: src, 24 hours;) alert udp [66.29.11.144,66.29.115.68,66.29.121.58,66.29.15.140,66.29.15.141,66.29.50.174,66.29.50.176,66.29.50.183,66.29.89.64,66.33.195.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (187)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407373; rev:140; fwsam: src, 24 hours;) alert tcp [66.35.111.73,66.36.241.193,66.36.242.224,66.39.5.165,66.40.52.62,66.40.52.63,66.40.52.64,66.40.52.66,66.40.52.70,66.40.52.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (188)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407374; rev:140; fwsam: src, 24 hours;) alert udp [66.35.111.73,66.36.241.193,66.36.242.224,66.39.5.165,66.40.52.62,66.40.52.63,66.40.52.64,66.40.52.66,66.40.52.70,66.40.52.71] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (188)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407375; rev:140; fwsam: src, 24 hours;) alert tcp [66.40.56.10,66.40.56.36,66.45.226.211,66.45.226.226,66.45.226.227,66.45.226.26,66.45.226.42,66.45.226.43,66.45.226.44,66.45.226.45] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (189)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407376; rev:140; fwsam: src, 24 hours;) alert udp [66.40.56.10,66.40.56.36,66.45.226.211,66.45.226.226,66.45.226.227,66.45.226.26,66.45.226.42,66.45.226.43,66.45.226.44,66.45.226.45] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (189)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407377; rev:140; fwsam: src, 24 hours;) alert tcp [66.45.227.90,66.45.227.91,66.45.227.92,66.45.227.93,66.45.227.94,66.45.229.50,66.45.229.51,66.45.229.52,66.45.229.53,66.45.229.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (190)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407378; rev:140; fwsam: src, 24 hours;) alert udp [66.45.227.90,66.45.227.91,66.45.227.92,66.45.227.93,66.45.227.94,66.45.229.50,66.45.229.51,66.45.229.52,66.45.229.53,66.45.229.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (190)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407379; rev:140; fwsam: src, 24 hours;) alert tcp [66.45.229.55,66.45.229.56,66.45.229.57,66.45.229.58,66.45.229.59,66.45.229.60,66.45.229.61,66.45.230.194,66.45.236.162,66.45.237.219] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (191)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407380; rev:140; fwsam: src, 24 hours;) alert udp [66.45.229.55,66.45.229.56,66.45.229.57,66.45.229.58,66.45.229.59,66.45.229.60,66.45.229.61,66.45.230.194,66.45.236.162,66.45.237.219] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (191)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407381; rev:140; fwsam: src, 24 hours;) alert tcp [66.48.82.31,66.49.222.162,66.63.167.50,66.7.179.198,66.7.213.144,66.7.215.209,66.7.219.192,66.7.56.125,66.70.156.114,66.71.244.69] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (192)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407382; rev:140; fwsam: src, 24 hours;) alert udp [66.48.82.31,66.49.222.162,66.63.167.50,66.7.179.198,66.7.213.144,66.7.215.209,66.7.219.192,66.7.56.125,66.70.156.114,66.71.244.69] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (192)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407383; rev:140; fwsam: src, 24 hours;) alert tcp [66.79.163.21,66.90.101.177,66.90.101.183,66.96.130.40,66.96.131.82,66.96.143.191,66.96.216.215,66.96.252.199,66.96.255.69,66.96.85.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (193)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407384; rev:140; fwsam: src, 24 hours;) alert udp [66.79.163.21,66.90.101.177,66.90.101.183,66.96.130.40,66.96.131.82,66.96.143.191,66.96.216.215,66.96.252.199,66.96.255.69,66.96.85.112] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (193)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407385; rev:140; fwsam: src, 24 hours;) alert tcp [66.96.85.113,66.98.242.165,66.98.242.18,67.130.99.0/24,67.137.217.219,67.15.107.168,67.15.11.100,67.15.184.7,67.15.253.241,67.15.56.128] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (194)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407386; rev:140; fwsam: src, 24 hours;) alert udp [66.96.85.113,66.98.242.165,66.98.242.18,67.130.99.0/24,67.137.217.219,67.15.107.168,67.15.11.100,67.15.184.7,67.15.253.241,67.15.56.128] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (194)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407387; rev:140; fwsam: src, 24 hours;) alert tcp [67.15.62.181,67.15.76.243,67.15.77.182,67.159.45.3,67.18.129.147,67.18.129.149,67.18.179.0/24,67.19.17.210,67.19.24.170,67.19.244.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (195)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407388; rev:140; fwsam: src, 24 hours;) alert udp [67.15.62.181,67.15.76.243,67.15.77.182,67.159.45.3,67.18.129.147,67.18.129.149,67.18.179.0/24,67.19.17.210,67.19.24.170,67.19.244.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (195)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407389; rev:140; fwsam: src, 24 hours;) alert tcp [67.19.244.5,67.19.244.9,67.19.72.201,67.19.72.202,67.205.75.0/24,67.205.93.165,67.207.71.171,67.207.71.174,67.210.0.0/20,67.210.12.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (196)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407390; rev:140; fwsam: src, 24 hours;) alert udp [67.19.244.5,67.19.244.9,67.19.72.201,67.19.72.202,67.205.75.0/24,67.205.93.165,67.207.71.171,67.207.71.174,67.210.0.0/20,67.210.12.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (196)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407391; rev:140; fwsam: src, 24 hours;) alert tcp [67.210.124.90,67.210.126.50,67.210.13.93,67.210.13.94,67.210.14.0/23,67.211.161.0,67.212.187.114,67.212.187.58,67.212.187.61,67.212.187.62] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (197)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407392; rev:140; fwsam: src, 24 hours;) alert udp [67.210.124.90,67.210.126.50,67.210.13.93,67.210.13.94,67.210.14.0/23,67.211.161.0,67.212.187.114,67.212.187.58,67.212.187.61,67.212.187.62] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (197)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407393; rev:140; fwsam: src, 24 hours;) alert tcp [67.212.188.154,67.212.80.121,67.212.80.124,67.212.80.125,67.212.81.29,67.215.12.140,67.215.231.242,67.215.241.202,67.215.253.2,67.215.66.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (198)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407394; rev:140; fwsam: src, 24 hours;) alert udp [67.212.188.154,67.212.80.121,67.212.80.124,67.212.80.125,67.212.81.29,67.215.12.140,67.215.231.242,67.215.241.202,67.215.253.2,67.215.66.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (198)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407395; rev:140; fwsam: src, 24 hours;) alert tcp [67.220.197.51,67.220.199.181,67.220.66.0/24,67.220.67.0/24,67.220.72.0/24,67.220.73.0/24,67.220.74.0/24,67.220.75.0/24,67.222.128.29,67.222.150.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (199)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407396; rev:140; fwsam: src, 24 hours;) alert udp [67.220.197.51,67.220.199.181,67.220.66.0/24,67.220.67.0/24,67.220.72.0/24,67.220.73.0/24,67.220.74.0/24,67.220.75.0/24,67.222.128.29,67.222.150.103] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (199)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407397; rev:140; fwsam: src, 24 hours;) alert tcp [67.225.136.4,67.225.137.254,67.225.151.248,67.225.151.254,67.225.151.4,67.225.158.16,67.225.179.95,67.228.10.28,67.228.10.29,67.228.101.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (200)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407398; rev:140; fwsam: src, 24 hours;) alert udp [67.225.136.4,67.225.137.254,67.225.151.248,67.225.151.254,67.225.151.4,67.225.158.16,67.225.179.95,67.228.10.28,67.228.10.29,67.228.101.157] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (200)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407399; rev:140; fwsam: src, 24 hours;) alert tcp [67.228.111.217,67.228.112.232,67.228.112.233,67.228.112.234,67.228.112.235,67.228.122.235,67.228.128.55,67.228.137.255,67.228.139.19,67.228.139.205] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (201)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407400; rev:140; fwsam: src, 24 hours;) alert udp [67.228.111.217,67.228.112.232,67.228.112.233,67.228.112.234,67.228.112.235,67.228.122.235,67.228.128.55,67.228.137.255,67.228.139.19,67.228.139.205] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (201)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407401; rev:140; fwsam: src, 24 hours;) alert tcp [67.228.139.26,67.228.144.205,67.228.144.211,67.228.144.253,67.228.144.26,67.228.177.181,67.228.188.64,67.228.189.128,67.228.189.192,67.228.194.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (202)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407402; rev:140; fwsam: src, 24 hours;) alert udp [67.228.139.26,67.228.144.205,67.228.144.211,67.228.144.253,67.228.144.26,67.228.177.181,67.228.188.64,67.228.189.128,67.228.189.192,67.228.194.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (202)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407403; rev:140; fwsam: src, 24 hours;) alert tcp [67.228.22.132,67.228.222.240,67.228.222.241,67.228.222.242,67.228.222.243,67.228.222.244,67.228.222.245,67.228.222.246,67.228.222.247,67.228.224.78] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (203)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407404; rev:140; fwsam: src, 24 hours;) alert udp [67.228.22.132,67.228.222.240,67.228.222.241,67.228.222.242,67.228.222.243,67.228.222.244,67.228.222.245,67.228.222.246,67.228.222.247,67.228.224.78] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (203)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407405; rev:140; fwsam: src, 24 hours;) alert tcp [67.228.237.248,67.228.237.249,67.228.237.251,67.228.250.128,67.228.38.114,67.228.39.240,67.228.39.241,67.228.39.242,67.228.39.243,67.228.39.244] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (204)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407406; rev:140; fwsam: src, 24 hours;) alert udp [67.228.237.248,67.228.237.249,67.228.237.251,67.228.250.128,67.228.38.114,67.228.39.240,67.228.39.241,67.228.39.242,67.228.39.243,67.228.39.244] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (204)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407407; rev:140; fwsam: src, 24 hours;) alert tcp [67.228.39.245,67.228.39.246,67.228.39.247,67.228.47.0,67.228.50.241,67.228.53.183,67.23.11.229,67.43.224.213,67.43.224.216,67.43.226.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (205)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407408; rev:140; fwsam: src, 24 hours;) alert udp [67.228.39.245,67.228.39.246,67.228.39.247,67.228.47.0,67.228.50.241,67.228.53.183,67.23.11.229,67.43.224.213,67.43.224.216,67.43.226.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (205)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407409; rev:140; fwsam: src, 24 hours;) alert tcp [67.43.226.242,67.43.230.125,67.43.230.98,67.43.230.99,67.43.236.0/24,67.43.237.75,67.43.237.77,67.43.237.78,67.43.239.57,67.43.239.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (206)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407410; rev:140; fwsam: src, 24 hours;) alert udp [67.43.226.242,67.43.230.125,67.43.230.98,67.43.230.99,67.43.236.0/24,67.43.237.75,67.43.237.77,67.43.237.78,67.43.239.57,67.43.239.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (206)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407411; rev:140; fwsam: src, 24 hours;) alert tcp [67.55.51.116,67.55.79.181,67.55.81.0/24,68.233.192.223,69.1.78.0/24,69.10.32.154,69.10.32.155,69.10.34.51,69.10.35.251,69.10.44.207] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (207)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407412; rev:140; fwsam: src, 24 hours;) alert udp [67.55.51.116,67.55.79.181,67.55.81.0/24,68.233.192.223,69.1.78.0/24,69.10.32.154,69.10.32.155,69.10.34.51,69.10.35.251,69.10.44.207] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (207)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407413; rev:140; fwsam: src, 24 hours;) alert tcp [69.10.49.193,69.10.52.11,69.10.52.12,69.10.52.13,69.10.52.14,69.10.59.34,69.147.239.106,69.154.143.170,69.16.229.102,69.162.75.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (208)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407414; rev:140; fwsam: src, 24 hours;) alert udp [69.10.49.193,69.10.52.11,69.10.52.12,69.10.52.13,69.10.52.14,69.10.59.34,69.147.239.106,69.154.143.170,69.16.229.102,69.162.75.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (208)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407415; rev:140; fwsam: src, 24 hours;) alert tcp [69.162.76.42,69.162.76.43,69.163.128.127,69.175.10.74,69.20.104.139,69.20.104.41,69.20.117.228,69.20.68.36,69.20.68.41,69.20.71.82] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (209)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407416; rev:140; fwsam: src, 24 hours;) alert udp [69.162.76.42,69.162.76.43,69.163.128.127,69.175.10.74,69.20.104.139,69.20.104.41,69.20.117.228,69.20.68.36,69.20.68.41,69.20.71.82] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (209)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407417; rev:140; fwsam: src, 24 hours;) alert tcp [69.20.71.83,69.22.162.0/23,69.22.168.0/21,69.22.184.0/22,69.237.82.158,69.251.151.205,69.253.217.224,69.26.176.28,69.28.252.35,69.30.192.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (210)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407418; rev:140; fwsam: src, 24 hours;) alert udp [69.20.71.83,69.22.162.0/23,69.22.168.0/21,69.22.184.0/22,69.237.82.158,69.251.151.205,69.253.217.224,69.26.176.28,69.28.252.35,69.30.192.58] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (210)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407419; rev:140; fwsam: src, 24 hours;) alert tcp [69.31.115.113,69.31.115.235,69.31.115.75,69.31.115.76,69.31.128.0/24,69.31.40.0/21,69.31.52.156,69.31.64.0/20,69.31.80.0/21,69.31.91.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (211)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407420; rev:140; fwsam: src, 24 hours;) alert udp [69.31.115.113,69.31.115.235,69.31.115.75,69.31.115.76,69.31.128.0/24,69.31.40.0/21,69.31.52.156,69.31.64.0/20,69.31.80.0/21,69.31.91.46] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (211)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407421; rev:140; fwsam: src, 24 hours;) alert tcp [69.39.224.0/24,69.4.230.204,69.4.230.232,69.4.230.80,69.4.230.81,69.4.230.82,69.4.230.83,69.4.230.84,69.4.230.85,69.4.232.241] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (212)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407422; rev:140; fwsam: src, 24 hours;) alert udp [69.39.224.0/24,69.4.230.204,69.4.230.232,69.4.230.80,69.4.230.81,69.4.230.82,69.4.230.83,69.4.230.84,69.4.230.85,69.4.232.241] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (212)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407423; rev:140; fwsam: src, 24 hours;) alert tcp [69.4.32.137,69.41.183.0/24,69.42.216.0/24,69.42.65.148,69.46.16.99,69.46.228.171,69.46.228.231,69.46.228.36,69.46.228.45,69.46.228.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (213)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407424; rev:140; fwsam: src, 24 hours;) alert udp [69.4.32.137,69.41.183.0/24,69.42.216.0/24,69.42.65.148,69.46.16.99,69.46.228.171,69.46.228.231,69.46.228.36,69.46.228.45,69.46.228.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (213)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407425; rev:140; fwsam: src, 24 hours;) alert tcp [69.46.230.60,69.46.25.35,69.50.160.0/19,69.50.198.57,69.50.198.72,69.55.51.5,69.59.17.194,69.59.17.195,69.59.17.196,69.59.17.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (214)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407426; rev:140; fwsam: src, 24 hours;) alert udp [69.46.230.60,69.46.25.35,69.50.160.0/19,69.50.198.57,69.50.198.72,69.55.51.5,69.59.17.194,69.59.17.195,69.59.17.196,69.59.17.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (214)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407427; rev:140; fwsam: src, 24 hours;) alert tcp [69.59.17.203,69.59.17.5,69.59.17.6,69.59.21.247,69.59.21.248,69.59.26.51,69.59.26.52,69.60.114.44,69.64.145.0/24,69.64.147.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (215)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407428; rev:140; fwsam: src, 24 hours;) alert udp [69.59.17.203,69.59.17.5,69.59.17.6,69.59.21.247,69.59.21.248,69.59.26.51,69.59.26.52,69.60.114.44,69.64.145.0/24,69.64.147.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (215)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407429; rev:140; fwsam: src, 24 hours;) alert tcp [69.64.147.14,69.64.147.16,69.64.147.17,69.64.147.19,69.64.147.20,69.64.147.200,69.64.147.208,69.64.147.21,69.64.147.213,69.64.147.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (216)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407430; rev:140; fwsam: src, 24 hours;) alert udp [69.64.147.14,69.64.147.16,69.64.147.17,69.64.147.19,69.64.147.20,69.64.147.200,69.64.147.208,69.64.147.21,69.64.147.213,69.64.147.214] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (216)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407431; rev:140; fwsam: src, 24 hours;) alert tcp [69.64.147.215,69.64.147.22,69.64.147.249,69.64.155.0/24,69.64.159.1,69.64.33.149,69.64.33.24,69.64.33.242,69.64.42.172,69.64.42.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (217)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407432; rev:140; fwsam: src, 24 hours;) alert udp [69.64.147.215,69.64.147.22,69.64.147.249,69.64.155.0/24,69.64.159.1,69.64.33.149,69.64.33.24,69.64.33.242,69.64.42.172,69.64.42.226] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (217)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407433; rev:140; fwsam: src, 24 hours;) alert tcp [69.64.50.161,69.64.59.172,69.64.67.194,69.65.5.122,69.65.96.217,69.72.255.8,69.73.129.21,69.73.158.14,69.89.17.18,69.89.27.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (218)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407434; rev:140; fwsam: src, 24 hours;) alert udp [69.64.50.161,69.64.59.172,69.64.67.194,69.65.5.122,69.65.96.217,69.72.255.8,69.73.129.21,69.73.158.14,69.89.17.18,69.89.27.211] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (218)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407435; rev:140; fwsam: src, 24 hours;) alert tcp [69.90.81.133,69.93.106.11,69.93.226.154,69.93.64.230,70.32.93.225,70.38.11.171,70.38.11.184,70.38.19.201,70.38.19.202,70.38.19.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (219)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407436; rev:140; fwsam: src, 24 hours;) alert udp [69.90.81.133,69.93.106.11,69.93.226.154,69.93.64.230,70.32.93.225,70.38.11.171,70.38.11.184,70.38.19.201,70.38.19.202,70.38.19.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (219)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407437; rev:140; fwsam: src, 24 hours;) alert tcp [70.38.19.204,70.38.19.205,70.38.19.206,70.38.19.250,70.38.71.118,70.38.71.47,70.38.73.25,70.38.73.26,70.38.73.28,70.38.90.254] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (220)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407438; rev:140; fwsam: src, 24 hours;) alert udp [70.38.19.204,70.38.19.205,70.38.19.206,70.38.19.250,70.38.71.118,70.38.71.47,70.38.73.25,70.38.73.26,70.38.73.28,70.38.90.254] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (220)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407439; rev:140; fwsam: src, 24 hours;) alert tcp [70.84.1.4,70.84.195.170,70.84.196.30,70.84.2.244,70.85.114.186,70.85.142.250,70.85.227.66,70.85.249.98,70.86.12.226,70.86.161.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (221)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407440; rev:140; fwsam: src, 24 hours;) alert udp [70.84.1.4,70.84.195.170,70.84.196.30,70.84.2.244,70.85.114.186,70.85.142.250,70.85.227.66,70.85.249.98,70.86.12.226,70.86.161.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (221)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407441; rev:140; fwsam: src, 24 hours;) alert tcp [70.86.182.194,70.86.196.66,70.86.54.100,70.86.54.101,70.86.54.98,70.86.54.99,70.87.14.10,70.87.14.11,70.87.14.12,70.87.14.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (222)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407442; rev:140; fwsam: src, 24 hours;) alert udp [70.86.182.194,70.86.196.66,70.86.54.100,70.86.54.101,70.86.54.98,70.86.54.99,70.87.14.10,70.87.14.11,70.87.14.12,70.87.14.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (222)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407443; rev:140; fwsam: src, 24 hours;) alert tcp [70.87.14.14,70.87.222.138,71.174.51.86,71.6.202.216,71.6.202.217,72.10.160.2,72.10.172.0/24,72.10.173.139,72.14.187.85,72.167.121.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (223)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407444; rev:140; fwsam: src, 24 hours;) alert udp [70.87.14.14,70.87.222.138,71.174.51.86,71.6.202.216,71.6.202.217,72.10.160.2,72.10.172.0/24,72.10.173.139,72.14.187.85,72.167.121.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (223)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407445; rev:140; fwsam: src, 24 hours;) alert tcp [72.167.131.114,72.167.131.174,72.167.195.124,72.167.195.125,72.18.141.26,72.20.33.49,72.21.41.194,72.21.45.234,72.21.45.235,72.21.45.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (224)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407446; rev:140; fwsam: src, 24 hours;) alert udp [72.167.131.114,72.167.131.174,72.167.195.124,72.167.195.125,72.18.141.26,72.20.33.49,72.21.41.194,72.21.45.234,72.21.45.235,72.21.45.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (224)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407447; rev:140; fwsam: src, 24 hours;) alert tcp [72.21.45.238,72.21.46.98,72.21.46.99,72.21.62.101,72.21.62.74,72.21.62.75,72.232.107.25/29,72.232.107.27,72.232.107.32,72.232.107.33/29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (225)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407448; rev:140; fwsam: src, 24 hours;) alert udp [72.21.45.238,72.21.46.98,72.21.46.99,72.21.62.101,72.21.62.74,72.21.62.75,72.232.107.25/29,72.232.107.27,72.232.107.32,72.232.107.33/29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (225)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407449; rev:140; fwsam: src, 24 hours;) alert tcp [72.232.107.35,72.232.107.36,72.232.116.36,72.232.116.39,72.232.116.51,72.232.116.77,72.232.116.84,72.232.117.65,72.232.117.84,72.232.163.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (226)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407450; rev:140; fwsam: src, 24 hours;) alert udp [72.232.107.35,72.232.107.36,72.232.116.36,72.232.116.39,72.232.116.51,72.232.116.77,72.232.116.84,72.232.117.65,72.232.117.84,72.232.163.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (226)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407451; rev:140; fwsam: src, 24 hours;) alert tcp [72.232.184.11,72.232.184.251,72.232.184.252,72.232.184.253,72.232.184.254,72.232.186.18,72.232.186.19,72.232.186.20,72.232.186.21,72.232.187.197] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (227)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407452; rev:140; fwsam: src, 24 hours;) alert udp [72.232.184.11,72.232.184.251,72.232.184.252,72.232.184.253,72.232.184.254,72.232.186.18,72.232.186.19,72.232.186.20,72.232.186.21,72.232.187.197] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (227)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407453; rev:140; fwsam: src, 24 hours;) alert tcp [72.232.187.198,72.232.191.48,72.232.200.210,72.232.200.211,72.232.201.252,72.232.202.162,72.232.202.163,72.232.220.34,72.232.220.35,72.232.229.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (228)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407454; rev:140; fwsam: src, 24 hours;) alert udp [72.232.187.198,72.232.191.48,72.232.200.210,72.232.200.211,72.232.201.252,72.232.202.162,72.232.202.163,72.232.220.34,72.232.220.35,72.232.229.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (228)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407455; rev:140; fwsam: src, 24 hours;) alert tcp [72.232.233.178,72.232.234.130,72.232.234.218,72.232.237.202,72.232.242.250,72.232.242.82,72.232.242.86,72.232.254.170,72.232.8.202,72.232.8.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (229)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407456; rev:140; fwsam: src, 24 hours;) alert udp [72.232.233.178,72.232.234.130,72.232.234.218,72.232.237.202,72.232.242.250,72.232.242.82,72.232.242.86,72.232.254.170,72.232.8.202,72.232.8.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (229)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407457; rev:140; fwsam: src, 24 hours;) alert tcp [72.232.84.186,72.232.97.234,72.232.97.235,72.233.114.126,72.233.114.90,72.233.115.169,72.233.28.210,72.233.34.6,72.233.43.2,72.233.50.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (230)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407458; rev:140; fwsam: src, 24 hours;) alert udp [72.232.84.186,72.232.97.234,72.232.97.235,72.233.114.126,72.233.114.90,72.233.115.169,72.233.28.210,72.233.34.6,72.233.43.2,72.233.50.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (230)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407459; rev:140; fwsam: src, 24 hours;) alert tcp [72.233.50.145,72.233.50.151,72.233.50.154,72.233.60.0/24,72.233.62.19,72.233.63.90,72.233.63.94,72.233.76.10,72.233.79.146,72.233.79.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (231)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407460; rev:140; fwsam: src, 24 hours;) alert udp [72.233.50.145,72.233.50.151,72.233.50.154,72.233.60.0/24,72.233.62.19,72.233.63.90,72.233.63.94,72.233.76.10,72.233.79.146,72.233.79.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (231)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407461; rev:140; fwsam: src, 24 hours;) alert tcp [72.233.79.19,72.233.89.148,72.233.89.151,72.249.105.234,72.249.108.120,72.26.145.118,72.29.67.139,72.29.70.127,72.32.134.197,72.32.242.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (232)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407462; rev:140; fwsam: src, 24 hours;) alert udp [72.233.79.19,72.233.89.148,72.233.89.151,72.249.105.234,72.249.108.120,72.26.145.118,72.29.67.139,72.29.70.127,72.32.134.197,72.32.242.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (232)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407463; rev:140; fwsam: src, 24 hours;) alert tcp [72.32.242.170,72.32.48.189,72.36.131.100,72.36.133.170,72.36.153.62,72.36.174.82,72.36.219.162,72.41.23.75,72.44.67.30,72.44.67.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (233)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407464; rev:140; fwsam: src, 24 hours;) alert udp [72.32.242.170,72.32.48.189,72.36.131.100,72.36.133.170,72.36.153.62,72.36.174.82,72.36.219.162,72.41.23.75,72.44.67.30,72.44.67.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (233)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407465; rev:140; fwsam: src, 24 hours;) alert tcp [72.44.67.7,72.44.67.8,72.46.130.169,72.46.130.170,72.46.131.40,72.46.131.43,72.46.131.45,72.47.221.40,72.52.140.4,72.52.180.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (234)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407466; rev:140; fwsam: src, 24 hours;) alert udp [72.44.67.7,72.44.67.8,72.46.130.169,72.46.130.170,72.46.131.40,72.46.131.43,72.46.131.45,72.47.221.40,72.52.140.4,72.52.180.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (234)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407467; rev:140; fwsam: src, 24 hours;) alert tcp [72.55.165.237,72.55.168.4,72.55.186.13,72.9.108.26,72.9.145.84,72.9.145.85,72.9.98.0/24,74.200.220.211,74.200.220.212,74.200.220.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (235)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407468; rev:140; fwsam: src, 24 hours;) alert udp [72.55.165.237,72.55.168.4,72.55.186.13,72.9.108.26,72.9.145.84,72.9.145.85,72.9.98.0/24,74.200.220.211,74.200.220.212,74.200.220.213] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (235)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407469; rev:140; fwsam: src, 24 hours;) alert tcp [74.200.220.214,74.200.220.215,74.200.71.22,74.200.72.198,74.200.80.10,74.200.80.101,74.200.89.54,74.204.170.230,74.205.8.2,74.205.8.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (236)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407470; rev:140; fwsam: src, 24 hours;) alert udp [74.200.220.214,74.200.220.215,74.200.71.22,74.200.72.198,74.200.80.10,74.200.80.101,74.200.89.54,74.204.170.230,74.205.8.2,74.205.8.5] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (236)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407471; rev:140; fwsam: src, 24 hours;) alert tcp [74.208.128.155,74.213.167.190,74.213.167.191,74.213.179.102,74.213.179.112,74.220.202.45,74.220.207.127,74.220.215.220,74.220.215.54,74.220.215.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (237)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407472; rev:140; fwsam: src, 24 hours;) alert udp [74.208.128.155,74.213.167.190,74.213.167.191,74.213.179.102,74.213.179.112,74.220.202.45,74.220.207.127,74.220.215.220,74.220.215.54,74.220.215.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (237)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407473; rev:140; fwsam: src, 24 hours;) alert tcp [74.222.6.53,74.50.100.117,74.50.104.114,74.50.107.165,74.50.108.226,74.50.109.254,74.50.110.184,74.50.110.20,74.50.110.21,74.50.110.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (238)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407474; rev:140; fwsam: src, 24 hours;) alert udp [74.222.6.53,74.50.100.117,74.50.104.114,74.50.107.165,74.50.108.226,74.50.109.254,74.50.110.184,74.50.110.20,74.50.110.21,74.50.110.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (238)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407475; rev:140; fwsam: src, 24 hours;) alert tcp [74.50.110.226,74.50.110.23,74.50.110.24,74.50.113.0/24,74.50.117.68,74.50.117.70,74.50.117.71,74.50.117.73,74.50.117.74,74.50.117.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (239)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407476; rev:140; fwsam: src, 24 hours;) alert udp [74.50.110.226,74.50.110.23,74.50.110.24,74.50.113.0/24,74.50.117.68,74.50.117.70,74.50.117.71,74.50.117.73,74.50.117.74,74.50.117.75] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (239)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407477; rev:140; fwsam: src, 24 hours;) alert tcp [74.50.117.76,74.50.117.77,74.50.117.84,74.50.117.85,74.50.117.86,74.50.117.87,74.50.117.88,74.50.117.89,74.50.117.94,74.50.117.95] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (240)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407478; rev:140; fwsam: src, 24 hours;) alert udp [74.50.117.76,74.50.117.77,74.50.117.84,74.50.117.85,74.50.117.86,74.50.117.87,74.50.117.88,74.50.117.89,74.50.117.94,74.50.117.95] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (240)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407479; rev:140; fwsam: src, 24 hours;) alert tcp [74.50.119.187,74.50.119.70,74.50.119.94,74.50.120.150,74.50.120.68,74.50.120.71,74.50.120.75,74.50.120.87,74.50.125.0/24,74.50.21.225] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (241)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407480; rev:140; fwsam: src, 24 hours;) alert udp [74.50.119.187,74.50.119.70,74.50.119.94,74.50.120.150,74.50.120.68,74.50.120.71,74.50.120.75,74.50.120.87,74.50.125.0/24,74.50.21.225] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (241)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407481; rev:140; fwsam: src, 24 hours;) alert tcp [74.50.97.51,74.50.98.132,74.50.98.152,74.50.98.156,74.50.98.158,74.50.98.162,74.50.98.219,74.50.99.236,74.52.118.178,74.52.119.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (242)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407482; rev:140; fwsam: src, 24 hours;) alert udp [74.50.97.51,74.50.98.132,74.50.98.152,74.50.98.156,74.50.98.158,74.50.98.162,74.50.98.219,74.50.99.236,74.52.118.178,74.52.119.146] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (242)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407483; rev:140; fwsam: src, 24 hours;) alert tcp [74.52.126.2,74.52.144.66,74.52.164.210,74.52.179.179,74.52.212.235,74.52.238.242,74.52.238.243,74.52.32.0/24,74.52.35.87,74.52.59.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (243)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407484; rev:140; fwsam: src, 24 hours;) alert udp [74.52.126.2,74.52.144.66,74.52.164.210,74.52.179.179,74.52.212.235,74.52.238.242,74.52.238.243,74.52.32.0/24,74.52.35.87,74.52.59.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (243)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407485; rev:140; fwsam: src, 24 hours;) alert tcp [74.52.59.67,74.52.78.234,74.52.94.178,74.53.128.243,74.53.128.246,74.53.169.2,74.53.251.34,74.53.26.178,74.53.60.228,74.53.60.234] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (244)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407486; rev:140; fwsam: src, 24 hours;) alert udp [74.52.59.67,74.52.78.234,74.52.94.178,74.53.128.243,74.53.128.246,74.53.169.2,74.53.251.34,74.53.26.178,74.53.60.228,74.53.60.234] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (244)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407487; rev:140; fwsam: src, 24 hours;) alert tcp [74.53.96.138,74.54.132.2,74.54.143.242,74.54.156.234,74.54.176.162,74.54.176.50,74.54.191.130,74.54.219.98,74.54.22.195,74.54.241.100] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (245)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407488; rev:140; fwsam: src, 24 hours;) alert udp [74.53.96.138,74.54.132.2,74.54.143.242,74.54.156.234,74.54.176.162,74.54.176.50,74.54.191.130,74.54.219.98,74.54.22.195,74.54.241.100] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (245)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407489; rev:140; fwsam: src, 24 hours;) alert tcp [74.54.29.67,74.54.29.70,74.54.82.0/24,74.54.93.130,74.55.100.8,74.55.113.34,74.55.136.192/28,74.55.136.200,74.55.136.201,74.55.136.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (246)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407490; rev:140; fwsam: src, 24 hours;) alert udp [74.54.29.67,74.54.29.70,74.54.82.0/24,74.54.93.130,74.55.100.8,74.55.113.34,74.55.136.192/28,74.55.136.200,74.55.136.201,74.55.136.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (246)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407491; rev:140; fwsam: src, 24 hours;) alert tcp [74.55.136.203,74.55.136.204,74.55.136.205,74.55.136.206,74.55.136.207,74.55.136.64,74.55.136.64/28,74.55.136.66,74.55.136.68,74.55.136.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (247)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407492; rev:140; fwsam: src, 24 hours;) alert udp [74.55.136.203,74.55.136.204,74.55.136.205,74.55.136.206,74.55.136.207,74.55.136.64,74.55.136.64/28,74.55.136.66,74.55.136.68,74.55.136.72] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (247)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407493; rev:140; fwsam: src, 24 hours;) alert tcp [74.55.136.73,74.55.136.76,74.55.136.79,74.55.158.58,74.55.212.55,74.55.39.12,74.55.47.88/29,74.55.98.12,74.63.217.81,74.63.35.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (248)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407494; rev:140; fwsam: src, 24 hours;) alert udp [74.55.136.73,74.55.136.76,74.55.136.79,74.55.158.58,74.55.212.55,74.55.39.12,74.55.47.88/29,74.55.98.12,74.63.217.81,74.63.35.204] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (248)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407495; rev:140; fwsam: src, 24 hours;) alert tcp [74.63.80.50,74.86.100.164,74.86.100.165,74.86.100.166,74.86.100.167,74.86.115.0/24,74.86.132.177,74.86.147.0/24,74.86.154.0/24,74.86.187.24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (249)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407496; rev:140; fwsam: src, 24 hours;) alert udp [74.63.80.50,74.86.100.164,74.86.100.165,74.86.100.166,74.86.100.167,74.86.115.0/24,74.86.132.177,74.86.147.0/24,74.86.154.0/24,74.86.187.24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (249)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407497; rev:140; fwsam: src, 24 hours;) alert tcp [74.86.207.103,74.86.22.177,75.101.129.55,75.102.17.5,75.102.24.14,75.102.9.7,75.119.216.186,75.125.132.0,75.125.132.0/27,75.125.135.192/28] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (250)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407498; rev:140; fwsam: src, 24 hours;) alert udp [74.86.207.103,74.86.22.177,75.101.129.55,75.102.17.5,75.102.24.14,75.102.9.7,75.119.216.186,75.125.132.0,75.125.132.0/27,75.125.135.192/28] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (250)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407499; rev:140; fwsam: src, 24 hours;) alert tcp [75.125.156.78,75.125.162.112/29,75.125.164.240,75.125.164.240/29,75.125.164.243,75.125.164.246,75.125.164.247,75.125.178.144/28,75.125.178.155,75.125.178.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (251)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407500; rev:140; fwsam: src, 24 hours;) alert udp [75.125.156.78,75.125.162.112/29,75.125.164.240,75.125.164.240/29,75.125.164.243,75.125.164.246,75.125.164.247,75.125.178.144/28,75.125.178.155,75.125.178.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (251)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407501; rev:140; fwsam: src, 24 hours;) alert tcp [75.125.178.157,75.125.178.158,75.125.200.226,75.125.207.50,75.125.215.35,75.125.215.48/28,75.125.215.50,75.125.215.54,75.125.215.57,75.126.137.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (252)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407502; rev:140; fwsam: src, 24 hours;) alert udp [75.125.178.157,75.125.178.158,75.125.200.226,75.125.207.50,75.125.215.35,75.125.215.48/28,75.125.215.50,75.125.215.54,75.125.215.57,75.126.137.166] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (252)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407503; rev:140; fwsam: src, 24 hours;) alert tcp [75.126.142.106,75.126.142.108,75.126.149.156,75.126.206.122,75.126.206.125,75.126.22.187,75.126.22.190,75.126.25.209,75.126.25.211,75.126.3.176] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (253)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407504; rev:140; fwsam: src, 24 hours;) alert udp [75.126.142.106,75.126.142.108,75.126.149.156,75.126.206.122,75.126.206.125,75.126.22.187,75.126.22.190,75.126.25.209,75.126.25.211,75.126.3.176] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (253)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407505; rev:140; fwsam: src, 24 hours;) alert tcp [75.126.3.177,75.126.3.178,75.126.3.181,75.126.3.191,75.126.57.16,75.126.75.50,75.126.75.53,75.126.85.199,75.127.81.214,75.127.91.231] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (254)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407506; rev:140; fwsam: src, 24 hours;) alert udp [75.126.3.177,75.126.3.178,75.126.3.181,75.126.3.191,75.126.57.16,75.126.75.50,75.126.75.53,75.126.85.199,75.127.81.214,75.127.91.231] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (254)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407507; rev:140; fwsam: src, 24 hours;) alert tcp [75.141.222.60,75.181.10.124,76.162.102.189,76.162.108.1,76.162.143.189,76.162.178.195,76.73.12.138,76.73.32.102,76.73.37.250,76.74.154.110] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (255)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407508; rev:140; fwsam: src, 24 hours;) alert udp [75.141.222.60,75.181.10.124,76.162.102.189,76.162.108.1,76.162.143.189,76.162.178.195,76.73.12.138,76.73.32.102,76.73.37.250,76.74.154.110] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (255)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407509; rev:140; fwsam: src, 24 hours;) alert tcp [76.74.239.143,76.74.239.45,76.74.249.30,76.74.249.5,76.76.101.84,76.76.101.85,76.76.101.86,76.76.103.162,76.76.103.163,76.76.103.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (256)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407510; rev:140; fwsam: src, 24 hours;) alert udp [76.74.239.143,76.74.239.45,76.74.249.30,76.74.249.5,76.76.101.84,76.76.101.85,76.76.101.86,76.76.103.162,76.76.103.163,76.76.103.164] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (256)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407511; rev:140; fwsam: src, 24 hours;) alert tcp [76.76.103.166,76.76.103.82,76.76.22.221,76.76.3.154,76.9.23.148,77.220.177.0/24,77.220.178.56,77.221.128.0/19,77.222.40.169,77.222.40.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (257)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407512; rev:140; fwsam: src, 24 hours;) alert udp [76.76.103.166,76.76.103.82,76.76.22.221,76.76.3.154,76.9.23.148,77.220.177.0/24,77.220.178.56,77.221.128.0/19,77.222.40.169,77.222.40.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (257)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407513; rev:140; fwsam: src, 24 hours;) alert tcp [77.222.40.207,77.222.40.3,77.222.40.33,77.232.66.18,77.244.211.0/24,77.244.220.0/24,77.245.146.10,77.245.146.2,77.245.146.3,77.245.146.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (258)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407514; rev:140; fwsam: src, 24 hours;) alert udp [77.222.40.207,77.222.40.3,77.222.40.33,77.232.66.18,77.244.211.0/24,77.244.220.0/24,77.245.146.10,77.245.146.2,77.245.146.3,77.245.146.4] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (258)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407515; rev:140; fwsam: src, 24 hours;) alert tcp [77.245.146.5,77.245.146.6,77.245.146.7,77.245.146.8,77.245.61.0/24,77.247.178.40,77.247.178.42,77.37.14.18,77.37.18.36,77.37.18.61] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (259)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407516; rev:140; fwsam: src, 24 hours;) alert udp [77.245.146.5,77.245.146.6,77.245.146.7,77.245.146.8,77.245.61.0/24,77.247.178.40,77.247.178.42,77.37.14.18,77.37.18.36,77.37.18.61] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (259)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407517; rev:140; fwsam: src, 24 hours;) alert tcp [77.37.19.173,77.37.19.179,77.37.19.43,77.73.98.0/24,77.74.12.60,77.74.197.117,77.74.48.107,77.91.224.0/21,77.92.145.10,77.92.145.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (260)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407518; rev:140; fwsam: src, 24 hours;) alert udp [77.37.19.173,77.37.19.179,77.37.19.43,77.73.98.0/24,77.74.12.60,77.74.197.117,77.74.48.107,77.91.224.0/21,77.92.145.10,77.92.145.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (260)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407519; rev:140; fwsam: src, 24 hours;) alert tcp [77.92.145.12,77.92.145.13,77.92.145.18,77.92.145.19,77.92.145.20,77.92.145.21,77.92.145.26,77.92.145.27,77.92.145.28,77.92.88.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (261)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407520; rev:140; fwsam: src, 24 hours;) alert udp [77.92.145.12,77.92.145.13,77.92.145.18,77.92.145.19,77.92.145.20,77.92.145.21,77.92.145.26,77.92.145.27,77.92.145.28,77.92.88.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (261)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407521; rev:140; fwsam: src, 24 hours;) alert tcp [77.93.210.188,78.107.239.134,78.108.177.103,78.108.177.104,78.108.177.2,78.108.177.3,78.108.177.31,78.108.177.32,78.108.177.34,78.108.177.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (262)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407522; rev:140; fwsam: src, 24 hours;) alert udp [77.93.210.188,78.107.239.134,78.108.177.103,78.108.177.104,78.108.177.2,78.108.177.3,78.108.177.31,78.108.177.32,78.108.177.34,78.108.177.94] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (262)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407523; rev:140; fwsam: src, 24 hours;) alert tcp [78.108.178.208,78.108.178.25,78.108.178.57,78.108.179.100,78.108.179.213,78.108.179.23,78.108.179.71,78.108.179.73,78.108.179.77,78.108.180.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (263)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407524; rev:140; fwsam: src, 24 hours;) alert udp [78.108.178.208,78.108.178.25,78.108.178.57,78.108.179.100,78.108.179.213,78.108.179.23,78.108.179.71,78.108.179.73,78.108.179.77,78.108.180.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (263)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407525; rev:140; fwsam: src, 24 hours;) alert tcp [78.108.180.233,78.108.180.90,78.108.182.164,78.108.183.227,78.108.184.48,78.108.81.100,78.109.16.219,78.109.18.10,78.109.18.205,78.109.18.234] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (264)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407526; rev:140; fwsam: src, 24 hours;) alert udp [78.108.180.233,78.108.180.90,78.108.182.164,78.108.183.227,78.108.184.48,78.108.81.100,78.109.16.219,78.109.18.10,78.109.18.205,78.109.18.234] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (264)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407527; rev:140; fwsam: src, 24 hours;) alert tcp [78.109.18.8,78.109.20.154,78.109.20.162,78.109.20.50,78.109.21.186,78.109.22.131,78.109.22.135,78.109.23.1/29,78.109.23.7,78.109.25.216] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (265)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407528; rev:140; fwsam: src, 24 hours;) alert udp [78.109.18.8,78.109.20.154,78.109.20.162,78.109.20.50,78.109.21.186,78.109.22.131,78.109.22.135,78.109.23.1/29,78.109.23.7,78.109.25.216] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (265)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407529; rev:140; fwsam: src, 24 hours;) alert tcp [78.109.25.217,78.109.25.218,78.109.28.144,78.109.28.216,78.109.28.217,78.109.28.41,78.109.28.45,78.109.29.112,78.109.29.114,78.109.29.116] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (266)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407530; rev:140; fwsam: src, 24 hours;) alert udp [78.109.25.217,78.109.25.218,78.109.28.144,78.109.28.216,78.109.28.217,78.109.28.41,78.109.28.45,78.109.29.112,78.109.29.114,78.109.29.116] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (266)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407531; rev:140; fwsam: src, 24 hours;) alert tcp [78.109.29.33,78.109.29.40,78.109.30.200,78.110.166.108,78.110.166.203,78.110.166.60,78.110.175.21,78.110.50.113,78.111.80.213,78.129.142.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (267)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407532; rev:140; fwsam: src, 24 hours;) alert udp [78.109.29.33,78.109.29.40,78.109.30.200,78.110.166.108,78.110.166.203,78.110.166.60,78.110.175.21,78.110.50.113,78.111.80.213,78.129.142.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (267)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407533; rev:140; fwsam: src, 24 hours;) alert tcp [78.129.158.68,78.129.166.0/24,78.129.166.233,78.129.202.0/24,78.129.205.64,78.129.207.168,78.129.223.19,78.137.168.33,78.140.132.11,78.140.133.15] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (268)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407534; rev:140; fwsam: src, 24 hours;) alert udp [78.129.158.68,78.129.166.0/24,78.129.166.233,78.129.202.0/24,78.129.205.64,78.129.207.168,78.129.223.19,78.137.168.33,78.140.132.11,78.140.133.15] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (268)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407535; rev:140; fwsam: src, 24 hours;) alert tcp [78.140.138.105,78.140.139.105,78.140.141.107,78.140.141.114,78.140.145.144,78.140.23.18,78.143.16.7,78.157.129.71,78.157.141.0/24,78.157.142.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (269)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407536; rev:140; fwsam: src, 24 hours;) alert udp [78.140.138.105,78.140.139.105,78.140.141.107,78.140.141.114,78.140.145.144,78.140.23.18,78.143.16.7,78.157.129.71,78.157.141.0/24,78.157.142.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (269)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407537; rev:140; fwsam: src, 24 hours;) alert tcp [78.157.143.0/24,78.159.101.166,78.159.101.239,78.159.101.27,78.159.101.40,78.159.102.97,78.159.102.99,78.159.106.128,78.159.106.128/25,78.159.106.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (270)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407538; rev:140; fwsam: src, 24 hours;) alert udp [78.157.143.0/24,78.159.101.166,78.159.101.239,78.159.101.27,78.159.101.40,78.159.102.97,78.159.102.99,78.159.106.128,78.159.106.128/25,78.159.106.129] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (270)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407539; rev:140; fwsam: src, 24 hours;) alert tcp [78.159.106.130,78.159.106.159,78.159.106.193,78.159.106.197,78.159.106.255,78.159.112.146,78.159.112.200,78.159.112.25,78.159.112.43,78.159.112.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (271)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407540; rev:140; fwsam: src, 24 hours;) alert udp [78.159.106.130,78.159.106.159,78.159.106.193,78.159.106.197,78.159.106.255,78.159.112.146,78.159.112.200,78.159.112.25,78.159.112.43,78.159.112.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (271)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407541; rev:140; fwsam: src, 24 hours;) alert tcp [78.159.114.116,78.159.114.175,78.159.115.122,78.159.115.215,78.159.115.216,78.159.117.102,78.159.118.144,78.159.118.165,78.159.118.207,78.159.118.215] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (272)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407542; rev:140; fwsam: src, 24 hours;) alert udp [78.159.114.116,78.159.114.175,78.159.115.122,78.159.115.215,78.159.115.216,78.159.117.102,78.159.118.144,78.159.118.165,78.159.118.207,78.159.118.215] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (272)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407543; rev:140; fwsam: src, 24 hours;) alert tcp [78.159.118.217,78.159.118.218,78.159.118.229,78.159.118.62,78.159.122.197,78.159.124.235,78.159.125.159,78.159.126.199,78.159.96.134,78.159.96.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (273)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407544; rev:140; fwsam: src, 24 hours;) alert udp [78.159.118.217,78.159.118.218,78.159.118.229,78.159.118.62,78.159.122.197,78.159.124.235,78.159.125.159,78.159.126.199,78.159.96.134,78.159.96.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (273)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407545; rev:140; fwsam: src, 24 hours;) alert tcp [78.159.96.42,78.159.97.21,78.159.97.49,78.159.98.112,78.159.98.139,78.159.98.217,78.159.98.93,78.159.99.224,78.159.99.52,78.159.99.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (274)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407546; rev:140; fwsam: src, 24 hours;) alert udp [78.159.96.42,78.159.97.21,78.159.97.49,78.159.98.112,78.159.98.139,78.159.98.217,78.159.98.93,78.159.99.224,78.159.99.52,78.159.99.54] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (274)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407547; rev:140; fwsam: src, 24 hours;) alert tcp [78.159.99.66,78.24.219.164,78.26.144.206,78.26.179.0/24,78.31.65.216,78.41.207.196,78.46.129.170,78.46.148.49,78.46.151.181,78.46.152.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (275)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407548; rev:140; fwsam: src, 24 hours;) alert udp [78.159.99.66,78.24.219.164,78.26.144.206,78.26.179.0/24,78.31.65.216,78.41.207.196,78.46.129.170,78.46.148.49,78.46.151.181,78.46.152.171] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (275)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407549; rev:140; fwsam: src, 24 hours;) alert tcp [78.46.152.8,78.46.183.24,78.46.183.24/29,78.46.183.25,78.46.183.26,78.46.183.30,78.46.183.31,78.46.205.65,78.46.205.69,78.46.205.70] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (276)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407550; rev:140; fwsam: src, 24 hours;) alert udp [78.46.152.8,78.46.183.24,78.46.183.24/29,78.46.183.25,78.46.183.26,78.46.183.30,78.46.183.31,78.46.205.65,78.46.205.69,78.46.205.70] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (276)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407551; rev:140; fwsam: src, 24 hours;) alert tcp [78.46.216.233,78.46.216.237,78.46.216.238,78.46.33.111,78.46.67.80,78.46.86.4,78.46.88.142,78.46.88.202,78.46.90.230,78.47.100.189] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (277)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407552; rev:140; fwsam: src, 24 hours;) alert udp [78.46.216.233,78.46.216.237,78.46.216.238,78.46.33.111,78.46.67.80,78.46.86.4,78.46.88.142,78.46.88.202,78.46.90.230,78.47.100.189] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (277)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407553; rev:140; fwsam: src, 24 hours;) alert tcp [78.47.127.10,78.47.132.216,78.47.132.220,78.47.132.221,78.47.159.185,78.47.159.54,78.47.168.82,78.47.172.66,78.47.172.67,78.47.200.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (278)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407554; rev:140; fwsam: src, 24 hours;) alert udp [78.47.127.10,78.47.132.216,78.47.132.220,78.47.132.221,78.47.159.185,78.47.159.54,78.47.168.82,78.47.172.66,78.47.172.67,78.47.200.154] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (278)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407555; rev:140; fwsam: src, 24 hours;) alert tcp [78.47.200.155,78.47.222.220,78.47.240.106,78.47.248.113,78.47.91.153,79.112.76.56,79.113.23.229,79.113.83.13,79.132.198.0/24,79.132.211.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (279)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407556; rev:140; fwsam: src, 24 hours;) alert udp [78.47.200.155,78.47.222.220,78.47.240.106,78.47.248.113,78.47.91.153,79.112.76.56,79.113.23.229,79.113.83.13,79.132.198.0/24,79.132.211.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (279)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407557; rev:140; fwsam: src, 24 hours;) alert tcp [79.135.160.0/19,79.143.176.0/22,79.170.40.21,79.170.40.38,79.174.64.13,79.174.64.228,79.174.66.47,79.71.239.81,79.98.25.99,79.99.122.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (280)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407558; rev:140; fwsam: src, 24 hours;) alert udp [79.135.160.0/19,79.143.176.0/22,79.170.40.21,79.170.40.38,79.174.64.13,79.174.64.228,79.174.66.47,79.71.239.81,79.98.25.99,79.99.122.34] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (280)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407559; rev:140; fwsam: src, 24 hours;) alert tcp [8.12.35.78,80.156.86.78,80.190.54.181,80.233.168.21,80.233.221.247,80.233.221.253,80.237.132.56,80.24.176.145,80.248.208.141,80.250.24.17] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (281)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407560; rev:140; fwsam: src, 24 hours;) alert udp [8.12.35.78,80.156.86.78,80.190.54.181,80.233.168.21,80.233.221.247,80.233.221.253,80.237.132.56,80.24.176.145,80.248.208.141,80.250.24.17] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (281)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407561; rev:140; fwsam: src, 24 hours;) alert tcp [80.250.24.18,80.70.224.0/20,80.77.80.0/20,80.79.118.184,80.83.210.226,80.86.87.241,80.86.89.131,80.87.199.13,80.87.199.14,80.87.206.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (282)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407562; rev:140; fwsam: src, 24 hours;) alert udp [80.250.24.18,80.70.224.0/20,80.77.80.0/20,80.79.118.184,80.83.210.226,80.86.87.241,80.86.89.131,80.87.199.13,80.87.199.14,80.87.206.99] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (282)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407563; rev:140; fwsam: src, 24 hours;) alert tcp [80.90.114.11,80.90.114.34,80.90.118.102,80.90.118.34,80.90.118.35,80.90.118.37,80.91.176.135,80.91.177.106,80.91.191.138,80.91.191.170] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (283)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407564; rev:140; fwsam: src, 24 hours;) alert udp [80.90.114.11,80.90.114.34,80.90.118.102,80.90.118.34,80.90.118.35,80.90.118.37,80.91.176.135,80.91.177.106,80.91.191.138,80.91.191.170] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (283)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407565; rev:140; fwsam: src, 24 hours;) alert tcp [80.91.191.188,80.91.76.147,80.91.76.148,80.91.76.149,80.91.76.150,80.91.76.151,80.91.76.152,80.91.76.153,80.91.76.154,80.92.162.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (284)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407566; rev:140; fwsam: src, 24 hours;) alert udp [80.91.191.188,80.91.76.147,80.91.76.148,80.91.76.149,80.91.76.150,80.91.76.151,80.91.76.152,80.91.76.153,80.91.76.154,80.92.162.40] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (284)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407567; rev:140; fwsam: src, 24 hours;) alert tcp [80.93.216.229,80.93.48.54,80.93.49.141,80.93.49.192,80.93.50.149,80.93.56.4,80.93.57.179,80.93.57.211,80.93.62.112,80.95.160.73] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (285)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407568; rev:140; fwsam: src, 24 hours;) alert udp [80.93.216.229,80.93.48.54,80.93.49.141,80.93.49.192,80.93.50.149,80.93.56.4,80.93.57.179,80.93.57.211,80.93.62.112,80.95.160.73] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (285)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407569; rev:140; fwsam: src, 24 hours;) alert tcp [81.169.145.69,81.169.145.72,81.174.66.128,81.176.232.102,81.176.232.103,81.176.236.12,81.176.68.175,81.176.68.18,81.176.68.61,81.177.157.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (286)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407570; rev:140; fwsam: src, 24 hours;) alert udp [81.169.145.69,81.169.145.72,81.174.66.128,81.176.232.102,81.176.232.103,81.176.236.12,81.176.68.175,81.176.68.18,81.176.68.61,81.177.157.22] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (286)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407571; rev:140; fwsam: src, 24 hours;) alert tcp [81.177.22.144,81.177.26.41,81.177.3.242,81.177.8.0/24,81.22.60.153,81.222.2.22,81.222.8.2,81.222.9.2,81.222.9.6,81.31.152.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (287)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407572; rev:140; fwsam: src, 24 hours;) alert udp [81.177.22.144,81.177.26.41,81.177.3.242,81.177.8.0/24,81.22.60.153,81.222.2.22,81.222.8.2,81.222.9.2,81.222.9.6,81.31.152.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (287)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407573; rev:140; fwsam: src, 24 hours;) alert tcp [81.31.42.131,81.9.5.197,81.94.16.0/20,81.95.128.0/19,81.95.144.0/20,81.95.156.0/22,82.103.130.171,82.103.131.211,82.103.132.114,82.103.137.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (288)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407574; rev:140; fwsam: src, 24 hours;) alert udp [81.31.42.131,81.9.5.197,81.94.16.0/20,81.95.128.0/19,81.95.144.0/20,81.95.156.0/22,82.103.130.171,82.103.131.211,82.103.132.114,82.103.137.14] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (288)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407575; rev:140; fwsam: src, 24 hours;) alert tcp [82.103.138.10,82.103.138.37,82.109.45.51,82.110.105.3,82.120.80.136,82.144.242.175,82.146.32.213,82.146.33.103,82.146.33.243,82.146.35.143] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (289)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407576; rev:140; fwsam: src, 24 hours;) alert udp [82.103.138.10,82.103.138.37,82.109.45.51,82.110.105.3,82.120.80.136,82.144.242.175,82.146.32.213,82.146.33.103,82.146.33.243,82.146.35.143] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (289)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407577; rev:140; fwsam: src, 24 hours;) alert tcp [82.146.35.18,82.146.40.34,82.146.42.15,82.146.42.8,82.146.43.173,82.146.43.2,82.146.43.3,82.146.49.1,82.146.50.202,82.146.51.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (290)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407578; rev:140; fwsam: src, 24 hours;) alert udp [82.146.35.18,82.146.40.34,82.146.42.15,82.146.42.8,82.146.43.173,82.146.43.2,82.146.43.3,82.146.49.1,82.146.50.202,82.146.51.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (290)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407579; rev:140; fwsam: src, 24 hours;) alert tcp [82.146.51.25,82.146.52.158,82.146.55.23,82.146.55.35,82.146.55.39,82.146.56.0/21,82.151.132.40,82.165.180.64,82.165.205.16,82.166.132.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (291)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407580; rev:140; fwsam: src, 24 hours;) alert udp [82.146.51.25,82.146.52.158,82.146.55.23,82.146.55.35,82.146.55.39,82.146.56.0/21,82.151.132.40,82.165.180.64,82.165.205.16,82.166.132.221] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (291)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407581; rev:140; fwsam: src, 24 hours;) alert tcp [82.192.87.96,82.197.131.14,82.197.131.17,82.197.131.21,82.198.176.34,82.200.96.0/23,82.204.219.135,82.204.219.208,82.204.219.221,82.204.219.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (292)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407582; rev:140; fwsam: src, 24 hours;) alert udp [82.192.87.96,82.197.131.14,82.197.131.17,82.197.131.21,82.198.176.34,82.200.96.0/23,82.204.219.135,82.204.219.208,82.204.219.221,82.204.219.223] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (292)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407583; rev:140; fwsam: src, 24 hours;) alert tcp [82.204.219.251,82.208.58.199,82.98.193.102,82.98.235.155,82.98.235.173,82.98.235.24,82.98.235.52,82.98.86.0/24,83.133.115.9,83.133.118.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (293)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407584; rev:140; fwsam: src, 24 hours;) alert udp [82.204.219.251,82.208.58.199,82.98.193.102,82.98.235.155,82.98.235.173,82.98.235.24,82.98.235.52,82.98.86.0/24,83.133.115.9,83.133.118.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (293)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407585; rev:140; fwsam: src, 24 hours;) alert tcp [83.133.118.70,83.133.118.72,83.133.123.113,83.133.123.139,83.133.123.140,83.133.123.166,83.133.123.174,83.133.124.81,83.133.125.116,83.133.126.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (294)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407586; rev:140; fwsam: src, 24 hours;) alert udp [83.133.118.70,83.133.118.72,83.133.123.113,83.133.123.139,83.133.123.140,83.133.123.166,83.133.123.174,83.133.124.81,83.133.125.116,83.133.126.155] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (294)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407587; rev:140; fwsam: src, 24 hours;) alert tcp [83.133.126.46,83.133.126.98,83.133.127.93,83.137.192.222,83.142.230.169,83.142.230.175,83.142.230.44,83.142.230.45,83.143.81.10,83.149.105.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (295)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407588; rev:140; fwsam: src, 24 hours;) alert udp [83.133.126.46,83.133.126.98,83.133.127.93,83.137.192.222,83.142.230.169,83.142.230.175,83.142.230.44,83.142.230.45,83.143.81.10,83.149.105.88] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (295)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407589; rev:140; fwsam: src, 24 hours;) alert tcp [83.149.69.46,83.149.69.47,83.149.72.171,83.149.72.172,83.149.74.250,83.149.75.50,83.149.75.56,83.149.82.186,83.149.85.100,83.149.86.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (296)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407590; rev:140; fwsam: src, 24 hours;) alert udp [83.149.69.46,83.149.69.47,83.149.72.171,83.149.72.172,83.149.74.250,83.149.75.50,83.149.75.56,83.149.82.186,83.149.85.100,83.149.86.132] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (296)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407591; rev:140; fwsam: src, 24 hours;) alert tcp [83.149.87.200,83.149.95.208,83.17.76.98,83.170.116.39,83.171.76.98,83.171.76.99,83.172.0.56,83.19.144.26,83.211.240.146,83.222.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (297)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407592; rev:140; fwsam: src, 24 hours;) alert udp [83.149.87.200,83.149.95.208,83.17.76.98,83.170.116.39,83.171.76.98,83.171.76.99,83.172.0.56,83.19.144.26,83.211.240.146,83.222.0.0/19] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (297)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407593; rev:140; fwsam: src, 24 hours;) alert tcp [83.229.248.147,83.229.250.27,83.229.251.28,83.229.251.29,83.229.251.37,83.229.252.71,83.233.30.140,83.233.30.159,83.243.70.11,83.68.16.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (298)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407594; rev:140; fwsam: src, 24 hours;) alert udp [83.229.248.147,83.229.250.27,83.229.251.28,83.229.251.29,83.229.251.37,83.229.252.71,83.233.30.140,83.233.30.159,83.243.70.11,83.68.16.30] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (298)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407595; rev:140; fwsam: src, 24 hours;) alert tcp [83.68.16.6,84.16.224.183,84.16.224.199,84.16.227.222,84.16.227.223,84.16.228.142,84.16.228.143,84.16.230.38,84.16.234.27,84.16.235.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (299)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407596; rev:140; fwsam: src, 24 hours;) alert udp [83.68.16.6,84.16.224.183,84.16.224.199,84.16.227.222,84.16.227.223,84.16.228.142,84.16.228.143,84.16.230.38,84.16.234.27,84.16.235.187] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (299)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407597; rev:140; fwsam: src, 24 hours;) alert tcp [84.16.236.16,84.16.237.46,84.16.240.233,84.16.244.114,84.16.244.121,84.16.247.12,84.16.251.238,84.16.252.138,84.16.252.183,84.16.252.73] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (300)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407598; rev:140; fwsam: src, 24 hours;) alert udp [84.16.236.16,84.16.237.46,84.16.240.233,84.16.244.114,84.16.244.121,84.16.247.12,84.16.251.238,84.16.252.138,84.16.252.183,84.16.252.73] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (300)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407599; rev:140; fwsam: src, 24 hours;) alert tcp [84.16.252.77,84.16.252.80,84.16.252.90,84.19.184.160,84.204.97.122,84.204.97.124,84.243.196.130,84.243.196.132,84.243.196.136,84.243.196.137] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (301)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407600; rev:140; fwsam: src, 24 hours;) alert udp [84.16.252.77,84.16.252.80,84.16.252.90,84.19.184.160,84.204.97.122,84.204.97.124,84.243.196.130,84.243.196.132,84.243.196.136,84.243.196.137] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (301)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407601; rev:140; fwsam: src, 24 hours;) alert tcp [84.243.196.6,84.243.197.10,84.243.197.183,84.243.197.184,84.243.197.191,84.243.197.197,84.243.197.45,84.243.200.143,84.243.200.147,84.243.213.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (302)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407602; rev:140; fwsam: src, 24 hours;) alert udp [84.243.196.6,84.243.197.10,84.243.197.183,84.243.197.184,84.243.197.191,84.243.197.197,84.243.197.45,84.243.200.143,84.243.200.147,84.243.213.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (302)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407603; rev:140; fwsam: src, 24 hours;) alert tcp [84.243.252.160,84.243.252.161,84.243.252.162,84.243.252.163,84.243.252.164,84.243.252.165,84.243.252.166,84.243.252.167,84.243.252.168,84.243.252.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (303)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407604; rev:140; fwsam: src, 24 hours;) alert udp [84.243.252.160,84.243.252.161,84.243.252.162,84.243.252.163,84.243.252.164,84.243.252.165,84.243.252.166,84.243.252.167,84.243.252.168,84.243.252.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (303)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407605; rev:140; fwsam: src, 24 hours;) alert tcp [84.243.252.170,84.243.252.171,84.243.252.172,84.243.252.173,84.243.252.174,84.243.252.175,84.243.252.176,84.243.252.177,84.243.252.178,84.243.252.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (304)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407606; rev:140; fwsam: src, 24 hours;) alert udp [84.243.252.170,84.243.252.171,84.243.252.172,84.243.252.173,84.243.252.174,84.243.252.175,84.243.252.176,84.243.252.177,84.243.252.178,84.243.252.179] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (304)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407607; rev:140; fwsam: src, 24 hours;) alert tcp [84.243.252.180,84.243.252.87,84.243.252.88,84.244.137.173,84.244.138.115,84.246.134.14,84.255.247.1,84.51.21.132,84.95.250.10,85.10.194.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (305)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407608; rev:140; fwsam: src, 24 hours;) alert udp [84.243.252.180,84.243.252.87,84.243.252.88,84.244.137.173,84.244.138.115,84.246.134.14,84.255.247.1,84.51.21.132,84.95.250.10,85.10.194.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (305)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407609; rev:140; fwsam: src, 24 hours;) alert tcp [85.10.208.252,85.10.221.161,85.10.243.126,85.114.131.69,85.114.141.207,85.12.43.99,85.13.129.230,85.13.135.43,85.13.236.154,85.14.6.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (306)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407610; rev:140; fwsam: src, 24 hours;) alert udp [85.10.208.252,85.10.221.161,85.10.243.126,85.114.131.69,85.114.141.207,85.12.43.99,85.13.129.230,85.13.135.43,85.13.236.154,85.14.6.159] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (306)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407611; rev:140; fwsam: src, 24 hours;) alert tcp [85.142.1.0/24,85.159.144.21,85.17.103.104,85.17.103.112,85.17.103.113,85.17.103.114,85.17.103.115,85.17.103.116,85.17.103.119,85.17.103.35] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (307)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407612; rev:140; fwsam: src, 24 hours;) alert udp [85.142.1.0/24,85.159.144.21,85.17.103.104,85.17.103.112,85.17.103.113,85.17.103.114,85.17.103.115,85.17.103.116,85.17.103.119,85.17.103.35] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (307)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407613; rev:140; fwsam: src, 24 hours;) alert tcp [85.17.103.47,85.17.136.135,85.17.136.137,85.17.136.140,85.17.138.29,85.17.138.60,85.17.139.54,85.17.141.20,85.17.143.132,85.17.143.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (308)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407614; rev:140; fwsam: src, 24 hours;) alert udp [85.17.103.47,85.17.136.135,85.17.136.137,85.17.136.140,85.17.138.29,85.17.138.60,85.17.139.54,85.17.141.20,85.17.143.132,85.17.143.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (308)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407615; rev:140; fwsam: src, 24 hours;) alert tcp [85.17.162.100,85.17.162.165,85.17.162.169,85.17.162.9,85.17.165.132,85.17.166.135,85.17.166.136,85.17.169.55,85.17.177.223,85.17.184.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (309)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407616; rev:140; fwsam: src, 24 hours;) alert udp [85.17.162.100,85.17.162.165,85.17.162.169,85.17.162.9,85.17.165.132,85.17.166.135,85.17.166.136,85.17.169.55,85.17.177.223,85.17.184.31] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (309)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407617; rev:140; fwsam: src, 24 hours;) alert tcp [85.17.19.118,85.17.19.132,85.17.201.143,85.17.209.45,85.17.216.83,85.17.224.149,85.17.232.198,85.17.254.136,85.17.254.158,85.17.3.246] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (310)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407618; rev:140; fwsam: src, 24 hours;) alert udp [85.17.19.118,85.17.19.132,85.17.201.143,85.17.209.45,85.17.216.83,85.17.224.149,85.17.232.198,85.17.254.136,85.17.254.158,85.17.3.246] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (310)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407619; rev:140; fwsam: src, 24 hours;) alert tcp [85.17.4.0/24,85.17.45.0/24,85.17.52.4,85.17.52.47,85.17.52.69,85.17.52.7,85.17.52.77,85.17.52.9,85.17.93.190,85.17.94.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (311)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407620; rev:140; fwsam: src, 24 hours;) alert udp [85.17.4.0/24,85.17.45.0/24,85.17.52.4,85.17.52.47,85.17.52.69,85.17.52.7,85.17.52.77,85.17.52.9,85.17.93.190,85.17.94.16] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (311)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407621; rev:140; fwsam: src, 24 hours;) alert tcp [85.17.94.42,85.192.34.156,85.192.43.102,85.197.99.39,85.21.125.197,85.21.68.35,85.214.23.161,85.214.90.254,85.235.208.0/24,85.235.209.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (312)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407622; rev:140; fwsam: src, 24 hours;) alert udp [85.17.94.42,85.192.34.156,85.192.43.102,85.197.99.39,85.21.125.197,85.21.68.35,85.214.23.161,85.214.90.254,85.235.208.0/24,85.235.209.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (312)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407623; rev:140; fwsam: src, 24 hours;) alert tcp [85.24.148.110,85.255.112.0/20,85.255.112.0/21,85.255.120.0/24,85.255.121.0/24,85.255.122.4,85.64.2.247,85.9.56.199,85.92.152.43,86.122.151.123] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (313)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407624; rev:140; fwsam: src, 24 hours;) alert udp [85.24.148.110,85.255.112.0/20,85.255.112.0/21,85.255.120.0/24,85.255.121.0/24,85.255.122.4,85.64.2.247,85.9.56.199,85.92.152.43,86.122.151.123] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (313)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407625; rev:140; fwsam: src, 24 hours;) alert tcp [86.17.173.169,86.203.230.213,86.35.15.212,86.57.246.186,87.106.103.122,87.106.220.76,87.117.234.92,87.117.252.0/24,87.117.255.0/24,87.118.116.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (314)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407626; rev:140; fwsam: src, 24 hours;) alert udp [86.17.173.169,86.203.230.213,86.35.15.212,86.57.246.186,87.106.103.122,87.106.220.76,87.117.234.92,87.117.252.0/24,87.117.255.0/24,87.118.116.11] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (314)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407627; rev:140; fwsam: src, 24 hours;) alert tcp [87.118.116.14,87.118.117.11,87.118.118.80,87.118.120.71,87.118.126.246,87.118.126.30,87.118.69.108,87.118.96.83,87.118.96.86,87.120.40.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (315)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407628; rev:140; fwsam: src, 24 hours;) alert udp [87.118.116.14,87.118.117.11,87.118.118.80,87.118.120.71,87.118.126.246,87.118.126.30,87.118.69.108,87.118.96.83,87.118.96.86,87.120.40.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (315)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407629; rev:140; fwsam: src, 24 hours;) alert tcp [87.121.76.9,87.230.25.199,87.233.159.186,87.237.13.203,87.238.162.146,87.242.116.123,87.242.73.95,87.242.76.68,87.242.78.57,87.242.90.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (316)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407630; rev:140; fwsam: src, 24 hours;) alert udp [87.121.76.9,87.230.25.199,87.233.159.186,87.237.13.203,87.238.162.146,87.242.116.123,87.242.73.95,87.242.76.68,87.242.78.57,87.242.90.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (316)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407631; rev:140; fwsam: src, 24 hours;) alert tcp [87.248.163.54,87.248.163.56,87.248.163.58,87.248.180.0/24,87.251.53.97,87.252.1.21,87.3.36.91,87.98.128.146,87.98.222.197,87.98.234.25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (317)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407632; rev:140; fwsam: src, 24 hours;) alert udp [87.248.163.54,87.248.163.56,87.248.163.58,87.248.180.0/24,87.251.53.97,87.252.1.21,87.3.36.91,87.98.128.146,87.98.222.197,87.98.234.25] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (317)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407633; rev:140; fwsam: src, 24 hours;) alert tcp [87.98.239.19,88.191.22.55,88.191.78.48,88.198.103.122,88.198.131.169,88.198.207.4,88.198.233.225,88.198.40.57,88.198.41.170,88.198.48.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (318)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407634; rev:140; fwsam: src, 24 hours;) alert udp [87.98.239.19,88.191.22.55,88.191.78.48,88.198.103.122,88.198.131.169,88.198.207.4,88.198.233.225,88.198.40.57,88.198.41.170,88.198.48.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (318)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407635; rev:140; fwsam: src, 24 hours;) alert tcp [88.198.58.147,88.198.62.171,88.198.8.15,88.201.208.0/20,88.208.0.0/21,88.208.16.116,88.208.16.144,88.208.16.147,88.208.16.234,88.208.16.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (319)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407636; rev:140; fwsam: src, 24 hours;) alert udp [88.198.58.147,88.198.62.171,88.198.8.15,88.201.208.0/20,88.208.0.0/21,88.208.16.116,88.208.16.144,88.208.16.147,88.208.16.234,88.208.16.235] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (319)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407637; rev:140; fwsam: src, 24 hours;) alert tcp [88.208.17.1,88.208.17.116,88.208.19.153,88.208.19.4,88.208.21.110,88.208.21.16,88.208.21.188,88.208.28.0/22,88.208.39.146,88.208.46.232] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (320)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407638; rev:140; fwsam: src, 24 hours;) alert udp [88.208.17.1,88.208.17.116,88.208.19.153,88.208.19.4,88.208.21.110,88.208.21.16,88.208.21.188,88.208.28.0/22,88.208.39.146,88.208.46.232] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (320)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407639; rev:140; fwsam: src, 24 hours;) alert tcp [88.208.46.239,88.212.196.87,88.212.202.56,88.214.192.0/18,88.214.192.0/20,88.214.200.165,88.214.200.5,88.214.202.110,88.255.0.0/17,88.80.203.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (321)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407640; rev:140; fwsam: src, 24 hours;) alert udp [88.208.46.239,88.212.196.87,88.212.202.56,88.214.192.0/18,88.214.192.0/20,88.214.200.165,88.214.200.5,88.214.202.110,88.255.0.0/17,88.80.203.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (321)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407641; rev:140; fwsam: src, 24 hours;) alert tcp [88.81.249.200,88.84.128.40,88.84.137.164,88.85.65.129,88.85.65.5,88.85.65.6,88.85.66.17,88.85.66.63,88.85.78.81,88.85.81.101] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (322)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407642; rev:140; fwsam: src, 24 hours;) alert udp [88.81.249.200,88.84.128.40,88.84.137.164,88.85.65.129,88.85.65.5,88.85.65.6,88.85.66.17,88.85.66.63,88.85.78.81,88.85.81.101] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (322)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407643; rev:140; fwsam: src, 24 hours;) alert tcp [88.85.82.148,88.85.89.16,88.85.89.5,88.85.89.7,88.86.103.186,89.104.71.235,89.104.82.198,89.108.64.39,89.108.68.31,89.108.68.86] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (323)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407644; rev:140; fwsam: src, 24 hours;) alert udp [88.85.82.148,88.85.89.16,88.85.89.5,88.85.89.7,88.86.103.186,89.104.71.235,89.104.82.198,89.108.64.39,89.108.68.31,89.108.68.86] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (323)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407645; rev:140; fwsam: src, 24 hours;) alert tcp [89.108.73.87,89.108.73.98,89.108.74.33,89.108.80.210,89.108.82.74,89.108.83.12,89.108.89.8,89.108.91.137,89.108.91.7,89.108.91.82] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (324)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407646; rev:140; fwsam: src, 24 hours;) alert udp [89.108.73.87,89.108.73.98,89.108.74.33,89.108.80.210,89.108.82.74,89.108.83.12,89.108.89.8,89.108.91.137,89.108.91.7,89.108.91.82] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (324)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407647; rev:140; fwsam: src, 24 hours;) alert tcp [89.108.94.111,89.108.94.180,89.108.94.183,89.108.94.245,89.108.95.135,89.111.171.191,89.111.173.65,89.111.176.207,89.111.176.21,89.111.176.35] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (325)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407648; rev:140; fwsam: src, 24 hours;) alert udp [89.108.94.111,89.108.94.180,89.108.94.183,89.108.94.245,89.108.95.135,89.111.171.191,89.111.173.65,89.111.176.207,89.111.176.21,89.111.176.35] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (325)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407649; rev:140; fwsam: src, 24 hours;) alert tcp [89.111.176.4,89.111.176.48,89.111.176.54,89.111.176.67,89.111.176.89,89.111.176.97,89.111.188.155,89.114.126.152,89.146.137.0,89.149.194.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (326)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407650; rev:140; fwsam: src, 24 hours;) alert udp [89.111.176.4,89.111.176.48,89.111.176.54,89.111.176.67,89.111.176.89,89.111.176.97,89.111.188.155,89.114.126.152,89.146.137.0,89.149.194.201] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (326)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407651; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.194.45,89.149.200.153,89.149.200.79,89.149.201.133,89.149.202.115,89.149.202.127,89.149.202.254,89.149.202.30,89.149.206.56,89.149.207.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (327)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407652; rev:140; fwsam: src, 24 hours;) alert udp [89.149.194.45,89.149.200.153,89.149.200.79,89.149.201.133,89.149.202.115,89.149.202.127,89.149.202.254,89.149.202.30,89.149.206.56,89.149.207.114] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (327)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407653; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.207.213,89.149.207.56,89.149.208.179,89.149.208.44,89.149.209.11,89.149.209.117,89.149.209.160,89.149.209.161,89.149.209.69,89.149.209.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (328)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407654; rev:140; fwsam: src, 24 hours;) alert udp [89.149.207.213,89.149.207.56,89.149.208.179,89.149.208.44,89.149.209.11,89.149.209.117,89.149.209.160,89.149.209.161,89.149.209.69,89.149.209.93] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (328)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407655; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.210.154,89.149.212.100,89.149.212.137,89.149.212.151,89.149.212.218,89.149.216.212,89.149.216.213,89.149.217.205,89.149.220.0/24,89.149.221.182] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (329)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407656; rev:140; fwsam: src, 24 hours;) alert udp [89.149.210.154,89.149.212.100,89.149.212.137,89.149.212.151,89.149.212.218,89.149.216.212,89.149.216.213,89.149.217.205,89.149.220.0/24,89.149.221.182] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (329)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407657; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.221.74,89.149.225.88,89.149.226.0/24,89.149.227.0/24,89.149.228.201,89.149.230.73,89.149.235.190,89.149.235.192,89.149.235.235,89.149.236.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (330)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407658; rev:140; fwsam: src, 24 hours;) alert udp [89.149.221.74,89.149.225.88,89.149.226.0/24,89.149.227.0/24,89.149.228.201,89.149.230.73,89.149.235.190,89.149.235.192,89.149.235.235,89.149.236.140] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (330)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407659; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.236.141,89.149.236.98,89.149.241.0/24,89.149.242.128,89.149.242.191,89.149.242.201,89.149.242.25,89.149.244.204,89.149.244.22,89.149.244.29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (331)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407660; rev:140; fwsam: src, 24 hours;) alert udp [89.149.236.141,89.149.236.98,89.149.241.0/24,89.149.242.128,89.149.242.191,89.149.242.201,89.149.242.25,89.149.244.204,89.149.244.22,89.149.244.29] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (331)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407661; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.244.83,89.149.247.244,89.149.249.237,89.149.251.111,89.149.251.130,89.149.251.203,89.149.251.33,89.149.251.43,89.149.251.44,89.149.251.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (332)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407662; rev:140; fwsam: src, 24 hours;) alert udp [89.149.244.83,89.149.247.244,89.149.249.237,89.149.251.111,89.149.251.130,89.149.251.203,89.149.251.33,89.149.251.43,89.149.251.44,89.149.251.56] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (332)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407663; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.252.154,89.149.252.155,89.149.252.19,89.149.252.24,89.149.252.252,89.149.253.215,89.149.253.239,89.149.254.12,89.149.254.46,89.149.254.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (333)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407664; rev:140; fwsam: src, 24 hours;) alert udp [89.149.252.154,89.149.252.155,89.149.252.19,89.149.252.24,89.149.252.252,89.149.253.215,89.149.253.239,89.149.254.12,89.149.254.46,89.149.254.55] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (333)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407665; rev:140; fwsam: src, 24 hours;) alert tcp [89.149.255.190,89.149.255.191,89.149.255.34,89.149.255.35,89.171.115.10,89.179.247.183,89.18.181.0/24,89.18.189.44,89.185.228.12,89.185.228.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (334)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407666; rev:140; fwsam: src, 24 hours;) alert udp [89.149.255.190,89.149.255.191,89.149.255.34,89.149.255.35,89.171.115.10,89.179.247.183,89.18.181.0/24,89.18.189.44,89.185.228.12,89.185.228.13] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (334)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407667; rev:140; fwsam: src, 24 hours;) alert tcp [89.185.228.141,89.185.228.17,89.185.228.59,89.185.229.126,89.185.229.127,89.186.5.153,89.187.48.0/24,89.188.112.0/24,89.188.122.66,89.188.16.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (335)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407668; rev:140; fwsam: src, 24 hours;) alert udp [89.185.228.141,89.185.228.17,89.185.228.59,89.185.229.126,89.185.229.127,89.186.5.153,89.187.48.0/24,89.188.112.0/24,89.188.122.66,89.188.16.12] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (335)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407669; rev:140; fwsam: src, 24 hours;) alert tcp [89.19.29.130,89.191.224.28,89.200.201.66,89.200.201.67,89.200.201.94,89.208.145.148,89.218.40.131,89.218.85.18,89.238.135.227,89.248.111.232] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (336)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407670; rev:140; fwsam: src, 24 hours;) alert udp [89.19.29.130,89.191.224.28,89.200.201.66,89.200.201.67,89.200.201.94,89.208.145.148,89.218.40.131,89.218.85.18,89.238.135.227,89.248.111.232] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (336)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407671; rev:140; fwsam: src, 24 hours;) alert tcp [89.248.160.227,89.248.160.231,89.248.168.22,89.248.168.46,89.248.168.70,89.248.168.74,89.248.172.0/23,89.249.22.196,89.250.63.123,89.254.139.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (337)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407672; rev:140; fwsam: src, 24 hours;) alert udp [89.248.160.227,89.248.160.231,89.248.168.22,89.248.168.46,89.248.168.70,89.248.168.74,89.248.172.0/23,89.249.22.196,89.250.63.123,89.254.139.247] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (337)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407673; rev:140; fwsam: src, 24 hours;) alert tcp [89.32.22.215,89.47.236.152,89.47.237.52,89.96.48.150,90.150.144.50,90.156.144.78,90.156.149.33,90.156.153.104,90.156.153.34,90.156.153.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (338)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407674; rev:140; fwsam: src, 24 hours;) alert udp [89.32.22.215,89.47.236.152,89.47.237.52,89.96.48.150,90.150.144.50,90.156.144.78,90.156.149.33,90.156.153.104,90.156.153.34,90.156.153.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (338)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407675; rev:140; fwsam: src, 24 hours;) alert tcp [90.156.178.37,90.156.178.40,90.156.178.46,90.156.178.47,91.103.216.240,91.121.124.22,91.121.140.44,91.121.146.101,91.121.8.196,91.142.209.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (339)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407676; rev:140; fwsam: src, 24 hours;) alert udp [90.156.178.37,90.156.178.40,90.156.178.46,90.156.178.47,91.103.216.240,91.121.124.22,91.121.140.44,91.121.146.101,91.121.8.196,91.142.209.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (339)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407677; rev:140; fwsam: src, 24 hours;) alert tcp [91.149.157.130,91.189.113.105,91.189.113.12,91.192.106.0/23,91.192.148.161,91.192.148.177,91.192.148.194,91.192.148.33,91.192.148.49,91.192.148.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (340)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407678; rev:140; fwsam: src, 24 hours;) alert udp [91.149.157.130,91.189.113.105,91.189.113.12,91.192.106.0/23,91.192.148.161,91.192.148.177,91.192.148.194,91.192.148.33,91.192.148.49,91.192.148.66] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (340)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407679; rev:140; fwsam: src, 24 hours;) alert tcp [91.192.148.82,91.192.148.85,91.192.149.161,91.192.149.177,91.192.149.194,91.192.149.33,91.192.149.49,91.192.149.66,91.192.149.82,91.192.68.52] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (341)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407680; rev:140; fwsam: src, 24 hours;) alert udp [91.192.148.82,91.192.148.85,91.192.149.161,91.192.149.177,91.192.149.194,91.192.149.33,91.192.149.49,91.192.149.66,91.192.149.82,91.192.68.52] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (341)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407681; rev:140; fwsam: src, 24 hours;) alert tcp [91.192.71.7,91.193.108.150,91.193.108.222,91.193.108.239,91.193.108.254,91.193.40.0/22,91.194.10.60,91.194.140.0/23,91.194.76.0/23,91.195.116.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (342)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407682; rev:140; fwsam: src, 24 hours;) alert udp [91.192.71.7,91.193.108.150,91.193.108.222,91.193.108.239,91.193.108.254,91.193.40.0/22,91.194.10.60,91.194.140.0/23,91.194.76.0/23,91.195.116.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (342)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407683; rev:140; fwsam: src, 24 hours;) alert tcp [91.196.232.0/22,91.197.130.18,91.197.130.20,91.197.130.21,91.197.130.39,91.197.160.20,91.198.71.0/24,91.199.112.0/24,91.199.245.101,91.200.122.153] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (343)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407684; rev:140; fwsam: src, 24 hours;) alert udp [91.196.232.0/22,91.197.130.18,91.197.130.20,91.197.130.21,91.197.130.39,91.197.160.20,91.198.71.0/24,91.199.112.0/24,91.199.245.101,91.200.122.153] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (343)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407685; rev:140; fwsam: src, 24 hours;) alert tcp [91.200.144.0/23,91.200.146.200,91.200.146.201,91.200.146.4,91.200.146.8,91.202.63.99,91.203.4.112,91.203.4.113,91.203.4.49,91.203.5.111] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (344)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407686; rev:140; fwsam: src, 24 hours;) alert udp [91.200.144.0/23,91.200.146.200,91.200.146.201,91.200.146.4,91.200.146.8,91.202.63.99,91.203.4.112,91.203.4.113,91.203.4.49,91.203.5.111] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (344)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407687; rev:140; fwsam: src, 24 hours;) alert tcp [91.203.5.133,91.203.68.0/22,91.203.92.0/22,91.203.92.0/24,91.205.233.33,91.205.96.12,91.206.10.173,91.206.10.190,91.206.226.41,91.206.226.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (345)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407688; rev:140; fwsam: src, 24 hours;) alert udp [91.203.5.133,91.203.68.0/22,91.203.92.0/22,91.203.92.0/24,91.205.233.33,91.205.96.12,91.206.10.173,91.206.10.190,91.206.226.41,91.206.226.42] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (345)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407689; rev:140; fwsam: src, 24 hours;) alert tcp [91.206.231.140,91.207.116.0/23,91.207.4.10,91.207.4.11,91.207.4.122,91.207.4.146,91.207.4.9,91.207.60.0/23,91.207.61.12,91.207.8.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (346)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407690; rev:140; fwsam: src, 24 hours;) alert udp [91.206.231.140,91.207.116.0/23,91.207.4.10,91.207.4.11,91.207.4.122,91.207.4.146,91.207.4.9,91.207.60.0/23,91.207.61.12,91.207.8.252] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (346)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407691; rev:140; fwsam: src, 24 hours;) alert tcp [91.208.0.0/24,91.208.162.9,91.208.228.101,91.209.163.171,91.209.163.178,91.209.163.182,91.209.163.184,91.209.163.201,91.209.163.202,91.209.163.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (347)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407692; rev:140; fwsam: src, 24 hours;) alert udp [91.208.0.0/24,91.208.162.9,91.208.228.101,91.209.163.171,91.209.163.178,91.209.163.182,91.209.163.184,91.209.163.201,91.209.163.202,91.209.163.203] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (347)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407693; rev:140; fwsam: src, 24 hours;) alert tcp [91.209.183.21,91.209.183.61,91.21.88.146,91.210.57.135,91.211.64.0/22,91.212.127.47,91.212.132.10,91.212.132.11,91.212.132.12,91.212.132.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (348)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407694; rev:140; fwsam: src, 24 hours;) alert udp [91.209.183.21,91.209.183.61,91.21.88.146,91.210.57.135,91.211.64.0/22,91.212.127.47,91.212.132.10,91.212.132.11,91.212.132.12,91.212.132.32] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (348)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407695; rev:140; fwsam: src, 24 hours;) alert tcp [91.212.132.34,91.212.158.5,91.212.41.0/24,91.212.65.0/24,91.212.65.133,91.212.65.35,91.212.65.48,91.92.165.55,91.93.133.4,92.168.61.133] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (349)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407696; rev:140; fwsam: src, 24 hours;) alert udp [91.212.132.34,91.212.158.5,91.212.41.0/24,91.212.65.0/24,91.212.65.133,91.212.65.35,91.212.65.48,91.92.165.55,91.93.133.4,92.168.61.133] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (349)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407697; rev:140; fwsam: src, 24 hours;) alert tcp [92.241.160.0/19,92.241.169.14,92.241.176.101,92.243.76.132,92.38.0.111,92.38.0.41,92.38.0.69,92.38.1.11,92.38.1.12,92.39.48.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (350)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407698; rev:140; fwsam: src, 24 hours;) alert udp [92.241.160.0/19,92.241.169.14,92.241.176.101,92.243.76.132,92.38.0.111,92.38.0.41,92.38.0.69,92.38.1.11,92.38.1.12,92.39.48.2] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (350)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407699; rev:140; fwsam: src, 24 hours;) alert tcp [92.42.186.73,92.48.112.77,92.48.119.151,92.48.122.144,92.48.122.60,92.48.122.61,92.48.127.134,92.48.192.0/18,92.48.69.13,92.48.91.144] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (351)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407700; rev:140; fwsam: src, 24 hours;) alert udp [92.42.186.73,92.48.112.77,92.48.119.151,92.48.122.144,92.48.122.60,92.48.122.61,92.48.127.134,92.48.192.0/18,92.48.69.13,92.48.91.144] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (351)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407701; rev:140; fwsam: src, 24 hours;) alert tcp [92.60.176.13,92.60.176.33,92.60.176.41,92.60.176.45,92.61.148.174,92.61.240.22,92.61.248.102,92.61.80.66,92.62.100.0/24,92.62.101.100] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (352)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407702; rev:140; fwsam: src, 24 hours;) alert udp [92.60.176.13,92.60.176.33,92.60.176.41,92.60.176.45,92.61.148.174,92.61.240.22,92.61.248.102,92.61.80.66,92.62.100.0/24,92.62.101.100] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (352)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407703; rev:140; fwsam: src, 24 hours;) alert tcp [92.62.101.110,92.62.101.111,92.62.101.117,92.62.101.122,92.62.101.123,92.62.101.126,92.62.101.130,92.62.101.132,92.62.101.17,92.62.101.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (353)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407704; rev:140; fwsam: src, 24 hours;) alert udp [92.62.101.110,92.62.101.111,92.62.101.117,92.62.101.122,92.62.101.123,92.62.101.126,92.62.101.130,92.62.101.132,92.62.101.17,92.62.101.39] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (353)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407705; rev:140; fwsam: src, 24 hours;) alert tcp [92.62.101.60,92.62.101.61,92.62.101.8,92.62.96.0/24,92.62.98.0/24,92.63.104.165,92.63.106.125,92.63.96.137,92.63.97.192,93.103.232.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (354)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407706; rev:140; fwsam: src, 24 hours;) alert udp [92.62.101.60,92.62.101.61,92.62.101.8,92.62.96.0/24,92.62.98.0/24,92.63.104.165,92.63.106.125,92.63.96.137,92.63.97.192,93.103.232.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (354)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407707; rev:140; fwsam: src, 24 hours;) alert tcp [93.174.92.197,93.174.92.66,93.174.93.110,93.174.93.164,93.174.93.196,93.174.93.220,93.174.93.34,93.174.93.36,93.174.93.80,93.174.93.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (355)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407708; rev:140; fwsam: src, 24 hours;) alert udp [93.174.92.197,93.174.92.66,93.174.93.110,93.174.93.164,93.174.93.196,93.174.93.220,93.174.93.34,93.174.93.36,93.174.93.80,93.174.93.81] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (355)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407709; rev:140; fwsam: src, 24 hours;) alert tcp [93.174.94.198,93.183.194.0/18,93.188.160.0/21,93.190.137.99,93.190.138.238,93.190.138.239,93.190.139.0/24,93.190.140.134,93.190.140.135,93.190.140.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (356)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407710; rev:140; fwsam: src, 24 hours;) alert udp [93.174.94.198,93.183.194.0/18,93.188.160.0/21,93.190.137.99,93.190.138.238,93.190.138.239,93.190.139.0/24,93.190.140.134,93.190.140.135,93.190.140.49] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (356)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407711; rev:140; fwsam: src, 24 hours;) alert tcp [93.190.140.56,93.190.142.135,94.102.48.0/20,94.103.80.220,94.103.90.10,94.103.90.120,94.103.90.160,94.103.90.220,94.103.90.80,94.124.84.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (357)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407712; rev:140; fwsam: src, 24 hours;) alert udp [93.190.140.56,93.190.142.135,94.102.48.0/20,94.103.80.220,94.103.90.10,94.103.90.120,94.103.90.160,94.103.90.220,94.103.90.80,94.124.84.10] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (357)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407713; rev:140; fwsam: src, 24 hours;) alert tcp [94.125.71.77,94.142.128.41,94.229.64.115,94.229.65.172,94.232.248.0/24,94.243.110.72,94.247.0.0/21,94.25.85.14,94.27.123.227,94.52.128.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (358)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407714; rev:140; fwsam: src, 24 hours;) alert udp [94.125.71.77,94.142.128.41,94.229.64.115,94.229.65.172,94.232.248.0/24,94.243.110.72,94.247.0.0/21,94.25.85.14,94.27.123.227,94.52.128.126] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (358)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407715; rev:140; fwsam: src, 24 hours;) alert tcp [94.75.192.66,94.75.193.14,94.75.193.167,94.75.199.168,94.75.199.178,94.75.209.11,94.75.210.39,94.75.214.117,94.75.214.138,94.75.214.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (359)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407716; rev:140; fwsam: src, 24 hours;) alert udp [94.75.192.66,94.75.193.14,94.75.193.167,94.75.199.168,94.75.199.178,94.75.209.11,94.75.210.39,94.75.214.117,94.75.214.138,94.75.214.18] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (359)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407717; rev:140; fwsam: src, 24 hours;) alert tcp [94.75.215.3,94.75.215.59,94.75.215.92,94.75.221.68,94.75.221.70,94.75.227.110,94.75.227.111,94.75.227.80,94.75.228.136,94.75.228.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (360)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407718; rev:140; fwsam: src, 24 hours;) alert udp [94.75.215.3,94.75.215.59,94.75.215.92,94.75.221.68,94.75.221.70,94.75.227.110,94.75.227.111,94.75.227.80,94.75.228.136,94.75.228.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (360)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407719; rev:140; fwsam: src, 24 hours;) alert tcp [94.75.229.229,94.75.229.253,94.75.233.162,94.75.233.8,94.75.234.35,94.75.234.7,94.75.236.231,94.75.240.242,94.75.243.114,94.75.243.115] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (361)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407720; rev:140; fwsam: src, 24 hours;) alert udp [94.75.229.229,94.75.229.253,94.75.233.162,94.75.233.8,94.75.234.35,94.75.234.7,94.75.236.231,94.75.240.242,94.75.243.114,94.75.243.115] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (361)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407721; rev:140; fwsam: src, 24 hours;) alert tcp [94.75.243.117,94.75.253.92,94.76.205.160,94.76.212.238,94.76.212.239,94.76.212.241,94.76.213.104,94.76.213.227,94.76.213.234,94.76.225.134] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (362)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407722; rev:140; fwsam: src, 24 hours;) alert udp [94.75.243.117,94.75.253.92,94.76.205.160,94.76.212.238,94.76.212.239,94.76.212.241,94.76.213.104,94.76.213.227,94.76.213.234,94.76.225.134] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (362)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407723; rev:140; fwsam: src, 24 hours;) alert tcp [94.76.225.98,95.129.144.12,95.129.144.13,95.129.144.186,95.129.144.210,95.129.144.227,95.129.144.228,95.129.144.236,95.129.144.244,95.129.145.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (363)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407724; rev:140; fwsam: src, 24 hours;) alert udp [94.76.225.98,95.129.144.12,95.129.144.13,95.129.144.186,95.129.144.210,95.129.144.227,95.129.144.228,95.129.144.236,95.129.144.244,95.129.145.43] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (363)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407725; rev:140; fwsam: src, 24 hours;) alert tcp [95.129.145.46,95.129.145.58,95.129.146.244,95.168.163.83,95.168.173.224,95.168.173.237,95.211.14.161,95.211.14.163,95.211.7.140,95.211.7.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (364)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407726; rev:140; fwsam: src, 24 hours;) alert udp [95.129.145.46,95.129.145.58,95.129.146.244,95.168.163.83,95.168.173.224,95.168.173.237,95.211.14.161,95.211.14.163,95.211.7.140,95.211.7.183] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (364)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407727; rev:140; fwsam: src, 24 hours;) alert tcp [95.211.8.136,95.211.8.61,95.211.9.27,95.221.15.44,97.74.144.150,98.124.198.1,98.126.211.138,98.126.29.234,98.126.41.36,98.126.9.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP TCP - BLOCKING (365)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407728; rev:140; fwsam: src, 24 hours;) alert udp [95.211.8.136,95.211.8.61,95.211.9.27,95.221.15.44,97.74.144.150,98.124.198.1,98.126.211.138,98.126.29.234,98.126.41.36,98.126.9.218] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network IP UDP - BLOCKING (365)"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2407729; rev:140; fwsam: src, 24 hours;)