# # Emerging Threats Tor rules. # # These will tell you if someone using Tor for source anonymization is communicating with your network. # # Tor in itself isn't inherently hostile. In many environments that may be a very suspicious way # to communicate. # # More information available at doc.emergingthreats.net/bin/view/Main/TorRules # # Please submit any feedback or ideas to emerging@emergingthreats.net or the emerging-sigs mailing list # #************************************************************* # # Copyright (c) 2003-2010, Emerging Threats # All rights reserved. # # Redistribution and use in source and binary forms, with or without modification, are permitted provided that the # following conditions are met: # # * Redistributions of source code must retain the above copyright notice, this list of conditions and the following # disclaimer. # * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the # following disclaimer in the documentation and/or other materials provided with the distribution. # * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived # from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES, # INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE # DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR # SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, # WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE # USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # # # VERSION 453 # Updated 2010-03-12 00:03:02 alert tcp [113.66.98.148,115.134.158.33,116.14.41.6,116.224.220.82,116.34.205.24,117.25.130.19,118.208.60.244,119.123.2.158,121.133.186.157,121.43.207.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (1)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520000; rev:453;) alert udp [113.66.98.148,115.134.158.33,116.14.41.6,116.224.220.82,116.34.205.24,117.25.130.19,118.208.60.244,119.123.2.158,121.133.186.157,121.43.207.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (1)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520001; rev:453;) alert tcp [122.100.41.137,123.108.108.147,123.121.208.49,124.171.119.243,124.195.233.122,124.43.162.69,124.64.160.115,125.116.29.95,125.83.2.69,128.186.232.87] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (2)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520002; rev:453;) alert udp [122.100.41.137,123.108.108.147,123.121.208.49,124.171.119.243,124.195.233.122,124.43.162.69,124.64.160.115,125.116.29.95,125.83.2.69,128.186.232.87] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (2)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520003; rev:453;) alert tcp [129.186.157.50,129.217.163.109,132.206.220.102,134.91.236.5,136.159.183.93,140.112.220.106,140.113.214.144,140.113.68.177,140.180.130.93,145.100.100.190] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (3)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520004; rev:453;) alert udp [129.186.157.50,129.217.163.109,132.206.220.102,134.91.236.5,136.159.183.93,140.112.220.106,140.113.214.144,140.113.68.177,140.180.130.93,145.100.100.190] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (3)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520005; rev:453;) alert tcp [145.100.104.14,145.100.104.19,145.99.223.82,151.32.142.64,151.33.211.251,151.49.44.248,151.57.162.95,151.59.58.60,151.60.196.169,151.61.171.27] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (4)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520006; rev:453;) alert udp [145.100.104.14,145.100.104.19,145.99.223.82,151.32.142.64,151.33.211.251,151.49.44.248,151.57.162.95,151.59.58.60,151.60.196.169,151.61.171.27] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (4)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520007; rev:453;) alert tcp [151.80.20.145,158.197.195.193,166.111.111.194,166.111.65.7,166.111.68.21,166.70.207.2,166.70.54.100,166.70.99.91,173.23.71.206,173.34.204.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (5)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520008; rev:453;) alert udp [151.80.20.145,158.197.195.193,166.111.111.194,166.111.65.7,166.111.68.21,166.70.207.2,166.70.54.100,166.70.99.91,173.23.71.206,173.34.204.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (5)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520009; rev:453;) alert tcp [173.49.70.164,173.76.134.150,173.8.164.189,174.18.235.70,18.51.6.190,186.58.1.168,188.129.79.47,188.132.4.207,188.16.75.144,188.4.216.161] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (6)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520010; rev:453;) alert udp [173.49.70.164,173.76.134.150,173.8.164.189,174.18.235.70,18.51.6.190,186.58.1.168,188.129.79.47,188.132.4.207,188.16.75.144,188.4.216.161] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (6)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520011; rev:453;) alert tcp [188.98.13.175,189.100.165.93,189.122.87.160,189.24.175.206,189.6.4.223,190.18.28.129,190.191.192.18,190.192.103.175,192.251.226.206,193.111.87.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (7)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520012; rev:453;) alert udp [188.98.13.175,189.100.165.93,189.122.87.160,189.24.175.206,189.6.4.223,190.18.28.129,190.191.192.18,190.192.103.175,192.251.226.206,193.111.87.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (7)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520013; rev:453;) alert tcp [193.146.210.229,193.201.52.133,193.252.214.96,193.253.242.186,194.154.227.103,195.131.152.218,195.132.121.150,195.20.207.174,195.24.137.198,195.240.144.129] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (8)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520014; rev:453;) alert udp [193.146.210.229,193.201.52.133,193.252.214.96,193.253.242.186,194.154.227.103,195.131.152.218,195.132.121.150,195.20.207.174,195.24.137.198,195.240.144.129] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (8)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520015; rev:453;) alert tcp [195.241.141.49,198.202.25.251,200.114.235.97,200.122.160.25,200.35.146.249,201.172.27.17,201.33.180.9,201.35.7.156,203.124.102.72,203.179.254.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (9)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520016; rev:453;) alert udp [195.241.141.49,198.202.25.251,200.114.235.97,200.122.160.25,200.35.146.249,201.172.27.17,201.33.180.9,201.35.7.156,203.124.102.72,203.179.254.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (9)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520017; rev:453;) alert tcp [204.209.56.56,204.8.156.142,205.168.84.133,205.209.142.210,207.229.181.176,207.237.205.72,208.223.208.181,208.43.127.247,208.75.57.100,208.75.88.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (10)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520018; rev:453;) alert udp [204.209.56.56,204.8.156.142,205.168.84.133,205.209.142.210,207.229.181.176,207.237.205.72,208.223.208.181,208.43.127.247,208.75.57.100,208.75.88.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (10)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520019; rev:453;) alert tcp [209.128.193.195,209.151.236.27,209.17.131.233,209.190.122.250,209.20.82.219,209.221.206.114,209.44.114.178,209.90.129.161,210.48.159.134,210.60.8.30] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (11)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520020; rev:453;) alert udp [209.128.193.195,209.151.236.27,209.17.131.233,209.190.122.250,209.20.82.219,209.221.206.114,209.44.114.178,209.90.129.161,210.48.159.134,210.60.8.30] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (11)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520021; rev:453;) alert tcp [212.117.166.26,212.158.169.98,212.198.172.232,212.21.140.66,212.24.147.228,212.41.104.60,212.41.118.74,212.42.236.140,212.7.7.146,212.74.233.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (12)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520022; rev:453;) alert udp [212.117.166.26,212.158.169.98,212.198.172.232,212.21.140.66,212.24.147.228,212.41.104.60,212.41.118.74,212.42.236.140,212.7.7.146,212.74.233.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (12)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520023; rev:453;) alert tcp [213.112.108.203,213.115.6.58,213.131.246.194,213.169.162.9,213.17.72.6,213.185.5.217,213.189.20.167,213.21.101.186,213.21.83.162,213.216.240.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (13)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520024; rev:453;) alert udp [213.112.108.203,213.115.6.58,213.131.246.194,213.169.162.9,213.17.72.6,213.185.5.217,213.189.20.167,213.21.101.186,213.21.83.162,213.216.240.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (13)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520025; rev:453;) alert tcp [213.220.221.92,213.220.233.230,213.251.166.137,213.33.0.253,213.64.217.237,213.65.45.113,213.98.246.2,216.165.188.242,216.195.144.89,216.224.124.124] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (14)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520026; rev:453;) alert udp [213.220.221.92,213.220.233.230,213.251.166.137,213.33.0.253,213.64.217.237,213.65.45.113,213.98.246.2,216.165.188.242,216.195.144.89,216.224.124.124] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (14)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520027; rev:453;) alert tcp [216.36.165.152,216.49.246.136,216.57.118.152,217.148.84.179,217.150.241.118,217.173.27.66,217.20.117.129,217.201.199.78,217.216.167.30,217.237.6.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (15)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520028; rev:453;) alert udp [216.36.165.152,216.49.246.136,216.57.118.152,217.148.84.179,217.150.241.118,217.173.27.66,217.20.117.129,217.201.199.78,217.216.167.30,217.237.6.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (15)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520029; rev:453;) alert tcp [217.238.163.191,217.238.228.173,217.25.124.51,217.94.221.67,218.16.120.12,218.73.136.112,218.81.252.247,218.82.75.131,219.142.225.71,221.10.194.55] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (16)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520030; rev:453;) alert udp [217.238.163.191,217.238.228.173,217.25.124.51,217.94.221.67,218.16.120.12,218.73.136.112,218.81.252.247,218.82.75.131,219.142.225.71,221.10.194.55] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (16)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520031; rev:453;) alert tcp [221.127.72.49,222.130.132.70,222.212.35.41,24.11.72.223,24.19.155.33,24.19.33.73,24.211.217.95,24.24.81.223,24.34.221.196,24.44.222.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (17)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520032; rev:453;) alert udp [221.127.72.49,222.130.132.70,222.212.35.41,24.11.72.223,24.19.155.33,24.19.33.73,24.211.217.95,24.24.81.223,24.34.221.196,24.44.222.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (17)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520033; rev:453;) alert tcp [24.92.56.124,41.207.17.180,58.24.132.232,58.24.132.31,58.34.59.30,59.155.125.191,59.46.233.20,59.54.32.169,60.54.78.251,61.152.188.244] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (18)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520034; rev:453;) alert udp [24.92.56.124,41.207.17.180,58.24.132.232,58.24.132.31,58.34.59.30,59.155.125.191,59.46.233.20,59.54.32.169,60.54.78.251,61.152.188.244] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (18)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520035; rev:453;) alert tcp [61.177.18.46,61.250.134.5,61.58.183.31,62.141.37.243,62.141.53.224,62.141.58.13,62.143.90.155,62.149.18.147,62.150.231.240,62.47.222.97] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (19)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520036; rev:453;) alert udp [61.177.18.46,61.250.134.5,61.58.183.31,62.141.37.243,62.141.53.224,62.141.58.13,62.143.90.155,62.149.18.147,62.150.231.240,62.47.222.97] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (19)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520037; rev:453;) alert tcp [62.75.162.104,62.8.60.184,62.85.124.125,64.56.250.137,65.102.167.145,65.111.169.81,65.26.39.63,65.35.18.146,65.39.67.100,65.92.8.109] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (20)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520038; rev:453;) alert udp [62.75.162.104,62.8.60.184,62.85.124.125,64.56.250.137,65.102.167.145,65.111.169.81,65.26.39.63,65.35.18.146,65.39.67.100,65.92.8.109] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (20)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520039; rev:453;) alert tcp [66.223.210.43,66.230.230.230,66.249.9.183,66.30.56.118,66.35.1.170,66.36.141.28,66.68.190.219,66.96.16.32,67.10.76.188,67.164.210.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (21)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520040; rev:453;) alert udp [66.223.210.43,66.230.230.230,66.249.9.183,66.30.56.118,66.35.1.170,66.36.141.28,66.68.190.219,66.96.16.32,67.10.76.188,67.164.210.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (21)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520041; rev:453;) alert tcp [67.167.244.65,67.183.210.254,67.197.82.255,67.81.123.193,67.82.55.142,68.146.224.205,68.147.60.137,68.212.4.98,68.248.195.75,68.32.108.23] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (22)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520042; rev:453;) alert udp [67.167.244.65,67.183.210.254,67.197.82.255,67.81.123.193,67.82.55.142,68.146.224.205,68.147.60.137,68.212.4.98,68.248.195.75,68.32.108.23] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (22)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520043; rev:453;) alert tcp [68.4.213.246,68.40.80.4,68.42.180.211,68.47.213.25,68.48.40.163,68.57.205.126,68.83.107.165,68.98.46.213,69.12.147.241,69.125.12.214] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (23)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520044; rev:453;) alert udp [68.4.213.246,68.40.80.4,68.42.180.211,68.47.213.25,68.48.40.163,68.57.205.126,68.83.107.165,68.98.46.213,69.12.147.241,69.125.12.214] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (23)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520045; rev:453;) alert tcp [69.14.154.76,69.14.16.228,69.181.139.141,69.3.33.160,69.31.13.209,69.34.151.223,69.39.49.200,69.59.212.183,70.119.149.219,70.160.105.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (24)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520046; rev:453;) alert udp [69.14.154.76,69.14.16.228,69.181.139.141,69.3.33.160,69.31.13.209,69.34.151.223,69.39.49.200,69.59.212.183,70.119.149.219,70.160.105.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (24)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520047; rev:453;) alert tcp [70.171.119.211,70.70.166.237,71.109.119.212,71.135.168.89,71.196.146.103,71.207.228.227,71.28.76.64,72.14.176.65,72.14.184.121,72.147.249.247] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (25)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520048; rev:453;) alert udp [70.171.119.211,70.70.166.237,71.109.119.212,71.135.168.89,71.196.146.103,71.207.228.227,71.28.76.64,72.14.176.65,72.14.184.121,72.147.249.247] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (25)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520049; rev:453;) alert tcp [72.193.102.146,72.196.195.177,72.225.243.88,72.228.34.205,72.235.212.227,72.43.122.208,72.47.35.186,72.90.76.46,74.194.148.219,74.196.216.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (26)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520050; rev:453;) alert udp [72.193.102.146,72.196.195.177,72.225.243.88,72.228.34.205,72.235.212.227,72.43.122.208,72.47.35.186,72.90.76.46,74.194.148.219,74.196.216.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (26)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520051; rev:453;) alert tcp [74.207.225.75,74.208.12.147,74.61.2.133,74.63.64.4,74.75.82.243,74.82.5.52,75.129.132.134,75.144.244.156,75.185.139.100,75.195.148.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (27)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520052; rev:453;) alert udp [74.207.225.75,74.208.12.147,74.61.2.133,74.63.64.4,74.75.82.243,74.82.5.52,75.129.132.134,75.144.244.156,75.185.139.100,75.195.148.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (27)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520053; rev:453;) alert tcp [75.206.103.213,75.64.127.187,75.69.29.210,75.70.139.108,75.89.28.209,76.166.191.206,76.169.246.186,77.131.190.112,77.185.150.119,77.187.63.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (28)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520054; rev:453;) alert udp [75.206.103.213,75.64.127.187,75.69.29.210,75.70.139.108,75.89.28.209,76.166.191.206,76.169.246.186,77.131.190.112,77.185.150.119,77.187.63.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (28)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520055; rev:453;) alert tcp [77.191.133.228,77.194.107.202,77.194.60.50,77.195.128.124,77.195.234.152,77.195.67.241,77.196.8.158,77.197.119.82,77.20.187.67,77.204.2.159] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (29)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520056; rev:453;) alert udp [77.191.133.228,77.194.107.202,77.194.60.50,77.195.128.124,77.195.234.152,77.195.67.241,77.196.8.158,77.197.119.82,77.20.187.67,77.204.2.159] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (29)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520057; rev:453;) alert tcp [77.21.90.137,77.23.10.181,77.23.110.29,77.35.245.111,77.37.16.189,77.49.237.202,77.54.227.222,77.57.221.207,77.64.168.96,78.107.237.16] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (30)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520058; rev:453;) alert udp [77.21.90.137,77.23.10.181,77.23.110.29,77.35.245.111,77.37.16.189,77.49.237.202,77.54.227.222,77.57.221.207,77.64.168.96,78.107.237.16] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (30)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520059; rev:453;) alert tcp [78.108.76.66,78.111.66.168,78.112.70.157,78.114.100.33,78.114.71.53,78.116.1.11,78.14.171.122,78.142.140.194,78.142.175.70,78.172.249.211] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (31)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520060; rev:453;) alert udp [78.108.76.66,78.111.66.168,78.112.70.157,78.114.100.33,78.114.71.53,78.116.1.11,78.14.171.122,78.142.140.194,78.142.175.70,78.172.249.211] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (31)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520061; rev:453;) alert tcp [78.224.13.236,78.229.206.91,78.31.65.16,78.34.169.119,78.34.172.131,78.40.38.155,78.43.59.9,78.46.176.185,78.47.192.194,78.47.196.123] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (32)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520062; rev:453;) alert udp [78.224.13.236,78.229.206.91,78.31.65.16,78.34.169.119,78.34.172.131,78.40.38.155,78.43.59.9,78.46.176.185,78.47.192.194,78.47.196.123] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (32)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520063; rev:453;) alert tcp [78.47.29.82,78.48.125.167,78.48.250.200,78.49.100.156,78.49.137.203,78.49.146.200,78.51.23.126,78.52.127.246,78.53.40.72,78.53.73.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (33)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520064; rev:453;) alert udp [78.47.29.82,78.48.125.167,78.48.250.200,78.49.100.156,78.49.137.203,78.49.146.200,78.51.23.126,78.52.127.246,78.53.40.72,78.53.73.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (33)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520065; rev:453;) alert tcp [78.53.80.0,78.53.98.235,78.54.63.199,78.54.98.147,78.86.114.143,78.86.43.15,78.94.62.248,78.97.174.65,79.116.2.197,79.125.50.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (34)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520066; rev:453;) alert udp [78.53.80.0,78.53.98.235,78.54.63.199,78.54.98.147,78.86.114.143,78.86.43.15,78.94.62.248,78.97.174.65,79.116.2.197,79.125.50.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (34)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520067; rev:453;) alert tcp [79.125.60.36,79.132.59.214,79.134.170.65,79.136.21.68,79.139.182.146,79.142.231.64,79.163.227.18,79.165.93.255,79.186.107.106,79.192.172.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (35)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520068; rev:453;) alert udp [79.125.60.36,79.132.59.214,79.134.170.65,79.136.21.68,79.139.182.146,79.142.231.64,79.163.227.18,79.165.93.255,79.186.107.106,79.192.172.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (35)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520069; rev:453;) alert tcp [79.194.29.163,79.196.249.57,79.197.72.36,79.201.171.94,79.212.232.81,79.241.213.124,79.36.169.59,79.41.177.107,79.44.127.166,79.80.69.41] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (36)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520070; rev:453;) alert udp [79.194.29.163,79.196.249.57,79.197.72.36,79.201.171.94,79.212.232.81,79.241.213.124,79.36.169.59,79.41.177.107,79.44.127.166,79.80.69.41] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (36)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520071; rev:453;) alert tcp [79.82.92.59,79.83.31.213,79.85.68.12,79.86.50.3,79.86.51.225,79.87.6.188,79.90.60.233,79.91.74.153,79.92.253.60,79.93.29.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (37)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520072; rev:453;) alert udp [79.82.92.59,79.83.31.213,79.85.68.12,79.86.50.3,79.86.51.225,79.87.6.188,79.90.60.233,79.91.74.153,79.92.253.60,79.93.29.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (37)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520073; rev:453;) alert tcp [79.94.189.61,79.94.232.232,79.95.174.159,79.99.236.2,80.109.75.107,80.128.74.114,80.138.103.230,80.138.251.32,80.190.250.108,80.216.36.233] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (38)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520074; rev:453;) alert udp [79.94.189.61,79.94.232.232,79.95.174.159,79.99.236.2,80.109.75.107,80.128.74.114,80.138.103.230,80.138.251.32,80.190.250.108,80.216.36.233] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (38)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520075; rev:453;) alert tcp [80.241.162.176,80.63.56.149,80.93.56.44,81.158.213.100,81.169.155.246,81.169.173.120,81.174.47.4,81.174.66.93,81.175.61.4,81.208.84.207] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (39)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520076; rev:453;) alert udp [80.241.162.176,80.63.56.149,80.93.56.44,81.158.213.100,81.169.155.246,81.169.173.120,81.174.47.4,81.174.66.93,81.175.61.4,81.208.84.207] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (39)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520077; rev:453;) alert tcp [81.210.190.158,81.216.185.18,81.227.136.249,81.233.224.95,81.237.245.9,81.32.64.17,81.49.2.166,81.56.90.147,82.125.67.151,82.143.158.39] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (40)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520078; rev:453;) alert udp [81.210.190.158,81.216.185.18,81.227.136.249,81.233.224.95,81.237.245.9,81.32.64.17,81.49.2.166,81.56.90.147,82.125.67.151,82.143.158.39] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (40)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520079; rev:453;) alert tcp [82.161.0.223,82.165.180.112,82.182.125.89,82.182.15.84,82.182.40.116,82.182.59.155,82.210.151.23,82.212.155.114,82.212.27.197,82.216.77.116] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (41)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520080; rev:453;) alert udp [82.161.0.223,82.165.180.112,82.182.125.89,82.182.15.84,82.182.40.116,82.182.59.155,82.210.151.23,82.212.155.114,82.212.27.197,82.216.77.116] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (41)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520081; rev:453;) alert tcp [82.223.163.137,82.224.139.147,82.225.190.111,82.226.75.27,82.227.12.18,82.227.167.52,82.227.184.3,82.227.73.32,82.227.76.76,82.228.252.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (42)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520082; rev:453;) alert udp [82.223.163.137,82.224.139.147,82.225.190.111,82.226.75.27,82.227.12.18,82.227.167.52,82.227.184.3,82.227.73.32,82.227.76.76,82.228.252.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (42)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520083; rev:453;) alert tcp [82.229.144.130,82.229.26.124,82.230.148.162,82.231.209.116,82.234.200.126,82.234.44.15,82.236.252.56,82.237.177.74,82.237.184.52,82.239.198.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (43)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520084; rev:453;) alert udp [82.229.144.130,82.229.26.124,82.230.148.162,82.231.209.116,82.234.200.126,82.234.44.15,82.236.252.56,82.237.177.74,82.237.184.52,82.239.198.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (43)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520085; rev:453;) alert tcp [82.24.125.183,82.24.229.68,82.240.174.25,82.240.200.223,82.240.221.167,82.240.84.32,82.241.224.220,82.243.235.59,82.244.102.224,82.244.229.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (44)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520086; rev:453;) alert udp [82.24.125.183,82.24.229.68,82.240.174.25,82.240.200.223,82.240.221.167,82.240.84.32,82.241.224.220,82.243.235.59,82.244.102.224,82.244.229.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (44)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520087; rev:453;) alert tcp [82.249.112.161,82.249.75.78,82.252.193.109,82.255.85.123,82.26.67.7,82.37.220.207,82.52.52.10,82.54.241.97,82.56.124.16,82.64.45.219] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (45)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520088; rev:453;) alert udp [82.249.112.161,82.249.75.78,82.252.193.109,82.255.85.123,82.26.67.7,82.37.220.207,82.52.52.10,82.54.241.97,82.56.124.16,82.64.45.219] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (45)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520089; rev:453;) alert tcp [82.66.120.184,82.66.151.110,82.67.115.165,82.83.218.146,83.112.20.81,83.114.106.57,83.114.220.171,83.132.224.10,83.135.45.157,83.145.228.238] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (46)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520090; rev:453;) alert udp [82.66.120.184,82.66.151.110,82.67.115.165,82.83.218.146,83.112.20.81,83.114.106.57,83.114.220.171,83.132.224.10,83.135.45.157,83.145.228.238] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (46)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520091; rev:453;) alert tcp [83.171.145.237,83.171.179.0,83.176.247.131,83.180.85.13,83.189.182.171,83.193.27.164,83.195.34.152,83.205.222.97,83.226.245.174,83.227.18.50] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (47)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520092; rev:453;) alert udp [83.171.145.237,83.171.179.0,83.176.247.131,83.180.85.13,83.189.182.171,83.193.27.164,83.195.34.152,83.205.222.97,83.226.245.174,83.227.18.50] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (47)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520093; rev:453;) alert tcp [83.227.225.36,83.227.89.245,83.233.110.182,83.233.203.67,83.233.30.202,83.24.232.223,83.251.170.161,83.35.209.235,83.64.118.186,83.8.103.74] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (48)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520094; rev:453;) alert udp [83.227.225.36,83.227.89.245,83.233.110.182,83.233.203.67,83.233.30.202,83.24.232.223,83.251.170.161,83.35.209.235,83.64.118.186,83.8.103.74] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (48)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520095; rev:453;) alert tcp [83.87.249.23,84.100.131.102,84.100.208.94,84.100.7.87,84.102.117.141,84.127.115.35,84.136.104.203,84.146.197.25,84.16.233.47,84.160.212.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (49)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520096; rev:453;) alert udp [83.87.249.23,84.100.131.102,84.100.208.94,84.100.7.87,84.102.117.141,84.127.115.35,84.136.104.203,84.146.197.25,84.16.233.47,84.160.212.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (49)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520097; rev:453;) alert tcp [84.170.181.217,84.179.100.184,84.188.185.170,84.215.71.115,84.222.183.207,84.242.231.69,84.25.173.164,84.38.64.85,84.38.66.15,84.42.249.118] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (50)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520098; rev:453;) alert udp [84.170.181.217,84.179.100.184,84.188.185.170,84.215.71.115,84.222.183.207,84.242.231.69,84.25.173.164,84.38.64.85,84.38.66.15,84.42.249.118] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (50)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520099; rev:453;) alert tcp [84.44.176.158,84.52.79.135,84.56.17.71,84.58.57.44,84.61.227.94,84.62.223.44,84.63.109.180,84.74.98.199,84.75.146.117,84.97.91.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (51)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520100; rev:453;) alert udp [84.44.176.158,84.52.79.135,84.56.17.71,84.58.57.44,84.61.227.94,84.62.223.44,84.63.109.180,84.74.98.199,84.75.146.117,84.97.91.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (51)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520101; rev:453;) alert tcp [85.10.209.67,85.11.229.201,85.120.190.173,85.124.169.93,85.125.106.58,85.126.48.6,85.130.38.50,85.14.217.51,85.140.153.243,85.140.2.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (52)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520102; rev:453;) alert udp [85.10.209.67,85.11.229.201,85.120.190.173,85.124.169.93,85.125.106.58,85.126.48.6,85.130.38.50,85.14.217.51,85.140.153.243,85.140.2.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (52)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520103; rev:453;) alert tcp [85.144.116.31,85.155.206.87,85.168.183.140,85.17.201.20,85.170.255.64,85.171.185.95,85.175.121.52,85.176.239.248,85.177.125.73,85.178.37.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (53)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520104; rev:453;) alert udp [85.144.116.31,85.155.206.87,85.168.183.140,85.17.201.20,85.170.255.64,85.171.185.95,85.175.121.52,85.176.239.248,85.177.125.73,85.178.37.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (53)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520105; rev:453;) alert tcp [85.178.7.36,85.180.235.144,85.181.48.171,85.195.240.30,85.214.101.130,85.214.66.61,85.214.68.153,85.214.73.63,85.222.111.211,85.224.229.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (54)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520106; rev:453;) alert udp [85.178.7.36,85.180.235.144,85.181.48.171,85.195.240.30,85.214.101.130,85.214.66.61,85.214.68.153,85.214.73.63,85.222.111.211,85.224.229.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (54)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520107; rev:453;) alert tcp [85.224.77.130,85.225.48.70,85.225.63.159,85.226.119.187,85.226.147.229,85.226.196.217,85.226.72.123,85.227.195.109,85.227.202.199,85.228.124.66] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (55)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520108; rev:453;) alert udp [85.224.77.130,85.225.48.70,85.225.63.159,85.226.119.187,85.226.147.229,85.226.196.217,85.226.72.123,85.227.195.109,85.227.202.199,85.228.124.66] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (55)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520109; rev:453;) alert tcp [85.228.216.217,85.228.220.115,85.229.73.222,85.230.10.249,85.230.39.213,85.235.21.9,85.238.100.43,85.239.126.188,85.24.245.164,85.24.252.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (56)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520110; rev:453;) alert udp [85.228.216.217,85.228.220.115,85.229.73.222,85.230.10.249,85.230.39.213,85.235.21.9,85.238.100.43,85.239.126.188,85.24.245.164,85.24.252.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (56)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520111; rev:453;) alert tcp [85.25.151.22,85.25.152.185,85.27.122.103,85.31.186.104,85.31.187.225,85.49.165.9,85.69.86.160,86.111.64.45,86.138.102.123,86.139.245.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (57)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520112; rev:453;) alert udp [85.25.151.22,85.25.152.185,85.27.122.103,85.31.186.104,85.31.187.225,85.49.165.9,85.69.86.160,86.111.64.45,86.138.102.123,86.139.245.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (57)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520113; rev:453;) alert tcp [86.154.60.205,86.192.151.146,86.198.252.89,86.199.42.8,86.200.199.2,86.200.252.253,86.209.75.229,86.209.80.50,86.210.62.52,86.214.162.217] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (58)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520114; rev:453;) alert udp [86.154.60.205,86.192.151.146,86.198.252.89,86.199.42.8,86.200.199.2,86.200.252.253,86.209.75.229,86.209.80.50,86.210.62.52,86.214.162.217] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (58)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520115; rev:453;) alert tcp [86.33.143.65,86.49.3.230,86.52.119.111,86.68.195.39,86.71.202.215,86.71.29.127,86.73.154.104,86.74.13.167,86.74.21.88,87.1.203.162] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (59)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520116; rev:453;) alert udp [86.33.143.65,86.49.3.230,86.52.119.111,86.68.195.39,86.71.202.215,86.71.29.127,86.73.154.104,86.74.13.167,86.74.21.88,87.1.203.162] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (59)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520117; rev:453;) alert tcp [87.10.5.236,87.106.188.238,87.106.244.170,87.106.82.46,87.111.126.135,87.117.217.163,87.118.104.203,87.120.199.10,87.123.249.147,87.14.253.248] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (60)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520118; rev:453;) alert udp [87.10.5.236,87.106.188.238,87.106.244.170,87.106.82.46,87.111.126.135,87.117.217.163,87.118.104.203,87.120.199.10,87.123.249.147,87.14.253.248] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (60)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520119; rev:453;) alert tcp [87.143.139.126,87.145.29.51,87.15.133.21,87.152.101.103,87.17.47.204,87.171.126.162,87.186.40.142,87.194.195.22,87.212.192.72,87.220.58.47] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (61)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520120; rev:453;) alert udp [87.143.139.126,87.145.29.51,87.15.133.21,87.152.101.103,87.17.47.204,87.171.126.162,87.186.40.142,87.194.195.22,87.212.192.72,87.220.58.47] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (61)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520121; rev:453;) alert tcp [87.227.83.103,87.230.11.166,87.230.79.240,87.231.141.73,87.234.205.226,87.234.87.35,87.236.199.73,87.241.92.191,87.246.203.79,87.62.147.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (62)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520122; rev:453;) alert udp [87.227.83.103,87.230.11.166,87.230.79.240,87.231.141.73,87.234.205.226,87.234.87.35,87.236.199.73,87.241.92.191,87.246.203.79,87.62.147.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (62)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520123; rev:453;) alert tcp [87.69.81.154,87.78.34.181,87.79.239.139,87.79.56.26,87.8.104.176,87.88.20.48,87.88.87.29,88.115.45.247,88.123.205.238,88.134.34.209] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (63)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520124; rev:453;) alert udp [87.69.81.154,87.78.34.181,87.79.239.139,87.79.56.26,87.8.104.176,87.88.20.48,87.88.87.29,88.115.45.247,88.123.205.238,88.134.34.209] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (63)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520125; rev:453;) alert tcp [88.149.251.115,88.152.113.87,88.152.83.115,88.153.14.35,88.153.164.214,88.161.146.43,88.161.54.214,88.162.255.94,88.164.41.61,88.166.113.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (64)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520126; rev:453;) alert udp [88.149.251.115,88.152.113.87,88.152.83.115,88.153.14.35,88.153.164.214,88.161.146.43,88.161.54.214,88.162.255.94,88.164.41.61,88.166.113.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (64)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520127; rev:453;) alert tcp [88.167.124.199,88.168.223.9,88.168.40.87,88.168.88.230,88.171.115.244,88.173.112.165,88.174.139.189,88.177.243.121,88.178.196.88,88.178.3.212] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (65)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520128; rev:453;) alert udp [88.167.124.199,88.168.223.9,88.168.40.87,88.168.88.230,88.171.115.244,88.173.112.165,88.174.139.189,88.177.243.121,88.178.196.88,88.178.3.212] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (65)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520129; rev:453;) alert tcp [88.180.56.99,88.183.72.33,88.184.164.108,88.191.37.66,88.191.50.87,88.191.58.7,88.191.77.176,88.191.79.3,88.198.20.109,88.198.224.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (66)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520130; rev:453;) alert udp [88.180.56.99,88.183.72.33,88.184.164.108,88.191.37.66,88.191.50.87,88.191.58.7,88.191.77.176,88.191.79.3,88.198.20.109,88.198.224.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (66)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520131; rev:453;) alert tcp [88.198.56.140,88.198.57.247,88.198.6.155,88.198.60.8,88.198.81.46,88.206.207.13,88.217.105.221,88.222.29.113,88.230.163.37,88.234.108.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (67)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520132; rev:453;) alert udp [88.198.56.140,88.198.57.247,88.198.6.155,88.198.60.8,88.198.81.46,88.206.207.13,88.217.105.221,88.222.29.113,88.230.163.37,88.234.108.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (67)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520133; rev:453;) alert tcp [88.234.9.223,88.242.51.39,88.65.117.58,88.66.55.167,88.67.192.130,88.68.234.33,88.68.84.167,88.72.246.205,88.72.248.192,88.75.42.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (68)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520134; rev:453;) alert udp [88.234.9.223,88.242.51.39,88.65.117.58,88.66.55.167,88.67.192.130,88.68.234.33,88.68.84.167,88.72.246.205,88.72.248.192,88.75.42.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (68)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520135; rev:453;) alert tcp [88.80.28.177,89.113.219.75,89.113.222.107,89.131.189.244,89.131.228.110,89.135.40.21,89.14.46.242,89.163.95.146,89.2.53.54,89.225.242.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (69)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520136; rev:453;) alert udp [88.80.28.177,89.113.219.75,89.113.222.107,89.131.189.244,89.131.228.110,89.135.40.21,89.14.46.242,89.163.95.146,89.2.53.54,89.225.242.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (69)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520137; rev:453;) alert tcp [89.227.148.234,89.245.47.252,89.253.105.39,89.30.128.228,89.38.235.83,89.62.98.33,89.62.99.64,89.78.194.36,89.79.147.254,89.79.72.233] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (70)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520138; rev:453;) alert udp [89.227.148.234,89.245.47.252,89.253.105.39,89.30.128.228,89.38.235.83,89.62.98.33,89.62.99.64,89.78.194.36,89.79.147.254,89.79.72.233] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (70)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520139; rev:453;) alert tcp [89.84.191.37,90.0.144.51,90.0.204.38,90.0.29.164,90.15.175.121,90.184.163.90,90.224.173.169,90.227.158.100,90.230.92.148,90.237.167.181] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (71)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520140; rev:453;) alert udp [89.84.191.37,90.0.144.51,90.0.204.38,90.0.29.164,90.15.175.121,90.184.163.90,90.224.173.169,90.227.158.100,90.230.92.148,90.237.167.181] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (71)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520141; rev:453;) alert tcp [90.29.130.45,90.3.114.82,90.30.213.62,90.37.68.22,90.4.87.204,90.42.110.53,90.52.174.200,90.53.100.39,90.6.24.41,90.8.153.21] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (72)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520142; rev:453;) alert udp [90.29.130.45,90.3.114.82,90.30.213.62,90.37.68.22,90.4.87.204,90.42.110.53,90.52.174.200,90.53.100.39,90.6.24.41,90.8.153.21] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (72)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520143; rev:453;) alert tcp [91.12.246.111,91.121.107.91,91.121.142.53,91.121.30.12,91.122.53.217,91.124.239.255,91.14.127.75,91.14.90.125,91.156.99.77,91.165.200.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (73)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520144; rev:453;) alert udp [91.12.246.111,91.121.107.91,91.121.142.53,91.121.30.12,91.122.53.217,91.124.239.255,91.14.127.75,91.14.90.125,91.156.99.77,91.165.200.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (73)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520145; rev:453;) alert tcp [91.178.235.138,91.193.172.157,91.198.227.49,91.204.168.9,91.206.225.125,91.45.171.158,91.64.131.94,91.65.222.47,91.91.236.251,91.93.132.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (74)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520146; rev:453;) alert udp [91.178.235.138,91.193.172.157,91.198.227.49,91.204.168.9,91.206.225.125,91.45.171.158,91.64.131.94,91.65.222.47,91.91.236.251,91.93.132.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (74)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520147; rev:453;) alert tcp [91.97.109.3,91.97.34.160,91.97.39.113,92.100.167.249,92.113.128.89,92.113.152.17,92.138.32.124,92.139.219.53,92.146.13.179,92.193.118.75] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (75)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520148; rev:453;) alert udp [91.97.109.3,91.97.34.160,91.97.39.113,92.100.167.249,92.113.128.89,92.113.152.17,92.138.32.124,92.139.219.53,92.146.13.179,92.193.118.75] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (75)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520149; rev:453;) alert tcp [92.196.123.104,92.229.194.230,92.51.139.207,92.80.212.169,92.80.228.174,93.11.115.216,93.130.7.5,93.144.169.134,93.146.39.155,93.148.211.79] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (76)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520150; rev:453;) alert udp [92.196.123.104,92.229.194.230,92.51.139.207,92.80.212.169,92.80.228.174,93.11.115.216,93.130.7.5,93.144.169.134,93.146.39.155,93.148.211.79] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (76)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520151; rev:453;) alert tcp [93.182.6.28,93.186.171.33,93.186.171.34,93.190.138.249,93.4.118.246,93.9.214.161,94.136.16.242,94.222.117.15,94.222.21.57,94.23.144.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (77)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520152; rev:453;) alert udp [93.182.6.28,93.186.171.33,93.186.171.34,93.190.138.249,93.4.118.246,93.9.214.161,94.136.16.242,94.222.117.15,94.222.21.57,94.23.144.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (77)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520153; rev:453;) alert tcp [94.23.144.16,94.23.46.33,94.23.49.47,94.76.246.74,95.114.223.129,95.220.12.78,95.221.194.236,95.234.134.71,95.24.180.186,95.24.47.130] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (78)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520154; rev:453;) alert udp [94.23.144.16,94.23.46.33,94.23.49.47,94.76.246.74,95.114.223.129,95.220.12.78,95.221.194.236,95.234.134.71,95.24.180.186,95.24.47.130] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (78)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520155; rev:453;) alert tcp [95.25.77.35,95.49.155.206,95.88.43.35,95.90.193.77,96.255.87.102,96.52.8.199,98.100.128.152,98.116.170.49,98.148.106.238,98.168.225.196] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (79)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520156; rev:453;) alert udp [95.25.77.35,95.49.155.206,95.88.43.35,95.90.193.77,96.255.87.102,96.52.8.199,98.100.128.152,98.116.170.49,98.148.106.238,98.168.225.196] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (79)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520157; rev:453;) alert tcp [98.203.151.106,98.208.82.186,98.212.175.107,98.216.141.92,98.23.44.183,98.243.189.178,98.27.143.54,99.164.60.248,99.168.110.252,99.253.51.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic (80)"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520158; rev:453;) alert udp [98.203.151.106,98.208.82.186,98.212.175.107,98.216.141.92,98.23.44.183,98.243.189.178,98.27.143.54,99.164.60.248,99.168.110.252,99.253.51.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node UDP Traffic (80)"; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; sid:2520159; rev:453;)