Back to Rule

Rule History

SID: 900509159 • Source: abuse.ch/feodotracker

Versions (11)

Version DetailsCurrent

Rev: 1Mar 7, 2026, 5:30 PM

Feodo Tracker: potential Emotet CnC Traffic detected

alert tcp $HOME_NET any -> [162.243.103.246] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold:type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/162.243.103.246/; sid:900509159; rev:1;)

Mar 7, 2026, 5:30 PM

Mar 7, 2026, 5:30 PM

Mar 7, 2026, 5:34 PM

Mar 7, 2026, 5:34 PM

feodotracker.rules