<Malwares>
  <Malware Snort="Backdoor.WebShell.HTTP.C&amp;C" Avp3="Backdoor.ASP.WebShell.a" />
  <Malware Snort="Backdoor.Adwind.TCP.ServerRequest" Avp3="Backdoor.Java.Adwind.a" />
  <Malware Snort="Backdoor.Agent.TCP.C&amp;C" Avp3="Backdoor.Java.Agent.a" />
  <Malware Snort="Backdoor.Godzilla.HTTP.C&amp;C" Avp3="Backdoor.Java.Godzilla.a" />
  <Malware Snort="Backdoor.Agent.HTTP.C&amp;C" Avp3="Backdoor.JS.Agent.a" />
  <Malware Avp3="Backdoor.Linux.Agent.a">
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.ICMP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Bpfdoor.IP.C&amp;C" Avp3="Backdoor.Linux.Bpfdoor.a" />
  <Malware Snort="Backdoor.Bvp47.ICMP.C&amp;C" Avp3="Backdoor.Linux.Bvp47.a" />
  <Malware Snort="Backdoor.DecoyDog.DNS.C&amp;C" Avp3="Backdoor.Linux.DecoyDog.a" />
  <Malware Snort="Backdoor.Dnspot.UDP.C&amp;C" Avp3="Backdoor.Linux.Dnspot.a" />
  <Malware Snort="Backdoor.Gafgyt.TCP.C&amp;C" Avp3="Backdoor.Linux.Gafgyt.a" />
  <Malware Snort="Backdoor.Ganiw.HTTP.C&amp;C" Avp3="Backdoor.Linux.Ganiw.a" />
  <Malware Avp3="Backdoor.Linux.Mirai.a">
    <Snort rule="Backdoor.Mirai.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Mirai.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Mirai.HTTP.ServerRequest" Avp3="Backdoor.Linux.Mirai.gen" />
  <Malware Snort="Backdoor.Pupy.TCP.C&amp;C" Avp3="Backdoor.Linux.Pupy.a" />
  <Malware Snort="Backdoor.Tsunami.HTTP.C&amp;C" Avp3="Backdoor.Linux.Tsunami.a" />
  <Malware Avp3="Backdoor.MSIL.Agent.a">
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TCP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TCP.ServerRequest" />
    <Snort rule="Backdoor.Agent.UDP.C&amp;C" />
    <Snort rule="Backdoor.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Backdoor.MSIL.Androm.a">
    <Snort rule="Backdoor.Androm.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Androm.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Backdoor.MSIL.AsyncRat.a">
    <Snort rule="Backdoor.AsyncRat.HTTP.C&amp;C" />
    <Snort rule="Backdoor.AsyncRat.TLS.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.MSIL.Bladabindi.a">
    <Snort rule="Backdoor.Bladabindi.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Bladabindi.TCP.C&amp;C" />
    <Snort rule="Backdoor.Bladabindi.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Bladabindi.TCP.C&amp;C" Avp3="Backdoor.MSIL.Bladabindi.sn" />
  <Malware Snort="Backdoor.Broide.TCP.ServerRequest" Avp3="Backdoor.MSIL.Broide.a" />
  <Malware Snort="Backdoor.Crysan.TCP.C&amp;C" Avp3="Backdoor.MSIL.Crysan.a" />
  <Malware Avp3="Backdoor.MSIL.Crysan.gen">
    <Snort rule="Backdoor.Crysan.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Crysan.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.DarkRat.HTTP.C&amp;C" Avp3="Backdoor.MSIL.DarkRat.a" />
  <Malware Avp3="Backdoor.MSIL.DCRat.a">
    <Snort rule="Backdoor.DCRat.HTTP.C&amp;C" />
    <Snort rule="Backdoor.DCRat.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.GrekGach.HTTP.C&amp;C" Avp3="Backdoor.MSIL.GrekGach.a" />
  <Malware Snort="Backdoor.Mokes.HTTP.C&amp;C" Avp3="Backdoor.MSIL.Mokes.a" />
  <Malware Avp3="Backdoor.MSIL.NanoBot.a">
    <Snort rule="Backdoor.NanoBot.HTTP.C&amp;C" />
    <Snort rule="Backdoor.NanoBot.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Pandora.TCP.C&amp;C" Avp3="Backdoor.MSIL.Pandora.a" />
  <Malware Snort="Backdoor.Proyecto.TCP.ServerRequest" Avp3="Backdoor.MSIL.Proyecto.a" />
  <Malware Snort="Backdoor.Ratasafa.TCP.C&amp;C" Avp3="Backdoor.MSIL.Ratasafa.a" />
  <Malware Snort="Backdoor.Remcos.UDP.C&amp;C" Avp3="Backdoor.MSIL.Remcos.a" />
  <Malware Snort="Backdoor.Remcos.HTTP.ServerRequest" Avp3="Backdoor.MSIL.Remcos.gen" />
  <Malware Snort="Backdoor.RRAT.HTTP.C&amp;C" Avp3="Backdoor.MSIL.RRAT.a" />
  <Malware Snort="Backdoor.Snodoor.HTTP.C&amp;C" Avp3="Backdoor.MSIL.Snodoor.a" />
  <Malware Avp3="Backdoor.MSIL.SpyGate.a">
    <Snort rule="Backdoor.SpyGate.TCP.C&amp;C" />
    <Snort rule="Backdoor.SpyGate.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.MSIL.Sunburst.a">
    <Snort rule="Backdoor.Sunburst.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Sunburst.SSL.C&amp;C" />
    <Snort rule="Backdoor.Sunburst.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.VanillaRAT.TCP.C&amp;C" Avp3="Backdoor.MSIL.VanillaRAT.a" />
  <Malware Snort="Backdoor.VKont.HTTP.C&amp;C" Avp3="Backdoor.MSIL.VKont.a" />
  <Malware Snort="Backdoor.WebRev.HTTP.C&amp;C" Avp3="Backdoor.MSIL.WebRev.a" />
  <Malware Snort="Backdoor.XClient.HTTP.C&amp;C" Avp3="Backdoor.MSIL.XClient.a" />
  <Malware Snort="Backdoor.XCore.HTTP.ServerRequest" Avp3="Backdoor.MSIL.XCore.a" />
  <Malware Snort="Backdoor.XWorm.HTTP.C&amp;C" Avp3="Backdoor.MSIL.XWorm.a" />
  <Malware Snort="Backdoor.WebShell.HTTP.C&amp;C" Avp3="Backdoor.PHP.WebShell.a" />
  <Malware Avp3="Backdoor.PowerShell.Agent.a">
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Hoaxshell.HTTP.C&amp;C" Avp3="Backdoor.PowerShell.Hoaxshell.a" />
  <Malware Snort="Backdoor.Agent.HTTP.C&amp;C" Avp3="Backdoor.Python.Agent.a" />
  <Malware Snort="Backdoor.Ares.HTTP.C&amp;C" Avp3="Backdoor.Python.Ares.a" />
  <Malware Snort="Backdoor.Agent.HTTP.C&amp;C" Avp3="Backdoor.Script.Agent.a" />
  <Malware Snort="Backdoor.WebShell.HTTP.C&amp;C" Avp3="Backdoor.Script.WebShell.a" />
  <Malware Snort="Backdoor.Agent.HTTP.C&amp;C" Avp3="Backdoor.VBS.Agent.a" />
  <Malware Snort="Backdoor.AdaptixC2.HTTP.C&amp;C" Avp3="Backdoor.Win32.AdaptixC2.a" />
  <Malware Snort="Backdoor.AdzokRAT.TCP.C&amp;C" Avp3="Backdoor.Win32.AdzokRAT.a" />
  <Malware Avp3="Backdoor.Win32.Agamida.a">
    <Snort rule="Backdoor.Agamida.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agamida.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Agent.a">
    <Snort rule="Backdoor.Agent.FTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.HTTP.Notification" />
    <Snort rule="Backdoor.Agent.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Agent.ICMP.C&amp;C" />
    <Snort rule="Backdoor.Agent.IP.C&amp;C" />
    <Snort rule="Backdoor.Agent.NTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.QEMU.C&amp;C" />
    <Snort rule="Backdoor.Agent.SMB.C&amp;C" />
    <Snort rule="Backdoor.Agent.SMTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TCP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TDS.C&amp;C" />
    <Snort rule="Backdoor.Agent.TLS.C&amp;C" />
    <Snort rule="Backdoor.Agent.UDP.C&amp;C" />
    <Snort rule="Backdoor.Agent.UDP.ServerRequest" />
    <Snort rule="Backdoor.Remcos.HTTP.C&amp;C" />
    <Snort rule="Backdoor.ValleyRAT.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-25371.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26911.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.Blackmoon.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Agent.gen">
    <Snort rule="Backdoor.Agent.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Agent.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Agentb.UDP.C&amp;C" Avp3="Backdoor.Win32.Agentb.a" />
  <Malware Snort="Backdoor.Agima.HTTP.C&amp;C" Avp3="Backdoor.Win32.Agima.a" />
  <Malware Snort="Backdoor.AllaKore.HTTP.C&amp;C" Avp3="Backdoor.Win32.AllaKore.a" />
  <Malware Snort="Backdoor.Anaptix.HTTP.ServerRequest" Avp3="Backdoor.Win32.Anaptix.a" />
  <Malware Avp3="Backdoor.Win32.Androm.a">
    <Snort rule="Backdoor.Androm.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Androm.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Androm.SSL.C&amp;C" />
    <Snort rule="Backdoor.Androm.TCP.C&amp;C" />
    <Snort rule="Backdoor.Androm.UDP.C&amp;C" />
    <Snort rule="Backdoor.Androm.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Androm.gen">
    <Snort rule="Backdoor.Androm.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Androm.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.BabyShark.HTTP.C&amp;C" Avp3="Backdoor.Win32.BabyShark.a" />
  <Malware Snort="Backdoor.BadIIS.HTTP.C&amp;C" Avp3="Backdoor.Win32.BadIIS.a" />
  <Malware Avp3="Backdoor.Win32.Bazdor.a">
    <Snort rule="Backdoor.Bazdor.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Bazdor.TLS.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Beacon.a">
    <Snort rule="Backdoor.Beacon.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Beacon.SSL.C&amp;C" />
    <Snort rule="Backdoor.Beacon.TCP.C&amp;C" />
    <Snort rule="Backdoor.Beacon.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Bladabindi.TCP.C&amp;C" Avp3="Backdoor.Win32.Bladabindi.a" />
  <Malware Snort="Backdoor.Bladabindi.TCP.ServerRequest" Avp3="Backdoor.Win32.Bladabindi.gen" />
  <Malware Snort="Backdoor.Bpfdoor.IP.C&amp;C" Avp3="Backdoor.Win32.Bpfdoor.a" />
  <Malware Snort="Backdoor.Buterat.HTTP.C&amp;C" Avp3="Backdoor.Win32.Buterat.a" />
  <Malware Snort="Backdoor.C3.TCP.C&amp;C" Avp3="Backdoor.Win32.C3.a" />
  <Malware Snort="Backdoor.Carbanak.HTTP.C&amp;C" Avp3="Backdoor.Win32.Carbanak.a" />
  <Malware Snort="Backdoor.Ceckno.TCP.C&amp;C" Avp3="Backdoor.Win32.Ceckno.a" />
  <Malware Snort="Backdoor.ChaCha.HTTP.C&amp;C" Avp3="Backdoor.Win32.ChaCha.a" />
  <Malware Snort="Backdoor.Cidox.HTTP.ServerRequest" Avp3="Backdoor.Win32.Cidox.a" />
  <Malware Snort="Backdoor.CloudAtlas.HTTP.C&amp;C" Avp3="Backdoor.Win32.CloudAtlas.a" />
  <Malware Avp3="Backdoor.Win32.Cobalt.a">
    <Snort rule="Backdoor.Cobalt.DNS.C&amp;C" />
    <Snort rule="Backdoor.Cobalt.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Cobalt.SMB.C&amp;C" />
    <Snort rule="Backdoor.Cobalt.SSH.C&amp;C" />
    <Snort rule="Backdoor.Cobalt.TCP.C&amp;C" />
    <Snort rule="Backdoor.Cobalt.TLS.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.CoolTx.a">
    <Snort rule="Backdoor.CoolTx.DNS.C&amp;C" />
    <Snort rule="Backdoor.CoolTx.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Crypminal.TCP.C&amp;C" Avp3="Backdoor.Win32.Crypminal.a" />
  <Malware Snort="Backdoor.Darak.HTTP.ServerRequest" Avp3="Backdoor.Win32.Darak.a" />
  <Malware Snort="Backdoor.DarkKomet.TCP.ServerRequest" Avp3="Backdoor.Win32.DarkKomet.a" />
  <Malware Snort="Backdoor.DarkVNC.TCP.C&amp;C" Avp3="Backdoor.Win32.DarkVNC.a" />
  <Malware Snort="Backdoor.DarkVNC.TCP.ServerRequest" Avp3="Backdoor.Win32.DarkVNC.gen" />
  <Malware Snort="Backdoor.DcRat.TLS.C&amp;C" Avp3="Backdoor.Win32.DcRat.a" />
  <Malware Avp3="Backdoor.Win32.Dridex.a">
    <Snort rule="Backdoor.Dridex.SSL.C&amp;C" />
    <Snort rule="Backdoor.Dridex.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Drivedos.HTTP.ServerRequest" Avp3="Backdoor.Win32.Drivedos.a" />
  <Malware Snort="Backdoor.Emotet.HTTP.C&amp;C" Avp3="Backdoor.Win32.Emotet.a" />
  <Malware Snort="Backdoor.Empire.HTTP.C&amp;C" Avp3="Backdoor.Win32.Empire.a" />
  <Malware Snort="Backdoor.Emud.HTTP.C&amp;C" Avp3="Backdoor.Win32.Emud.a" />
  <Malware Avp3="Backdoor.Win32.Enfal.a">
    <Snort rule="Backdoor.Enfal.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Enfal.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Farfli.a">
    <Snort rule="Backdoor.Farfli.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Farfli.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Farfli.TCP.C&amp;C" />
    <Snort rule="Backdoor.Farfli.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Farfli.TCP.C&amp;C" Avp3="Backdoor.Win32.Farfli.c" />
  <Malware Snort="Backdoor.Farfli.TCP.ServerRequest" Avp3="Backdoor.Win32.Farfli.gen" />
  <Malware Snort="Backdoor.Flagpro.HTTP.C&amp;C" Avp3="Backdoor.Win32.Flagpro.a" />
  <Malware Snort="Backdoor.Fonten.HTTP.ServerRequest" Avp3="Backdoor.Win32.Fonten.a" />
  <Malware Snort="Backdoor.Godlua.TCP.ServerRequest" Avp3="Backdoor.Win32.Godlua.a" />
  <Malware Snort="Backdoor.GoldenSpy.UDP.C&amp;C" Avp3="Backdoor.Win32.GoldenSpy.a" />
  <Malware Snort="Backdoor.GoldMax.HTTP.C&amp;C" Avp3="Backdoor.Win32.GoldMax.a" />
  <Malware Snort="Backdoor.GoRat.HTTP.C&amp;C" Avp3="Backdoor.Win32.GoRat.a" />
  <Malware Avp3="Backdoor.Win32.Grunt.a">
    <Snort rule="Backdoor.Grunt.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Grunt.SMB.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Gulpix.a">
    <Snort rule="Backdoor.Gulpix.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Gulpix.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Havoc.HTTP.C&amp;C" Avp3="Backdoor.Win32.Havoc.a" />
  <Malware Snort="Backdoor.Hlux.HTTP.C&amp;C" Avp3="Backdoor.Win32.Hlux.a" />
  <Malware Avp3="Backdoor.Win32.Hupigon.a">
    <Snort rule="Backdoor.Hupigon.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Hupigon.TCP.ServerRequest" />
    <Snort rule="Backdoor.Hupigon.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.IRCBot.TCP.C&amp;C" Avp3="Backdoor.Win32.IRCBot.a" />
  <Malware Snort="Backdoor.Juniper.HTTP.ServerRequest" Avp3="Backdoor.Win32.Juniper.a" />
  <Malware Snort="Backdoor.Kasidet.HTTP.C&amp;C" Avp3="Backdoor.Win32.Kasidet.a" />
  <Malware Snort="Backdoor.KitsuneRAT.TLS.C&amp;C" Avp3="Backdoor.Win32.KitsuneRAT.a" />
  <Malware Snort="Backdoor.Konus.HTTP.C&amp;C" Avp3="Backdoor.Win32.Konus.a" />
  <Malware Snort="Backdoor.KryptonC2.TCP.C&amp;C" Avp3="Backdoor.Win32.KryptonC2.a" />
  <Malware Snort="Backdoor.Lecna.HTTP.ServerRequest" Avp3="Backdoor.Win32.Lecna.a" />
  <Malware Snort="Backdoor.LimeRat.TCP.C&amp;C" Avp3="Backdoor.Win32.LimeRat.a" />
  <Malware Avp3="Backdoor.Win32.Lotok.a">
    <Snort rule="Backdoor.Lotok.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Lotok.TCP.C&amp;C" />
    <Snort rule="Backdoor.Lotok.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Lotok.TCP.ServerRequest" Avp3="Backdoor.Win32.Lotok.gen" />
  <Malware Snort="Backdoor.Meciv.HTTP.ServerRequest" Avp3="Backdoor.Win32.Meciv.a" />
  <Malware Snort="Backdoor.Merlin.HTTP.C&amp;C" Avp3="Backdoor.Win32.Merlin.a" />
  <Malware Avp3="Backdoor.Win32.Mokes.a">
    <Snort rule="Backdoor.Mokes.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Mokes.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Mokes.gen">
    <Snort rule="Backdoor.Mokes.TCP.ServerRequest" />
    <Snort rule="Backdoor.Mokes.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Moriya.TCP.C&amp;C" Avp3="Backdoor.Win32.Moriya.a" />
  <Malware Snort="Backdoor.Nayn.TCP.C&amp;C" Avp3="Backdoor.Win32.Nayn.a" />
  <Malware Snort="Backdoor.Nbdd.TCP.ServerRequest" Avp3="Backdoor.Win32.Nbdd.a" />
  <Malware Snort="Backdoor.Nbdd.TCP.ServerRequest" Avp3="Backdoor.Win32.Nbdd.b" />
  <Malware Avp3="Backdoor.Win32.NetWiredRC.a">
    <Snort rule="Backdoor.NetWiredRC.TCP.C&amp;C" />
    <Snort rule="Backdoor.NetWiredRC.TCP.ServerRequest" />
    <Snort rule="Backdoor.NetWiredRC.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.PhantomCore.HTTP.C&amp;C" Avp3="Backdoor.Win32.PhantomCore.a" />
  <Malware Snort="Backdoor.Plurox.TCP.ServerRequest" Avp3="Backdoor.Win32.Plurox.a" />
  <Malware Avp3="Backdoor.Win32.Poison.a">
    <Snort rule="Backdoor.Poison.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Poison.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Poison.TCP.C&amp;C" />
    <Snort rule="Backdoor.Poison.UDP.C&amp;C" />
    <Snort rule="Backdoor.Poison.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.PoisonIvy.TCP.C&amp;C" Avp3="Backdoor.Win32.PoisonIvy.a" />
  <Malware Snort="Backdoor.Pucodex.HTTP.C&amp;C" Avp3="Backdoor.Win32.Pucodex.a" />
  <Malware Avp3="Backdoor.Win32.Pupy.a">
    <Snort rule="Backdoor.Pupy.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Pupy.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.PyXie.TCP.ServerRequest" Avp3="Backdoor.Win32.PyXie.a" />
  <Malware Snort="Backdoor.RABased.TCP.C&amp;C" Avp3="Backdoor.Win32.RABased.a" />
  <Malware Snort="Backdoor.RA-based.HTTP.C&amp;C" Avp3="Backdoor.Win32.RA-based.a" />
  <Malware Snort="Backdoor.Ragnatela.HTTP.C&amp;C" Avp3="Backdoor.Win32.Ragnatela.a" />
  <Malware Snort="Backdoor.Rancor.HTTP.C&amp;C" Avp3="Backdoor.Win32.Rancor.a" />
  <Malware Snort="Backdoor.Raroger.HTTP.C&amp;C" Avp3="Backdoor.Win32.Raroger.a" />
  <Malware Avp3="Backdoor.Win32.Raroger.gen">
    <Snort rule="Backdoor.Raroger.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Raroger.TCP.ServerRequest" />
    <Snort rule="Backdoor.Raroger.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Ratsnif.HTTP.C&amp;C" Avp3="Backdoor.Win32.Ratsnif.a" />
  <Malware Avp3="Backdoor.Win32.Remcos.a">
    <Snort rule="Backdoor.Remcos.DNS.C&amp;C" />
    <Snort rule="Backdoor.Remcos.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Remcos.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Remcos.TCP.C&amp;C" />
    <Snort rule="Backdoor.Remcos.TLS.C&amp;C" />
    <Snort rule="Backdoor.Remcos.UDP.C&amp;C" />
    <Snort rule="TCP.Backdoor.Remcos.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.RESHELL.HTTP.C&amp;C" Avp3="Backdoor.Win32.RESHELL.a" />
  <Malware Snort="Backdoor.RGDoor.HTTP.C&amp;C" Avp3="Backdoor.Win32.RGDoor.a" />
  <Malware Snort="Backdoor.RRAT.TCP.C&amp;C" Avp3="Backdoor.Win32.RRAT.a" />
  <Malware Snort="Backdoor.Ruledor.HTTP.ServerRequest" Avp3="Backdoor.Win32.Ruledor.a" />
  <Malware Snort="Backdoor.Sainbox.HTTP.C&amp;C" Avp3="Backdoor.Win32.Sainbox.a" />
  <Malware Snort="Backdoor.Schnabrom.HTTP.C&amp;C" Avp3="Backdoor.Win32.Schnabrom.a" />
  <Malware Snort="Backdoor.SdBot.IRC.C&amp;C" Avp3="Backdoor.Win32.SdBot.a" />
  <Malware Snort="Backdoor.ServHelper.UDP.C&amp;C" Avp3="Backdoor.Win32.ServHelper.a" />
  <Malware Snort="Backdoor.SharpDNSExfil.DNS.C&amp;C" Avp3="Backdoor.Win32.SharpDNSExfil.a" />
  <Malware Snort="Backdoor.SharPi.HTTP.C&amp;C" Avp3="Backdoor.Win32.SharPi.a" />
  <Malware Snort="Backdoor.Shiz.HTTP.C&amp;C" Avp3="Backdoor.Win32.Shiz.a" />
  <Malware Snort="Backdoor.Sinowal.HTTP.Notification" Avp3="Backdoor.Win32.Sinowal.a" />
  <Malware Snort="Backdoor.Small.HTTP.C&amp;C" Avp3="Backdoor.Win32.Small.a" />
  <Malware Avp3="Backdoor.Win32.Spyder.gen">
    <Snort rule="Backdoor.Spyder.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Spyder.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.StrongPity.HTTP.C&amp;C" Avp3="Backdoor.Win32.StrongPity.a" />
  <Malware Snort="Backdoor.Sudox.HTTP.C&amp;C" Avp3="Backdoor.Win32.Sudox.a" />
  <Malware Snort="Backdoor.Sudox.HTTP.ServerRequest" Avp3="Backdoor.Win32.Sudox.gen" />
  <Malware Snort="Backdoor.Sunburst.HTTP.C&amp;C" Avp3="Backdoor.Win32.Sunburst.a" />
  <Malware Snort="Backdoor.TeamBot.HTTP.Download" Avp3="Backdoor.Win32.TeamBot.a" />
  <Malware Snort="Backdoor.Telebot.HTTP.C&amp;C" Avp3="Backdoor.Win32.Telebot.a" />
  <Malware Snort="Backdoor.TeviRat.HTTP.C&amp;C" Avp3="Backdoor.Win32.TeviRat.a" />
  <Malware Avp3="Backdoor.Win32.TinyFluff.a">
    <Snort rule="Backdoor.TinyFluff.HTTP.C&amp;C" />
    <Snort rule="Backdoor.TinyFluff.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Backdoor.Win32.Tofsee.a">
    <Snort rule="Backdoor.Tofsee.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Tofsee.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Tofsee.TCP.ServerRequest" />
    <Snort rule="Backdoor.Tofsee.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.TrevorC2.HTTP.C&amp;C" Avp3="Backdoor.Win32.TrevorC2.a" />
  <Malware Snort="Backdoor.TripleCross.TCP.C&amp;C" Avp3="Backdoor.Win32.TripleCross.a" />
  <Malware Snort="Backdoor.Turla.HTTP.C&amp;C" Avp3="Backdoor.Win32.Turla.a" />
  <Malware Avp3="Backdoor.Win32.VB.a">
    <Snort rule="Backdoor.VB.HTTP.C&amp;C" />
    <Snort rule="Backdoor.VB.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.VenomRAT.TLS.C&amp;C" Avp3="Backdoor.Win32.VenomRAT.a" />
  <Malware Snort="Backdoor.VSingle.HTTP.C&amp;C" Avp3="Backdoor.Win32.VSingle.a" />
  <Malware Snort="Backdoor.Winnti.TCP.C&amp;C" Avp3="Backdoor.Win32.Winnti.a" />
  <Malware Snort="Backdoor.WinUOJ.HTTP.ServerRequest" Avp3="Backdoor.Win32.WinUOJ.a" />
  <Malware Avp3="Backdoor.Win32.Xaparo.a">
    <Snort rule="Backdoor.Xaparo.TCP.C&amp;C" />
    <Snort rule="Backdoor.Xaparo.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.Xidu.HTTP.C&amp;C" Avp3="Backdoor.Win32.Xidu.a" />
  <Malware Snort="Backdoor.Xkcp.HTTP.C&amp;C" Avp3="Backdoor.Win32.Xkcp.a" />
  <Malware Snort="Backdoor.Xkcp.TCP.ServerRequest" Avp3="Backdoor.Win32.Xkcp.gen" />
  <Malware Snort="Backdoor.Yokai.HTTP.C&amp;C" Avp3="Backdoor.Win32.Yokai.a" />
  <Malware Avp3="Backdoor.Win32.ZAccess.a">
    <Snort rule="Backdoor.ZAccess.NTP.ServerRequest" />
    <Snort rule="Backdoor.ZAccess.TCP.C&amp;C" />
    <Snort rule="Backdoor.ZAccess.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Zapchast.HTTP.C&amp;C" Avp3="Backdoor.Win32.Zapchast.a" />
  <Malware Snort="Backdoor.Zebrocy.HTTP.ServerRequest" Avp3="Backdoor.Win32.Zebrocy.a" />
  <Malware Snort="Backdoor.Zegost.TCP.C&amp;C" Avp3="Backdoor.Win32.Zegost.a" />
  <Malware Snort="Backdoor.Zepfod.HTTP.C&amp;C" Avp3="Backdoor.Win32.Zepfod.a" />
  <Malware Snort="Backdoor.ZZSlash.TCP.C&amp;C" Avp3="Backdoor.Win32.ZZSlash.a" />
  <Malware Snort="Backdoor.AdaptixC2.HTTP.C&amp;C" Avp3="Backdoor.Win64.AdaptixC2.a" />
  <Malware Avp3="Backdoor.Win64.Agent.a">
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.Agent.TCP.ServerRequest" Avp3="Backdoor.Win64.Agent.gen" />
  <Malware Avp3="Backdoor.Win64.Bazdor.a">
    <Snort rule="Backdoor.Bazdor.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Bazdor.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Backdoor.BrockenDoor.HTTP.C&amp;C" Avp3="Backdoor.Win64.BrockenDoor.a" />
  <Malware Snort="Backdoor.BruteRatel.HTTP.C&amp;C" Avp3="Backdoor.Win64.BruteRatel.a" />
  <Malware Snort="Backdoor.C4rat.TLS.C&amp;C" Avp3="Backdoor.Win64.C4rat.gen" />
  <Malware Snort="Backdoor.Chaos.HTTP.C&amp;C" Avp3="Backdoor.Win64.Chaos.a" />
  <Malware Snort="Backdoor.Chisel.HTTP.C&amp;C" Avp3="Backdoor.Win64.Chisel.a" />
  <Malware Snort="Backdoor.DiscoRAT.HTTP.C&amp;C" Avp3="Backdoor.Win64.DiscoRAT.a" />
  <Malware Avp3="Backdoor.Win64.Havoc.a">
    <Snort rule="Backdoor.Havoc.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Havoc.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Backdoor.NimPlant.HTTP.C&amp;C" Avp3="Backdoor.Win64.NimPlant.a" />
  <Malware Snort="Backdoor.PhantomCore.TCP.C&amp;C" Avp3="Backdoor.Win64.PhantomCore.a" />
  <Malware Snort="Backdoor.TGBot.HTTP.C&amp;C" Avp3="Backdoor.Win64.TGBot.a" />
  <Malware Snort="Downloader.AdLoad.HTTP.C&amp;C" Avp3="Downloader.Win32.AdLoad.a" />
  <Malware Avp3="EICAR-test-file">
    <Snort rule="Adware1-test-file" />
    <Snort rule="Adware2-test-file" />
    <Snort rule="Adware3-test-file" />
    <Snort rule="Apt1-test-file" />
    <Snort rule="Apt2-test-file" />
    <Snort rule="Apt3-test-file" />
    <Snort rule="EICAR-test-file" />
    <Snort rule="General1-test-file" />
    <Snort rule="General2-test-file" />
    <Snort rule="General3-test-file" />
    <Snort rule="Riskware1-test-file" />
    <Snort rule="Riskware2-test-file" />
    <Snort rule="Riskware3-test-file" />
    <Snort rule="Trojan1-test-file" />
    <Snort rule="Trojan2-test-file" />
    <Snort rule="Trojan3-test-file" />
  </Malware>
  <Malware Avp3="Email-Worm.Win32.Agent.a">
    <Snort rule="Email-Worm.Agent.SMTP.C&amp;C" />
    <Snort rule="Email-Worm.Agent.SMTP.ServerRequest" />
  </Malware>
  <Malware Snort="Email-Worm.Bagle.HTTP.C&amp;C" Avp3="Email-Worm.Win32.Bagle.a" />
  <Malware Snort="Email-Worm.Bloored.TCP.C&amp;C" Avp3="Email-Worm.Win32.Bloored.a" />
  <Malware Snort="Email-Worm.Brontok.HTTP.C&amp;C" Avp3="Email-Worm.Win32.Brontok.a" />
  <Malware Snort="Email-Worm.LovGate.TCP.ServerRequest" Avp3="Email-Worm.Win32.LovGate.a" />
  <Malware Snort="Email-Worm.LovGate.TCP.ServerRequest" Avp3="Email-Worm.Win32.LovGate.gen" />
  <Malware Snort="Email-Worm.Mydoom.HTTP.C&amp;C" Avp3="Email-Worm.Win32.Mydoom.a" />
  <Malware Snort="Email-Worm.NetSky.TCP.ServerRequest" Avp3="Email-Worm.Win32.NetSky.a" />
  <Malware Snort="Email-Worm.Warezov.HTTP.C&amp;C" Avp3="Email-Worm.Win32.Warezov.a" />
  <Malware Snort="Exploit.CVE-2022-22965.HTTP.C&amp;C" Avp3="Exploit.Java.CVE-2022-22965.b" />
  <Malware Avp3="Exploit.Java.Serial.a">
    <Snort rule="Exploit.Serial.HTTP.C&amp;C" />
    <Snort rule="Exploit.Serial.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.YsoserialNet.TCP.C&amp;C" Avp3="Exploit.Java.YsoserialNet.a" />
  <Malware Snort="Exploit.Agent.HTTP.C&amp;C" Avp3="Exploit.JS.Agent.a" />
  <Malware Snort="Exploit.CVE-2007-2586.FTP.C&amp;C" Avp3="Exploit.Linux.CVE-2007-2586.a" />
  <Malware Snort="Exploit.CVE-2017-17215.HTTP.C&amp;C" Avp3="Exploit.Linux.CVE-2017-17215.a" />
  <Malware Snort="Exploit.CVE-2017-18368.HTTP.C&amp;C" Avp3="Exploit.Linux.CVE-2017-18368.a" />
  <Malware Snort="Exploit.CVE-2017-6736.SNMP.C&amp;C" Avp3="Exploit.Linux.CVE-2017-6736.a" />
  <Malware Snort="Exploit.CVE-2019-20197.HTTP.C&amp;C" Avp3="Exploit.Linux.CVE-2019-20197.a" />
  <Malware Snort="Exploit.CVE-2020-13160.UDP.C&amp;C" Avp3="Exploit.Linux.CVE-2020-13160.a" />
  <Malware Snort="Exploit.Agent.HTTP.ServerRequest" Avp3="Exploit.MSOffice.Agent.a" />
  <Malware Snort="Exploit.Agentb.TLS.C&amp;C" Avp3="Exploit.MSOffice.Agentb.gen" />
  <Malware Snort="Exploit.Generic.UDP.ServerRequest" Avp3="Exploit.MSOffice.Generic.gen" />
  <Malware Snort="Exploit.Oleink.UDP.ServerRequest" Avp3="Exploit.MSOffice.Oleink.gen" />
  <Malware Snort="Exploit.CVE-2018-14847.TCP.ServerRequest" Avp3="Exploit.Python.Agent.a" />
  <Malware Snort="Exploit.CVE-2010-1871.HTTP.C&amp;C" Avp3="Exploit.Python.CVE-2010-1871.a" />
  <Malware Snort="Exploit.CVE-2017-11882.UDP.ServerRequest" Avp3="Exploit.RTF.CVE-2017-11882.gen" />
  <Malware Snort="Exploit.Oleink.UDP.ServerRequest" Avp3="Exploit.RTF.Oleink.gen" />
  <Malware Snort="Exploit.Carbid.HTTP.C&amp;C" Avp3="Exploit.Shell.Carbid.a" />
  <Malware Snort="Exploit.Agent.HTTP.ServerRequest" Avp3="Exploit.SWF.Agent.a" />
  <Malware Avp3="Exploit.Win32.Agent.a">
    <Snort rule="Exploit.Agent.HTTP.C&amp;C" />
    <Snort rule="Exploit.Agent.TCP.C&amp;C" />
    <Snort rule="Exploit.Agent.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.CVE-2008-4114.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2008-4114.a" />
  <Malware Avp3="Exploit.Win32.CVE-2008-4834.a">
    <Snort rule="Exploit.CVE-2008-4834.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-4834.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Exploit.Win32.CVE-2008-4835.a">
    <Snort rule="Exploit.CVE-2008-4835.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-4835.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.CVE-2009-0102.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2009-0102.a" />
  <Malware Snort="Exploit.CVE-2010-0020.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2010-0020.a" />
  <Malware Avp3="Exploit.Win32.CVE-2010-0022.a">
    <Snort rule="Exploit.CVE-2010-0022.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2010-0022.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.CVE-2010-0231.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2010-0231.a" />
  <Malware Snort="Exploit.CVE-2012-0002.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2012-0002.a" />
  <Malware Snort="Exploit.CVE-2014-6324.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2014-6324.a" />
  <Malware Snort="Exploit.CVE-2015-1635.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2015-1635.a" />
  <Malware Snort="Exploit.CVE-2017-0144.SMB.ServerRequest" Avp3="Exploit.Win32.CVE-2017-0144.a" />
  <Malware Snort="Exploit.CVE-2017-10271.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2017-10271.a" />
  <Malware Snort="Exploit.CVE-2017-7269.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2017-7269.a" />
  <Malware Snort="Exploit.CVE-2018-11776.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2018-11776.a" />
  <Malware Snort="Exploit.CVE-2018-12613.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2018-12613.a" />
  <Malware Snort="Exploit.CVE-2018-13379.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2018-13379.a" />
  <Malware Snort="Exploit.CVE-2018-8423.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2018-8423.a" />
  <Malware Snort="Exploit.CVE-2019-0227.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-0227.a" />
  <Malware Snort="Exploit.CVE-2019-0232.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-0232.a" />
  <Malware Snort="Exploit.CVE-2019-0708.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-0708.a" />
  <Malware Snort="Exploit.CVE-2019-0885.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-0885.a" />
  <Malware Snort="Exploit.CVE-2019-0891.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-0891.a" />
  <Malware Snort="Exploit.CVE-2019-0893.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-0893.a" />
  <Malware Snort="Exploit.CVE-2019-0898.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-0898.a" />
  <Malware Snort="Exploit.CVE-2019-11510.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-11510.a" />
  <Malware Snort="Exploit.CVE-2019-12409.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-12409.a" />
  <Malware Snort="Exploit.CVE-2019-1333.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-1333.a" />
  <Malware Snort="Exploit.CVE-2019-1359.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-1359.a" />
  <Malware Snort="Exploit.CVE-2019-17571.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-17571.a" />
  <Malware Snort="Exploit.CVE-2019-19109.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2019-19109.a" />
  <Malware Snort="Exploit.CVE-2019-2647.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-2647.a" />
  <Malware Snort="Exploit.CVE-2019-3396.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-3396.a" />
  <Malware Snort="Exploit.CVE-2019-3398.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-3398.a" />
  <Malware Snort="Exploit.CVE-2019-3799.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2019-3799.a" />
  <Malware Snort="Exploit.CVE-2020-0601.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2020-0601.a" />
  <Malware Snort="Exploit.CVE-2020-0646.HTTP.ServerRequest" Avp3="Exploit.Win32.CVE-2020-0646.a" />
  <Malware Snort="Exploit.CVE-2020-0796.SMB.Spreading" Avp3="Exploit.Win32.CVE-2020-0796.a" />
  <Malware Snort="Exploit.CVE-2020-1020.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2020-1020.a" />
  <Malware Snort="Exploit.CVE-2020-1153.TCP.C&amp;C" Avp3="Exploit.Win32.CVE-2020-1153.a" />
  <Malware Snort="Exploit.CVE-2020-1206.SMB.C&amp;C" Avp3="Exploit.Win32.CVE-2020-1206.a" />
  <Malware Snort="Exploit.CVE-2020-12695.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2020-12695.a" />
  <Malware Snort="Exploit.CVE-2020-1472.NETLOGON.C&amp;C" Avp3="Exploit.Win32.CVE-2020-1472.c" />
  <Malware Snort="Exploit.CVE-2020-1472.NETLOGON.C&amp;C" Avp3="Exploit.Win32.CVE-2020-1472.f" />
  <Malware Snort="Exploit.CVE-2020-3452.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2020-3452.a" />
  <Malware Snort="Exploit.CVE-2021-21220.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2021-21220.a" />
  <Malware Snort="Exploit.CVE-2021-21224.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2021-21224.a" />
  <Malware Snort="Exploit.CVE-2021-33766.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2021-33766.a" />
  <Malware Snort="Exploit.CVE-2021-40444.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2021-40444.a" />
  <Malware Snort="Exploit.CVE-2022-22972.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2022-22972.a" />
  <Malware Avp3="Exploit.Win32.CVE-2022-26134.a">
    <Snort rule="Exploit.CVE-2022-26134.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26134.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26134.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.CVE-2022-30190.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2022-30190.a" />
  <Malware Snort="Exploit.CVE-2022-34713.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2022-34713.a" />
  <Malware Snort="Exploit.CVE-2022-41040.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2022-41040.a" />
  <Malware Snort="Exploit.CVE-2022-41082.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2022-41082.a" />
  <Malware Snort="Exploit.CVE-2023-34478.HTTP.C&amp;C" Avp3="Exploit.Win32.CVE-2023-34478.a" />
  <Malware Snort="Exploit.Grunt.HTTP.C&amp;C" Avp3="Exploit.Win32.Grunt.a" />
  <Malware Avp3="Exploit.Win32.Shellcode.a">
    <Snort rule="Exploit.Shellcode.HTTP.C&amp;C" />
    <Snort rule="Exploit.ShellCode.IP.C&amp;C" />
    <Snort rule="Exploit.ShellCode.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Exploit.Shellcode.UDP.C&amp;C" Avp3="Exploit.Win32.Shellcode.gen" />
  <Malware Snort="Exploit.XModeCheck.TCP.C&amp;C" Avp3="Exploit.Win32.XModeCheck.a" />
  <Malware Snort="Exploit.Shellcode.UDP.ServerRequest" Avp3="Exploit.Win64.Shellcode.gen" />
  <Malware Snort="Flooder.CoreWarrior.HTTP.C&amp;C" Avp3="Flooder.Win32.CoreWarrior.a" />
  <Malware Snort="Flooder.VK.HTTP.C&amp;C" Avp3="Flooder.Win32.VK.a" />
  <Malware Snort="FLOWBITS_CHECKER" Avp3="FLOWBITS_CHECKER" />
  <Malware Avp3="Generic suspicious network activity">
    <Snort rule="Backdoor.Agent.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Agent.ICMP.C&amp;C" />
    <Snort rule="Backdoor.Agent.TCP.C&amp;C" />
    <Snort rule="Backdoor.JavaRevShell.HTTP.C&amp;C" />
    <Snort rule="Backdoor.Mirai.HTTP.ServerRequest" />
    <Snort rule="Backdoor.Pupy.TCP.C&amp;C" />
    <Snort rule="Backdoor.PwncatCs.TCP.C&amp;C" />
    <Snort rule="Backdoor.WebShell.HTTP.C&amp;C" />
    <Snort rule="Downloader.Dropmefiles.DNS.C&amp;C" />
    <Snort rule="Downloader.UnoSetup.HTTP.C&amp;C" />
    <Snort rule="EICAR-test-file.Agent.HTTP.C&amp;C" />
    <Snort rule="EICAR-test-file.Agent.UDP.C&amp;C" />
    <Snort rule="EICAR-test-file-full.Agent.UDP.C&amp;C" />
    <Snort rule="Exploit.2023-23752.HTTP.C&amp;C" />
    <Snort rule="Exploit.2023-36498.HTTP.C&amp;C" />
    <Snort rule="Exploit.Agent.FTP.C&amp;C" />
    <Snort rule="Exploit.Agent.HTTP.C&amp;C" />
    <Snort rule="Exploit.Agent.HTTP.ServerRequest" />
    <Snort rule="Exploit.Agent.SIP.C&amp;C" />
    <Snort rule="Exploit.Agent.SMTP.C&amp;C" />
    <Snort rule="Exploit.Agent.TELNET.C&amp;C" />
    <Snort rule="Exploit.Agent.UDP.C&amp;C" />
    <Snort rule="Exploit.Bitrix.HTTP.C&amp;C" />
    <Snort rule="Exploit.CNVD-2018-04757.HTTP.C&amp;C" />
    <Snort rule="Exploit.CNVD-2019-16798.HTTP.C&amp;C" />
    <Snort rule="Exploit.CNVD-2021-30167.HTTP.C&amp;C" />
    <Snort rule="Exploit.CNVD-2022-43247.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-1999-0128.IP.C&amp;C" />
    <Snort rule="Exploit.CVE-2000-0114.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2001-1473.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2002-0012.SNMP.C&amp;C" />
    <Snort rule="Exploit.CVE-2003-0109.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2003-0812.DCERPC.C&amp;C" />
    <Snort rule="Exploit.CVE-2004-0519.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-1983.PNP.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-2120.DCERPC.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-2120.PNP.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-2428.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-3344.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2005-4385.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2006-1681.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2006-1688.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2006-5276.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2006-6026.RTSP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-0885.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-1542.SIP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-1561.SIP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-4504.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-4556.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2007-5728.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-1059.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-2398.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-2650.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-4024.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-4031.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2008-5416.TDS.C&amp;C" />
    <Snort rule="Exploit.CVE-2009-3960.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2009-4490.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2010-0258.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2011-0029.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2013-1418.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2013-2460.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2013-3652.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2013-7471.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2014-100005.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2014-2321.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2014-3566.SSL.ServerRequest" />
    <Snort rule="Exploit.CVE-2014-6324.Kerberos.C&amp;C" />
    <Snort rule="Exploit.CVE-2014-9118.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-1635.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-1641.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-1648.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-2051.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-2373.RDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-4852.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-4902.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2015-8399.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-1287.IKEv2.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-1879.SCTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-2510.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-6415.IKEv1.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-6909.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2016-8735.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-11774.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-11774.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-11882.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-12149.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-12637.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-17105.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-17215.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-3606.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-5638.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-6079.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-7577.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-7991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-8729.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-8779.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-9822.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2017-9841.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-0171.Cisco.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-0886.RDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-1000861.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-1111.DHCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-11776.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-13023.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-13379.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-14767.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-15957.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-15961.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2018-16130.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-16763.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-17246.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-17254.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-18809.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-19410.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-19518.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-20020.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-20062.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-3810.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-3811.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-5230.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-5430.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-6789.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-8581.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2018-8653.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-8828.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2018-9276.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-0193.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-0235.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-0604.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-100300.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-10655.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-11001.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-11469.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-11500.IMAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-11542.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-11580.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-11956.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-12643.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-12725.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-13272.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-13345.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15311.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15678.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15683.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15976.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15980.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-15984.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-1620.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-1622.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-1652.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-1653.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-1653.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-16663.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-16759.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-16997.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-17418.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-18187.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-18935.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-18935.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-19781.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-19781.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-19781.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-19824.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-3396.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-3398.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-3822.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-5544.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-5544.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-7195.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-8287.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-8394.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2019-9670.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-9874.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2019-9978.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2020-0609.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0610.DRPUDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0618.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0664.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0681.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0688.HTTP.ServerRequest" />
    <Snort rule="Exploit.CVE-2020-0688.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2020-0692.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0824.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0824.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0832.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0832.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0833.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0833.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0847.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0847.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0856.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0938.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0938.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0968.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-0968.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-10189.TCP.ServerRequest" />
    <Snort rule="Exploit.CVE-2020-1020.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1020.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-10204.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1035.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1035.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1058.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1058.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1060.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1062.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1062.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-11547.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-11749.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-11798.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-11854.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-11991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-12116.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-12124.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1213.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1213.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-12133.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1214.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1214.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-12145.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1215.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1215.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1216.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1216.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1219.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1219.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1230.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1230.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1260.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-12688.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1284.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1300.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1301.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13448.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1350.DNS.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1350.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13562.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13564.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13619.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13693.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13782.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1380.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1380.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13851.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13856.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13857.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13859.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13921.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13925.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-13965.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-14092.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1472.NETLOGON.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-14882.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-15049.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-15227.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1567.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1567.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1570.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1570.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-15906.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-15922.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16043.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16152.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16896.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16898.ICMP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16915.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16915.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16922.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-16922.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17047.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17051.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17052.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17052.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17053.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17053.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17056.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17087.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17087.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17096.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17096.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17121.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17132.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17140.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17143.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17144.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17152.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17158.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17456.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17496.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17519.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-17530.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1938.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-1947.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-21224.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-22253.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-24949.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-2555.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-25787.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-25858.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-26073.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-27128.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-28188.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3153.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3161.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3259.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3452.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3495.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-35228.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-35232.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3580.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-36197.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-36289.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3657.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3952.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3984.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3992.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-3992.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-4000.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-4001.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-40475.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-5405.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-5902.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-6008.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-6286.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-6287.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-6287.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-7247.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-7961.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-8193.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-8209.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-8657.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-8958.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-9020.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-9465.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2020-9484.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1289.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1290.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1291.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1292.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1293.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1295.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1393.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1497.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1498.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1499.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-1647.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-20016.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-20039.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-20090.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-2109.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21300.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21315.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21972.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21973.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21974.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-21975.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22123.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22204.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22502.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22652.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22893.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22941.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22945.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-22986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-23758.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-24563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-24910.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-25094.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-25282.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-25646.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26084.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26085.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26086.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26295.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26754.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26812.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26828.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26855.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-26919.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27137.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27171.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27198.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27513.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27561.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-27907.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-29003.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-3120.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31207.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31250.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31643.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31755.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-31986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-32648.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-3297.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-3317.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-33959.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34228.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34429.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34473.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34527.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34749.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-3493.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34979.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-34991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35211.SSH.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35211.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35232.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35392.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35394.UDP.ServerRequest" />
    <Snort rule="Exploit.CVE-2021-35395.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-35464.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-36942.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-37162.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-37164.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-37343.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-37415.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-38647.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-39144.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-39226.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40323.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40324.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-4034.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-4039.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40407.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40410.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40412.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40444.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40539.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40655.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40661.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-40870.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-41163.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-41277.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42278.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42287.Kerberos.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42287.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42321.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42669.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-42671.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-43258.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-43267.TIPC.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-43286.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-43788.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44026.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44077.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44228.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44228.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44228.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44228.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-4436.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44515.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44529.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-44790.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-45382.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-46422.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2021-46442.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0289.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0306.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0337.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0482.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0543.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0609.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0778.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0847.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-0944.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1026.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1040.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1096.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1162.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1232.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1271.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1292.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1329.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1364.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1388.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1471.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-1661.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-20699.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-21449.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-21587.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2185.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-21907.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-21971.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22241.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22242.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22244.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22245.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22246.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22733.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2294.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22947.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22954.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22963.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-22965.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23131.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23134.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23227.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23270.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23748.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2376.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2376.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2383.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-23854.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24086.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24112.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24124.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24252.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24491.NFS.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24497.NFS.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24697.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24697.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24706.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2486.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24990.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-24999.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-25064.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-25075.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-25236.XMPP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-25237.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26134.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26135.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26138.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26186.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26210.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26258.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26259.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26318.XML-RPC.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26352.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26501.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26925.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26937.NFS.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-26954.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27002.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27226.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27255.SIP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27593.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27643.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-27665.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2770.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2771.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-28219.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2827.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2840.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-28810.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-28958.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-29464.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-29593.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-29593.Modbus.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2992.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-2998.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30075.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30078.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30333.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30333.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30333.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3038.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30525.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-30694.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31137.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31161.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31245.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31269.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31499.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31626.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31629.FTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31656.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31659.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31675.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31680.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31704.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31711.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31814.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3184.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-31898.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-32199.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-32275.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3236.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-32532.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-33891.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-34597.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-34878.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-34907.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-34919.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35148.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35405.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35413.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35914.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35914.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-35947.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3602.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36067.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36200.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36408.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36429.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36537.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36633.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36635.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36642.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-36804.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37042.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37061.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37299.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37299.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37337.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3786.SSL.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37958.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37970.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37974.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-37989.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38050.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38051.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38066.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38108.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38577.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-38715.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-3875.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39028.TELNET.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39045.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39073.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39838.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39952.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39960.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-39986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40127.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40220.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40259.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40624.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40684.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40684.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40734.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40881.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40955.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-40969.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41034.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41040.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-410400.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41082.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41333.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41343.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41352.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41401.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41412.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41678.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-41852.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-42140.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-4223.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-42475.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-42867.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-42889.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-42889.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-4325.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43672.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43684.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43769.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43781.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43781.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-43939.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44015.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44149.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44267.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44268.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44456.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44666.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-44877.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45104.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45362.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45600.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45699.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45701.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45922.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45924.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45925.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45926.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-45928.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-46161.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-46169.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-46604.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47002.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47615.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47872.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47940.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47966.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47966.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-47986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-48323.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2022-4874.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0099.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0126.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0236.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0261.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0297.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0315.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0334.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0448.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0514.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0527.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0630.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0669.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0744.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-0957.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1009.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1080.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1112.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1162.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1163.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1177.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1389.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1671.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1713.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1714.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1716.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1717.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1718.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1719.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-1835.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20026.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20048.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20118.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20128.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20198.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20273.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2033.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20860.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20864.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20887.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-20890.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2114.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21433.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21529.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21554.MSMQ.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21608.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21706.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21768.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21768.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21839.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21931.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-21932.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22374.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2249.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22515.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22518.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22522.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22527.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22621.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22952.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22960.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-22974.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2316.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-23333.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-23397.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-23488.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-23752.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-23924.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24229.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24317.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24488.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24489.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24580.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24610.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24733.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24749.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24762.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24941.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24950.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-24955.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-25194.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-25346.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-25581.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-25690.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-25717.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26035.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26119.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26258.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26359.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26360.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26492.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26615.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26801.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26802.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26842.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26843.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26976.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-26984.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27008.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27076.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27100.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27229.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2724.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27240.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27253.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2732.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27350.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27357.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27361.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27367.TFTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27369.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2745.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27532.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27587.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2779.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27842.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27855.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27856.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27922.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27992.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-27997.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28121.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28130.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28220.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28231.DHCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28231.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2825.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28250.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28310.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28343.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28366.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28384.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28432.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28447.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28461.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28665.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2868.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28760.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28771.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-28771.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29017.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29084.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29154.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2916.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2917.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2928.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29298.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29300.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29324.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2935.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29357.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2936.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-29489.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2982.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-2986.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-30145.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-30210.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-30258.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-30459.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-30777.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31058.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31461.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31541.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31548.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31594.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-31718.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32007.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32073.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3217.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3224.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32243.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32315.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32439.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32521.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32560.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32562.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32985.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-32986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33009.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33010.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33134.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33157.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33160.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33246.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33246.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33253.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33404.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33405.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33617.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33778.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33782.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-33782.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34000.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34048.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34096.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34192.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3420.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3420.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34362.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34537.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34598.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3460.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34634.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34843.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34939.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34960.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-34992.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35036.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35078.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35081.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35082.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35086.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3519.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35386.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35628.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35636.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35813.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35843.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35844.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-35885.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-3595.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36025.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36025.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36319.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36553.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36643.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36644.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36812.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36844.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36845.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36846.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36884.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36899.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-36934.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-37474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-37580.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-37979.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38035.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38148.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38205.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38286.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38434.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38501.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38545.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38646.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38836.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-38861.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39002.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39143.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39144.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39147.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39265.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39361.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39476.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39598.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39600.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39676.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39677.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39700.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-39796.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40044.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40208.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40275.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40276.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40278.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40279.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40280.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40498.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40626.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40779.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-40924.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41080.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4116.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41265.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41266.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41362.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41373.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4148.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41538.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41642.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41717.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41763.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4198.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-41998.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42000.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42115.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42325.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42326.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42327.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42343.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42442.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-42793.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4296.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43154.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43177.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43208.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43242.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43261.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43284.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43323.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43325.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43326.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4352.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4355.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43654.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43770.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43770.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-43838.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4427.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-44351.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-44352.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-44353.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4450.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4451.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4473.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-45184.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4528.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4547.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-45542.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-45852.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4596.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46214.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46214.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46262.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46263.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46264.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4634.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46454.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46455.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46456.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46574.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46604.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46694.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46747.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46748.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46805.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-46805.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47211.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47218.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47246.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47261.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47444.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47473.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47564.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47565.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-47643.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4863.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-48782.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-48783.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-48788.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-48842.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49070.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49103.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49105.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49105.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49606.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4966.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-4966.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49897.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-49964.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50029.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50089.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50104.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50164.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5043.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5044.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5070.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50917.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50919.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-50969.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-51467.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-51764.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-52041.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-52251.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5244.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5360.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5399.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5556.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5561.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5631.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5631.IMAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5631.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-5702.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6063.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6112.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6112.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6265.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6319.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6379.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6538.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6553.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6831.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6848.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6875.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6895.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-6909.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2023-7028.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0012.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0195.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0204.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0305.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0352.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0507.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0517.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0769.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0778.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0939.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0967.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-0986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1019.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10470.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10508.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10557.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10605.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1071.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10811.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10914.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10924.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-10979.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-11638.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-11667.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-11680.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1208.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1209.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-12105.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1212.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-12971.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-12987.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-12992.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-13159.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-13160.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-13161.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-13869.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-13925.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1403.TCP.C&amp;C.a" />
    <Snort rule="Exploit.CVE-2024-1708.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1709.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1709.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1800.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-1874.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20287.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20356.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20419.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20439.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20440.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-2054.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20767.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-20931.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21320.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21412.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21413.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21413.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21683.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21762.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21793.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21887.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-21893.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22024.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22107.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22120.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22319.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22320.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22567.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22900.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22901.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22902.SSH.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-22939.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-23108.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-23113.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-23692.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-23759.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-2389.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-23897.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24034.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24386.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24398.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24520.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24576.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24919.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-24942.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-25153.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-25251.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-25600.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-25832.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-26026.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-26331.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-26503.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-2667.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27130.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27198.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27198.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27199.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27199.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27348.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-27954.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28116.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28247.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28255.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28353.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28354.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-2895.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28987.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28987.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-28995.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29014.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29059.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29269.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29272.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29824.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29849.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29895.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29972.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29973.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29974.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-29976.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-30044.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-30080.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-30568.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3080.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-30850.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3094.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3116.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-31449.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-31819.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-31982.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32030.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32113.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32238.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32370.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32371.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32399.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32523.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-32640.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3272.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3273.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-33003.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-33113.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-33775.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3400.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3400.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3408.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34102.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34221.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34223.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34313.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34361.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34470.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34471.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34832.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-34833.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-35286.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36104.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36401.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36435.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36527.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36539.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-36991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37084.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3721.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37383.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37393.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37397.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37404.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-37759.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38030.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-3806.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38063.IPv6.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38094.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38112.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38112.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38178.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38200.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38237.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38238.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38241.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38242.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38243.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38368.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38473.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38653.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38816.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38821.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-38856.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-39202.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-39205.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-39717.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40110.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40324.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40348.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4040.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40422.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40711.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40711.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40725.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-40890.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41107.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41570.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41660.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41710.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41713.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-41730.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-42327.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-42815.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-43044.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4323.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-43461.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-43572.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-43573.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4358.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-43642.SMB.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-44000.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-44849.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-44867.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45175.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45176.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45177.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45195.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45241.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45388.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45519.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-45519.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4577.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-46310.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-46507.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-46538.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-46982.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-47177.CUPS.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-47177.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-47575.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-47910.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-48217.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-48248.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4879.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4883.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4885.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4885.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4898.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49019.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49033.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49039.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49112.CLDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49112.LDAP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-49368.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4956.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-4978.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5009.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50340.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50379.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50603.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50623.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50623.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-50633.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5084.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-51132.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-51378.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-51567.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-51568.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-51977.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-52012.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5217.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5276.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-52875.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-52875.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-52883.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5326.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53615.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53675.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53677.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53691.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53704.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-53991.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-54085.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-54502.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-54772.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-54772.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-54887.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55417.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55591.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55956.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55956.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55963.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55964.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-55965.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-56145.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-56325.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-56337.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-56902.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57004.SMTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57050.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57229.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57727.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57778.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-57968.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5806.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-58136.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5910.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-5932.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6242.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6366.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6386.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6387.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6587.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6633.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6648.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6670.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6782.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-6802.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7023.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7029.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7094.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7120.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7262.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7332.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7339.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7340.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7591.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7593.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7781.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7928.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7954.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-7965.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8069.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8124.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8190.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8190.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8353.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8752.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8877.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8956.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-8963.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9014.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9095.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9264.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9379.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9380.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9441.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9463.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9464.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9465.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9474.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9487.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9680.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2024-9765.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0107.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0108.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0282.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0282.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0626.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0868.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-0890.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1002.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1025.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1035.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1097.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1098.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1304.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1316.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1833.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1847.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1848.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1849.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1876.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-1974.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-20231.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-20281.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2032.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21189.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21219.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21247.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21269.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21298.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21299.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21309.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21376.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21385.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-21400.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-22457.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-22952.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24016.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24132.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24367.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24514.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24799.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24801.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24813.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-24893.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25181.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25257.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25279.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2546.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25740.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25741.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-25745.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-26319.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2651.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-26794.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2689.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2690.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27007.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27112.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27134.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27140.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27218.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27364.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27409.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2746.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2747.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-27636.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2775.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28017.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28018.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28024.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28029.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28030.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28032.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28033.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28034.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28035.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28036.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28037.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28038.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28039.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28072.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28137.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28142.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28143.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28144.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28145.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-28146.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2825.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29062.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29209.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29446.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-2945.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29743.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29774.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29775.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29789.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29793.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29793.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29794.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29809.TCP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29809.UDP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-29927.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-30208.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-30397.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3102.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31131.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31161.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31324.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31486.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31489.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-31644.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32101.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32421.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32432.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32433.SSH.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3244.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3248.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32819.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32820.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-32821.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3328.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3346.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-34026.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-34028.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-34067.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-34490.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3471.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3563.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3565.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3585.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3605.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3665.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3729.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3764.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3765.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3785.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3830.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3914.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3959.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3960.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3963.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3964.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3966.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3969.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3975.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3979.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3980.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3981.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3983.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3987.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3988.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-3990.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4012.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4036.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-42999.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4310.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4322.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4336.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4355.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-43864.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-43865.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4389.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4403.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44071.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44176.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4427.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4428.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4462.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44835.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44836.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44844.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44845.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44858.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44872.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44880.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44881.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-44882.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45009.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45010.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45011.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45042.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45250.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45320.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45343.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45427.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45428.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45429.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4544.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45487.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45488.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45492.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45513.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45514.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45529.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45746.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45787.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45788.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45789.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45790.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45797.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45798.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45841.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45842.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45843.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45844.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45845.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45861.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45863.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45865.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45947.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45949.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45953.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45984.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45986.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-45997.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4603.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4631.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-46347.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-46348.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-46566.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-46630.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-46631.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4720.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-47227.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-47228.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-47423.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4751.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-47549.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-47812.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-48045.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4809.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4810.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-48703.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-48827.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4883.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4901.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4902.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4903.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-49113.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-4923.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5058.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5126.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5130.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5132.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5136.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5139.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5215.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5299.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5328.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-5777.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6151.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6302.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6393.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6615.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6616.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6617.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6824.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-6899.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-7082.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-7094.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-7194.HTTP.C&amp;C" />
    <Snort rule="Exploit.CVE-2025-7206.HTTP.C&amp;C" />
    <Snort rule="Exploit.FindProxyForURL.HTTP.C&amp;C" />
    <Snort rule="Exploit.HIDRCE.UDP.C&amp;C" />
    <Snort rule="Exploit.LoadFile.MySQL.C&amp;C" />
    <Snort rule="Exploit.MissionAbrt.PJL.C&amp;C" />
    <Snort rule="Exploit.NameWreck.UDP.C&amp;C" />
    <Snort rule="Exploit.NUUOOSComInject.HTTP.C&amp;C" />
    <Snort rule="Exploit.OutFile.MySQL.C&amp;C" />
    <Snort rule="Exploit.PHPInjection.HTTP.C&amp;C" />
    <Snort rule="Exploit.PHPInputInjection.HTTP.C&amp;C" />
    <Snort rule="Exploit.RCE.HTTP.C&amp;C" />
    <Snort rule="Exploit.RequestSmuggling.HTTP.C&amp;C" />
    <Snort rule="Exploit.ShellCodeA.IP.C&amp;C" />
    <Snort rule="Exploit.ShellCodeB.IP.C&amp;C" />
    <Snort rule="Exploit.ShellCodeC.IP.C&amp;C" />
    <Snort rule="Exploit.ShellCodePowerShell.IP.C&amp;C" />
    <Snort rule="Exploit.SiemensCP710.TCP.C&amp;C" />
    <Snort rule="Exploit.SiemensSiprotecDos.UDP.C&amp;C" />
    <Snort rule="Exploit.SIET.TCP.C&amp;C" />
    <Snort rule="Exploit.Spring4Shell.HTTP.C&amp;C" />
    <Snort rule="Exploit.TRS-MAS-RCE.HTTP.C&amp;C" />
    <Snort rule="Exploit.UserAnonymous.FTP.C&amp;C" />
    <Snort rule="Exploit.WebDAVUpload.HTTP.C&amp;C" />
    <Snort rule="Exploit.WiresharkDNP3.TCP.C&amp;C" />
    <Snort rule="Exploit.XXEInjection.HTTP.C&amp;C" />
    <Snort rule="Exploit.YsoserialJava.BeanShell" />
    <Snort rule="Exploit.YsoserialJava.C3P0" />
    <Snort rule="Exploit.YsoserialJava.Clojure" />
    <Snort rule="Exploit.YsoserialJava.FileUpload1" />
    <Snort rule="Exploit.YsoserialJava.Groovy1" />
    <Snort rule="Exploit.YsoserialJava.Hibernate2" />
    <Snort rule="Exploit.YsoserialJava.JRMPListener" />
    <Snort rule="Exploit.YsoserialJava.Jython1" />
    <Snort rule="Exploit.YsoserialJava.MozillaRhino1" />
    <Snort rule="Exploit.YsoserialJava.MyFaces" />
    <Snort rule="Exploit.YsoserialJava.URLDNS" />
    <Snort rule="Exploit.YsoserialNet.TCP.C&amp;C" />
    <Snort rule="Exploit.ZabbixRCE.HTTP.C&amp;C" />
    <Snort rule="HackTool.Addspn.LDAP.C&amp;C" />
    <Snort rule="HackTool.AdFind.LDAP.C&amp;C" />
    <Snort rule="HackTool.AdFindTrustdmp.LDAP.C&amp;C" />
    <Snort rule="HackTool.AdFindTrustdmpForest.LDAP.C&amp;C" />
    <Snort rule="HackTool.AdminSDHolder.LDAP.ServerRequest" />
    <Snort rule="HackTool.ADToSqlite.LDAP.ServerRequest" />
    <Snort rule="HackTool.Agent.HTTP.C&amp;C" />
    <Snort rule="HackTool.Agent.HTTP.ServerRequest" />
    <Snort rule="HackTool.AnonymousLogonAttempt.SMB.C&amp;C" />
    <Snort rule="HackTool.AnySession.SMB.ServerRequest" />
    <Snort rule="HackTool.ApacheBench.HTTP.ServerRequest" />
    <Snort rule="HackTool.APosT.HTTP.ServerRequest" />
    <Snort rule="HackTool.ATestA1.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestA2.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestA3.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestAS.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestN1.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestN2.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestN3.LDAP.C&amp;C" />
    <Snort rule="HackTool.ATestNS.LDAP.C&amp;C" />
    <Snort rule="HackTool.AXFRZoneTransferQ.TCP.ServerRequest" />
    <Snort rule="HackTool.AXFRZoneTransferS.TCP.ServerRequest" />
    <Snort rule="HackTool.BindTaskSchedulerService.ATSVC.C&amp;C" />
    <Snort rule="HackTool.BloodHound.LDAP.ServerRequest" />
    <Snort rule="HackTool.Boomerang.HTTP.C&amp;C" />
    <Snort rule="HackTool.Boomerang.TCP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.DICOM.C&amp;C" />
    <Snort rule="HackTool.BruteForce.FTP.ServerRequest" />
    <Snort rule="HackTool.BruteForce.HTTP.ServerRequest" />
    <Snort rule="HackTool.BruteForce.IMAP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.Kerberos.C&amp;C" />
    <Snort rule="HackTool.BruteForce.MQTT.ServerRequest" />
    <Snort rule="HackTool.BruteForce.POP3.C&amp;C" />
    <Snort rule="HackTool.BruteForce.RADIUS.C&amp;C" />
    <Snort rule="HackTool.BruteForce.RDP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.Rlogin.C&amp;C" />
    <Snort rule="HackTool.BruteForce.RTSP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.SMB.C&amp;C" />
    <Snort rule="HackTool.BruteForce.SMTP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.SSH.C&amp;C" />
    <Snort rule="HackTool.BurpCollaborator.HTTP.C&amp;C" />
    <Snort rule="HackTool.CertifyCas.LDAP.ServerRequest" />
    <Snort rule="HackTool.CertifyDownload.DCOM.ServerRequest" />
    <Snort rule="HackTool.CertifyFind.LDAP.ServerRequest" />
    <Snort rule="HackTool.CertifyPkiobjects.LDAP.ServerRequest" />
    <Snort rule="HackTool.ClearServicePrincipalName.LDAP.C&amp;C" />
    <Snort rule="HackTool.CmdStartup.DCERPC.C&amp;C" />
    <Snort rule="HackTool.Cmstp.HTTP.C&amp;C" />
    <Snort rule="HackTool.CommandStartup.DCERPC.C&amp;C" />
    <Snort rule="HackTool.CommunityBruteForce.SNMP.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.DCERPC.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.HTTP.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.LDAP.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.RDP.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.SMB.C&amp;C" />
    <Snort rule="HackTool.CrackMapExec.WinRM.C&amp;C" />
    <Snort rule="HackTool.CrackMapExecEnableRdp.WINREG.C&amp;C" />
    <Snort rule="HackTool.CrackMapExecNtds.DRSUAPI.C&amp;C" />
    <Snort rule="HackTool.CrackMapExecUsers.SAMR.C&amp;C" />
    <Snort rule="HackTool.CreateNewDomainController.DRSUAPI.C&amp;C" />
    <Snort rule="HackTool.CreateRequestExternalFile.SMB.C&amp;C" />
    <Snort rule="HackTool.CreateServiceCOMSPEC.SVCCTL.C&amp;C" />
    <Snort rule="HackTool.CreateServiceNtds.SVCCTL.C&amp;C" />
    <Snort rule="HackTool.CreateServiceStartCmd.SVCCTL.C&amp;C" />
    <Snort rule="HackTool.CreateServiceWINDOWSTemp.SVCCTL.C&amp;C" />
    <Snort rule="HackTool.Db2Version.DB2.C&amp;C" />
    <Snort rule="HackTool.Dcomexec.DCOM.C&amp;C" />
    <Snort rule="HackTool.DefaultWeblogic.TCP.ServerRequest" />
    <Snort rule="HackTool.DFSCoerce.DFSNM.C&amp;C" />
    <Snort rule="HackTool.DnsProbe.UDP.C&amp;C" />
    <Snort rule="HackTool.DnstoolAddAddRequest.LDAP.C&amp;C" />
    <Snort rule="HackTool.DnstoolAddSearchRequest.LDAP.C&amp;C" />
    <Snort rule="HackTool.DumpNtuserDat.SMB.C&amp;C" />
    <Snort rule="HackTool.DumpNtuserDat.TCP.C&amp;C" />
    <Snort rule="HackTool.Enum4Linux.SAMR.C&amp;C" />
    <Snort rule="HackTool.Enum4Linux.SMB.C&amp;C" />
    <Snort rule="HackTool.EnumAdBitlocker.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdComputers.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdGroups.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdManagedbyGroups.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdServicePrincipalNames.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdToWordlist.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdUserComments.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumAdUsers.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumDomainUsers.SAMR.C&amp;C" />
    <Snort rule="HackTool.EnumDontReqPreauth.LDAP.C&amp;C" />
    <Snort rule="HackTool.EnumerateSccm.LDAP.C&amp;C" />
    <Snort rule="HackTool.Enumeration.LDAP.C&amp;C" />
    <Snort rule="HackTool.EvilentCoerce.DCERPC.C&amp;C" />
    <Snort rule="HackTool.EvilentCoerce.SMB.C&amp;C" />
    <Snort rule="HackTool.ExecuteShellCommand.DCOM.C&amp;C" />
    <Snort rule="HackTool.Exfiltration.TCP.C&amp;C" />
    <Snort rule="HackTool.ExternalNegotiateProtocolResponse.SMB.C&amp;C" />
    <Snort rule="HackTool.ExternalSessionSetupResponse.SMB.C&amp;C" />
    <Snort rule="HackTool.Fscan.HTTP.C&amp;C" />
    <Snort rule="HackTool.GetAdDecodedPassword.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetAdmPwdPassword.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetADUsers.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetAppDataLocal.SMB.C&amp;C" />
    <Snort rule="HackTool.Get-GPPPassword.SMB.C&amp;C" />
    <Snort rule="HackTool.GetMsDSAllowedToActOnBehalfOfOtherIdentity.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetMsDSAllowedToDelegateTo.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetMsFVERecoveryPassword.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetOrclCommonAttribute.LDAP.C&amp;C" />
    <Snort rule="HackTool.GetUserSPNs.LDAP.C&amp;C" />
    <Snort rule="HackTool.GlobalSocket.TCP.C&amp;C" />
    <Snort rule="HackTool.GlobalSocket.TLS.C&amp;C" />
    <Snort rule="HackTool.GlobalSocket.UDP.C&amp;C" />
    <Snort rule="HackTool.GlobalSocketDownload.HTTP.C&amp;C" />
    <Snort rule="HackTool.Gobuster.HTTP.C&amp;C" />
    <Snort rule="HackTool.GOSimpleTunnel.DTLS.C&amp;C" />
    <Snort rule="HackTool.GOSimpleTunnel.HTTP.C&amp;C" />
    <Snort rule="HackTool.GOSimpleTunnel.ICMP.C&amp;C" />
    <Snort rule="HackTool.GOSimpleTunnel.TCP.C&amp;C" />
    <Snort rule="HackTool.Impacket.Kerberos.C&amp;C" />
    <Snort rule="HackTool.Impacket.SAMR.C&amp;C" />
    <Snort rule="HackTool.Impacket.SMB.C&amp;C" />
    <Snort rule="HackTool.ImpacketAddComputer.SMB.C&amp;C" />
    <Snort rule="HackTool.ImpacketAtExec.SMB.C&amp;C" />
    <Snort rule="HackTool.ImpacketLookupSid.SMB.C&amp;C" />
    <Snort rule="HackTool.ImpacketOpenSCManager.SVCCTL.C&amp;C" />
    <Snort rule="HackTool.ImpacketRegLsa.WINREG.C&amp;C" />
    <Snort rule="HackTool.ImpacketRegNTDS.WINREG.C&amp;C" />
    <Snort rule="HackTool.ImpacketRegSAM.WINREG.C&amp;C" />
    <Snort rule="HackTool.ImpacketRegSECURITY.WINREG.C&amp;C" />
    <Snort rule="HackTool.ImpacketRegSYSTEM.WINREG.C&amp;C" />
    <Snort rule="HackTool.ImpacketSecretsDump.SMB.C&amp;C" />
    <Snort rule="HackTool.ImpacketSmbExec.SMB.C&amp;C" />
    <Snort rule="HackTool.InvokeACLpwn.LDAP.ServerRequest" />
    <Snort rule="HackTool.IPCShare.SMB.ServerRequest" />
    <Snort rule="HackTool.ISFEnipScan.UDP.C&amp;C" />
    <Snort rule="HackTool.IXFRZoneTransferQ.TCP.ServerRequest" />
    <Snort rule="HackTool.IXFRZoneTransferS.TCP.ServerRequest" />
    <Snort rule="HackTool.Kali.DHCP.C&amp;C" />
    <Snort rule="HackTool.Kali.DNS.C&amp;C" />
    <Snort rule="HackTool.KaliDownload.HTTP.Download" />
    <Snort rule="HackTool.Kerberoasting.LDAP.C&amp;C" />
    <Snort rule="HackTool.KerbruteUserenum.Kerberos.C&amp;C" />
    <Snort rule="HackTool.KrbRelay.LDAP.C&amp;C" />
    <Snort rule="HackTool.LDAPDomainDump.LDAP.C&amp;C" />
    <Snort rule="HackTool.LDAPInjection.HTTP.C&amp;C" />
    <Snort rule="HackTool.LDAPInjection.LDAP.C&amp;C" />
    <Snort rule="HackTool.LdapRelayScan.LDAP.C&amp;C" />
    <Snort rule="HackTool.LdapRelayScan.TLS.C&amp;C" />
    <Snort rule="HackTool.LDAPSearch.LDAP.C&amp;C" />
    <Snort rule="HackTool.Masscan.HTTP.C&amp;C" />
    <Snort rule="HackTool.Masscan.HTTP.ServerRequest" />
    <Snort rule="HackTool.Metasploit.DCERPC.ServerRequest" />
    <Snort rule="HackTool.Metasploit.SMB.C&amp;C" />
    <Snort rule="HackTool.Meterpreter.TCP.C&amp;C" />
    <Snort rule="HackTool.Meterpreter.TLS.C&amp;C" />
    <Snort rule="HackTool.Mitm6.DHCPv6.C&amp;C" />
    <Snort rule="HackTool.MJET.HTTP.C&amp;C" />
    <Snort rule="HackTool.ModifyDCSyncGUIDs.LDAP.C&amp;C" />
    <Snort rule="HackTool.ModifyDSReplicationGetChanges.LDAP.C&amp;C" />
    <Snort rule="HackTool.ModifyDSReplicationGetChangesAll.LDAP.C&amp;C" />
    <Snort rule="HackTool.ModifyMsDSAdditionalDnsHostName.LDAP.C&amp;C" />
    <Snort rule="HackTool.ModifyMsDSAllowedToActOnBehalfOfOtherIdentity.LDAP.C&amp;C" />
    <Snort rule="HackTool.ModifyMsDSAllowedToDelegateTo.LDAP.C&amp;C" />
    <Snort rule="HackTool.Nessus.DCOM.C&amp;C" />
    <Snort rule="HackTool.Nessus.HTTP.C&amp;C" />
    <Snort rule="HackTool.Nessus.ICMP.C&amp;C" />
    <Snort rule="HackTool.Nessus.ICP.C&amp;C" />
    <Snort rule="HackTool.Nessus.SMB.C&amp;C" />
    <Snort rule="HackTool.Nessus.TCP.C&amp;C" />
    <Snort rule="HackTool.Nessus.TFTP.C&amp;C" />
    <Snort rule="HackTool.Nessus.UDP.C&amp;C" />
    <Snort rule="HackTool.NetExec.LDAP.C&amp;C" />
    <Snort rule="HackTool.NetExec.RPC.C&amp;C" />
    <Snort rule="HackTool.NetExec.TDS.C&amp;C" />
    <Snort rule="HackTool.NetworkScan.SNMP.C&amp;C" />
    <Snort rule="HackTool.Nikto.HTTP.C&amp;C" />
    <Snort rule="HackTool.Nmap.DB2.C&amp;C" />
    <Snort rule="HackTool.Nmap.DHCP.C&amp;C" />
    <Snort rule="HackTool.Nmap.DICOM.C&amp;C" />
    <Snort rule="HackTool.Nmap.HTTP.C&amp;C" />
    <Snort rule="HackTool.Nmap.HTTP.ServerRequest" />
    <Snort rule="HackTool.Nmap.ICAP.C&amp;C" />
    <Snort rule="HackTool.Nmap.LDAP.C&amp;C" />
    <Snort rule="HackTool.Nmap.mDNS.C&amp;C" />
    <Snort rule="HackTool.Nmap.MongoDB.C&amp;C" />
    <Snort rule="HackTool.Nmap.MySQL.C&amp;C" />
    <Snort rule="HackTool.Nmap.Portmap.C&amp;C" />
    <Snort rule="HackTool.Nmap.RDP.C&amp;C" />
    <Snort rule="HackTool.Nmap.RTSP.C&amp;C" />
    <Snort rule="HackTool.Nmap.SAMR.C&amp;C" />
    <Snort rule="HackTool.Nmap.SIP.ServerRequest" />
    <Snort rule="HackTool.Nmap.SMB.C&amp;C" />
    <Snort rule="HackTool.Nmap.SSL.C&amp;C" />
    <Snort rule="HackTool.Nmap.TCP.C&amp;C" />
    <Snort rule="HackTool.Nmap.TCP.ServerRequest" />
    <Snort rule="HackTool.Nmap.TFTP.ServerRequest" />
    <Snort rule="HackTool.Nmap.TLS.C&amp;C" />
    <Snort rule="HackTool.Nmap.UDP.C&amp;C" />
    <Snort rule="HackTool.NmapBruteForce.LDAP.C&amp;C" />
    <Snort rule="HackTool.NoiseStorm.ICMP.C&amp;C" />
    <Snort rule="HackTool.NPS.TCP.C&amp;C" />
    <Snort rule="HackTool.Ntlmrelayx.HTTP.C&amp;C" />
    <Snort rule="HackTool.Ntlmrelayx.LDAP.C&amp;C" />
    <Snort rule="HackTool.NtlmsspAuthExternalRequest.SMB.C&amp;C" />
    <Snort rule="HackTool.Oast.DNS.C&amp;C" />
    <Snort rule="HackTool.OpenVAS.HTTP.ServerRequest" />
    <Snort rule="HackTool.OverpassTheHash.Kerberos.C&amp;C" />
    <Snort rule="HackTool.PathTraversal.HTTP.C&amp;C" />
    <Snort rule="HackTool.PortScan.ECHO.C&amp;C" />
    <Snort rule="HackTool.PowerSCCM.IWbemLevel1Login.ServerRequest" />
    <Snort rule="HackTool.PowerSCCM.TDS.ServerRequest" />
    <Snort rule="HackTool.PowerShellStartup.DCERPC.C&amp;C" />
    <Snort rule="HackTool.PowerSploit.LDAP.C&amp;C" />
    <Snort rule="HackTool.PowerSploit.LDAP.ServerRequest" />
    <Snort rule="HackTool.PowerViewDomainEnum.LDAP.ServerRequest" />
    <Snort rule="HackTool.PowerViewGetDomainGroup.LDAP.C&amp;C" />
    <Snort rule="HackTool.PowerViewGetDomainUser.LDAP.ServerRequest" />
    <Snort rule="HackTool.PrinterBug.SPOOLSS.C&amp;C" />
    <Snort rule="HackTool.PrintSpoofer.SMB.C&amp;C" />
    <Snort rule="HackTool.PrivExchange.HTTP.C&amp;C" />
    <Snort rule="HackTool.PyWhisker.LDAP.C&amp;C" />
    <Snort rule="HackTool.ReconScan.HTTP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.ICMP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.IP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.SSDP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.TCP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.TFTP.ServerRequest" />
    <Snort rule="HackTool.ReconScan.UDP.ServerRequest" />
    <Snort rule="HackTool.RemotePotato.DCOM.C&amp;C" />
    <Snort rule="HackTool.RenameSamAccountName.LDAP.C&amp;C" />
    <Snort rule="HackTool.RenameUserPrincipalName.LDAP.C&amp;C" />
    <Snort rule="HackTool.Responder.NBNS.C&amp;C" />
    <Snort rule="HackTool.ResponderSMB.NTLMSSP.C&amp;C" />
    <Snort rule="HackTool.Retina.DCERPC.C&amp;C" />
    <Snort rule="HackTool.Retina.ECHO.C&amp;C" />
    <Snort rule="HackTool.Retina.RDP.C&amp;C" />
    <Snort rule="HackTool.Retina.RTSP.C&amp;C" />
    <Snort rule="HackTool.Retina.SIP.C&amp;C" />
    <Snort rule="HackTool.Retina.SMB.C&amp;C" />
    <Snort rule="HackTool.Retina.SNMP.C&amp;C" />
    <Snort rule="HackTool.Retina.SSH.C&amp;C" />
    <Snort rule="HackTool.Retina.TFTP.C&amp;C" />
    <Snort rule="HackTool.Retina.UDP.C&amp;C" />
    <Snort rule="HackTool.RoguePotato.DCOM.C&amp;C" />
    <Snort rule="HackTool.RogueWinRM.HTTP.C&amp;C" />
    <Snort rule="HackTool.RouterScan.HTTP.ServerRequest" />
    <Snort rule="HackTool.RpcclientBruteForceUsersRIDs.SAMR.C&amp;C" />
    <Snort rule="HackTool.Rpcmap.DCERPC.ServerRequest" />
    <Snort rule="HackTool.RPIVOT.TCP.C&amp;C" />
    <Snort rule="HackTool.Rubeus.Kerberos.C&amp;C" />
    <Snort rule="HackTool.RubeusASRepRoast.LDAP.C&amp;C" />
    <Snort rule="HackTool.SchRpcRegisterTask.ATSVC.C&amp;C" />
    <Snort rule="HackTool.SchRpcRun.ATSVC.C&amp;C" />
    <Snort rule="HackTool.Secretsdump.SMB.C&amp;C" />
    <Snort rule="HackTool.Secretsdump.WINREG.C&amp;C" />
    <Snort rule="HackTool.ShadowCoerce.FSRVP.ServerRequest" />
    <Snort rule="HackTool.ShadowCoerce.SMB.C&amp;C" />
    <Snort rule="HackTool.ShellExecute.DCOM.C&amp;C" />
    <Snort rule="HackTool.SipCLI.SIP.ServerRequest" />
    <Snort rule="HackTool.SIPScanner.SIP.C&amp;C" />
    <Snort rule="HackTool.SIPScanner.SIP.ServerRequest" />
    <Snort rule="HackTool.SIPVicious.UDP.ServerRequest" />
    <Snort rule="HackTool.Sliver.TLS.C&amp;C" />
    <Snort rule="HackTool.SOAPHound.ADWS.C&amp;C" />
    <Snort rule="HackTool.SPNEnumRubeus.LDAP.C&amp;C" />
    <Snort rule="HackTool.SQLMap.HTTP.C&amp;C" />
    <Snort rule="HackTool.SQLPowerInjector.HTTP.C&amp;C" />
    <Snort rule="HackTool.SQLScan.HTTP.C&amp;C" />
    <Snort rule="HackTool.SQLScan.TCP.C&amp;C" />
    <Snort rule="HackTool.SQLScan.TCP.ServerRequest" />
    <Snort rule="HackTool.SQLScan.TDS.ServerRequest" />
    <Snort rule="HackTool.SSF.TLS.C&amp;C" />
    <Snort rule="HackTool.StandIn.LDAP.C&amp;C" />
    <Snort rule="HackTool.StandIn.LDAP.ServerRequest" />
    <Snort rule="HackTool.STUNNER.HTTP.C&amp;C" />
    <Snort rule="HackTool.SuspiciousTGSEtypes.Kerberos.C&amp;C" />
    <Snort rule="HackTool.TGCD.TCP.C&amp;C" />
    <Snort rule="HackTool.THC-Hydra.HTTP.ServerRequest" />
    <Snort rule="HackTool.TNSPoison.TNS.C&amp;C" />
    <Snort rule="HackTool.TNSRCE.TNS.C&amp;C" />
    <Snort rule="HackTool.UPnP-Hack.SSDP.ServerRequest" />
    <Snort rule="HackTool.VulnScan.HTTP.C&amp;C" />
    <Snort rule="HackTool.WebShell.HTTP.C&amp;C" />
    <Snort rule="HackTool.WebShell.ORTHANC.C&amp;C" />
    <Snort rule="HackTool.WindapSearch.LDAP.C&amp;C" />
    <Snort rule="HackTool.WinPwn.TCP.C&amp;C" />
    <Snort rule="HackTool.WmiCmdCopy.DCERPC.C&amp;C" />
    <Snort rule="HackTool.WmiCmdVssadmin.DCERPC.C&amp;C" />
    <Snort rule="HackTool.Wmiexec.DCERPC.C&amp;C" />
    <Snort rule="HackTool.Wmiexec.SMB.C&amp;C" />
    <Snort rule="HackTool.Wmiquery.DCERPC.C&amp;C" />
    <Snort rule="HackTool.WMISploit.DCERPC.C&amp;C" />
    <Snort rule="HackTool.WSUSpendu.HTTP.C&amp;C" />
    <Snort rule="HackTool.XpCmdShell.TDS.ServerRequest" />
    <Snort rule="HackTool.XSSScript.HTTP.C&amp;C" />
    <Snort rule="Hoax.DeceptPCClean.HTTP.ServerRequest" />
    <Snort rule="Hoax.Phish.HTTP.C&amp;C" />
    <Snort rule="Hoax.Phish.SMTP.ServerRequest" />
    <Snort rule="NetTool.ActiveScriptEventConsumer.DCERPC.C&amp;C" />
    <Snort rule="NetTool.AddComputer.SMB.C&amp;C" />
    <Snort rule="NetTool.AdministratorAuth.NTLMSSP.C&amp;C" />
    <Snort rule="NetTool.AdminShareAccessDenied.SMB.C&amp;C" />
    <Snort rule="NetTool.AdminShareSuccess.SMB.C&amp;C" />
    <Snort rule="NetTool.AdsiPS.LDAP.ServerRequest" />
    <Snort rule="NetTool.AdvancedIPScanner.HTTP.C&amp;C" />
    <Snort rule="NetTool.AdvancedIPScanner.SNMP.C&amp;C" />
    <Snort rule="NetTool.AdvancedIPScanner.UDP.C&amp;C" />
    <Snort rule="NetTool.Agent.IPP.C&amp;C" />
    <Snort rule="NetTool.Agent.ReadMail.TFTP.C&amp;C" />
    <Snort rule="NetTool.Agent.ReadNetascii.TFTP.C&amp;C" />
    <Snort rule="NetTool.Agent.ReadOctet.TFTP.C&amp;C" />
    <Snort rule="NetTool.Agent.WriteMail.TFTP.C&amp;C" />
    <Snort rule="NetTool.Agent.WriteNetascii.TFTP.C&amp;C" />
    <Snort rule="NetTool.Agent.WriteOctet.TFTP.C&amp;C" />
    <Snort rule="NetTool.AlterContext.DRSUAPI.C&amp;C" />
    <Snort rule="NetTool.AlterContextIWbemServices.DCERPC.C&amp;C" />
    <Snort rule="NetTool.AnomalousICMP.ICMP.C&amp;C" />
    <Snort rule="NetTool.Aria2.HTTP.C&amp;C" />
    <Snort rule="NetTool.AuthenticationSimple.LDAP.C&amp;C" />
    <Snort rule="NetTool.AuthenticationSimpleCredentials.LDAP.C&amp;C" />
    <Snort rule="NetTool.AWSAWSRetrieveRDS.HTTP.C&amp;C" />
    <Snort rule="NetTool.AWSCreateEC2.HTTP.C&amp;C" />
    <Snort rule="NetTool.AWSInvokeLambda.HTTP.C&amp;C" />
    <Snort rule="NetTool.AWSListS3Buckets.HTTP.C&amp;C" />
    <Snort rule="NetTool.AWSPublishToSNS.HTTP.C&amp;C" />
    <Snort rule="NetTool.AXFRZoneTransfer.TCP.ServerRequest" />
    <Snort rule="NetTool.BindDFSNM.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindDRSUAPI.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindFSRVP.DCERPC.ServerRequest" />
    <Snort rule="NetTool.BindIDispatch.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindIOXIDResolver.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindIRemUnknown2.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindISystemActivator.DCERPC.ServerRequest" />
    <Snort rule="NetTool.BindLsarpcLSAD.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindNETLOGON.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindSAMR.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindSPOOLSS.DCERPC.C&amp;C" />
    <Snort rule="NetTool.BindSRVSVC.DCERPC.ServerRequest" />
    <Snort rule="NetTool.BindSVCCTL.DCERPC.ServerRequest" />
    <Snort rule="NetTool.BindTaskSchedulerService.DCERPC.C&amp;C" />
    <Snort rule="NetTool.Bitsadmin.HTTP.C&amp;C" />
    <Snort rule="NetTool.Capsa.DNS.C&amp;C" />
    <Snort rule="NetTool.Capsa.HTTP.C&amp;C" />
    <Snort rule="NetTool.Capsa.TLS.C&amp;C" />
    <Snort rule="NetTool.CenScan.HTTP.C&amp;C" />
    <Snort rule="NetTool.CenScan.TCP.C&amp;C" />
    <Snort rule="NetTool.CenScan.UDP.C&amp;C" />
    <Snort rule="NetTool.Certoc.HTTP.C&amp;C" />
    <Snort rule="NetTool.Certreq.HTTP.C&amp;C" />
    <Snort rule="NetTool.ChangeServiceConfig.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.ChangingUserPassAttempt.SAMR.ServerRequest" />
    <Snort rule="NetTool.CharlesProxy.DNS.C&amp;C" />
    <Snort rule="NetTool.CharlesProxy.HTTP.C&amp;C" />
    <Snort rule="NetTool.CharlesProxy.TLS.C&amp;C" />
    <Snort rule="NetTool.ClickOnceApplicationInstall.HTTP.C&amp;C" />
    <Snort rule="NetTool.CommandLineEventConsumer.DCERPC.C&amp;C" />
    <Snort rule="NetTool.CommonUNIXPrintingSystem.IPP.C&amp;C" />
    <Snort rule="NetTool.CommView.DNS.C&amp;C" />
    <Snort rule="NetTool.CommView.HTTP.C&amp;C" />
    <Snort rule="NetTool.CommView.TLS.C&amp;C" />
    <Snort rule="NetTool.Connect2.SAMR.C&amp;C" />
    <Snort rule="NetTool.Connect4.SAMR.C&amp;C" />
    <Snort rule="NetTool.Connect5.SAMR.C&amp;C" />
    <Snort rule="NetTool.ControlService.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.CopyRegistryDumpOutlook.TCP.C&amp;C" />
    <Snort rule="NetTool.CreateRequestFileWinreg.SMB.ServerRequest" />
    <Snort rule="NetTool.CreateUser2.SAMR.C&amp;C" />
    <Snort rule="NetTool.CUPSUserAgent.HTTP.Download" />
    <Snort rule="NetTool.cURLDelete.HTTP.C&amp;C" />
    <Snort rule="NetTool.cURLGet.HTTP.C&amp;C" />
    <Snort rule="NetTool.cURLHead.HTTP.C&amp;C" />
    <Snort rule="NetTool.cURLPatch.HTTP.C&amp;C" />
    <Snort rule="NetTool.cURLPost.HTTP.C&amp;C" />
    <Snort rule="NetTool.cURLPut.HTTP.C&amp;C" />
    <Snort rule="NetTool.DataSvcUtil.HTTP.C&amp;C" />
    <Snort rule="NetTool.Daze.HTTP.C&amp;C" />
    <Snort rule="NetTool.Daze.TCP.C&amp;C" />
    <Snort rule="NetTool.DDosAmplification.UDP.C&amp;C" />
    <Snort rule="NetTool.DefaultCommunity.SNMP.ServerRequest" />
    <Snort rule="NetTool.DHCPv6Advertise.UDP.C&amp;C" />
    <Snort rule="NetTool.Disco.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscoCreateChannel.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscoEditMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscoGetMe.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscoListMessages.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscordGatewayBot.HTTP.C&amp;C" />
    <Snort rule="NetTool.DiscoSendMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.DnsANYQuery.UDP.C&amp;C" />
    <Snort rule="NetTool.DomainPassInfo.SAMR.ServerRequest" />
    <Snort rule="NetTool.Download1Cdt.HTTP.C&amp;C" />
    <Snort rule="NetTool.Download1Cdt.TCP.C&amp;C" />
    <Snort rule="NetTool.Download1CEpf.HTTP.C&amp;C" />
    <Snort rule="NetTool.Download1CEpf.TCP.C&amp;C" />
    <Snort rule="NetTool.Dropbox.TLS.C&amp;C" />
    <Snort rule="NetTool.Dropbox.UDP.C&amp;C" />
    <Snort rule="NetTool.DropboxApi.TLS.C&amp;C" />
    <Snort rule="NetTool.DropboxContent.TLS.C&amp;C" />
    <Snort rule="NetTool.DropboxCreateFolder.HTTP.C&amp;C" />
    <Snort rule="NetTool.DropboxDelete.HTTP.C&amp;C" />
    <Snort rule="NetTool.DropboxDownloadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.DropboxListContent.HTTP.C&amp;C" />
    <Snort rule="NetTool.DropboxUploadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.EfsrpcPipe.SMB.ServerRequest" />
    <Snort rule="NetTool.EnableAdvancedOptions.TDS.ServerRequest" />
    <Snort rule="NetTool.EnumComputers.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumDomainTrusts.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumerateDomainTrusts.NETLOGON.C&amp;C" />
    <Snort rule="NetTool.EnumGroups.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumObjectClassGroup.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumOrganizationalUnits.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumPersons.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumPrintQueue.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumServicesStatus.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.EnumSubnets.LDAP.C&amp;C" />
    <Snort rule="NetTool.EnumUsersAndGroups.LDAP.C&amp;C" />
    <Snort rule="NetTool.Equinox.UDP.Updater" />
    <Snort rule="NetTool.ExecMethod.IWbemServices.C&amp;C" />
    <Snort rule="NetTool.ExecQuery.IWbemServices.C&amp;C" />
    <Snort rule="NetTool.ExecuteRemoteCommands.DCERPC.C&amp;C" />
    <Snort rule="NetTool.Fiddler.DNS.C&amp;C" />
    <Snort rule="NetTool.Fiddler.HTTP.C&amp;C" />
    <Snort rule="NetTool.Fiddler.TLS.C&amp;C" />
    <Snort rule="NetTool.FRP.TCP.C&amp;C" />
    <Snort rule="NetTool.GCalendarCreateEvent.HTTP.C&amp;C" />
    <Snort rule="NetTool.GCalendarDeleteEvent.HTTP.C&amp;C" />
    <Snort rule="NetTool.GCalendarGetEvent.HTTP.C&amp;C" />
    <Snort rule="NetTool.GCalendarList.HTTP.C&amp;C" />
    <Snort rule="NetTool.GCalendarUpdateEvent.HTTP.C&amp;C" />
    <Snort rule="NetTool.GDriveDeleteFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.GDriveDownloadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.GDriveListFiles.HTTP.C&amp;C" />
    <Snort rule="NetTool.GDriveUpdateFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.GDriveUploadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.GetAdministrator.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetAdmins.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetComputersServerDomainScope.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDnsAdmins.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDnsNode.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDnsRecord.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDnsZone.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDomainAdmins.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDomainControllers.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDomainControllersGpocmt.SMB.C&amp;C" />
    <Snort rule="NetTool.GetDomainControllersGptini.SMB.C&amp;C" />
    <Snort rule="NetTool.GetDomainControllersPolicy.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDomainPolicy.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetDomainPolicyGpocmt.SMB.C&amp;C" />
    <Snort rule="NetTool.GetInterdomainTrustAccount.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetMsDsMachineAccountQuota.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetObjectSid.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetReadOnlyDomainControllers.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetRemoteDesktopUsers.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetSamGroupObject.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetSamMachineAccount.LDAP.C&amp;C" />
    <Snort rule="NetTool.GetSamUserObject.LDAP.C&amp;C" />
    <Snort rule="NetTool.GitHubCreateComment.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubCreateRepo.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubCreateUpdateFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubCreateWebhook.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubDeleteRepo.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubGetComments.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubGetRepo.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubGetRepoContent.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubGetUser.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubGetWebhook.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubListRepos.HTTP.C&amp;C" />
    <Snort rule="NetTool.GitHubUpdateRepo.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleAppscriptCreateScript.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleAppscriptDeployScript.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleAppscriptGetScript.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleAppscriptRunScript.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleAppscriptUpdateScript.HTTP.C&amp;C" />
    <Snort rule="NetTool.Googlebot.HTTP.ServerRequest" />
    <Snort rule="NetTool.GoogleDocsCreateDoc.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleDocsDeleteText.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleDocsInsertText.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleDocsReadDoc.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleDocsReplaceText.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsAddToForm.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsAppendData.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsCreate.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsCreateForm.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsDeleteQuestion.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsGetFormAnswers.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsReadData.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsUpdateForm.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsUpdateProperties.HTTP.C&amp;C" />
    <Snort rule="NetTool.GoogleSheetsWriteData.HTTP.C&amp;C" />
    <Snort rule="NetTool.HTTPToolkit.DNS.C&amp;C" />
    <Snort rule="NetTool.HTTPToolkit.HTTP.C&amp;C" />
    <Snort rule="NetTool.HTTPToolkit.TLS.C&amp;C" />
    <Snort rule="NetTool.HuggingFace.TLS.C&amp;C" />
    <Snort rule="NetTool.HuggingFace.UDP.C&amp;C" />
    <Snort rule="NetTool.I2PReseed.TLS.C&amp;C" />
    <Snort rule="NetTool.I2PReseed.UDP.C&amp;C" />
    <Snort rule="NetTool.Industrial_BACnet_WriteConfiguration.UDP.C&amp;C" />
    <Snort rule="NetTool.Industrial_Bristol_StopPLC.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_DeltaV_EnableOnlineMode.UDP.C&amp;C" />
    <Snort rule="NetTool.Industrial_EtherSIO_Status_diag.UDP.C&amp;C" />
    <Snort rule="NetTool.Industrial_GEsrtp_PlcCopyFileFromTo.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_Mitsubishi_RemoteStop.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_MMS_CommonOperation.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_Relematika_WriteConfiguration.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_S7CommPlus_DeleteObj.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_S-Bus_WriteRegister.UDP.C&amp;C" />
    <Snort rule="NetTool.Industrial_SPAbus_WriteVariable.TCP.C&amp;C" />
    <Snort rule="NetTool.Industrial_VnetIP_Stop.UDP.C&amp;C" />
    <Snort rule="NetTool.InstAuth.HTTP.C&amp;C" />
    <Snort rule="NetTool.InstGetMedia.HTTP.C&amp;C" />
    <Snort rule="NetTool.InstGetToken.HTTP.C&amp;C" />
    <Snort rule="NetTool.InstRetrieveMedia.HTTP.C&amp;C" />
    <Snort rule="NetTool.IPCShare.SMB.ServerRequest" />
    <Snort rule="NetTool.IPv4overIPv4Tunneling.IP.C&amp;C" />
    <Snort rule="NetTool.IPv6overIPv4Tunneling.IP.C&amp;C" />
    <Snort rule="NetTool.ISystemActivator.DCOM.C&amp;C" />
    <Snort rule="NetTool.IWbemLevel1Login.DCERPC.ServerRequest" />
    <Snort rule="NetTool.IWbemLevel1Login.DCOM.C&amp;C" />
    <Snort rule="NetTool.IWbemServices.DCERPC.C&amp;C" />
    <Snort rule="NetTool.JavaUserAgent.HTTP.Download" />
    <Snort rule="NetTool.LdapQuery.ADWS.C&amp;C" />
    <Snort rule="NetTool.LDAPSearchDCEnum.LDAP.C&amp;C" />
    <Snort rule="NetTool.LsarEnumerateTrustedDomains.LSAD.C&amp;C" />
    <Snort rule="NetTool.LsarpcPipe.SMB.ServerRequest" />
    <Snort rule="NetTool.LsarRetrievePrivateData.LSAD.C&amp;C" />
    <Snort rule="NetTool.LwpDownloadUserAgent.HTTP.Download" />
    <Snort rule="NetTool.MediafireAuthUser.HTTP.C&amp;C" />
    <Snort rule="NetTool.MediafireDeleteFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.MediafireDownloadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.MediafireListFiles.HTTP.C&amp;C" />
    <Snort rule="NetTool.MediafireUploadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.Metascan.HTTP.C&amp;C" />
    <Snort rule="NetTool.MitmProxy.DNS.C&amp;C" />
    <Snort rule="NetTool.MitmProxy.HTTP.C&amp;C" />
    <Snort rule="NetTool.MitmProxy.TLS.C&amp;C" />
    <Snort rule="NetTool.ModifySecurityDescriptor.LDAP.ServerRequest" />
    <Snort rule="NetTool.MpCmdRun.HTTP.C&amp;C" />
    <Snort rule="NetTool.MsedgeHeadless.HTTP.C&amp;C" />
    <Snort rule="NetTool.Mshta.HTTP.C&amp;C" />
    <Snort rule="NetTool.Mshta.SMB.C&amp;C" />
    <Snort rule="NetTool.Msxsl.HTTP.C&amp;C" />
    <Snort rule="NetTool.NetAccountsDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetAddUserDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetGroupAdminDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetGroupAdminsAddUserDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetGroupDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetLocalgroupDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetLocalgroupDomainAdministrators.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetSess.SRVSVC.ServerRequest" />
    <Snort rule="NetTool.NetUserDomain.SAMR.C&amp;C" />
    <Snort rule="NetTool.NetworkMiner.DNS.C&amp;C" />
    <Snort rule="NetTool.NetworkMiner.HTTP.C&amp;C" />
    <Snort rule="NetTool.NetworkMiner.TLS.C&amp;C" />
    <Snort rule="NetTool.Ngrok.HTTP.C&amp;C" />
    <Snort rule="NetTool.Ngrok.TLS.C&amp;C" />
    <Snort rule="NetTool.Ngrok.UDP.C&amp;C" />
    <Snort rule="NetTool.Nltest.NETLOGON.C&amp;C" />
    <Snort rule="NetTool.Omnipeek.DNS.C&amp;C" />
    <Snort rule="NetTool.Omnipeek.HTTP.C&amp;C" />
    <Snort rule="NetTool.Omnipeek.TLS.C&amp;C" />
    <Snort rule="NetTool.OneDriveCreateFolder.HTTP.C&amp;C" />
    <Snort rule="NetTool.OneDriveDeleteFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.OneDriveDownloadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.OneDriveListFiles.HTTP.C&amp;C" />
    <Snort rule="NetTool.OneDriveUploadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.OpenAliasAdministrators.SAMR.C&amp;C" />
    <Snort rule="NetTool.OpenFile.TDS.ClientRequest" />
    <Snort rule="NetTool.OpenSCManager.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.OpenSCManager.SVCCTL.ServerRequest" />
    <Snort rule="NetTool.OpenSSHForWindows.SSH.C&amp;C" />
    <Snort rule="NetTool.OpenUser.SAMR.C&amp;C" />
    <Snort rule="NetTool.OpenVPNByTCP.OpenVPN.C&amp;C" />
    <Snort rule="NetTool.OpenVPNByUDP.OpenVPN.C&amp;C" />
    <Snort rule="NetTool.OracleCheckVersion.TNS.C&amp;C" />
    <Snort rule="NetTool.PermissionDenied.FTP.C&amp;C" />
    <Snort rule="NetTool.Pitunnel.HTTP.C&amp;C" />
    <Snort rule="NetTool.Pitunnel.TCP.C&amp;C" />
    <Snort rule="NetTool.Pitunnel.TLS.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.FTP.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.HTTP.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.IMAP.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.POP3.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.SMTP.C&amp;C" />
    <Snort rule="NetTool.PlainTextCredentials.SNMP.C&amp;C" />
    <Snort rule="NetTool.PowerDNScout.UDP.C&amp;C" />
    <Snort rule="NetTool.PowerShellGet.HTTP.C&amp;C" />
    <Snort rule="NetTool.PowerShellPost.HTTP.C&amp;C" />
    <Snort rule="NetTool.PowerShellUA.HTTP.C&amp;C" />
    <Snort rule="NetTool.PPTPTunnel.PPTP.C&amp;C" />
    <Snort rule="NetTool.PrinterInfoStatus.PJL.C&amp;C" />
    <Snort rule="NetTool.ProcessStartup.DCERPC.C&amp;C" />
    <Snort rule="NetTool.PSAD.LDAP.ServerRequest" />
    <Snort rule="NetTool.PsiphonVPN.HTTP.C&amp;C" />
    <Snort rule="NetTool.PsLoggedOn.SMB.ServerRequest" />
    <Snort rule="NetTool.PythonParamiko.SSH.C&amp;C" />
    <Snort rule="NetTool.PythonUserAgent.HTTP.Download" />
    <Snort rule="NetTool.Qemu.QEMU.C&amp;C" />
    <Snort rule="NetTool.QueryDomainInfo.SAMR.C&amp;C" />
    <Snort rule="NetTool.QueryForestTrustInfo.LSAD.C&amp;C" />
    <Snort rule="NetTool.QueryServiceConfig.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.QueryServiceStatus.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.RCEAttempt.SMB.ServerRequest" />
    <Snort rule="NetTool.RedirectForHost.ICMP.C&amp;C" />
    <Snort rule="NetTool.RefractionNetworking.HTTP.C&amp;C" />
    <Snort rule="NetTool.ResticUserAgent.HTTP.Download" />
    <Snort rule="NetTool.RouterAdvertisement.ICMPv6.C&amp;C" />
    <Snort rule="NetTool.RpcclientEnumdomgroups.SAMR.C&amp;C" />
    <Snort rule="NetTool.RpcclientEnumdomusers.SAMR.C&amp;C" />
    <Snort rule="NetTool.RpcclientNetshareenumall.SRVSVC.C&amp;C" />
    <Snort rule="NetTool.RpcclientQuerydispinfo.SAMR.C&amp;C" />
    <Snort rule="NetTool.Rpcping.DCERPC.C&amp;C" />
    <Snort rule="NetTool.Rsync.HTTP.C&amp;C" />
    <Snort rule="NetTool.RubyUserAgent.HTTP.Download" />
    <Snort rule="NetTool.SearchKerbDelegatedAccounts.LDAP.C&amp;C" />
    <Snort rule="NetTool.SearchReqUsersFindUsersWithSidHistorySet.LDAP.ServerRequest" />
    <Snort rule="NetTool.SecureSocketTunneling.HTTP.C&amp;C" />
    <Snort rule="NetTool.SharpAdidnsdump.LDAP.C&amp;C" />
    <Snort rule="NetTool.Shellhub.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackChatPostMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackConversationsList.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackFilesCompleteUploadExternal.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackFilesRemoteAdd.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackFilesUpload.HTTP.C&amp;C" />
    <Snort rule="NetTool.SlackUploadPE.HTTP.C&amp;C" />
    <Snort rule="NetTool.SmartSniff.DNS.C&amp;C" />
    <Snort rule="NetTool.SmartSniff.HTTP.C&amp;C" />
    <Snort rule="NetTool.SmartSniff.TLS.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkCreatePost.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkDeletePost.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkGetComments.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkGetUser.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkListPhotos.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkPostComment.HTTP.C&amp;C" />
    <Snort rule="NetTool.SocialNetworkUploadPhoto.HTTP.C&amp;C" />
    <Snort rule="NetTool.SOCKS4ByTCP.SOCKS4.C&amp;C" />
    <Snort rule="NetTool.SOCKS4ByUDP.SOCKS4.C&amp;C" />
    <Snort rule="NetTool.SOCKS5ByTCP.SOCKS5.C&amp;C" />
    <Snort rule="NetTool.SOCKS5ByUDP.SOCKS5.C&amp;C" />
    <Snort rule="NetTool.SoftEtherVPN.UDP.C&amp;C" />
    <Snort rule="NetTool.SoftPerfectNetworkScanner.DNS.C&amp;C" />
    <Snort rule="NetTool.SoftPerfectNetworkScanner.TLS.C&amp;C" />
    <Snort rule="NetTool.StartService.SVCCTL.C&amp;C" />
    <Snort rule="NetTool.SuspiciousMultiSQLLoginFailed.TDS.ServerRequest" />
    <Snort rule="NetTool.SuspiciousMultiSqlSAConnect.TDS.ServerRequest" />
    <Snort rule="NetTool.Sysinternals.TCP.ServerRequest" />
    <Snort rule="NetTool.TaskSchedulerServiceCreateFolder.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceDeleteTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceEnableTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceEndTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceEnumFolders.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceEnumInstances.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceEnumTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceGetInstanceInfo.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceGetLastRun.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceGetNumberOfMissedRuns.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceGetSecurity.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceGetTaskInfo.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceRegisterTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceRenameTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceRetriveTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceRunTask.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceScheduledRuntimes.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceSetSecurity.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TaskSchedulerServiceStopInstance.DCERPC.C&amp;C" />
    <Snort rule="NetTool.TelegramDeleteMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.TelegramEditMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.TelegramGetBotUpdates.HTTP.C&amp;C" />
    <Snort rule="NetTool.TelegramMessenger.HTTP.C&amp;C" />
    <Snort rule="NetTool.TelegramSendMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.TelegramSendPhoto.HTTP.C&amp;C" />
    <Snort rule="NetTool.Terrahost.UDP.C&amp;C" />
    <Snort rule="NetTool.Test-Wsman-Ping.WinRM.C&amp;C" />
    <Snort rule="NetTool.Test-Wsman-Pong.WinRM.C&amp;C" />
    <Snort rule="NetTool.TgsReqRPCSS.Kerberos.C&amp;C" />
    <Snort rule="NetTool.Tmate.SSH.C&amp;C" />
    <Snort rule="NetTool.TorTerrahost.UDP.C&amp;C" />
    <Snort rule="NetTool.TorTool.HTTP.C&amp;C" />
    <Snort rule="NetTool.TorTool.SSL.C&amp;C" />
    <Snort rule="NetTool.TorTool.TCP.C&amp;C" />
    <Snort rule="NetTool.TorTool.UDP.C&amp;C" />
    <Snort rule="NetTool.TorToolE.TCP.C&amp;C" />
    <Snort rule="NetTool.TryCloudflare.DNS.C&amp;C" />
    <Snort rule="NetTool.TunnelBeeceptor.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelBeeceptor.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelBore.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelBore.TCP.C&amp;C" />
    <Snort rule="NetTool.TunnelBTunnel.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelBTunnel.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelExpose.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelExpose.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelExpose.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelJkuribore.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelJprq.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalhostrun.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalhostrun.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocaltonet.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocaltonet.TCP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocaltonet.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelLocaltonet.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalTunnelMe.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalTunnelMe.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalTunnelMe.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalXpose.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalXpose.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelLocalXpose.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelPageKite.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelPageKite.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelPageKite.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelPinggy.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelPinggy.SSH.C&amp;C" />
    <Snort rule="NetTool.TunnelPinggy.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelPinggy.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelServeo.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelServeo.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelServeo.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelStaqLab.UDP.C&amp;C" />
    <Snort rule="NetTool.TunnelTryCloudflare.DNS.C&amp;C" />
    <Snort rule="NetTool.TunnelTryCloudflare.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelVisualStudio.HTTP.C&amp;C" />
    <Snort rule="NetTool.TunnelVisualStudio.TLS.C&amp;C" />
    <Snort rule="NetTool.TunnelVisualStudio.UDP.C&amp;C" />
    <Snort rule="NetTool.TwitterCreateTweet.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterDeleteTweet.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterGetTweets.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterGetUser.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterQuoteTweets.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterSearchTweets.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterSendMessage.HTTP.C&amp;C" />
    <Snort rule="NetTool.TwitterStreamTweets.HTTP.C&amp;C" />
    <Snort rule="NetTool.UDIDLeak.HTTP.ServerRequest" />
    <Snort rule="NetTool.UploadFile.TDS.ClientRequest" />
    <Snort rule="NetTool.ViaRecordMex.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordUserNameAccountManagement.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordUserNameEnumeration.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordUserNameResource.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordUserNameResourceFactory.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordUserNameTopologyManagement.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordWindowsAccountManagement.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordWindowsEnumeration.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordWindowsResource.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordWindowsResourceFactory.ADWS.C&amp;C" />
    <Snort rule="NetTool.ViaRecordWindowsTopologyManagement.ADWS.C&amp;C" />
    <Snort rule="NetTool.VpnCloud.UDP.C&amp;C" />
    <Snort rule="NetTool.VulnScannerNERVE.HTTP.C&amp;C" />
    <Snort rule="NetTool.WBEMTEST.DCERPC.C&amp;C" />
    <Snort rule="NetTool.Wget.HTTP.C&amp;C" />
    <Snort rule="NetTool.WinGet.HTTP.C&amp;C" />
    <Snort rule="NetTool.WinPcap.DNS.C&amp;C" />
    <Snort rule="NetTool.WinPcap.HTTP.C&amp;C" />
    <Snort rule="NetTool.WinPcap.TLS.C&amp;C" />
    <Snort rule="NetTool.WireGuard.UDP.C&amp;C" />
    <Snort rule="NetTool.Wireshark.DNS.C&amp;C" />
    <Snort rule="NetTool.Wireshark.HTTP.C&amp;C" />
    <Snort rule="NetTool.Wireshark.TLS.C&amp;C" />
    <Snort rule="NetTool.WmiAccessDenied.DCERPC.C&amp;C" />
    <Snort rule="NetTool.WMIWin32Process.DCERPC.C&amp;C" />
    <Snort rule="NetTool.WMIWin32Product.DCERPC.C&amp;C" />
    <Snort rule="NetTool.WpadDnsReponseOverIPv6.UDP.C&amp;C" />
    <Snort rule="NetTool.WPADIPv6.UDP.ServerRequest" />
    <Snort rule="NetTool.WqlEventQuery.DCERPC.C&amp;C" />
    <Snort rule="NetTool.XpCmdShell.TDS.ClientRequest" />
    <Snort rule="NetTool.YaDiskDownloadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.YaDiskUploadFile.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeDeleteVideo.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeInsertComment.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeListComments.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeListVideos.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeReplyComment.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeUpdateVideo.HTTP.C&amp;C" />
    <Snort rule="NetTool.YouTubeUploadVideo.HTTP.C&amp;C" />
    <Snort rule="Net-Worm.Kido.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.ADWSAccountManagement.MC-NMF.ServerRequest" />
    <Snort rule="RemoteAdmin.AeroAdmin.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.AeroAdmin.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.Ammyy.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.Ammyy.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.Ammyy.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.AnyDesk.HTTP.ServerRequest" />
    <Snort rule="RemoteAdmin.AnyDesk.TLS.ServerRequest" />
    <Snort rule="RemoteAdmin.AnyDesk.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.Dameware.DNS.C&amp;C" />
    <Snort rule="RemoteAdmin.Dameware.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.Dameware.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.imPcRemote.DNS.C&amp;C" />
    <Snort rule="RemoteAdmin.imPcRemote.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.imPcRemote.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.ISLOnline.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.KonturDostup.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.KonturDostup.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.LiteManager.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.LiteManager.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.MSRemoteDesktopConnection.RDP.C&amp;C" />
    <Snort rule="RemoteAdmin.MyAssist.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.MyAssist.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.MyAssist.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.MyAssist.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.PandoraRC.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.PandoraRC.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.PsExec.SMB.C&amp;C" />
    <Snort rule="RemoteAdmin.PsExec.SMB.ServerRequest" />
    <Snort rule="RemoteAdmin.RemoteUtilities.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.RMS.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.RustDesk.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.RustDesk.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.Syncro.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.TeamViewer.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.TeamViewer.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.ToDesk.DNS.C&amp;C" />
    <Snort rule="RemoteAdmin.UltraViewer.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.UltraViewer.UDP.C&amp;C" />
    <Snort rule="RemoteAdmin.WinRM.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.WinVNC.RFB.C&amp;C" />
    <Snort rule="RemoteAdmin.Zoho.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.Zoho.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.Zoho.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARadw1.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARadw2.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARadw3.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARr1.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARr2.UDP.C&amp;C" />
    <Snort rule="RiskTool.EICARr3.UDP.C&amp;C" />
    <Snort rule="RiskTool.Miner.UDP.C&amp;C" />
    <Snort rule="Server-Proxy.3proxy.HTTP.C&amp;C" />
    <Snort rule="Server-Proxy.3proxy.POP3.C&amp;C" />
    <Snort rule="Server-Proxy.Honeygain.TLS.C&amp;C" />
    <Snort rule="Server-Proxy.TinyProxy.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.SMTP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.C&amp;C" />
    <Snort rule="Trojan.Dyns.HTTP.ServerRequest" />
    <Snort rule="Trojan.EICARa1.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARa2.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARa3.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARg1.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARg2.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARg3.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARs.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARt1.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARt2.UDP.C&amp;C" />
    <Snort rule="Trojan.EICARt3.UDP.C&amp;C" />
    <Snort rule="Trojan.EICAR-Test.HTTP.ServerRequest" />
    <Snort rule="Trojan.EICAR-Test-File.HTTP.Download" />
    <Snort rule="Trojan.EICAR-Test-File.TCP.Download" />
    <Snort rule="Trojan.EICAR-Test-File.UDP.Download" />
    <Snort rule="Trojan.Industroyer.TCP.C&amp;C" />
    <Snort rule="Trojan.Miner.TCP.C&amp;C" />
    <Snort rule="Trojan.Miner.UDP.C&amp;C" />
    <Snort rule="Trojan.Ramnit.HTTP.Download" />
    <Snort rule="Trojan.Ramnit.HTTP.ServerRequest" />
    <Snort rule="Trojan.Sshsnake.TCP.C&amp;C" />
    <Snort rule="Trojan.StartUper.SMB.C&amp;C" />
    <Snort rule="Trojan-DDoS.CLDAP.UDP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Miner.HTTP.Download" />
    <Snort rule="Trojan-PSW.Mimikatz.Kerberos.C&amp;C" />
    <Snort rule="Trojan-PSW.Mimikatz.SMB.C&amp;C" />
    <Snort rule="Trojan-PSW.Mimikatz.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.DeathBot.HTTP.C&amp;C" Avp3="HackTool.Java.DeathBot.a" />
  <Malware Snort="HackTool.Agent.HTTP.C&amp;C" Avp3="HackTool.MSIL.Agent.a" />
  <Malware Snort="HackTool.DnsExf.UDP.C&amp;C" Avp3="HackTool.MSIL.DnsExf.a" />
  <Malware Snort="HackTool.GameHack.HTTP.C&amp;C" Avp3="HackTool.MSIL.GameHack.a" />
  <Malware Snort="HackTool.PoshC2.HTTP.C&amp;C" Avp3="HackTool.MSIL.PoshC2.a" />
  <Malware Snort="HackTool.Rubeus.Kerberos.C&amp;C" Avp3="HackTool.MSIL.Rubeus.a" />
  <Malware Avp3="HackTool.MSOffice.Agent.a">
    <Snort rule="HackTool.Agent.HTTP.C&amp;C" />
    <Snort rule="HackTool.Agent.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.BloodHound.HTTP.ServerRequest" Avp3="HackTool.PowerShell.BloodHound.a" />
  <Malware Snort="HackTool.DNSlivery.UDP.C&amp;C" Avp3="HackTool.PowerShell.DNSlivery.a" />
  <Malware Snort="HackTool.PowerSploit.TCP.C&amp;C" Avp3="HackTool.PowerShell.PowerSploit.a" />
  <Malware Snort="HackTool.ReDuh.HTTP.C&amp;C" Avp3="HackTool.Script.ReDuh.a" />
  <Malware Snort="HackTool.Agent.ICMP.C&amp;C" Avp3="HackTool.Win32.Agent.a" />
  <Malware Snort="HackTool.Atexec.ATSVC.C&amp;C" Avp3="HackTool.Win32.Atexec.a" />
  <Malware Snort="HackTool.Binder.TCP.ServerRequest" Avp3="HackTool.Win32.Binder.gen" />
  <Malware Snort="HackTool.BlueCode.HTTP.ServerRequest" Avp3="HackTool.Win32.BlueCode.a" />
  <Malware Avp3="HackTool.Win32.BruteForce.a">
    <Snort rule="HackTool.BruteForce.FTP.C&amp;C" />
    <Snort rule="HackTool.BruteForce.HTTP.ServerRequest" />
    <Snort rule="HackTool.BruteForce.TDS.ServerRequest" />
  </Malware>
  <Malware Snort="HackTool.BurpCollaborator.UDP.C&amp;C" Avp3="HackTool.Win32.BurpCollaborator.a" />
  <Malware Snort="HackTool.Bypass.HTTP.C&amp;C" Avp3="HackTool.Win32.Bypass.a" />
  <Malware Avp3="HackTool.Win32.Chisel.a">
    <Snort rule="HackTool.Chisel.HTTP.C&amp;C" />
    <Snort rule="HackTool.Chisel.WebSocket.C&amp;C" />
  </Malware>
  <Malware Avp3="HackTool.Win32.Cobalt.a">
    <Snort rule="HackTool.Cobalt.HTTP.C&amp;C" />
    <Snort rule="HackTool.Cobalt.HTTP.ServerRequest" />
    <Snort rule="HackTool.Cobalt.SMTP.C&amp;C" />
    <Snort rule="HackTool.Cobalt.TCP.C&amp;C" />
    <Snort rule="HackTool.Cobalt.UDP.C&amp;C" />
    <Snort rule="HackTool.Cobalt.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="HackTool.DavRelayUp.Kerberos.C&amp;C" Avp3="HackTool.Win32.DavRelayUp.a" />
  <Malware Snort="HackTool.Dnscat.UDP.C&amp;C" Avp3="HackTool.Win32.Dnscat.a" />
  <Malware Snort="HackTool.Dnscat2.UDP.C&amp;C" Avp3="HackTool.Win32.Dnscat2.a" />
  <Malware Snort="HackTool.Dnslog.UDP.C&amp;C" Avp3="HackTool.Win32.Dnslog.a" />
  <Malware Snort="HackTool.DnslogCn.UDP.C&amp;C" Avp3="HackTool.Win32.DnslogCn.a" />
  <Malware Snort="HackTool.DnslogStore.UDP.C&amp;C" Avp3="HackTool.Win32.DnslogStore.a" />
  <Malware Snort="HackTool.DragonCastle.WINREG.ServerRequest" Avp3="HackTool.Win32.DragonCastle.a" />
  <Malware Snort="HackTool.FileTunnel.SMB.C&amp;C" Avp3="HackTool.Win32.FileTunnel.a" />
  <Malware Avp3="HackTool.Win32.FlyStudio.a">
    <Snort rule="HackTool.FlyStudio.HTTP.C&amp;C" />
    <Snort rule="HackTool.FlyStudio.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="HackTool.GameHack.HTTP.C&amp;C" Avp3="HackTool.Win32.GameHack.a" />
  <Malware Snort="HackTool.Gophish.HTTP.C&amp;C" Avp3="HackTool.Win32.Gophish.a" />
  <Malware Snort="HackTool.GOSimpleTunnel.HTTP.C&amp;C" Avp3="HackTool.Win32.GOSimpleTunnel.a" />
  <Malware Snort="HackTool.Impacket.SMB.C&amp;C" Avp3="HackTool.Win32.Impacket.a" />
  <Malware Snort="HackTool.Inject.HTTP.ServerRequest" Avp3="HackTool.Win32.Inject.a" />
  <Malware Snort="HackTool.Iodine.DNS.C&amp;C" Avp3="HackTool.Win32.Iodine.a" />
  <Malware Avp3="HackTool.Win32.KMSAuto.a">
    <Snort rule="HackTool.KMSAuto.HTTP.ServerRequest" />
    <Snort rule="HackTool.KMSAuto.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.Koadic.HTTP.C&amp;C" Avp3="HackTool.Win32.Koadic.a" />
  <Malware Avp3="HackTool.Win32.LateralMovement.a">
    <Snort rule="HackTool.LateralMovement.DCOM.C&amp;C" />
    <Snort rule="HackTool.LateralMovement.NetBIOS.C&amp;C" />
  </Malware>
  <Malware Avp3="HackTool.Win32.Metasploit.a">
    <Snort rule="HackTool.Metasploit.HTTP.C&amp;C" />
    <Snort rule="HackTool.Metasploit.TCP.C&amp;C" />
    <Snort rule="HackTool.Metasploit.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.Meterpreter.TCP.C&amp;C" Avp3="HackTool.Win32.Meterpreter.a" />
  <Malware Snort="HackTool.NeoReGeorg.HTTP.C&amp;C" Avp3="HackTool.Win32.NeoReGeorg.a" />
  <Malware Snort="HackTool.NetBiosSpoofer.NBNS.C&amp;C" Avp3="HackTool.Win32.NetBiosSpoofer.a" />
  <Malware Snort="HackTool.Nmap.HTTP.C&amp;C" Avp3="HackTool.Win32.Nmap.a" />
  <Malware Snort="HackTool.NPS.TCP.C&amp;C" Avp3="HackTool.Win32.NPS.a" />
  <Malware Snort="HackTool.PAExec.SMB.C&amp;C" Avp3="HackTool.Win32.PAExec.a" />
  <Malware Snort="HackTool.PowerSploit.HTTP.ServerRequest" Avp3="HackTool.Win32.PowerSploit.a" />
  <Malware Snort="HackTool.RemCom.SMB.C&amp;C" Avp3="HackTool.Win32.RemCom.a" />
  <Malware Avp3="HackTool.Win32.Responder.a">
    <Snort rule="HackTool.Responder.HTTP.C&amp;C" />
    <Snort rule="HackTool.Responder.LDAP.C&amp;C" />
    <Snort rule="HackTool.Responder.NetBIOS.C&amp;C" />
    <Snort rule="HackTool.Responder.SMB.C&amp;C" />
    <Snort rule="HackTool.Responder.SMTP.C&amp;C" />
    <Snort rule="HackTool.Responder.TCP.C&amp;C" />
    <Snort rule="HackTool.Responder.TDS.C&amp;C" />
    <Snort rule="HackTool.Responder.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.Scanner.HTTP.C&amp;C" Avp3="HackTool.Win32.Scanner.a" />
  <Malware Snort="HackTool.SIPScanner.SIP.C&amp;C" Avp3="HackTool.Win32.SIPScanner.a" />
  <Malware Avp3="HackTool.Win32.Sliver.a">
    <Snort rule="HackTool.Sliver.HTTP.C&amp;C" />
    <Snort rule="HackTool.Sliver.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.SMBRelay.POP3.C&amp;C" Avp3="HackTool.Win32.SMBRelay.a" />
  <Malware Avp3="HackTool.Win32.Stowaway.a">
    <Snort rule="HackTool.Stowaway.HTTP.C&amp;C" />
    <Snort rule="HackTool.Stowaway.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.WebShell.HTTP.C&amp;C" Avp3="HackTool.Win32.WebShell.a" />
  <Malware Avp3="HackTool.Win64.DogTunnel.a">
    <Snort rule="HackTool.DogTunnel.TCP.C&amp;C" />
    <Snort rule="HackTool.DogTunnel.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="HackTool.FusoProxy.TCP.C&amp;C" Avp3="HackTool.Win64.FusoProxy.a" />
  <Malware Snort="HackTool.Rsocket.TCP.C&amp;C" Avp3="HackTool.Win64.Rsocket.a" />
  <Malware Snort="Hoax.Phish.HTTP.C&amp;C" Avp3="Hoax.HTML.Phish.a" />
  <Malware Snort="Hoax.Phish.HTTP.C&amp;C" Avp3="Hoax.RTF.Phish.a" />
  <Malware Snort="Hoax.ArchSMS.HTTP.ServerRequest" Avp3="Hoax.Win32.ArchSMS.a" />
  <Malware Snort="Hoax.DeceptPCClean.HTTP.ServerRequest" Avp3="Hoax.Win32.DeceptPCClean.a" />
  <Malware Snort="Hoax.PCChist.HTTP.C&amp;C" Avp3="Hoax.Win32.PCChist.a" />
  <Malware Snort="Hoax.Phish.HTTP.C&amp;C" Avp3="Hoax.Win32.Phish.a" />
  <Malware Snort="Hoax.SafeCleaner.HTTP.C&amp;C" Avp3="Hoax.Win32.SafeCleaner.a" />
  <Malware Snort="Hoax.SpeedUpMyPC.HTTP.C&amp;C" Avp3="Hoax.Win32.SpeedUpMyPC.a" />
  <Malware Snort="IM-Worm.Ckbface.IP.ServerRequest" Avp3="IM-Worm.Win32.Ckbface.a" />
  <Malware Snort="IM-Worm.Sohanad.HTTP.C&amp;C" Avp3="IM-Worm.Win32.Sohanad.a" />
  <Malware Avp3="KICS4Net IDSIR test packet is detected">
    <Snort rule="KICS4Net IDSIR test packet is detected" />
    <Snort rule="KICS4Net IDSIR test SECOND packet is detected" />
  </Malware>
  <Malware Snort="Net-Worm.Aspxor.HTTP.C&amp;C" Avp3="Net-Worm.Win32.Aspxor.a" />
  <Malware Avp3="Net-Worm.Win32.Kido.a">
    <Snort rule="Net-Worm.Kido.TCP.C&amp;C" />
    <Snort rule="Net-Worm.Kido.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Net-Worm.Koobface.HTTP.C&amp;C" Avp3="Net-Worm.Win32.Koobface.a" />
  <Malware Snort="AdWare.BrowseFox.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.MSIL.BrowseFox.a" />
  <Malware Snort="AdWare.Dotdo.HTTP.Download" Avp3="not-a-virus:AdWare.MSIL.Dotdo.a" />
  <Malware Snort="AdWare.Zaitu.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.NSIS.Zaitu.a" />
  <Malware Snort="AdWare.Bnodlero.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.OSX.Bnodlero.a" />
  <Malware Snort="AdWare.Ketin.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.OSX.Ketin.a" />
  <Malware Snort="AdWare.4Shared.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.4Shared.a" />
  <Malware Snort="AdWare.Ad2345.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Ad2345.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.AdLoad.a">
    <Snort rule="AdWare.AdLoad.HTTP.ServerRequest" />
    <Snort rule="AdWare.AdLoad.UDP.C&amp;C" />
    <Snort rule="AdWare.AdLoad.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.Adposhel.a">
    <Snort rule="AdWare.Adposhel.HTTP.C&amp;C" />
    <Snort rule="AdWare.Adposhel.HTTP.Notification" />
    <Snort rule="AdWare.Adposhel.HTTP.ServerRequest" />
    <Snort rule="AdWare.Adposhel.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.Agent.a">
    <Snort rule="AdWare.Agent.HTTP.C&amp;C" />
    <Snort rule="AdWare.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.AirAdInstaller.a">
    <Snort rule="AdWare.AirAdInstaller.HTTP.ServerRequest" />
    <Snort rule="AdWare.AirAdInstaller.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.Amonetize.a">
    <Snort rule="AdWare.Amonetize.HTTP.C&amp;C" />
    <Snort rule="AdWare.Amonetize.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.Bang5mai.a">
    <Snort rule="AdWare.Bang5mai.HTTP.C&amp;C" />
    <Snort rule="AdWare.Bang5mai.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="AdWare.Browext.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Browext.a" />
  <Malware Snort="AdWare.BrowSecX.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.BrowSecX.a" />
  <Malware Snort="AdWare.BrowseFox.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.BrowseFox.a" />
  <Malware Snort="AdWare.Bundle.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Bundle.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.Burden.a">
    <Snort rule="AdWare.Burden.HTTP.C&amp;C" />
    <Snort rule="AdWare.Burden.HTTP.Download" />
  </Malware>
  <Malware Snort="AdWare.CognosAds.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.CognosAds.a" />
  <Malware Snort="AdWare.ConvertAd.HTTP.Download" Avp3="not-a-virus:AdWare.Win32.ConvertAd.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.CrossRider.a">
    <Snort rule="AdWare.CrossRider.HTTP.C&amp;C" />
    <Snort rule="AdWare.CrossRider.HTTP.ServerRequest" />
    <Snort rule="AdWare.CrossRider.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.DealPly.a">
    <Snort rule="AdWare.DealPly.HTTP.Notification" />
    <Snort rule="AdWare.DealPly.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.DLBoost.a">
    <Snort rule="AdWare.DLBoost.HTTP.C&amp;C" />
    <Snort rule="AdWare.DLBoost.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="AdWare.DownloadHelper.UDP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.DownloadHelper.a" />
  <Malware Snort="AdWare.Eorezo.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Eorezo.a" />
  <Malware Snort="AdWare.EZula.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.EZula.a" />
  <Malware Snort="AdWare.FileFinder.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.FileFinder.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.FileTour.a">
    <Snort rule="AdWare.FileTour.HTTP.C&amp;C" />
    <Snort rule="AdWare.FileTour.HTTP.Download" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.FlyStudio.a">
    <Snort rule="AdWare.FlyStudio.HTTP.C&amp;C" />
    <Snort rule="AdWare.FlyStudio.HTTP.Download" />
  </Malware>
  <Malware Snort="AdWare.Gamevance.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Gamevance.a" />
  <Malware Snort="AdWare.Hebogo.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Hebogo.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.iBryte.a">
    <Snort rule="AdWare.iBryte.HTTP.C&amp;C" />
    <Snort rule="AdWare.iBryte.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="AdWare.ICLoader.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.ICLoader.a" />
  <Malware Snort="AdWare.InstallMonster.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.InstallMonster.a" />
  <Malware Snort="AdWare.Kqheb.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Kqheb.a" />
  <Malware Snort="AdWare.Kraddare.HTTP.Download" Avp3="not-a-virus:AdWare.Win32.Kraddare.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.Kuaiba.a">
    <Snort rule="AdWare.Kuaiba.HTTP.C&amp;C" />
    <Snort rule="AdWare.Kuaiba.HTTP.Download" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.KuaiZip.a">
    <Snort rule="AdWare.KuaiZip.HTTP.C&amp;C" />
    <Snort rule="AdWare.KuaiZip.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="AdWare.KuwanBar.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.KuwanBar.a" />
  <Malware Snort="AdWare.KuziTui.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.KuziTui.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.Linkury.a">
    <Snort rule="AdWare.Linkury.HTTP.ServerRequest" />
    <Snort rule="AdWare.Linkury.UDP.Notification" />
  </Malware>
  <Malware Avp3="not-a-virus:AdWare.Win32.LoadMoney.a">
    <Snort rule="AdWare.LoadMoney.HTTP.C&amp;C" />
    <Snort rule="AdWare.LoadMoney.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="AdWare.LoudMo.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.LoudMo.a" />
  <Malware Snort="AdWare.Machaer.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Machaer.a" />
  <Malware Snort="AdWare.MiniPages.UDP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.MiniPages.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.MultiPlug.a">
    <Snort rule="AdWare.MultiPlug.HTTP.C&amp;C" />
    <Snort rule="AdWare.MultiPlug.HTTP.ServerRequest" />
    <Snort rule="AdWare.MultiPlug.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="AdWare.Neoreklami.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Neoreklami.a" />
  <Malware Snort="AdWare.Notifier.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Notifier.a" />
  <Malware Snort="AdWare.OpenSUpdater.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.OpenSUpdater.a" />
  <Malware Snort="AdWare.PayPop.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.PayPop.a" />
  <Malware Snort="AdWare.PCAppStore.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.PCAppStore.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.PiCol.a">
    <Snort rule="AdWare.PiCol.HTTP.C&amp;C" />
    <Snort rule="AdWare.PiCol.HTTP.Notification" />
  </Malware>
  <Malware Snort="AdWare.PurityScan.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.PurityScan.a" />
  <Malware Snort="AdWare.Qjwmonkey.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Qjwmonkey.a" />
  <Malware Snort="AdWare.Relevant.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Relevant.a" />
  <Malware Snort="AdWare.SaMon.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.SaMon.a" />
  <Malware Snort="AdWare.ScreenSaver.HTTP.Notification" Avp3="not-a-virus:AdWare.Win32.ScreenSaver.a" />
  <Malware Snort="AdWare.Sendori.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Sendori.a" />
  <Malware Snort="AdWare.SilentOffer.UDP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.SilentOffer.a" />
  <Malware Snort="AdWare.SmartInstaller.HTTP.Download" Avp3="not-a-virus:AdWare.Win32.SmartInstaller.a" />
  <Malware Snort="AdWare.Snojan.UDP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Snojan.a" />
  <Malware Snort="AdWare.Softcnapp.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Softcnapp.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.StartSurf.a">
    <Snort rule="AdWare.StartSurf.HTTP.C&amp;C" />
    <Snort rule="AdWare.StartSurf.HTTP.Download" />
    <Snort rule="AdWare.StartSurf.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="AdWare.SwJoy.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.SwJoy.a" />
  <Malware Snort="AdWare.Ucmore.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Ucmore.a" />
  <Malware Snort="AdWare.Vittalia.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.Vittalia.a" />
  <Malware Snort="AdWare.VKDJ.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.VKDJ.a" />
  <Malware Snort="AdWare.Vopak.HTTP.Download" Avp3="not-a-virus:AdWare.Win32.Vopak.a" />
  <Malware Snort="AdWare.Wajam.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Wajam.a" />
  <Malware Snort="AdWare.WatchMan.HTTP.Download" Avp3="not-a-virus:AdWare.Win32.WatchMan.a" />
  <Malware Snort="AdWare.WebCompanion.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.WebCompanion.a" />
  <Malware Snort="AdWare.WinFetcher.HTTP.ServerRequest" Avp3="not-a-virus:AdWare.Win32.WinFetcher.a" />
  <Malware Snort="AdWare.Yzon.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.Win32.Yzon.a" />
  <Malware Avp3="not-a-virus:AdWare.Win32.ZvuZona.a">
    <Snort rule="AdWare.ZvuZona.HTTP.C&amp;C" />
    <Snort rule="AdWare.ZvuZona.HTTP.Download" />
  </Malware>
  <Malware Snort="AdWare.Agent.HTTP.C&amp;C" Avp3="not-a-virus:AdWare.WinLNK.Agent.a" />
  <Malware Snort="Downloader.Agent.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Linux.Agent.a" />
  <Malware Snort="Downloader.DriverHub.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.MSIL.DriverHub.a" />
  <Malware Snort="Downloader.SoftBase.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.NSIS.SoftBase.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.AdLoad.a">
    <Snort rule="Downloader.AdLoad.HTTP.C&amp;C" />
    <Snort rule="Downloader.AdLoad.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:Downloader.Win32.Agent.a">
    <Snort rule="Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Downloader.Agent.HTTP.Download" />
    <Snort rule="Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Downloader.Agent.HTTP.Updater" />
  </Malware>
  <Malware Snort="Downloader.Atoz.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Atoz.a" />
  <Malware Snort="Downloader.Bablosoft.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Bablosoft.a" />
  <Malware Snort="Downloader.BindEx.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.BindEx.a" />
  <Malware Snort="Downloader.Boxero.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Boxero.a" />
  <Malware Snort="Downloader.DoubleZe.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.DoubleZe.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.DownloadAsist.a">
    <Snort rule="Downloader.DownloadAsist.HTTP.Download" />
    <Snort rule="Downloader.DownloadAsist.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Downloader.DownloaderGuide.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.DownloaderGuide.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.DownloAdmin.a">
    <Snort rule="Downloader.DownloAdmin.HTTP.C&amp;C" />
    <Snort rule="Downloader.DownloAdmin.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="not-a-virus:Downloader.Win32.DownloadSponsor.a">
    <Snort rule="Downloader.DownloadSponsor.HTTP.Download" />
    <Snort rule="Downloader.DownloadSponsor.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Downloader.DriverHub.UDP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.DriverHub.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.DriverPack.a">
    <Snort rule="Downloader.DriverPack.HTTP.Download" />
    <Snort rule="Downloader.DriverPack.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Downloader.DStudio.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.DStudio.a" />
  <Malware Snort="Downloader.Elemental.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Elemental.a" />
  <Malware Snort="Downloader.Elemental.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Elemental.gen" />
  <Malware Snort="Downloader.ExPortal.UDP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.ExPortal.a" />
  <Malware Snort="Downloader.Falco.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Falco.a" />
  <Malware Snort="Downloader.Funshion.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Funshion.a" />
  <Malware Snort="Downloader.Gnome.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.Gnome.a" />
  <Malware Snort="Downloader.InnoBundle.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.InnoBundle.a" />
  <Malware Snort="Downloader.InstallMate.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.InstallMate.a" />
  <Malware Snort="Downloader.InstallPack.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.InstallPack.a" />
  <Malware Snort="Downloader.InstallShare.UDP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.InstallShare.a" />
  <Malware Snort="Downloader.Kasinst.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Kasinst.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.LMN.a">
    <Snort rule="Downloader.LMN.HTTP.C&amp;C" />
    <Snort rule="Downloader.LMN.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Downloader.MagMedia.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.MagMedia.a" />
  <Malware Snort="Downloader.MediaDrug.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.MediaDrug.a" />
  <Malware Snort="Downloader.Morstar.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.Morstar.a" />
  <Malware Snort="Downloader.MPCrow.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.MPCrow.a" />
  <Malware Snort="Downloader.NetSeal.HTTP.Download" Avp3="not-a-virus:Downloader.Win32.NetSeal.a" />
  <Malware Snort="Downloader.OfferPack.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.OfferPack.a" />
  <Malware Snort="Downloader.OneClick.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.OneClick.a" />
  <Malware Snort="Downloader.RostDown.HTTP.Download" Avp3="not-a-virus:Downloader.Win32.RostDown.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.Snojan.a">
    <Snort rule="Downloader.Snojan.HTTP.C&amp;C" />
    <Snort rule="Downloader.Snojan.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Downloader.Softonic.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Softonic.a" />
  <Malware Snort="Downloader.SpiritSoft.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.SpiritSoft.a" />
  <Malware Snort="Downloader.TorLoader.UDP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.TorLoader.a" />
  <Malware Avp3="not-a-virus:Downloader.Win32.Trick.a">
    <Snort rule="Downloader.Trick.HTTP.C&amp;C" />
    <Snort rule="Downloader.Trick.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Downloader.Ubot.HTTP.Download" Avp3="not-a-virus:Downloader.Win32.Ubot.a" />
  <Malware Snort="Downloader.VrBrothers.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.VrBrothers.a" />
  <Malware Snort="Downloader.WebCompanion.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.WebCompanion.a" />
  <Malware Snort="Downloader.Widoman.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Widoman.a" />
  <Malware Snort="Downloader.WinWrapper.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.WinWrapper.a" />
  <Malware Snort="Downloader.Yantai.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.Win32.Yantai.a" />
  <Malware Snort="Downloader.Yantai.HTTP.ServerRequest" Avp3="not-a-virus:Downloader.Win32.Yantai.gen" />
  <Malware Avp3="not-a-virus:Downloader.Win32.YXdown.a">
    <Snort rule="Downloader.YXdown.HTTP.C&amp;C" />
    <Snort rule="Downloader.YXdown.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Downloader.Agent.HTTP.C&amp;C" Avp3="not-a-virus:Downloader.WinLNK.Agent.a" />
  <Malware Snort="Monitor.Ardamax.HTTP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.Ardamax.a" />
  <Malware Snort="Monitor.BestFreeKeylogger.HTTP.ServerRequest" Avp3="not-a-virus:Monitor.Win32.BestFreeKeylogger.a" />
  <Malware Snort="Monitor.HomGrd.UDP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.HomGrd.a" />
  <Malware Snort="Monitor.iMonitorSoft.TCP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.iMonitorSoft.a" />
  <Malware Snort="Monitor.iTeeNotifier.UDP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.iTeeNotifier.a" />
  <Malware Snort="Monitor.KeyLogger.HTTP.ServerRequest" Avp3="not-a-virus:Monitor.Win32.KeyLogger.a" />
  <Malware Snort="Monitor.RealtimeSpy.HTTP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.RealtimeSpy.a" />
  <Malware Snort="Monitor.Sprx.HTTP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.Sprx.a" />
  <Malware Snort="Monitor.SpyAgent.HTTP.C&amp;C" Avp3="not-a-virus:Monitor.Win32.SpyAgent.a" />
  <Malware Snort="NetTool.Agent.HTTP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.Agent.a" />
  <Malware Snort="NetTool.AmanVPN.HTTP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.AmanVPN.a" />
  <Malware Snort="NetTool.LibP2P.UDP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.LibP2P.a" />
  <Malware Snort="NetTool.NetFilter.HTTP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.NetFilter.a" />
  <Malware Avp3="not-a-virus:NetTool.Win32.Ngrok.a">
    <Snort rule="NetTool.Ngrok.HTTP.C&amp;C" />
    <Snort rule="NetTool.Ngrok.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="NetTool.Proxy.HTTP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.Proxy.a" />
  <Malware Snort="NetTool.RequestCatcher.HTTP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.RequestCatcher.a" />
  <Malware Snort="NetTool.Revsocks.TCP.C&amp;C" Avp3="not-a-virus:NetTool.Win32.Revsocks.a" />
  <Malware Snort="NetTool.WinRS.WinRM.C&amp;C" Avp3="not-a-virus:NetTool.Win32.WinRS.a" />
  <Malware Snort="NetTool.FRP.IP.C&amp;C" Avp3="not-a-virus:NetTool.Win64.FRP.a" />
  <Malware Snort="NetTool.NetFilter.HTTP.ServerRequest" Avp3="not-a-virus:NetTool.Win64.NetFilter.a" />
  <Malware Snort="Porn-Dialer.EgroupDial.HTTP.ServerRequest" Avp3="not-a-virus:Porn-Dialer.Win32.EgroupDial.a" />
  <Malware Snort="Porn-Dialer.InstantAccess.HTTP.C&amp;C" Avp3="not-a-virus:Porn-Dialer.Win32.InstantAccess.a" />
  <Malware Snort="PSWTool.SnadBoy.HTTP.C&amp;C" Avp3="not-a-virus:PSWTool.Win32.SnadBoy.a" />
  <Malware Snort="RemoteAdmin.Agent.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.MSIL.Agent.a" />
  <Malware Snort="RemoteAdmin.Syncro.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.MSIL.Syncro.a" />
  <Malware Snort="RemoteAdmin.Agent.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.Agent.a" />
  <Malware Snort="RemoteAdmin.Ammyy.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.Ammyy.a" />
  <Malware Snort="RemoteAdmin.AnyplaceControl.TCP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.AnyplaceControl.a" />
  <Malware Snort="RemoteAdmin.Conne.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.Conne.a" />
  <Malware Snort="RemoteAdmin.ConnectWise.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.ConnectWise.a" />
  <Malware Avp3="not-a-virus:RemoteAdmin.Win32.MeshAgent.a">
    <Snort rule="RemoteAdmin.MeshAgent.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.MeshAgent.TCP.C&amp;C" />
    <Snort rule="RemoteAdmin.MeshAgent.TLS.C&amp;C" />
    <Snort rule="RemoteAdmin.MeshAgent.WebSocket.C&amp;C" />
  </Malware>
  <Malware Avp3="not-a-virus:RemoteAdmin.Win32.NetSup.a">
    <Snort rule="RemoteAdmin.NetSup.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.NetSup.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="not-a-virus:RemoteAdmin.Win32.RAdmin.a">
    <Snort rule="RemoteAdmin.RAdmin.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.RAdmin.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="RemoteAdmin.RemoteManipulator.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.RemoteManipulator.a" />
  <Malware Avp3="not-a-virus:RemoteAdmin.Win32.RMS.a">
    <Snort rule="RemoteAdmin.RMS.HTTP.C&amp;C" />
    <Snort rule="RemoteAdmin.RMS.HTTP.ServerRequest" />
    <Snort rule="RemoteAdmin.RMS.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="RemoteAdmin.RTCBased.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.RTCBased.a" />
  <Malware Snort="RemoteAdmin.WinVNC.RFB.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win32.WinVNC.a" />
  <Malware Snort="RemoteAdmin.Remsim.HTTP.C&amp;C" Avp3="not-a-virus:RemoteAdmin.Win64.Remsim.a" />
  <Malware Snort="RiskTool.MinerDownloader.HTTP.C&amp;C" Avp3="not-a-virus:RiskTool.Shell.MinerDownloader.a" />
  <Malware Snort="RiskTool.AIOMiner.HTTP.C&amp;C" Avp3="not-a-virus:RiskTool.Win32.AIOMiner.a" />
  <Malware Avp3="not-a-virus:RiskTool.Win32.AmanVPN.a">
    <Snort rule="RiskTool.AmanVPN.HTTP.C&amp;C" />
    <Snort rule="RiskTool.AmanVPN.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="RiskTool.BEUT.HTTP.C&amp;C" Avp3="not-a-virus:RiskTool.Win32.BEUT.a" />
  <Malware Avp3="not-a-virus:RiskTool.Win32.BitCoinMiner.a">
    <Snort rule="RiskTool.BitCoinMiner.HTTP.C&amp;C" />
    <Snort rule="RiskTool.BitCoinMiner.TCP.C&amp;C" />
    <Snort rule="RiskTool.BitCoinMiner.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="not-a-virus:RiskTool.Win32.FlyStudio.a">
    <Snort rule="RiskTool.FlyStudio.HTTP.C&amp;C" />
    <Snort rule="RiskTool.FlyStudio.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="RiskTool.Injector.HTTP.C&amp;C" Avp3="not-a-virus:RiskTool.Win32.Injector.a" />
  <Malware Avp3="not-a-virus:RiskTool.Win32.Miner.a">
    <Snort rule="RiskTool.Miner.HTTP.C&amp;C" />
    <Snort rule="RiskTool.Miner.TCP.C&amp;C" />
    <Snort rule="RiskTool.Miner.UDP.C&amp;C" />
    <Snort rule="RiskTool.Miner.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="RiskTool.Yopmail.UDP.C&amp;C" Avp3="not-a-virus:RiskTool.Win32.Yopmail.a" />
  <Malware Snort="RiskTool.BitCoinMiner.UDP.C&amp;C" Avp3="not-a-virus:RiskTool.Win64.BitCoinMiner.a" />
  <Malware Snort="RiskTool.TrollAV.HTTP.C&amp;C" Avp3="not-a-virus:RiskTool.Win64.TrollAV.a" />
  <Malware Snort="Server-Proxy.RPCVan.UDP.C&amp;C" Avp3="not-a-virus:Server-Proxy.MSIL.RPCVan.a" />
  <Malware Snort="Server-Proxy.NatappFree.UDP.C&amp;C" Avp3="not-a-virus:Server-Proxy.Win32.NatappFree.a" />
  <Malware Avp3="not-a-virus:Server-Proxy.Win32.PPro.a">
    <Snort rule="Server-Proxy.PPro.HTTP.C&amp;C" />
    <Snort rule="Server-Proxy.PPro.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="WebToolbar.Agent.HTTP.C&amp;C" Avp3="not-a-virus:WebToolbar.Win32.Agent.a" />
  <Malware Avp3="not-a-virus:WebToolbar.Win32.Asparnet.a">
    <Snort rule="WebToolbar.Asparnet.HTTP.C&amp;C" />
    <Snort rule="WebToolbar.Asparnet.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="WebToolbar.Codiby.HTTP.ServerRequest" Avp3="not-a-virus:WebToolbar.Win32.Codiby.a" />
  <Malware Snort="WebToolbar.MultiBarDownloader.HTTP.C&amp;C" Avp3="not-a-virus:WebToolbar.Win32.MultiBarDownloader.a" />
  <Malware Snort="WebToolbar.MyWebSearch.HTTP.ServerRequest" Avp3="not-a-virus:WebToolbar.Win32.MyWebSearch.a" />
  <Malware Snort="WebToolbar.OpenInstall.HTTP.C&amp;C" Avp3="not-a-virus:WebToolbar.Win32.OpenInstall.a" />
  <Malware Avp3="not-a-virus:WebToolbar.Win32.Perion.a">
    <Snort rule="WebToolbar.Perion.HTTP.C&amp;C" />
    <Snort rule="WebToolbar.Perion.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="WebToolbar.SearchSuite.HTTP.ServerRequest" Avp3="not-a-virus:WebToolbar.Win32.SearchSuite.a" />
  <Malware Avp3="not-a-virus:WebToolbar.Win32.Zango.a">
    <Snort rule="WebToolbar.Zango.HTTP.C&amp;C" />
    <Snort rule="WebToolbar.Zango.HTTP.C&amp;C.a" />
    <Snort rule="WebToolbar.Zango.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="P2P-Worm.Win32.Palevo.a">
    <Snort rule="P2P-Worm.Palevo.HTTP.C&amp;C" />
    <Snort rule="P2P-Worm.Palevo.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="P2P-Worm.SpyBot.IRC.C&amp;C" Avp3="P2P-Worm.Win32.SpyBot.a" />
  <Malware Snort="Rootkit.Agent.HTTP.C&amp;C" Avp3="Rootkit.Win32.Agent.a" />
  <Malware Snort="Rootkit.Agent.HTTP.C&amp;C" Avp3="Rootkit.Win64.Agent.a" />
  <Malware Snort="Trojan.Agent.UDP.C&amp;C" Avp3="Trojan.HTA.Agent.a" />
  <Malware Avp3="Trojan.HTA.SAgent.gen">
    <Snort rule="Trojan.SAgent.HTTP.ServerRequest" />
    <Snort rule="Trojan.SAgent.TCP.ServerRequest" />
    <Snort rule="Trojan.SAgent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Alien.TCP.ServerRequest" Avp3="Trojan.Java.Alien.gen" />
  <Malware Avp3="Trojan.JS.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Agentb.UDP.C&amp;C" Avp3="Trojan.JS.Agentb.a" />
  <Malware Snort="Trojan.Miner.UDP.C&amp;C" Avp3="Trojan.JS.Miner.a" />
  <Malware Avp3="Trojan.Linux.Agent.a">
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Drovorub.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.MSIL.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.MSIL.Agent.gen">
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Agentb.HTTP.C&amp;C" Avp3="Trojan.MSIL.Agentb.a" />
  <Malware Snort="Trojan.Agentb.TCP.ServerRequest" Avp3="Trojan.MSIL.Agentb.gen" />
  <Malware Snort="Trojan.APosT.UDP.ServerRequest" Avp3="Trojan.MSIL.APosT.a" />
  <Malware Snort="Trojan.Bsymem.UDP.C&amp;C" Avp3="Trojan.MSIL.Bsymem.a" />
  <Malware Snort="Trojan.Chapak.TCP.ServerRequest" Avp3="Trojan.MSIL.Chapak.a" />
  <Malware Avp3="Trojan.MSIL.Chapak.gen">
    <Snort rule="Trojan.Chapak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Chapak.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Crypt.UDP.C&amp;C" Avp3="Trojan.MSIL.Crypt.a" />
  <Malware Avp3="Trojan.MSIL.Crypt.gen">
    <Snort rule="Trojan.Crypt.HTTP.ServerRequest" />
    <Snort rule="Trojan.Crypt.TCP.ServerRequest" />
    <Snort rule="Trojan.Crypt.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.MSIL.Cryptos.a">
    <Snort rule="Trojan.Cryptos.HTTP.ServerRequest" />
    <Snort rule="Trojan.Cryptos.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.DelShad.HTTP.ServerRequest" Avp3="Trojan.MSIL.DelShad.a" />
  <Malware Snort="Trojan.DelShad.HTTP.ServerRequest" Avp3="Trojan.MSIL.DelShad.gen" />
  <Malware Avp3="Trojan.MSIL.Disfa.a">
    <Snort rule="Trojan.Disfa.TCP.ServerRequest" />
    <Snort rule="Trojan.Disfa.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Dizemp.HTTP.ServerRequest" Avp3="Trojan.MSIL.Dizemp.gen" />
  <Malware Snort="Trojan.Finac.HTTP.C&amp;C" Avp3="Trojan.MSIL.Finac.a" />
  <Malware Snort="Trojan.Ftker.HTTP.C&amp;C" Avp3="Trojan.MSIL.Ftker.a" />
  <Malware Snort="Trojan.Grunt.HTTP.C&amp;C" Avp3="Trojan.MSIL.Grunt.a" />
  <Malware Snort="Trojan.Hesv.UDP.C&amp;C" Avp3="Trojan.MSIL.Hesv.a" />
  <Malware Avp3="Trojan.MSIL.Inject.a">
    <Snort rule="Trojan.Inject.HTTP.C&amp;C" />
    <Snort rule="Trojan.Inject.HTTP.ServerRequest" />
    <Snort rule="Trojan.Inject.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.InjectorNetT.UDP.C&amp;C" Avp3="Trojan.MSIL.InjectorNetT.gen" />
  <Malware Snort="Trojan.Injects.TCP.ServerRequest" Avp3="Trojan.MSIL.Injects.a" />
  <Malware Snort="Trojan.Injuke.HTTP.C&amp;C" Avp3="Trojan.MSIL.Injuke.a" />
  <Malware Avp3="Trojan.MSIL.Injuke.gen">
    <Snort rule="Trojan.Injuke.TCP.ServerRequest" />
    <Snort rule="Trojan.Injuke.UDP.C&amp;C" />
    <Snort rule="Trojan.Injuke.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Khalesi.HTTP.C&amp;C" Avp3="Trojan.MSIL.Khalesi.a" />
  <Malware Snort="Trojan.Kryptik.TCP.ServerRequest" Avp3="Trojan.MSIL.Kryptik.a" />
  <Malware Snort="Trojan.Llac.UDP.C&amp;C" Avp3="Trojan.MSIL.Llac.a" />
  <Malware Avp3="Trojan.MSIL.Miner.a">
    <Snort rule="Trojan.Miner.HTTP.C&amp;C" />
    <Snort rule="Trojan.Miner.HTTP.Download" />
    <Snort rule="Trojan.Miner.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Mueta.HTTP.ServerRequest" Avp3="Trojan.MSIL.Mueta.a" />
  <Malware Snort="Trojan.NetWire.HTTP.C&amp;C" Avp3="Trojan.MSIL.NetWire.a" />
  <Malware Snort="Trojan.Quasar.TLS.C&amp;C" Avp3="Trojan.MSIL.Quasar.a" />
  <Malware Snort="Trojan.Reconyc.HTTP.C&amp;C" Avp3="Trojan.MSIL.Reconyc.a" />
  <Malware Snort="Trojan.SelfDel.HTTP.C&amp;C" Avp3="Trojan.MSIL.SelfDel.a" />
  <Malware Avp3="Trojan.MSIL.Shelpak.gen">
    <Snort rule="Trojan.Shelpak.HTTP.ServerRequest" />
    <Snort rule="Trojan.Shelpak.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Stelpak.TLS.C&amp;C" Avp3="Trojan.MSIL.Stelpak.gen" />
  <Malware Snort="Trojan.Sunburst.HTTP.C&amp;C" Avp3="Trojan.MSIL.Sunburst.a" />
  <Malware Snort="Trojan.Tasker.TCP.ServerRequest" Avp3="Trojan.MSIL.Tasker.gen" />
  <Malware Snort="Trojan.Taskun.TCP.C&amp;C" Avp3="Trojan.MSIL.Taskun.a" />
  <Malware Snort="Trojan.Taskun.TCP.ServerRequest" Avp3="Trojan.MSIL.Taskun.gen" />
  <Malware Snort="Trojan.Vasal.HTTP.ServerRequest" Avp3="Trojan.MSIL.Vasal.a" />
  <Malware Snort="Trojan.Agent.HTTP.C&amp;C" Avp3="Trojan.MSOffice.Agent.a" />
  <Malware Avp3="Trojan.MSOffice.Agent.gen">
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.SAgent.HTTP.C&amp;C" Avp3="Trojan.MSOffice.SAgent.a" />
  <Malware Snort="Trojan.SAgent.HTTP.ServerRequest" Avp3="Trojan.MSOffice.SAgent.gen" />
  <Malware Snort="Trojan.Shellex.HTTP.C&amp;C" Avp3="Trojan.MSOffice.Shellex.a" />
  <Malware Snort="Trojan.Agent.UDP.ServerRequest" Avp3="Trojan.Multi.Agent.gen" />
  <Malware Snort="Trojan.Powedon.HTTP.C&amp;C" Avp3="Trojan.Multi.Powedon.gen" />
  <Malware Snort="Trojan.Makoob.HTTP.C&amp;C" Avp3="Trojan.NSIS.Makoob.a" />
  <Malware Snort="Trojan.Agent.HTTP.C&amp;C" Avp3="Trojan.PDF.Agent.a" />
  <Malware Avp3="Trojan.PDF.Phish.a">
    <Snort rule="Trojan.Phish.HTTP.C&amp;C" />
    <Snort rule="Trojan.Phish.HTTP.ServerRequest" />
    <Snort rule="Trojan.Phish.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.WebShell.HTTP.C&amp;C" Avp3="Trojan.PHP.WebShell.a" />
  <Malware Avp3="Trojan.PowerShell.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.PowerShell.Agent.gen">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Agentb.HTTP.ServerRequest" Avp3="Trojan.PowerShell.Agentb.gen" />
  <Malware Snort="Trojan.Miner.HTTP.C&amp;C" Avp3="Trojan.PowerShell.Miner.a" />
  <Malware Snort="Trojan.Agent.HTTP.C&amp;C" Avp3="Trojan.Python.Agent.a" />
  <Malware Snort="Trojan.Stitch.TCP.C&amp;C" Avp3="Trojan.Python.Stitch.a" />
  <Malware Snort="Trojan.Stitch.TCP.ServerRequest" Avp3="Trojan.Python.Stitch.gen" />
  <Malware Avp3="Trojan.Script.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Script.Agent.gen">
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Agent.HTTP.C&amp;C" Avp3="Trojan.Script.Agentb.a" />
  <Malware Avp3="Trojan.Script.Agentb.gen">
    <Snort rule="Trojan.Agentb.TCP.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Generic.HTTP.ServerRequest" Avp3="Trojan.Script.Generic.gen" />
  <Malware Avp3="Trojan.Script.Ostrak.a">
    <Snort rule="Trojan.Ostrak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Ostrak.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.SAgent.HTTP.C&amp;C" Avp3="Trojan.Script.SAgent.a" />
  <Malware Snort="Trojan.SAgent.TCP.C&amp;C" Avp3="Trojan.Script.SAgent.gen" />
  <Malware Avp3="Trojan.VBS.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.SMTP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Runner.HTTP.C&amp;C" Avp3="Trojan.VBS.Runner.a" />
  <Malware Snort="Trojan.Runner.HTTP.ServerRequest" Avp3="Trojan.VBS.Runner.gen" />
  <Malware Snort="Trojan.SAgent.HTTP.C&amp;C" Avp3="Trojan.VBS.SAgent.a" />
  <Malware Avp3="Trojan.VBS.SAgent.gen">
    <Snort rule="Trojan.SAgent.HTTP.ServerRequest" />
    <Snort rule="Trojan.SAgent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Agent.a">
    <Snort rule="Trojan.Agent.FTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.AntiCaptcha" />
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.Download" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.IP.C&amp;C" />
    <Snort rule="Trojan.Agent.IP.ServerRequest" />
    <Snort rule="Trojan.Agent.SMTP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.TLS.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
    <Snort rule="Trojan.Win32.Agent.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Agent.gen">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Agentb.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agentb.ICMP.C&amp;C" />
    <Snort rule="Trojan.Agentb.TCP.C&amp;C" />
    <Snort rule="Trojan.Agentb.TLS.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.ServerRequest" />
    <Snort rule="Trojan.Packed.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Agentb.gen">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agentb.TCP.C&amp;C" />
    <Snort rule="Trojan.Agentb.TCP.ServerRequest" />
    <Snort rule="Trojan.Agentb.TLS.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.ServerRequest" />
    <Snort rule="Trojan.Exnet.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Antavmu.TCP.C&amp;C" Avp3="Trojan.Win32.Antavmu.a" />
  <Malware Avp3="Trojan.Win32.AntiAV.a">
    <Snort rule="Trojan.AntiAV.HTTP.ServerRequest" />
    <Snort rule="Trojan.AntiAV.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.APosT.a">
    <Snort rule="Trojan.APosT.HTTP.C&amp;C" />
    <Snort rule="Trojan.APosT.HTTP.ServerRequest" />
    <Snort rule="Trojan.APosT.TCP.C&amp;C" />
    <Snort rule="Trojan.APosT.TCP.Download" />
    <Snort rule="Trojan.APosT.UDP.C&amp;C" />
    <Snort rule="Trojan.APosT.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.APosT.gen">
    <Snort rule="Trojan.APosT.TCP.ServerRequest" />
    <Snort rule="Trojan.APosT.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Autoit.a">
    <Snort rule="Trojan.Autoit.HTTP.C&amp;C" />
    <Snort rule="Trojan.Autoit.HTTP.ServerRequest" />
    <Snort rule="Trojan.Autoit.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.BadJoke.HTTP.C&amp;C" Avp3="Trojan.Win32.BadJoke.a" />
  <Malware Snort="Trojan.BaiCai.HTTP.C&amp;C" Avp3="Trojan.Win32.BaiCai.a" />
  <Malware Snort="Trojan.Bayrob.HTTP.C&amp;C" Avp3="Trojan.Win32.Bayrob.a" />
  <Malware Snort="Trojan.Bingoml.HTTP.C&amp;C" Avp3="Trojan.Win32.Bingoml.a" />
  <Malware Snort="Trojan.BitCoinMiner.UDP.C&amp;C" Avp3="Trojan.Win32.BitCoinMiner.a" />
  <Malware Avp3="Trojan.Win32.Blamon.a">
    <Snort rule="Trojan.Blamon.HTTP.C&amp;C" />
    <Snort rule="Trojan.Blamon.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Bsymem.HTTP.C&amp;C" Avp3="Trojan.Win32.Bsymem.a" />
  <Malware Avp3="Trojan.Win32.Bublik.a">
    <Snort rule="Trojan.Bublik.HTTP.C&amp;C" />
    <Snort rule="Trojan.Bublik.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Burden.UDP.ServerRequest" Avp3="Trojan.Win32.Burden.a" />
  <Malware Snort="Trojan.BurHon.HTTP.ServerRequest" Avp3="Trojan.Win32.BurHon.a" />
  <Malware Avp3="Trojan.Win32.Chapak.a">
    <Snort rule="Trojan.Chapak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Chapak.HTTP.ServerRequest" />
    <Snort rule="Trojan.Chapak.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.CHS.a">
    <Snort rule="Trojan.CHS.HTTP.C&amp;C" />
    <Snort rule="Trojan.CHS.HTTP.Notification" />
  </Malware>
  <Malware Snort="Trojan.CMY3U.HTTP.ServerRequest" Avp3="Trojan.Win32.CMY3U.gen" />
  <Malware Avp3="Trojan.Win32.Cnopa.a">
    <Snort rule="Trojan.Cnopa.HTTP.C&amp;C" />
    <Snort rule="Trojan.Cnopa.HTTP.Download" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Cobalt.a">
    <Snort rule="Trojan.Cobalt.HTTP.C&amp;C" />
    <Snort rule="Trojan.Cobalt.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Cobalt.HTTP.ServerRequest" Avp3="Trojan.Win32.Cobalt.gen" />
  <Malware Snort="Trojan.CobaltStrike.HTTP.C&amp;C" Avp3="Trojan.Win32.CobaltStrike.a" />
  <Malware Snort="Trojan.CobaltStrike.HTTP.ServerRequest" Avp3="Trojan.Win32.CobaltStrike.gen" />
  <Malware Snort="Trojan.Cometer.HTTP.C&amp;C" Avp3="Trojan.Win32.Cometer.a" />
  <Malware Snort="Trojan.Copak.HTTP.C&amp;C" Avp3="Trojan.Win32.Copak.a" />
  <Malware Snort="Trojan.Cosmu.HTTP.C&amp;C" Avp3="Trojan.Win32.Cosmu.a" />
  <Malware Snort="Trojan.Cozybear.HTTP.Download" Avp3="Trojan.Win32.Cozybear.a" />
  <Malware Avp3="Trojan.Win32.Crypt.a">
    <Snort rule="Trojan.Crypt.TCP.C&amp;C" />
    <Snort rule="Trojan.Crypt.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Csfrsys.TCP.C&amp;C" Avp3="Trojan.Win32.Csfrsys.a" />
  <Malware Avp3="Trojan.Win32.Cutwail.a">
    <Snort rule="Trojan.Cutwail.HTTP.C&amp;C" />
    <Snort rule="Trojan.Cutwail.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Cyclun.TCP.C&amp;C" Avp3="Trojan.Win32.Cyclun.a" />
  <Malware Snort="Trojan.Dapter.HTTP.Download" Avp3="Trojan.Win32.Dapter.a" />
  <Malware Snort="Trojan.Delf.HTTP.C&amp;C" Avp3="Trojan.Win32.Delf.a" />
  <Malware Snort="Trojan.DelShad.HTTP.C&amp;C" Avp3="Trojan.Win32.DelShad.a" />
  <Malware Snort="Trojan.Denes.UDP.C&amp;C" Avp3="Trojan.Win32.Denes.a" />
  <Malware Snort="Trojan.DesertWind.HTTP.C&amp;C" Avp3="Trojan.Win32.DesertWind.a" />
  <Malware Snort="Trojan.Dialer.HTTP.ServerRequest" Avp3="Trojan.Win32.Dialer.a" />
  <Malware Avp3="Trojan.Win32.Diple.a">
    <Snort rule="Trojan.Diple.HTTP.C&amp;C" />
    <Snort rule="Trojan.Diple.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Discogram.HTTP.C&amp;C" Avp3="Trojan.Win32.Discogram.a" />
  <Malware Snort="Trojan.Diztakun.HTTP.ServerRequest" Avp3="Trojan.Win32.Diztakun.a" />
  <Malware Snort="Trojan.DLLhijack.TCP.ServerRequest" Avp3="Trojan.Win32.DLLhijack.gen" />
  <Malware Snort="Trojan.Dns2Tcp.DNS.C&amp;C" Avp3="Trojan.Win32.Dns2Tcp.a" />
  <Malware Snort="Trojan.DNSShell.DNS.C&amp;C" Avp3="Trojan.Win32.DNSShell.a" />
  <Malware Snort="Trojan.DNSSubTun.DNS.C&amp;C" Avp3="Trojan.Win32.DNSSubTun.a" />
  <Malware Avp3="Trojan.Win32.DNSTun.a">
    <Snort rule="Trojan.DNSTun.DNS.C&amp;C" />
    <Snort rule="Trojan.DNSTun.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.DNSTxtTun.DNS.C&amp;C" Avp3="Trojan.Win32.DNSTxtTun.a" />
  <Malware Snort="Trojan.DNSTxtTunFast.DNS.C&amp;C" Avp3="Trojan.Win32.DNSTxtTunFast.a" />
  <Malware Snort="Trojan.Drefir.IRC.C&amp;C" Avp3="Trojan.Win32.Drefir.a" />
  <Malware Snort="Trojan.Droma.HTTP.ServerRequest" Avp3="Trojan.Win32.Droma.gen" />
  <Malware Avp3="Trojan.Win32.Dynara.gen">
    <Snort rule="Trojan.Dynara.TCP.ServerRequest" />
    <Snort rule="Trojan.Dynara.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Ekstak.a">
    <Snort rule="Trojan.Ekstak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Ekstak.HTTP.ServerRequest" />
    <Snort rule="Trojan.Ekstak.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Exuma.HTTP.C&amp;C" Avp3="Trojan.Win32.Exuma.a" />
  <Malware Avp3="Trojan.Win32.FakeAV.a">
    <Snort rule="Trojan.FakeAV.HTTP.C&amp;C" />
    <Snort rule="Trojan.FakeAV.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.FlyStudio.HTTP.C&amp;C" Avp3="Trojan.Win32.FlyStudio.a" />
  <Malware Snort="Trojan.Fosniw.HTTP.C&amp;C" Avp3="Trojan.Win32.Fosniw.a" />
  <Malware Snort="Trojan.Fraud.HTTP.ServerRequest" Avp3="Trojan.Win32.Fraud.a" />
  <Malware Snort="Trojan.FraudPack.HTTP.ServerRequest" Avp3="Trojan.Win32.FraudPack.a" />
  <Malware Avp3="Trojan.Win32.Fsysna.a">
    <Snort rule="Trojan.Fsysna.HTTP.C&amp;C" />
    <Snort rule="Trojan.Fsysna.TCP.C&amp;C" />
    <Snort rule="Trojan.Fsysna.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Gatak.TCP.C&amp;C" Avp3="Trojan.Win32.Gatak.gen" />
  <Malware Snort="Trojan.Generic.HTTP.ServerRequest" Avp3="Trojan.Win32.Generic.gen" />
  <Malware Avp3="Trojan.Win32.Genome.a">
    <Snort rule="Trojan.Genome.HTTP.C&amp;C" />
    <Snort rule="Trojan.Genome.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Graftor.HTTP.C&amp;C" Avp3="Trojan.Win32.Graftor.a" />
  <Malware Snort="Trojan.Havex.HTTP.ServerRequest" Avp3="Trojan.Win32.Havex.a" />
  <Malware Avp3="Trojan.Win32.Inject.a">
    <Snort rule="Trojan.Inject.HTTP.C&amp;C" />
    <Snort rule="Trojan.Inject.HTTP.Download" />
    <Snort rule="Trojan.Inject.HTTP.ServerRequest" />
    <Snort rule="Trojan.Inject.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Inject.gen">
    <Snort rule="Trojan.Inject.TLS.C&amp;C" />
    <Snort rule="Trojan.Inject.UDP.C&amp;C" />
    <Snort rule="Trojan.Inject.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.InjectorNetT.TLS.C&amp;C" Avp3="Trojan.Win32.InjectorNetT.gen" />
  <Malware Snort="Trojan.Injuke.HTTP.C&amp;C" Avp3="Trojan.Win32.Injuke.a" />
  <Malware Avp3="Trojan.Win32.Injuke.gen">
    <Snort rule="Trojan.Injuke.HTTP.ServerRequest" />
    <Snort rule="Trojan.Injuke.TCP.ServerRequest" />
    <Snort rule="Trojan.Injuke.TLS.C&amp;C" />
    <Snort rule="Trojan.Injuke.UDP.C&amp;C" />
    <Snort rule="Trojan.Injuke.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.IRCbot.a">
    <Snort rule="Trojan.IRCbot.IRC.C&amp;C" />
    <Snort rule="Trojan.IRCbot.TCP.C&amp;C" />
    <Snort rule="Trojan.IRCbot.TCP.ServerRequest" />
    <Snort rule="Trojan.IRCbot.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Ismdoor.HTTP.C&amp;C" Avp3="Trojan.Win32.Ismdoor.a" />
  <Malware Snort="Trojan.JakyllHyde.HTTP.C&amp;C" Avp3="Trojan.Win32.JakyllHyde.a" />
  <Malware Snort="Trojan.Johnnie.UDP.ServerRequest" Avp3="Trojan.Win32.Johnnie.a" />
  <Malware Snort="Trojan.Khalesi.HTTP.C&amp;C" Avp3="Trojan.Win32.Khalesi.a" />
  <Malware Snort="Trojan.Khalesi.TCP.ServerRequest" Avp3="Trojan.Win32.Khalesi.gen" />
  <Malware Snort="Trojan.KillAV.HTTP.ServerRequest" Avp3="Trojan.Win32.KillAV.a" />
  <Malware Snort="Trojan.Kovter.HTTP.ServerRequest" Avp3="Trojan.Win32.Kovter.a" />
  <Malware Snort="Trojan.Krament.HTTP.Download" Avp3="Trojan.Win32.Krament.a" />
  <Malware Snort="Trojan.Lazzzy.UDP.C&amp;C" Avp3="Trojan.Win32.Lazzzy.gen" />
  <Malware Avp3="Trojan.Win32.Llac.a">
    <Snort rule="Trojan.Llac.TCP.ServerRequest" />
    <Snort rule="Trojan.Llac.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Marut.a">
    <Snort rule="Trojan.Marut.HTTP.C&amp;C" />
    <Snort rule="Trojan.Marut.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.McRat.TCP.C&amp;C" Avp3="Trojan.Win32.McRat.a" />
  <Malware Snort="Trojan.Menti.UDP.ServerRequest" Avp3="Trojan.Win32.Menti.a" />
  <Malware Snort="Trojan.Metla.HTTP.C&amp;C" Avp3="Trojan.Win32.Metla.a" />
  <Malware Snort="Trojan.Miancha.HTTP.C&amp;C" Avp3="Trojan.Win32.Miancha.a" />
  <Malware Avp3="Trojan.Win32.Microcin.a">
    <Snort rule="Trojan.Agentb.UDP.C&amp;C" />
    <Snort rule="Trojan.Microcin.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Miner.a">
    <Snort rule="Trojan.Miner.HTTP.C&amp;C" />
    <Snort rule="Trojan.Miner.HTTP.ServerRequest" />
    <Snort rule="Trojan.Miner.TCP.C&amp;C" />
    <Snort rule="Trojan.Miner.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Miner.gen">
    <Snort rule="Trojan.Miner.HTTP.ServerRequest" />
    <Snort rule="Trojan.Miner.TCP.ServerRequest" />
    <Snort rule="Trojan.Miner.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Monderd.HTTP.ServerRequest" Avp3="Trojan.Win32.Monderd.a" />
  <Malware Snort="Trojan.Morphisil.UDP.C&amp;C" Avp3="Trojan.Win32.Morphisil.a" />
  <Malware Avp3="Trojan.Win32.Mucc.a">
    <Snort rule="Trojan.Mucc.HTTP.C&amp;C" />
    <Snort rule="Trojan.Mucc.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Mycop.UDP.ServerRequest" Avp3="Trojan.Win32.Mycop.a" />
  <Malware Avp3="Trojan.Win32.Mythic.a">
    <Snort rule="Trojan.Mythic.AMQP.C&amp;C" />
    <Snort rule="Trojan.Mythic.HTTP.C&amp;C" />
    <Snort rule="Trojan.Mythic.WebSocket.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Nanobot.HTTP.C&amp;C" Avp3="Trojan.Win32.Nanobot.a" />
  <Malware Snort="Trojan.Natrix.TCP.C&amp;C" Avp3="Trojan.Win32.Natrix.a" />
  <Malware Snort="Trojan.NetWire.TCP.ServerRequest" Avp3="Trojan.Win32.NetWire.a" />
  <Malware Avp3="Trojan.Win32.Neurevt.a">
    <Snort rule="Trojan.Neurevt.HTTP.C&amp;C" />
    <Snort rule="Trojan.Neurevt.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Newsbeef.UDP.ServerRequest" Avp3="Trojan.Win32.Newsbeef.a" />
  <Malware Snort="Trojan.NgrBot.IRC.C&amp;C" Avp3="Trojan.Win32.NgrBot.a" />
  <Malware Snort="Trojan.Nitrokod.UDP.C&amp;C" Avp3="Trojan.Win32.Nitrokod.a" />
  <Malware Snort="Trojan.NJRat.TCP.C&amp;C" Avp3="Trojan.Win32.NJRat.a" />
  <Malware Snort="Trojan.Nymaim.HTTP.C&amp;C" Avp3="Trojan.Win32.Nymaim.a" />
  <Malware Snort="Trojan.Nystprac.UDP.ServerRequest" Avp3="Trojan.Win32.Nystprac.a" />
  <Malware Avp3="Trojan.Win32.Obfuscated.a">
    <Snort rule="Trojan.Obfuscated.HTTP.ServerRequest" />
    <Snort rule="Trojan.Obfuscated.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.OceanLotus.UDP.C&amp;C" Avp3="Trojan.Win32.OceanLotus.a" />
  <Malware Avp3="Trojan.Win32.Oficla.a">
    <Snort rule="Trojan.Oficla.HTTP.C&amp;C" />
    <Snort rule="Trojan.Oficla.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Packed.TCP.ServerRequest" Avp3="Trojan.Win32.Packed.gen" />
  <Malware Snort="Trojan.Pasta.HTTP.C&amp;C" Avp3="Trojan.Win32.Pasta.a" />
  <Malware Avp3="Trojan.Win32.Patched.a">
    <Snort rule="Trojan.Patched.HTTP.C&amp;C" />
    <Snort rule="Trojan.Patched.HTTP.ServerRequest" />
    <Snort rule="Trojan.Patched.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.PEDICOM.DICOM.C&amp;C" Avp3="Trojan.Win32.PEDICOM.a" />
  <Malware Avp3="Trojan.Win32.Penguish.gen">
    <Snort rule="Trojan.Penguish.HTTP.C&amp;C" />
    <Snort rule="Trojan.Penguish.TCP.ServerRequest" />
    <Snort rule="Trojan.Penguish.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Phpw.gen">
    <Snort rule="Trojan.Phpw.TLS.C&amp;C" />
    <Snort rule="Trojan.Phpw.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Pincav.TCP.ServerRequest" Avp3="Trojan.Win32.Pincav.a" />
  <Malware Snort="Trojan.Plodor.HTTP.C&amp;C" Avp3="Trojan.Win32.Plodor.a" />
  <Malware Snort="Trojan.PoorWeb.HTTP.ServerRequest" Avp3="Trojan.Win32.PoorWeb.a" />
  <Malware Snort="Trojan.Propagate.HTTP.ServerRequest" Avp3="Trojan.Win32.Propagate.a" />
  <Malware Snort="Trojan.ProxyChanger.HTTP.C&amp;C" Avp3="Trojan.Win32.ProxyChanger.a" />
  <Malware Avp3="Trojan.Win32.PurpleFox.a">
    <Snort rule="Trojan.PurpleFox.TCP.C&amp;C" />
    <Snort rule="Trojan.PurpleFox.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Pushel.TCP.C&amp;C" Avp3="Trojan.Win32.Pushel.gen" />
  <Malware Avp3="Trojan.Win32.Qhost.a">
    <Snort rule="Trojan.Qhost.HTTP.C&amp;C" />
    <Snort rule="Trojan.Qhost.HTTP.Download" />
  </Malware>
  <Malware Snort="Trojan.Ramnit.TCP.C&amp;C" Avp3="Trojan.Win32.Ramnit.a" />
  <Malware Snort="Trojan.RanPSO.HTTP.Download" Avp3="Trojan.Win32.RanPSO.a" />
  <Malware Snort="Trojan.Rebrecus.TCP.C&amp;C" Avp3="Trojan.Win32.Rebrecus.a" />
  <Malware Avp3="Trojan.Win32.Reconyc.a">
    <Snort rule="Trojan.Reconyc.HTTP.C&amp;C" />
    <Snort rule="Trojan.Reconyc.HTTP.ServerRequest" />
    <Snort rule="Trojan.Reconyc.TCP.ServerRequest" />
    <Snort rule="Trojan.Reconyc.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Reflective.HTTP.C&amp;C" Avp3="Trojan.Win32.Reflective.a" />
  <Malware Snort="Trojan.Refroso.HTTP.C&amp;C" Avp3="Trojan.Win32.Refroso.a" />
  <Malware Avp3="Trojan.Win32.Regrun.a">
    <Snort rule="Trojan.Regrun.HTTP.ServerRequest" />
    <Snort rule="Trojan.Regrun.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Regsup.UDP.ServerRequest" Avp3="Trojan.Win32.Regsup.a" />
  <Malware Snort="Trojan.Remcos.TCP.ServerRequest" Avp3="Trojan.Win32.Remcos.a" />
  <Malware Snort="Trojan.Rofin.HTTP.C&amp;C" Avp3="Trojan.Win32.Rofin.a" />
  <Malware Snort="Trojan.RunDll.HTTP.ServerRequest" Avp3="Trojan.Win32.RunDll.a" />
  <Malware Avp3="Trojan.Win32.Scar.a">
    <Snort rule="Trojan.Scar.HTTP.C&amp;C" />
    <Snort rule="Trojan.Scar.HTTP.ServerRequest" />
    <Snort rule="Trojan.Scar.TCP.C&amp;C" />
    <Snort rule="Trojan.Scar.TCP.ServerRequest" />
    <Snort rule="Trojan.Scar.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Scar.gen">
    <Snort rule="Trojan.Scar.HTTP.ServerRequest" />
    <Snort rule="Trojan.Scar.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Scarsi.a">
    <Snort rule="Trojan.Scarsi.HTTP.C&amp;C" />
    <Snort rule="Trojan.Scarsi.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.SchoolBoy.HTTP.ServerRequest" Avp3="Trojan.Win32.SchoolBoy.a" />
  <Malware Snort="Trojan.Sefnit.HTTP.C&amp;C" Avp3="Trojan.Win32.Sefnit.a" />
  <Malware Snort="Trojan.SelfDel.HTTP.ServerRequest" Avp3="Trojan.Win32.SelfDel.a" />
  <Malware Avp3="Trojan.Win32.ShadowBrokers.a">
    <Snort rule="Trojan.ShadowBrokers.SMB.ServerRequest" />
    <Snort rule="Trojan.ShadowBrokers.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.ShadowPad.UDP.C&amp;C" Avp3="Trojan.Win32.ShadowPad.a" />
  <Malware Snort="Trojan.Sharik.HTTP.ServerRequest" Avp3="Trojan.Win32.Sharik.a" />
  <Malware Snort="Trojan.Shelma.TCP.ServerRequest" Avp3="Trojan.Win32.Shelma.a" />
  <Malware Snort="Trojan.Slowpok.TCP.C&amp;C" Avp3="Trojan.Win32.Slowpok.a" />
  <Malware Avp3="Trojan.Win32.Small.a">
    <Snort rule="Trojan.Small.HTTP.ServerRequest" />
    <Snort rule="Trojan.Small.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Snojan.a">
    <Snort rule="Trojan.Snojan.HTTP.C&amp;C" />
    <Snort rule="Trojan.Snojan.HTTP.ServerRequest" />
    <Snort rule="Trojan.Snojan.TCP.ServerRequest" />
    <Snort rule="Trojan.Snojan.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Snovir.a">
    <Snort rule="Trojan.Snovir.HTTP.C&amp;C" />
    <Snort rule="Trojan.Snovir.HTTP.ServerRequest" />
    <Snort rule="Trojan.Snovir.UDP.C&amp;C" />
    <Snort rule="Trojan.Snovir.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Sofacy.a">
    <Snort rule="Trojan.Sofacy.HTTP.C&amp;C" />
    <Snort rule="Trojan.Sofacy.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.StartPage.HTTP.C&amp;C" Avp3="Trojan.Win32.StartPage.a" />
  <Malware Snort="Trojan.StartServ.TCP.C&amp;C" Avp3="Trojan.Win32.StartServ.a" />
  <Malware Avp3="Trojan.Win32.Staser.a">
    <Snort rule="Trojan.Staser.HTTP.C&amp;C" />
    <Snort rule="Trojan.Staser.HTTP.ServerRequest" />
    <Snort rule="Trojan.Staser.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Stealer.HTTP.C&amp;C" Avp3="Trojan.Win32.Stealer.a" />
  <Malware Avp3="Trojan.Win32.Stelpak.gen">
    <Snort rule="Trojan.Stelpak.TLS.C&amp;C" />
    <Snort rule="Trojan.Stelpak.UDP.C&amp;C" />
    <Snort rule="Trojan.Stelpak.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Strab.HTTP.C&amp;C" Avp3="Trojan.Win32.Strab.a" />
  <Malware Avp3="Trojan.Win32.Strab.gen">
    <Snort rule="Trojan.Strab.TCP.C&amp;C" />
    <Snort rule="Trojan.Strab.TCP.ServerRequest" />
    <Snort rule="Trojan.Strab.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.StrongPity.HTTP.C&amp;C" Avp3="Trojan.Win32.StrongPity.a" />
  <Malware Avp3="Trojan.Win32.Swisyn.a">
    <Snort rule="Trojan.Swisyn.TCP.C&amp;C" />
    <Snort rule="Trojan.Swisyn.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Swizzor.HTTP.C&amp;C" Avp3="Trojan.Win32.Swizzor.a" />
  <Malware Snort="Trojan.Swrort.HTTP.ServerRequest" Avp3="Trojan.Win32.Swrort.a" />
  <Malware Avp3="Trojan.Win32.Tasker.a">
    <Snort rule="Trojan.Tasker.HTTP.C&amp;C" />
    <Snort rule="Trojan.Tasker.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Tasker.gen">
    <Snort rule="Trojan.Tasker.TCP.ServerRequest" />
    <Snort rule="Trojan.Tasker.UDP.C&amp;C" />
    <Snort rule="Trojan.Tasker.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Tbma.UDP.ServerRequest" Avp3="Trojan.Win32.Tbma.a" />
  <Malware Snort="Trojan.TDSS.HTTP.ServerRequest" Avp3="Trojan.Win32.TDSS.a" />
  <Malware Snort="Trojan.Tibs.HTTP.Notification" Avp3="Trojan.Win32.Tibs.a" />
  <Malware Avp3="Trojan.Win32.Tinba.a">
    <Snort rule="Trojan.Tinba.HTTP.C&amp;C" />
    <Snort rule="Trojan.Tinba.HTTP.Notification" />
  </Malware>
  <Malware Snort="Trojan.TorJok.UDP.C&amp;C" Avp3="Trojan.Win32.TorJok.a" />
  <Malware Avp3="Trojan.Win32.Tremp.a">
    <Snort rule="Trojan.Tremp.HTTP.C&amp;C" />
    <Snort rule="Trojan.Tremp.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Trickpak.HTTP.C&amp;C" Avp3="Trojan.Win32.Trickpak.a" />
  <Malware Avp3="Trojan.Win32.Trickster.a">
    <Snort rule="Trojan.Trickster.HTTP.ServerRequest" />
    <Snort rule="Trojan.Trickster.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Vaklik.HTTP.C&amp;C" Avp3="Trojan.Win32.Vaklik.a" />
  <Malware Snort="Trojan.Valcaryx.HTTP.C&amp;C" Avp3="Trojan.Win32.Valcaryx.a" />
  <Malware Snort="Trojan.Vasal.HTTP.ServerRequest" Avp3="Trojan.Win32.Vasal.a" />
  <Malware Avp3="Trojan.Win32.VBKrypt.a">
    <Snort rule="Trojan.VBKrypt.HTTP.ServerRequest" />
    <Snort rule="Trojan.VBKrypt.UDP.C&amp;C" />
    <Snort rule="Trojan.VBKrypt.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Vebzenpak.a">
    <Snort rule="Trojan.Vebzenpak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Vebzenpak.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Vehidis.TCP.C&amp;C" Avp3="Trojan.Win32.Vehidis.a" />
  <Malware Snort="Trojan.Vemptik.TCP.ServerRequest" Avp3="Trojan.Win32.Vemptik.a" />
  <Malware Snort="Trojan.Vilsel.HTTP.ServerRequest" Avp3="Trojan.Win32.Vilsel.a" />
  <Malware Avp3="Trojan.Win32.Vimditator.a">
    <Snort rule="Trojan.Vimditator.HTTP.C&amp;C" />
    <Snort rule="Trojan.Vimditator.HTTP.ServerRequest" />
    <Snort rule="Trojan.Vimditator.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.vjWorm.HTTP.C&amp;C" Avp3="Trojan.Win32.vjWorm.a" />
  <Malware Avp3="Trojan.Win32.Vobfus.a">
    <Snort rule="Trojan.Vobfus.HTTP.Download" />
    <Snort rule="Trojan.Vobfus.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Vtflooder.UDP.ServerRequest" Avp3="Trojan.Win32.Vtflooder.a" />
  <Malware Snort="Trojan.Wecod.HTTP.C&amp;C" Avp3="Trojan.Win32.Wecod.a" />
  <Malware Snort="Trojan.WhiteAtlas.HTTP.C&amp;C" Avp3="Trojan.Win32.WhiteAtlas.a" />
  <Malware Snort="Trojan.XRed.UDP.C&amp;C" Avp3="Trojan.Win32.XRed.a" />
  <Malware Snort="Trojan.Xtrat.HTTP.C&amp;C" Avp3="Trojan.Win32.Xtrat.a" />
  <Malware Avp3="Trojan.Win32.Yakes.a">
    <Snort rule="Trojan.Yakes.HTTP.ServerRequest" />
    <Snort rule="Trojan.Yakes.TCP.C&amp;C" />
    <Snort rule="Trojan.Yakes.TCP.ServerRequest" />
    <Snort rule="Trojan.Yakes.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Yephiler.HTTP.C&amp;C" Avp3="Trojan.Win32.Yephiler.a" />
  <Malware Snort="Trojan.Zapchast.HTTP.C&amp;C" Avp3="Trojan.Win32.Zapchast.a" />
  <Malware Snort="Trojan.Zenfly.HTTP.C&amp;C" Avp3="Trojan.Win32.Zenfly.wb" />
  <Malware Avp3="Trojan.Win32.Zenpak.a">
    <Snort rule="Trojan.Zenpak.HTTP.C&amp;C" />
    <Snort rule="Trojan.Zenpak.HTTP.ServerRequest" />
    <Snort rule="Trojan.Zenpak.TCP.ServerRequest" />
    <Snort rule="Trojan.Zenpak.UDP.C&amp;C" />
    <Snort rule="Trojan.Zenpak.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win32.Zenpak.gen">
    <Snort rule="Trojan.Zenpak.HTTP.ServerRequest" />
    <Snort rule="Trojan.Zenpak.TCP.ServerRequest" />
    <Snort rule="Trojan.Zenpak.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Zonebac.HTTP.Notification" Avp3="Trojan.Win32.Zonebac.a" />
  <Malware Avp3="Trojan.Win64.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.Win64.Agentb.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agentb.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Agentb.UDP.ServerRequest" Avp3="Trojan.Win64.Agentb.gen" />
  <Malware Snort="Trojan.Alien.HTTP.C&amp;C" Avp3="Trojan.Win64.Alien.a" />
  <Malware Snort="Trojan.BitMin.HTTP.C&amp;C" Avp3="Trojan.Win64.BitMin.a" />
  <Malware Snort="Trojan.BitMiner.UDP.ServerRequest" Avp3="Trojan.Win64.BitMiner.a" />
  <Malware Snort="Trojan.Cobalt.HTTP.C&amp;C" Avp3="Trojan.Win64.Cobalt.a" />
  <Malware Snort="Trojan.CobaltStrike.HTTP.C&amp;C" Avp3="Trojan.Win64.CobaltStrike.a" />
  <Malware Snort="Trojan.CollectionRAT.HTTP.C&amp;C" Avp3="Trojan.Win64.CollectionRAT.a" />
  <Malware Snort="Trojan.DBadur.UDP.C&amp;C" Avp3="Trojan.Win64.DBadur.gen" />
  <Malware Snort="Trojan.Egguard.HTTP.ServerRequest" Avp3="Trojan.Win64.Egguard.a" />
  <Malware Avp3="Trojan.Win64.GoInj.gen">
    <Snort rule="Trojan.GoInj.TCP.ServerRequest" />
    <Snort rule="Trojan.GoInj.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.Goshell.HTTP.C&amp;C" Avp3="Trojan.Win64.Goshell.a" />
  <Malware Snort="Trojan.Goshell.HTTP.ServerRequest" Avp3="Trojan.Win64.Goshell.gen" />
  <Malware Snort="Trojan.GriffithRAT.TCP.C&amp;C" Avp3="Trojan.Win64.GriffithRAT.a" />
  <Malware Snort="Trojan.Ligooc.UDP.ServerRequest" Avp3="Trojan.Win64.Ligooc.gen" />
  <Malware Snort="Trojan.Manuscrypt.UDP.ServerRequest" Avp3="Trojan.Win64.Manuscrypt.g" />
  <Malware Avp3="Trojan.Win64.Miner.a">
    <Snort rule="Trojan.Miner.HTTP.C&amp;C" />
    <Snort rule="Trojan.Miner.HTTP.ServerRequest" />
    <Snort rule="Trojan.Miner.TCP.C&amp;C" />
    <Snort rule="Trojan.Miner.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.Reflo.UDP.ServerRequest" Avp3="Trojan.Win64.Reflo.gen" />
  <Malware Snort="Trojan.Rozena.HTTP.C&amp;C" Avp3="Trojan.Win64.Rozena.a" />
  <Malware Snort="Trojan.Shellcode.UDP.ServerRequest" Avp3="Trojan.Win64.Shellcode.gen" />
  <Malware Snort="Trojan.StaryDobry.HTTP.C&amp;C" Avp3="Trojan.Win64.StaryDobry.a" />
  <Malware Avp3="Trojan.Win64.Vilers.a">
    <Snort rule="Trojan.Vilers.HTTP.C&amp;C" />
    <Snort rule="Trojan.Vilers.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan.WildPositron.HTTP.ServerRequest" Avp3="Trojan.Win64.WildPositron.a" />
  <Malware Avp3="Trojan.WinLNK.Agent.a">
    <Snort rule="Trojan.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan.Agent.HTTP.Notification" />
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.WinLNK.Agent.gen">
    <Snort rule="Trojan.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan.WinLNK.Powecod.gen">
    <Snort rule="Trojan.Powecod.TCP.ServerRequest" />
    <Snort rule="Trojan.Powecod.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan.StartPage.HTTP.ServerRequest" Avp3="Trojan.WinLNK.StartPage.a" />
  <Malware Snort="Trojan-Banker.Banker.UDP.C&amp;C" Avp3="Trojan-Banker.MSIL.Banker.a" />
  <Malware Snort="Trojan-Banker.ClipBanker.HTTP.ServerRequest" Avp3="Trojan-Banker.MSIL.ClipBanker.gen" />
  <Malware Snort="Trojan-Banker.Evital.UDP.ServerRequest" Avp3="Trojan-Banker.MSIL.Evital.a" />
  <Malware Snort="Trojan-Banker.NuclearWinter.HTTP.ServerRequest" Avp3="Trojan-Banker.MSIL.NuclearWinter.gen" />
  <Malware Snort="Trojan-Banker.ClipBanker.HTTP.C&amp;C" Avp3="Trojan-Banker.Python.ClipBanker.gen" />
  <Malware Avp3="Trojan-Banker.Win32.Banbra.a">
    <Snort rule="Trojan-Banker.Banbra.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.Banbra.HTTP.ServerRequest" />
    <Snort rule="Trojan-Banker.Banbra.TCP.C&amp;C" />
    <Snort rule="Trojan-Banker.Banbra.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Banker.Banbra.HTTP.ServerRequest" Avp3="Trojan-Banker.Win32.Banbra.gen" />
  <Malware Snort="Trojan-Banker.Bancos.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Bancos.a" />
  <Malware Snort="Trojan-Banker.Bandra.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Bandra.a" />
  <Malware Avp3="Trojan-Banker.Win32.Banker.a">
    <Snort rule="Trojan-Banker.Banker.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.Banker.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Banker.ChePro.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.ChePro.a" />
  <Malware Snort="Trojan-Banker.Chthonic.TCP.C&amp;C" Avp3="Trojan-Banker.Win32.Chthonic.a" />
  <Malware Avp3="Trojan-Banker.Win32.ClipBanker.a">
    <Snort rule="Trojan-Banker.ClipBanker.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.ClipBanker.HTTP.ServerRequest" />
    <Snort rule="Trojan-Banker.ClipBanker.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Banker.Win32.ClipBanker.gen">
    <Snort rule="Trojan-Banker.ClipBanker.HTTP.ServerRequest" />
    <Snort rule="Trojan-Banker.ClipBanker.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Banker.CliptoShuffler.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.CliptoShuffler.a" />
  <Malware Snort="Trojan-Banker.CoreBot.HTTP.ServerRequest" Avp3="Trojan-Banker.Win32.CoreBot.a" />
  <Malware Avp3="Trojan-Banker.Win32.Danabot.a">
    <Snort rule="Trojan-Banker.Danabot.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.Danabot.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Banker.Win32.Emotet.a">
    <Snort rule="Trojan-Banker.Emotet.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.Emotet.TCP.C&amp;C" />
    <Snort rule="Trojan-Banker.Emotet.TLS.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Banker.Emotet.UDP.C&amp;C" Avp3="Trojan-Banker.Win32.Emotet.gen" />
  <Malware Avp3="Trojan-Banker.Win32.Express.gen">
    <Snort rule="Trojan-Banker.Express.TLS.C&amp;C" />
    <Snort rule="Trojan-Banker.Express.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Banker.Win32.Ghoul.a">
    <Snort rule="Trojan-Banker.Ghoul.TCP.C&amp;C" />
    <Snort rule="Trojan-Banker.Ghoul.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Banker.Gozi.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Gozi.a" />
  <Malware Avp3="Trojan-Banker.Win32.IcedID.a">
    <Snort rule="Trojan-Banker.IcedID.HTTP.C&amp;C" />
    <Snort rule="Trojan-Banker.IcedID.TCP.C&amp;C" />
    <Snort rule="Trojan-Banker.IcedID.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Banker.IcedID.UDP.ServerRequest" Avp3="Trojan-Banker.Win32.IcedID.gen" />
  <Malware Snort="Trojan-Banker.Mekoban.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Mekoban.a" />
  <Malware Snort="Trojan-Banker.Mekotio.TCP.C&amp;C" Avp3="Trojan-Banker.Win32.Mekotio.a" />
  <Malware Snort="Trojan-Banker.NeutrinoPOS.HTTP.ServerRequest" Avp3="Trojan-Banker.Win32.NeutrinoPOS.a" />
  <Malware Snort="Trojan-Banker.Passteal.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Passteal.a" />
  <Malware Snort="Trojan-Banker.Ponteiro.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Ponteiro.a" />
  <Malware Snort="Trojan-Banker.RTM.UDP.C&amp;C" Avp3="Trojan-Banker.Win32.RTM.a" />
  <Malware Snort="Trojan-Banker.Trickster.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Trickster.a" />
  <Malware Snort="Trojan-Banker.Vadokrist.HTTP.C&amp;C" Avp3="Trojan-Banker.Win32.Vadokrist.a" />
  <Malware Snort="Trojan-Banker.Banbra.HTTP.C&amp;C" Avp3="Trojan-Banker.Win64.Banbra.a" />
  <Malware Snort="Trojan-Clicker.Agent.HTTP.C&amp;C" Avp3="Trojan-Clicker.MSIL.Agent.a" />
  <Malware Avp3="Trojan-Clicker.Win32.Agent.a">
    <Snort rule="Trojan-Clicker.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Clicker.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Clicker.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Clicker.Cycler.HTTP.Clicker" Avp3="Trojan-Clicker.Win32.Cycler.a" />
  <Malware Snort="Trojan-Clicker.VB.HTTP.ServerRequest" Avp3="Trojan-Clicker.Win32.VB.a" />
  <Malware Snort="Trojan-Clicker.Vesloruki.HTTP.Clicker" Avp3="Trojan-Clicker.Win32.Vesloruki.a" />
  <Malware Avp3="Trojan-DDoS.Linux.Fodcha.a">
    <Snort rule="Trojan-DDoS.Fodcha.HTTP.C&amp;C" />
    <Snort rule="Trojan-DDoS.Fodcha.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-DDoS.Droirtg.HTTP.C&amp;C" Avp3="Trojan-DDoS.Win32.Droirtg.a" />
  <Malware Snort="Trojan-DDoS.Gotiness.UDP.C&amp;C" Avp3="Trojan-DDoS.Win64.Gotiness.a" />
  <Malware Avp3="Trojan-Downloader.BAT.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.FTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agent.HTTP.C&amp;C" Avp3="Trojan-Downloader.HTA.Agent.a" />
  <Malware Snort="Trojan-Downloader.Agent.HTTP.C&amp;C" Avp3="Trojan-Downloader.Java.Agent.a" />
  <Malware Avp3="Trojan-Downloader.JS.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agentb.HTTP.C&amp;C" Avp3="Trojan-Downloader.JS.Agentb.a" />
  <Malware Avp3="Trojan-Downloader.JS.SLoad.a">
    <Snort rule="Trojan-Downloader.SLoad.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.SLoad.HTTP.Download" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agent.HTTP.C&amp;C" Avp3="Trojan-Downloader.Linux.Agent.a" />
  <Malware Snort="Trojan-Downloader.Agent.HTTP.Download" Avp3="Trojan-Downloader.MSExcel.Agent.a" />
  <Malware Snort="Trojan-Downloader.Adload.TCP.ServerRequest" Avp3="Trojan-Downloader.MSIL.Adload.a" />
  <Malware Avp3="Trojan-Downloader.MSIL.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agent.HTTP.ServerRequest" Avp3="Trojan-Downloader.MSIL.Agent.gen" />
  <Malware Snort="Trojan-Downloader.Alien.HTTP.C&amp;C" Avp3="Trojan-Downloader.MSIL.Alien.a" />
  <Malware Snort="Trojan-Downloader.Balamid.HTTP.C&amp;C" Avp3="Trojan-Downloader.MSIL.Balamid.a" />
  <Malware Snort="Trojan-Downloader.Banload.HTTP.ServerRequest" Avp3="Trojan-Downloader.MSIL.Banload.a" />
  <Malware Snort="Trojan-Downloader.Bitmin.HTTP.C&amp;C" Avp3="Trojan-Downloader.MSIL.Bitmin.a" />
  <Malware Avp3="Trojan-Downloader.MSIL.Seraph.gen">
    <Snort rule="Trojan-Downloader.Seraph.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Seraph.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Snoload.HTTP.Download" Avp3="Trojan-Downloader.MSIL.Snoload.a" />
  <Malware Snort="Trojan-Downloader.Tiny.HTTP.Download" Avp3="Trojan-Downloader.MSIL.Tiny.a" />
  <Malware Avp3="Trojan-Downloader.MSOffice.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Agent.TLS.Download" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.MSOffice.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Dotmer.HTTP.C&amp;C" Avp3="Trojan-Downloader.MSOffice.Dotmer.a" />
  <Malware Avp3="Trojan-Downloader.MSOffice.Dotmer.gen">
    <Snort rule="Trojan-Downloader.Dotmer.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Dotmer.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.SAgent.HTTP.C&amp;C" Avp3="Trojan-Downloader.MSOffice.SAgent.a" />
  <Malware Avp3="Trojan-Downloader.MSOffice.SLoad.a">
    <Snort rule="Trojan-Downloader.SLoad.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.SLoad.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.SLoad.TCP.ServerRequest" Avp3="Trojan-Downloader.MSOffice.SLoad.gen" />
  <Malware Avp3="Trojan-Downloader.MSWord.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Cloader.HTTP.C&amp;C" Avp3="Trojan-Downloader.NSIS.Cloader.a" />
  <Malware Snort="Trojan-Downloader.Snoload.HTTP.Download" Avp3="Trojan-Downloader.NSIS.Snoload.a" />
  <Malware Snort="Trojan-Downloader.Agent.TCP.ServerRequest" Avp3="Trojan-Downloader.OLE2.Agent.gen" />
  <Malware Avp3="Trojan-Downloader.PowerShell.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.WebDAV.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.PowerShell.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Dotmer.HTTP.ServerRequest" Avp3="Trojan-Downloader.RTF.Dotmer.gen" />
  <Malware Snort="Trojan-Downloader.Agent.HTTP.C&amp;C" Avp3="Trojan-Downloader.Script.Agent.a" />
  <Malware Avp3="Trojan-Downloader.Script.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Generic.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Script.Agentb.gen">
    <Snort rule="Trojan-Downloader.Agentb.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agentb.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.DarkGate.HTTP.ServerRequest" Avp3="Trojan-Downloader.Script.DarkGate.gen" />
  <Malware Avp3="Trojan-Downloader.Script.Generic.gen">
    <Snort rule="Trojan-Downloader.Generic.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Generic.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Generic.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.SLoad.HTTP.C&amp;C" Avp3="Trojan-Downloader.Script.SLoad.a" />
  <Malware Avp3="Trojan-Downloader.Script.SLoad.gen">
    <Snort rule="Trojan-Downloader.SLoad.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.SLoad.TLS.C&amp;C" />
    <Snort rule="Trojan-Downloader.SLoad.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.SLoad.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agent.HTTP.C&amp;C" Avp3="Trojan-Downloader.Shell.Agent.a" />
  <Malware Snort="Trojan-Downloader.Agent.UDP.ServerRequest" Avp3="Trojan-Downloader.Shell.Agent.gen" />
  <Malware Avp3="Trojan-Downloader.VBS.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.TDS.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.VBS.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.VBS.SLoad.a">
    <Snort rule="Trojan-Downloader.SLoad.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.SLoad.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.SLoad.UDP.ServerRequest" Avp3="Trojan-Downloader.VBS.SLoad.gen" />
  <Malware Avp3="Trojan-Downloader.Win32.Adload.a">
    <Snort rule="Trojan-Downloader.Adload.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Adload.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Adload.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Adload.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.FTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.TCP.Download" />
    <Snort rule="Trojan-Downloader.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
    <Snort rule="Trojan-Downloader.TorConnect.HTTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Agentb.a">
    <Snort rule="Trojan-Downloader.Agentb.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agentb.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Agentb.gen">
    <Snort rule="Trojan-Downloader.Agentb.TLS.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agentb.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.AutoIt.a">
    <Snort rule="Trojan-Downloader.AutoIt.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.AutoIt.HTTP.Download" />
    <Snort rule="Trojan-Downloader.AutoIt.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.AutoIt.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Bandit.a">
    <Snort rule="Trojan-Downloader.Bandit.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Bandit.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Banload.a">
    <Snort rule="Trojan-Downloader.Banload.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Banload.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Banload.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Bitmin.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Bitmin.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Buerak.a">
    <Snort rule="Trojan-Downloader.Buerak.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Buerak.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Cabby.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Cabby.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Cepera.a">
    <Snort rule="Trojan-Downloader.Cepera.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Cepera.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Chindo.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Chindo.a" />
  <Malware Snort="Trojan-Downloader.Cryptoloader.HTTP.Download" Avp3="Trojan-Downloader.Win32.Cryptoloader.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Delf.a">
    <Snort rule="Trojan-Downloader.Delf.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Delf.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Delf.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Deyma.gen">
    <Snort rule="Trojan-Downloader.Deyma.TLS.C&amp;C" />
    <Snort rule="Trojan-Downloader.Deyma.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Dofoil.a">
    <Snort rule="Trojan-Downloader.Dofoil.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Dofoil.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Agent.HTTP.Download" Avp3="Trojan-Downloader.Win32.Download.a" />
  <Malware Snort="Trojan-Downloader.DrivLoad.TCP.C&amp;C.a" Avp3="Trojan-Downloader.Win32.DrivLoad.a" />
  <Malware Snort="Trojan-Downloader.DrivLoad.TCP.C&amp;C.b" Avp3="Trojan-Downloader.Win32.DrivLoad.b" />
  <Malware Snort="Trojan-Downloader.DrivLoad.TCP.C&amp;C" Avp3="Trojan-Downloader.Win32.DrivLoader.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Dupzom.a">
    <Snort rule="Trojan-Downloader.Dupzom.HTTP.Download" />
    <Snort rule="Trojan-Downloader.Dupzom.UDP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Dupzom.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Dyfuca.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Dyfuca.a" />
  <Malware Snort="Trojan-Downloader.Eyooun.UDP.C&amp;C" Avp3="Trojan-Downloader.Win32.Eyooun.a" />
  <Malware Snort="Trojan-Downloader.Faddon.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Faddon.a" />
  <Malware Snort="Trojan-Downloader.Farfli.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Farfli.a" />
  <Malware Snort="Trojan-Downloader.FlyStudio.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.FlyStudio.a" />
  <Malware Snort="Trojan-Downloader.Foold.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Foold.a" />
  <Malware Snort="Trojan-Downloader.Fosniw.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Fosniw.a" />
  <Malware Snort="Trojan-Downloader.Gamup.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Gamup.a" />
  <Malware Snort="Trojan-Downloader.GCleaner.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.GCleaner.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Genome.a">
    <Snort rule="Trojan-Downloader.Genome.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Genome.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Geral.a">
    <Snort rule="Trojan-Downloader.Geral.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Geral.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Harnig.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Harnig.a" />
  <Malware Snort="Trojan-Downloader.Inject.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Inject.a" />
  <Malware Avp3="Trojan-Downloader.Win32.IstBar.a">
    <Snort rule="Trojan-Downloader.IstBar.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.IstBar.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Karagany.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Karagany.a" />
  <Malware Snort="Trojan-Downloader.Knigsfot.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Knigsfot.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Lipler.a">
    <Snort rule="Trojan-Downloader.Lipler.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Lipler.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win32.Miner.a">
    <Snort rule="Trojan-Downloader.Miner.FTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Miner.HTTP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.MsChe.UDP.ServerRequest" Avp3="Trojan-Downloader.Win32.MsChe.a" />
  <Malware Avp3="Trojan-Downloader.Win32.MultiDL.a">
    <Snort rule="Trojan-Downloader.MultiDL.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.MultiDL.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Newsbeef.UDP.ServerRequest" Avp3="Trojan-Downloader.Win32.Newsbeef.a" />
  <Malware Snort="Trojan-Downloader.NSIS.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.NSIS.a" />
  <Malware Avp3="Trojan-Downloader.Win32.OffLoader.a">
    <Snort rule="Trojan-Downloader.OffLoader.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.OffLoader.HTTP.Download" />
    <Snort rule="Trojan-Downloader.OffLoader.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Downloader.OffLoader.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.OffLoader.gen" />
  <Malware Snort="Trojan-Downloader.Onestage.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Onestage.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Paph.a">
    <Snort rule="Trojan-Downloader.Paph.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Paph.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Paph.UDP.ServerRequest" Avp3="Trojan-Downloader.Win32.Paph.gen" />
  <Malware Snort="Trojan-Downloader.Phpw.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Phpw.a" />
  <Malware Snort="Trojan-Downloader.PirateMatryoshka.UDP.ServerRequest" Avp3="Trojan-Downloader.Win32.PirateMatryoshka.a" />
  <Malware Snort="Trojan-Downloader.PsDownload.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.PsDownload.a" />
  <Malware Snort="Trojan-Downloader.PsDownload.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.PsDownload.gen" />
  <Malware Snort="Trojan-Downloader.PurityScan.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.PurityScan.a" />
  <Malware Snort="Trojan-Downloader.Rakhni.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Rakhni.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Satacom.a">
    <Snort rule="Trojan-Downloader.Satacom.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Satacom.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Satan.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Satan.a" />
  <Malware Snort="Trojan-Downloader.Small.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Small.a" />
  <Malware Snort="Trojan-Downloader.Stantinko.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Stantinko.a" />
  <Malware Snort="Trojan-Downloader.Stralo.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.Stralo.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Tiny.a">
    <Snort rule="Trojan-Downloader.Tiny.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Tiny.HTTP.Download" />
  </Malware>
  <Malware Snort="Trojan-Downloader.Tovkater.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Tovkater.a" />
  <Malware Snort="Trojan-Downloader.Tuvir.UDP.C&amp;C" Avp3="Trojan-Downloader.Win32.Tuvir.a" />
  <Malware Avp3="Trojan-Downloader.Win32.Upatre.a">
    <Snort rule="Trojan-Downloader.Upatre.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Upatre.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.VB.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.VB.a" />
  <Malware Snort="Trojan-Downloader.VB.HTTP.Download" Avp3="Trojan-Downloader.Win32.VB.agw" />
  <Malware Snort="Trojan-Downloader.ZippyLoader.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win32.ZippyLoader.a" />
  <Malware Snort="Trojan-Downloader.Zload.UDP.ServerRequest" Avp3="Trojan-Downloader.Win32.Zload.gen" />
  <Malware Snort="Trojan-Downloader.Zlob.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win32.Zlob.a" />
  <Malware Avp3="Trojan-Downloader.Win64.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.Download" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.Win64.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.BitMin.HTTP.ServerRequest" Avp3="Trojan-Downloader.Win64.BitMin.a" />
  <Malware Avp3="Trojan-Downloader.Win64.BumbleBee.gen">
    <Snort rule="Trojan-Downloader.BumbleBee.TCP.C&amp;C" />
    <Snort rule="Trojan-Downloader.BumbleBee.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Downloader.PhantomDL.HTTP.C&amp;C" Avp3="Trojan-Downloader.Win64.PhantomDL.a" />
  <Malware Avp3="Trojan-Downloader.WinLNK.Agent.a">
    <Snort rule="Trojan-Downloader.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Downloader.WinLNK.Agent.gen">
    <Snort rule="Trojan-Downloader.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Downloader.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Dropper.Agent.UDP.ServerRequest" Avp3="Trojan-Dropper.BAT.Agent.gen" />
  <Malware Snort="Trojan-Dropper.Agent.TCP.ServerRequest" Avp3="Trojan-Dropper.MSIL.Agent.a" />
  <Malware Snort="Trojan-Dropper.Agent.TCP.ServerRequest" Avp3="Trojan-Dropper.MSIL.Agent.gen" />
  <Malware Snort="Trojan-Dropper.Scrop.UDP.ServerRequest" Avp3="Trojan-Dropper.MSIL.Scrop.gen" />
  <Malware Snort="Trojan-Dropper.Agent.HTTP.ServerRequest" Avp3="Trojan-Dropper.MSOffice.Agent.a" />
  <Malware Snort="Trojan-Dropper.Wink.UDP.ServerRequest" Avp3="Trojan-Dropper.VBS.Wink.gen" />
  <Malware Snort="Trojan-Dropper.Addrop.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Addrop.a" />
  <Malware Avp3="Trojan-Dropper.Win32.Agent.a">
    <Snort rule="Trojan-Dropper.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Dropper.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Dropper.Agent.TLS.C&amp;C" />
    <Snort rule="Trojan-Dropper.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Dropper.Agent.UDP.ServerRequest" Avp3="Trojan-Dropper.Win32.Agent.gen" />
  <Malware Snort="Trojan-Dropper.BadUpdate.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.BadUpdate.a" />
  <Malware Snort="Trojan-Dropper.Cyns.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Cyns.a" />
  <Malware Avp3="Trojan-Dropper.Win32.Dapato.a">
    <Snort rule="Trojan-Dropper.Dapato.HTTP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Dapato.HTTP.ServerRequest" />
    <Snort rule="Trojan-Dropper.Dapato.UDP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Dapato.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Dropper.Dapato.UDP.C&amp;C" Avp3="Trojan-Dropper.Win32.Dapato.gen" />
  <Malware Snort="Trojan-Dropper.Daws.HTTP.ServerRequest" Avp3="Trojan-Dropper.Win32.Daws.a" />
  <Malware Avp3="Trojan-Dropper.Win32.Delf.a">
    <Snort rule="Trojan-Dropper.Delf.HTTP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Delf.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Dropper.Win32.Demp.a">
    <Snort rule="Trojan-Dropper.Demp.HTTP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Demp.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Dropper.Dinwod.HTTP.ServerRequest" Avp3="Trojan-Dropper.Win32.Dinwod.a" />
  <Malware Snort="Trojan-Dropper.Dorifel.HTTP.ServerRequest" Avp3="Trojan-Dropper.Win32.Dorifel.a" />
  <Malware Snort="Trojan-Dropper.Flystud.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Flystud.a" />
  <Malware Avp3="Trojan-Dropper.Win32.Injector.a">
    <Snort rule="Trojan-Dropper.Injector.HTTP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Injector.HTTP.ServerRequest" />
    <Snort rule="Trojan-Dropper.Injector.TCP.ServerRequest" />
    <Snort rule="Trojan-Dropper.Injector.UDP.C&amp;C" />
    <Snort rule="Trojan-Dropper.Injector.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Dropper.Juntador.HTTP.ServerRequest" Avp3="Trojan-Dropper.Win32.Juntador.a" />
  <Malware Snort="Trojan-Dropper.Necurs.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Necurs.a" />
  <Malware Snort="Trojan-Dropper.Patched.TLS.ServerRequest" Avp3="Trojan-Dropper.Win32.Patched.a" />
  <Malware Snort="Trojan-Dropper.Peerad.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Peerad.a" />
  <Malware Snort="Trojan-Dropper.Small.HTTP.ServerRequest" Avp3="Trojan-Dropper.Win32.Small.a" />
  <Malware Snort="Trojan-Dropper.Sysn.HTTP.C&amp;C" Avp3="Trojan-Dropper.Win32.Sysn.a" />
  <Malware Snort="Trojan-Dropper.Sysn.TCP.ServerRequest" Avp3="Trojan-Dropper.Win32.Sysn.gen" />
  <Malware Snort="Trojan-Dropper.VB.TCP.ServerRequest" Avp3="Trojan-Dropper.Win32.VB.a" />
  <Malware Snort="Trojan-FakeAV.Agent.HTTP.ServerRequest" Avp3="Trojan-FakeAV.Win32.Agent.a" />
  <Malware Snort="Trojan-FakeAV.Onescan.HTTP.ServerRequest" Avp3="Trojan-FakeAV.Win32.Onescan.a" />
  <Malware Snort="Trojan-FakeAV.SmartFortress2012.HTTP.Notification" Avp3="Trojan-FakeAV.Win32.SmartFortress2012.a" />
  <Malware Snort="Trojan-GameThief.Agent.HTTP.C&amp;C" Avp3="Trojan-GameThief.MSIL.Agent.a" />
  <Malware Snort="Trojan-GameThief.Borlox.HTTP.C&amp;C" Avp3="Trojan-GameThief.MSIL.Borlox.a" />
  <Malware Snort="Trojan-GameThief.Worgtop.HTTP.C&amp;C" Avp3="Trojan-GameThief.MSIL.Worgtop.a" />
  <Malware Snort="Trojan-GameThief.Agent.HTTP.C&amp;C" Avp3="Trojan-GameThief.Win32.Agent.a" />
  <Malware Snort="Trojan-GameThief.Agent.UDP.C&amp;C" Avp3="Trojan-GameThief.Win32.Agent.gen" />
  <Malware Avp3="Trojan-GameThief.Win32.Magania.a">
    <Snort rule="Trojan-GameThief.Magania.TCP.C&amp;C" />
    <Snort rule="Trojan-GameThief.Magania.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-GameThief.Win32.OnLineGames.a">
    <Snort rule="Trojan-GameThief.OnLineGames.HTTP.C&amp;C" />
    <Snort rule="Trojan-GameThief.OnLineGames.HTTP.ServerRequest" />
    <Snort rule="Trojan-GameThief.OnLineGames.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-GameThief.Tibia.HTTP.C&amp;C" Avp3="Trojan-GameThief.Win32.Tibia.a" />
  <Malware Snort="Trojan-Notifier.Agent.HTTP.Notification" Avp3="Trojan-Notifier.Python.Agent.a" />
  <Malware Avp3="Trojan-Proxy.Win32.Agent.a">
    <Snort rule="Trojan-Proxy.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Proxy.Agent.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Proxy.Coco.HTTP.ServerRequest" Avp3="Trojan-Proxy.Win32.Coco.a" />
  <Malware Snort="Trojan-Proxy.Glupteba.HTTP.C&amp;C" Avp3="Trojan-Proxy.Win32.Glupteba.a" />
  <Malware Snort="Trojan-Proxy.Hioles.TCP.C&amp;C" Avp3="Trojan-Proxy.Win32.Hioles.a" />
  <Malware Avp3="Trojan-Proxy.Win32.Lethic.a">
    <Snort rule="Trojan-Proxy.Lethic.TCP.C&amp;C" />
    <Snort rule="Trojan-Proxy.Lethic.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Proxy.PexTea.HTTP.ServerRequest" Avp3="Trojan-Proxy.Win32.PexTea.a" />
  <Malware Snort="Trojan-Proxy.StarV.HTTP.C&amp;C" Avp3="Trojan-Proxy.Win32.StarV.a" />
  <Malware Snort="Trojan-Proxy.Sybici.HTTP.C&amp;C" Avp3="Trojan-Proxy.Win32.Sybici.a" />
  <Malware Snort="Trojan-Proxy.Windigo.HTTP.C&amp;C" Avp3="Trojan-Proxy.Win32.Windigo.a" />
  <Malware Snort="Trojan-Proxy.Windigo.TCP.ServerRequest" Avp3="Trojan-Proxy.Win32.Windigo.gen" />
  <Malware Avp3="Trojan-PSW.MSIL.Agensla.a">
    <Snort rule="Trojan-PSW.Agensla.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agensla.SMTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agensla.TCP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agensla.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Agensla.TCP.ServerRequest" Avp3="Trojan-PSW.MSIL.Agensla.gen" />
  <Malware Avp3="Trojan-PSW.MSIL.Agent.a">
    <Snort rule="Trojan-PSW.Agent.FTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Agent.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-PSW.Anagra.TCP.ServerRequest" Avp3="Trojan-PSW.MSIL.Anagra.gen" />
  <Malware Snort="Trojan-PSW.Azorult.TCP.ServerRequest" Avp3="Trojan-PSW.MSIL.Azorult.a" />
  <Malware Snort="Trojan-PSW.Azorult.UDP.ServerRequest" Avp3="Trojan-PSW.MSIL.Azorult.gen" />
  <Malware Snort="Trojan-PSW.Cerna.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.Cerna.a" />
  <Malware Avp3="Trojan-PSW.MSIL.Coins.gen">
    <Snort rule="Trojan-PSW.Coins.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Coins.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.DCRat.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.DCRat.a" />
  <Malware Snort="Trojan-PSW.Disco.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.Disco.a" />
  <Malware Avp3="Trojan-PSW.MSIL.Disco.gen">
    <Snort rule="Trojan-PSW.Disco.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Disco.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Disco.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.MSIL.Growtopia.a">
    <Snort rule="Trojan-PSW.Growtopia.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Growtopia.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-PSW.MSIL.Lumma.gen">
    <Snort rule="Trojan-PSW.Lumma.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Lumma.TLS.C&amp;C" />
    <Snort rule="Trojan-PSW.Lumma.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-PSW.PrivateLoader.TCP.ServerRequest" Avp3="Trojan-PSW.MSIL.PrivateLoader.gen" />
  <Malware Snort="Trojan-PSW.PureLogs.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.PureLogs.a" />
  <Malware Snort="Trojan-PSW.PureLogs.TCP.C&amp;C" Avp3="Trojan-PSW.MSIL.PureLogs.gen" />
  <Malware Snort="Trojan-PSW.Reline.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.Reline.a" />
  <Malware Avp3="Trojan-PSW.MSIL.Reline.gen">
    <Snort rule="Trojan-PSW.Reline.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Reline.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Reline.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.MSIL.RisePro.gen">
    <Snort rule="Trojan-PSW.RisePro.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.RisePro.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Stealer.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.Stealer.a" />
  <Malware Avp3="Trojan-PSW.MSIL.Stealer.gen">
    <Snort rule="Trojan-PSW.Stealer.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealer.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.MSIL.Stealerc.gen">
    <Snort rule="Trojan-PSW.Stealerc.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealerc.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealerc.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Stelega.HTTP.ServerRequest" Avp3="Trojan-PSW.MSIL.Stelega.a" />
  <Malware Snort="Trojan-PSW.StormKitty.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.StormKitty.a" />
  <Malware Snort="Trojan-PSW.WhiteSnake.HTTP.C&amp;C" Avp3="Trojan-PSW.MSIL.WhiteSnake.a" />
  <Malware Snort="Trojan-PSW.HashBreaker.HTTP.C&amp;C" Avp3="Trojan-PSW.OSX.HashBreaker.a" />
  <Malware Snort="Trojan-PSW.Stealer.HTTP.C&amp;C" Avp3="Trojan-PSW.OSX.Stealer.a" />
  <Malware Snort="Trojan-PSW.Stealer.HTTP.C&amp;C" Avp3="Trojan-PSW.Python.Stealer.a" />
  <Malware Snort="Trojan-PSW.Agent.HTTP.C&amp;C" Avp3="Trojan-PSW.Script.Agent.a" />
  <Malware Snort="Trojan-PSW.Lumma.HTTP.C&amp;C" Avp3="Trojan-PSW.Script.Lumma.a" />
  <Malware Avp3="Trojan-PSW.Win32.Agent.a">
    <Snort rule="Trojan-PSW.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agent.HTTP.Notification" />
    <Snort rule="Trojan-PSW.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-PSW.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Agent.TLS.C&amp;C" />
    <Snort rule="Trojan-PSW.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Agentb.UDP.C&amp;C" Avp3="Trojan-PSW.Win32.Agentb.gen" />
  <Malware Avp3="Trojan-PSW.Win32.Azorult.a">
    <Snort rule="Trojan-PSW.Azorult.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Azorult.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Azorult.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Chisburg.a">
    <Snort rule="Trojan-PSW.Chisburg.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Chisburg.HTTP.Notification" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Coins.a">
    <Snort rule="Trojan-PSW.Coins.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Coins.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Coins.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Coins.gen">
    <Snort rule="Trojan-PSW.Coins.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Coins.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.CoinStealer.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.CoinStealer.a" />
  <Malware Snort="Trojan-PSW.Convagent.UDP.C&amp;C" Avp3="Trojan-PSW.Win32.Convagent.gen" />
  <Malware Snort="Trojan-PSW.CopperStealer.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.CopperStealer.a" />
  <Malware Snort="Trojan-PSW.Cryptnot.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Cryptnot.a" />
  <Malware Snort="Trojan-PSW.Cryptnot.UDP.ServerRequest" Avp3="Trojan-PSW.Win32.Cryptnot.gen" />
  <Malware Avp3="Trojan-PSW.Win32.DarkCloud.gen">
    <Snort rule="Trojan-PSW.DarkCloud.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.DarkCloud.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Disbuk.UDP.C&amp;C" Avp3="Trojan-PSW.Win32.Disbuk.a" />
  <Malware Snort="Trojan-PSW.Disco.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Disco.a" />
  <Malware Avp3="Trojan-PSW.Win32.Disco.gen">
    <Snort rule="Trojan-PSW.Disco.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Disco.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Fareit.a">
    <Snort rule="Trojan-PSW.Fareit.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Fareit.HTTP.Download" />
    <Snort rule="Trojan-PSW.Fareit.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Fareit.TCP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Heye.a">
    <Snort rule="Trojan-PSW.Heye.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Heye.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Kliper.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Kliper.a" />
  <Malware Snort="Trojan-PSW.Kpot.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Kpot.a" />
  <Malware Avp3="Trojan-PSW.Win32.Kykymber.a">
    <Snort rule="Trojan-PSW.Kykymber.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Kykymber.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.LdPinch.a">
    <Snort rule="Trojan-PSW.LdPinch.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.LdPinch.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Lumma.a">
    <Snort rule="Trojan-PSW.Lumma.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Lumma.HTTP.Download" />
    <Snort rule="Trojan-PSW.Lumma.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Lumma.gen">
    <Snort rule="Trojan-PSW.Lumma.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Lumma.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Lumma.TLS.C&amp;C" />
    <Snort rule="Trojan-PSW.Lumma.UDP.C&amp;C" />
    <Snort rule="Trojan-PSW.Lumma.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Maslog.FTP.C&amp;C" Avp3="Trojan-PSW.Win32.Maslog.a" />
  <Malware Avp3="Trojan-PSW.Win32.Mimikatz.a">
    <Snort rule="Trojan-PSW.Mimikatz.DRSUAPI.C&amp;C" />
    <Snort rule="Trojan-PSW.Mimikatz.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-PSW.Mimikatz.TCP.ServerRequest" Avp3="Trojan-PSW.Win32.Mimikatz.gen" />
  <Malware Snort="Trojan-PSW.Murida.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Murida.a" />
  <Malware Snort="Trojan-PSW.PdPinch.HTTP.ServerRequest" Avp3="Trojan-PSW.Win32.PdPinch.a" />
  <Malware Snort="Trojan-PSW.Phpw.UDP.ServerRequest" Avp3="Trojan-PSW.Win32.Phpw.a" />
  <Malware Snort="Trojan-PSW.Predator.HTTP.ServerRequest" Avp3="Trojan-PSW.Win32.Predator.a" />
  <Malware Snort="Trojan-PSW.PrivateLoader.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.PrivateLoader.a" />
  <Malware Snort="Trojan-PSW.PrivateLoader.HTTP.ServerRequest" Avp3="Trojan-PSW.Win32.PrivateLoader.gen" />
  <Malware Snort="Trojan-PSW.Purqos.HTTP.ServerRequest" Avp3="Trojan-PSW.Win32.Purqos.a" />
  <Malware Avp3="Trojan-PSW.Win32.QQPass.a">
    <Snort rule="Trojan-PSW.QQPass.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.QQPass.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-PSW.QQPass.HTTP.ServerRequest" Avp3="Trojan-PSW.Win32.QQPass.gen" />
  <Malware Snort="Trojan-PSW.QQRob.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.QQRob.a" />
  <Malware Avp3="Trojan-PSW.Win32.Racealer.a">
    <Snort rule="Trojan-PSW.Racealer.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Racealer.HTTP.Download" />
    <Snort rule="Trojan-PSW.Racealer.TLS.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Reline.gen">
    <Snort rule="Trojan-PSW.Reline.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Reline.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Rhadamanthus.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Rhadamanthus.a" />
  <Malware Snort="Trojan-PSW.Rhadamathys.TLS.C&amp;C" Avp3="Trojan-PSW.Win32.Rhadamathys.a" />
  <Malware Snort="Trojan-PSW.RisePro.TCP.C&amp;C" Avp3="Trojan-PSW.Win32.RisePro.a" />
  <Malware Avp3="Trojan-PSW.Win32.RisePro.gen">
    <Snort rule="Trojan-PSW.RisePro.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.RisePro.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Stealer.a">
    <Snort rule="Trojan-PSW.Stealer.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Stealer.TCP.C&amp;C" />
    <Snort rule="Trojan-PSW.Stealer.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-PSW.Win32.Stealer.gen">
    <Snort rule="Trojan-PSW.Stealer.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealer.TCP.C&amp;C" />
    <Snort rule="Trojan-PSW.Stealer.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealer.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Stealerc.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Stealerc.a" />
  <Malware Avp3="Trojan-PSW.Win32.Stealerc.gen">
    <Snort rule="Trojan-PSW.Stealerc.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealerc.TCP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealerc.TLS.C&amp;C" />
    <Snort rule="Trojan-PSW.Stealerc.UDP.C&amp;C" />
    <Snort rule="Trojan-PSW.Stealerc.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Stelega.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Stelega.a" />
  <Malware Snort="Trojan-PSW.Taurus.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Taurus.a" />
  <Malware Snort="Trojan-PSW.TeleBot.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.TeleBot.a" />
  <Malware Avp3="Trojan-PSW.Win32.Tepfer.a">
    <Snort rule="Trojan-PSW.Tepfer.HTTP.C&amp;C" />
    <Snort rule="Trojan-PSW.Tepfer.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-PSW.Tepfer.UDP.ServerRequest" Avp3="Trojan-PSW.Win32.Tepfer.gen" />
  <Malware Snort="Trojan-PSW.Vidar.HTTP.C&amp;C" Avp3="Trojan-PSW.Win32.Vidar.a" />
  <Malware Avp3="Trojan-PSW.Win32.WinDealer.a">
    <Snort rule="Trojan-PSW.WinDealer.TCP.C&amp;C" />
    <Snort rule="Trojan-PSW.WinDealer.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-PSW.Agent.HTTP.C&amp;C" Avp3="Trojan-PSW.Win64.Agent.a" />
  <Malware Snort="Trojan-PSW.Coins.HTTP.C&amp;C" Avp3="Trojan-PSW.Win64.Coins.a" />
  <Malware Snort="Trojan-PSW.Disco.HTTP.C&amp;C" Avp3="Trojan-PSW.Win64.Disco.a" />
  <Malware Snort="Trojan-PSW.Stealer.HTTP.C&amp;C" Avp3="Trojan-PSW.Win64.Stealer.a" />
  <Malware Avp3="Trojan-PSW.Win64.Stealer.gen">
    <Snort rule="Trojan-PSW.Stealer.HTTP.ServerRequest" />
    <Snort rule="Trojan-PSW.Stealer.TCP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Ransom.MSIL.Blocker.gen">
    <Snort rule="Trojan-Ransom.Blocker.HTTP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Blocker.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Loki.HTTP.C&amp;C" Avp3="Trojan-Ransom.MSIL.Loki.a" />
  <Malware Snort="Trojan-Ransom.Tear.HTTP.C&amp;C" Avp3="Trojan-Ransom.MSIL.Tear.a" />
  <Malware Snort="Trojan-Ransom.Agent.HTTP.C&amp;C" Avp3="Trojan-Ransom.PowerShell.Agent.a" />
  <Malware Avp3="Trojan-Ransom.Win32.Agent.a">
    <Snort rule="Trojan-Ransom.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Agent.SMTP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Ransom.Win32.Agent.gen">
    <Snort rule="Trojan-Ransom.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Birele.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Birele.a" />
  <Malware Avp3="Trojan-Ransom.Win32.Bitman.a">
    <Snort rule="Trojan-Ransom.Bitman.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Bitman.HTTP.Download" />
    <Snort rule="Trojan-Ransom.Bitman.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Ransom.Win32.Blocker.a">
    <Snort rule="Trojan-Ransom.Blocker.HTTP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Blocker.TCP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Blocker.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Blocker.TCP.ServerRequest" Avp3="Trojan-Ransom.Win32.Blocker.gen" />
  <Malware Snort="Trojan-Ransom.Crypmod.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Crypmod.a" />
  <Malware Snort="Trojan-Ransom.Crypmodng.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Crypmodng.a" />
  <Malware Snort="Trojan-Ransom.Cryptodef.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Cryptodef.a" />
  <Malware Snort="Trojan-Ransom.Cryptor.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Cryptor.a" />
  <Malware Snort="Trojan-Ransom.Darkside.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Darkside.a" />
  <Malware Snort="Trojan-Ransom.Darkside.TCP.ServerRequest" Avp3="Trojan-Ransom.Win32.Darkside.gen" />
  <Malware Avp3="Trojan-Ransom.Win32.Encoder.a">
    <Snort rule="Trojan-Ransom.Encoder.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Encoder.HTTP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Encoder.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Ransom.Win32.Encoder.gen">
    <Snort rule="Trojan-Ransom.Encoder.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Encoder.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Foreign.TCP.ServerRequest" Avp3="Trojan-Ransom.Win32.Foreign.a" />
  <Malware Snort="Trojan-Ransom.Fury.HTTP.Notification" Avp3="Trojan-Ransom.Win32.Fury.a" />
  <Malware Avp3="Trojan-Ransom.Win32.GandCrypt.a">
    <Snort rule="Trojan-Ransom.GandCrypt.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.GandCrypt.UDP.C&amp;C" />
    <Snort rule="Trojan-Ransom.GandCrypt.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Gimemo.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Gimemo.a" />
  <Malware Snort="Trojan-Ransom.JSWorm.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.JSWorm.a" />
  <Malware Snort="Trojan-Ransom.Limbozar.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Limbozar.a" />
  <Malware Avp3="Trojan-Ransom.Win32.Locky.a">
    <Snort rule="Trojan-Ransom.Locky.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Locky.HTTP.Notification" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Mallox.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Mallox.a" />
  <Malware Snort="Trojan-Ransom.Matrix.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Matrix.a" />
  <Malware Snort="Trojan-Ransom.Mbro.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Mbro.a" />
  <Malware Snort="Trojan-Ransom.Phpw.HTTP.ServerRequest" Avp3="Trojan-Ransom.Win32.Phpw.gen" />
  <Malware Avp3="Trojan-Ransom.Win32.PornoAsset.a">
    <Snort rule="Trojan-Ransom.PornoAsset.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.PornoAsset.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.SageCrypt.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.SageCrypt.a" />
  <Malware Snort="Trojan-Ransom.Scatter.UDP.ServerRequest" Avp3="Trojan-Ransom.Win32.Scatter.a" />
  <Malware Snort="Trojan-Ransom.Shade.UDP.C&amp;C" Avp3="Trojan-Ransom.Win32.Shade.a" />
  <Malware Snort="Trojan-Ransom.Snocry.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Snocry.a" />
  <Malware Avp3="Trojan-Ransom.Win32.Spora.a">
    <Snort rule="Trojan-Ransom.Spora.HTTP.Download" />
    <Snort rule="Trojan-Ransom.Spora.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Stop.TCP.ServerRequest" Avp3="Trojan-Ransom.Win32.Stop.gen" />
  <Malware Snort="Trojan-Ransom.Takbum.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win32.Takbum.a" />
  <Malware Avp3="Trojan-Ransom.Win32.Wanna.a">
    <Snort rule="Trojan-Ransom.Wanna.HTTP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Wanna.HTTP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Wanna.TCP.ServerRequest" />
    <Snort rule="Trojan-Ransom.Wanna.TCP.Spreading" />
    <Snort rule="Trojan-Ransom.Wanna.UDP.C&amp;C" />
    <Snort rule="Trojan-Ransom.Wanna.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Ransom.Zerber.UDP.C&amp;C" Avp3="Trojan-Ransom.Win32.Zerber.a" />
  <Malware Snort="Trojan-Ransom.Agent.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win64.Agent.a" />
  <Malware Snort="Trojan-Ransom.CryWiper.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win64.CryWiper.a" />
  <Malware Snort="Trojan-Ransom.Encoder.HTTP.C&amp;C" Avp3="Trojan-Ransom.Win64.Encoder.a" />
  <Malware Snort="Trojan-SMS.Agent.HTTP.C&amp;C" Avp3="Trojan-SMS.MSIL.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.Java.Agent.a" />
  <Malware Avp3="Trojan-Spy.MSIL.Agent.a">
    <Snort rule="Trojan-Spy.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Agent.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Spy.MSIL.Banker.a">
    <Snort rule="Trojan-Spy.Banker.HTTP.Notification" />
    <Snort rule="Trojan-Spy.Banker.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Spy.MSIL.Bobik.a">
    <Snort rule="Trojan-Spy.Bobik.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Bobik.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.KeyBase.HTTP.C&amp;C" Avp3="Trojan-Spy.MSIL.KeyBase.a" />
  <Malware Avp3="Trojan-Spy.MSIL.Keylogger.a">
    <Snort rule="Trojan-Spy.Keylogger.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Keylogger.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.KeyLogger.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Spy.Noon.TCP.ServerRequest" Avp3="Trojan-Spy.MSIL.Noon.a" />
  <Malware Snort="Trojan-Spy.Noon.TCP.ServerRequest" Avp3="Trojan-Spy.MSIL.Noon.gen" />
  <Malware Snort="Trojan-Spy.Phpw.UDP.C&amp;C" Avp3="Trojan-Spy.MSIL.Phpw.gen" />
  <Malware Avp3="Trojan-Spy.MSIL.Quasar.a">
    <Snort rule="Trojan-Spy.Quasar.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.Quasar.UDP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Spy.Quasar.HTTP.ServerRequest" Avp3="Trojan-Spy.MSIL.Quasar.gen" />
  <Malware Snort="Trojan-Spy.Reon.FTP.C&amp;C" Avp3="Trojan-Spy.MSIL.Reon.a" />
  <Malware Snort="Trojan-PSW.SnakeLogger.HTTP.C&amp;C" Avp3="Trojan-Spy.MSIL.SnakeLogger.a" />
  <Malware Avp3="Trojan-Spy.MSIL.Stealer.a">
    <Snort rule="Trojan-Spy.Stealer.FTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Stealer.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Stealer.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Spy.MSIL.Stealer.gen">
    <Snort rule="Trojan-Spy.Stealer.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Stealer.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.OLE.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.OLE2.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.PHP.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.Python.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.Script.Agent.a" />
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.Shell.Agent.a" />
  <Malware Snort="Trojan-Spy.Unicorn.HTTP.C&amp;C" Avp3="Trojan-Spy.VBS.Unicorn.a" />
  <Malware Avp3="Trojan-Spy.Win32.Agent.a">
    <Snort rule="Trojan-Spy.Agent.FTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Agent.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Agent.UDP.C&amp;C" />
    <Snort rule="Trojan-Spy.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.Agent.gen">
    <Snort rule="Trojan-Spy.Agent.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.Ardamax.SMTP.C&amp;C" Avp3="Trojan-Spy.Win32.Ardamax.a" />
  <Malware Avp3="Trojan-Spy.Win32.AveMaria.a">
    <Snort rule="Trojan-Spy.AveMaria.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.AveMaria.TCP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Spy.Bobik.HTTP.C&amp;C" Avp3="Trojan-Spy.Win32.Bobik.a" />
  <Malware Snort="Trojan-Spy.Hoaki.TLS.C&amp;C" Avp3="Trojan-Spy.Win32.Hoaki.gen" />
  <Malware Snort="Trojan-Spy.KeyLogger.HTTP.C&amp;C" Avp3="Trojan-Spy.Win32.KeyLogger.a" />
  <Malware Snort="Trojan-Spy.KeyLogger.HTTP.ServerRequest" Avp3="Trojan-Spy.Win32.KeyLogger.gen" />
  <Malware Snort="Trojan-Spy.MetaStealer.HTTP.C&amp;C" Avp3="Trojan-Spy.Win32.MetaStealer.a" />
  <Malware Snort="Trojan-Spy.Mufila.HTTP.C&amp;C" Avp3="Trojan-Spy.Win32.Mufila.a" />
  <Malware Snort="Trojan-Spy.Mufila.HTTP.ServerRequest" Avp3="Trojan-Spy.Win32.Mufila.gen" />
  <Malware Avp3="Trojan-Spy.Win32.Noon.a">
    <Snort rule="Trojan-Spy.Noon.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Noon.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Noon.TCP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.Noon.UDP.C&amp;C" Avp3="Trojan-Spy.Win32.Noon.gen" />
  <Malware Snort="Trojan-Spy.PerfectKeylogger.TCP.ServerRequest" Avp3="Trojan-Spy.Win32.PerfectKeylogger.a" />
  <Malware Snort="Trojan-Spy.POSBrut.HTTP.ServerRequest" Avp3="Trojan-Spy.Win32.POSBrut.a" />
  <Malware Snort="Trojan-Spy.Recam.HTTP.ServerRequest" Avp3="Trojan-Spy.Win32.Recam.a" />
  <Malware Avp3="Trojan-Spy.Win32.SpyEyes.a">
    <Snort rule="Trojan-Spy.SpyEyes.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.SpyEyes.HTTP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.Stealer.a">
    <Snort rule="Trojan-Spy.Stealer.FTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Stealer.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.Stealer.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.Stealer.gen">
    <Snort rule="Trojan-Spy.Stealer.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Stealer.UDP.ServerRequest" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.TeleBot.a">
    <Snort rule="Trojan-PSW.TeleBot.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.TeleBot.HTTP.C&amp;C" />
  </Malware>
  <Malware Snort="Trojan-Spy.TgRat.HTTP.C&amp;C" Avp3="Trojan-Spy.Win32.TgRat.a" />
  <Malware Snort="Trojan-Spy.TheRat.HTTP.Download" Avp3="Trojan-Spy.Win32.TheRat.a" />
  <Malware Snort="Trojan-Spy.TravNet.HTTP.ServerRequest" Avp3="Trojan-Spy.Win32.TravNet.a" />
  <Malware Avp3="Trojan-Spy.Win32.Ursnif.a">
    <Snort rule="Trojan-Spy.Ursnif.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Ursnif.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.Windigo.a">
    <Snort rule="Trojan-Spy.Windigo.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Windigo.UDP.C&amp;C" />
  </Malware>
  <Malware Avp3="Trojan-Spy.Win32.Windigo.gen">
    <Snort rule="Trojan-Spy.Windigo.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Windigo.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.WinSpy.TCP.ServerRequest" Avp3="Trojan-Spy.Win32.WinSpy.a" />
  <Malware Avp3="Trojan-Spy.Win32.Zbot.a">
    <Snort rule="Trojan-Spy.Zbot.HTTP.C&amp;C" />
    <Snort rule="Trojan-Spy.Zbot.HTTP.ServerRequest" />
    <Snort rule="Trojan-Spy.Zbot.TCP.C&amp;C" />
    <Snort rule="Trojan-Spy.Zbot.TCP.ServerRequest" />
    <Snort rule="Trojan-Spy.Zbot.UDP.C&amp;C" />
    <Snort rule="Trojan-Spy.Zbot.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Trojan-Spy.Agent.HTTP.C&amp;C" Avp3="Trojan-Spy.Win64.Agent.a" />
  <Malware Snort="Trojan-Spy.Alien.TCP.ServerRequest" Avp3="Trojan-Spy.Win64.Alien.gen" />
  <Malware Snort="Trojan-Spy.AntiAV.TCP.ServerRequest" Avp3="Trojan-Spy.Win64.AntiAV.gen" />
  <Malware Snort="Trojan-Spy.Lockbit.HTTP.C&amp;C" Avp3="Trojan-Spy.Win64.Lockbit.a" />
  <Malware Snort="Trojan-Spy.Netke.TCP.ServerRequest" Avp3="Trojan-Spy.Win64.Netke.gen" />
  <Malware Snort="UDP.EICAR.dns.test.a" Avp3="UDP.EICAR.dns.test.a" />
  <Malware Snort="UDP.EICAR.dns.test.c" Avp3="UDP.EICAR.dns.test.c" />
  <Malware Snort="Virus.Moiva.UDP.ServerRequest" Avp3="Virus.Win32.Moiva.gen" />
  <Malware Snort="Virus.Moiva.UDP.ServerRequest" Avp3="Virus.Win64.Moiva.gen" />
  <Malware Avp3="Worm.MSIL.Arcdoor.a">
    <Snort rule="Worm.Arcdoor.HTTP.C&amp;C" />
    <Snort rule="Worm.Arcdoor.HTTP.ServerRequest" />
  </Malware>
  <Malware Snort="Worm.Miner.UDP.C&amp;C" Avp3="Worm.Python.Miner.a" />
  <Malware Snort="Worm.Agent.HTTP.C&amp;C" Avp3="Worm.VBS.Agent.a" />
  <Malware Snort="Worm.Dinihou.HTTP.C&amp;C" Avp3="Worm.VBS.Dinihou.a" />
  <Malware Avp3="Worm.Win32.Agent.a">
    <Snort rule="Worm.Agent.HTTP.C&amp;C" />
    <Snort rule="Worm.Agent.HTTP.Notification" />
    <Snort rule="Worm.Agent.HTTP.ServerRequest" />
    <Snort rule="Worm.Agent.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Worm.AutoIt.HTTP.C&amp;C" Avp3="Worm.Win32.AutoIt.a" />
  <Malware Snort="Worm.AutoRun.HTTP.C&amp;C" Avp3="Worm.Win32.AutoRun.a" />
  <Malware Snort="Worm.Drolnux.HTTP.C&amp;C" Avp3="Worm.Win32.Drolnux.a" />
  <Malware Snort="Worm.FFAuto.HTTP.C&amp;C" Avp3="Worm.Win32.FFAuto.a" />
  <Malware Snort="Worm.Fipp.UDP.ServerRequest" Avp3="Worm.Win32.Fipp.a" />
  <Malware Snort="Worm.Hamweq.IRC.C&amp;C" Avp3="Worm.Win32.Hamweq.a" />
  <Malware Snort="Worm.Luder.HTTP.C&amp;C" Avp3="Worm.Win32.Luder.a" />
  <Malware Avp3="Worm.Win32.Ngrbot.a">
    <Snort rule="Worm.Ngrbot.IRC.C&amp;C" />
    <Snort rule="Worm.Ngrbot.UDP.ServerRequest" />
  </Malware>
  <Malware Snort="Worm.Radminer.ICMP.ServerRequest" Avp3="Worm.Win32.Radminer.a" />
  <Malware Snort="Worm.Rokut.HTTP.ServerRequest" Avp3="Worm.Win32.Rokut.a" />
  <Malware Snort="Worm.Sid.HTTP.ServerRequest" Avp3="Worm.Win32.Sid.a" />
  <Malware Snort="Worm.VB.HTTP.C&amp;C" Avp3="Worm.Win32.VB.a" />
  <Malware Snort="Worm.VBNA.HTTP.ServerRequest" Avp3="Worm.Win32.VBNA.a" />
  <Malware Avp3="Worm.Win32.Viking.a">
    <Snort rule="Worm.Viking.HTTP.C&amp;C" />
    <Snort rule="Worm.Viking.ICMP.ServerRequest" />
  </Malware>
  <Malware Snort="Worm.Wogue.HTTP.ServerRequest" Avp3="Worm.Win32.Wogue.a" />
  <Malware Snort="Worm.Agent.HTTP.C&amp;C" Avp3="Worm.Win64.Agent.a" />
</Malwares>