# # Emerging Threats Tor rules. # # These will tell you if someone using Tor for source anonymization is communicating with your network. # # Tor in itself isn't inherently hostile. In many environments that may be a very suspicious way # to communicate. # # More information available at doc.emergingthreats.net/bin/view/Main/TorRules # # Please submit any feedback or ideas to support@emergingthreats.net or the emerging-sigs mailing list # #************************************************************* # # Copyright (c) 2003-2025, Emerging Threats # All rights reserved. # # Redistribution and use in source and binary forms, with or without modification, are permitted provided that the # following conditions are met: # # * Redistributions of source code must retain the above copyright notice, this list of conditions and the following # disclaimer. # * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the # following disclaimer in the documentation and/or other materials provided with the distribution. # * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived # from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES, # INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE # DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR # SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, # WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE # USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # # # VERSION 5970 # Updated 2025-08-01 00:30:01 alert tcp [102.130.117.167,102.130.127.117,102.211.56.12,102.211.56.200,103.109.101.105,103.146.203.11,103.164.54.199,103.193.179.233,103.20.241.102,103.251.167.10] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 1"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520000; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.251.167.20,103.253.24.18,103.28.52.93,104.167.241.4,104.167.242.116,104.167.242.117,104.167.242.118,104.192.3.74,104.219.236.100,104.244.72.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 2"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520001; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.244.73.136,104.244.73.190,104.244.73.193,104.244.73.43,104.244.74.23,104.244.74.97,104.244.75.140,104.244.75.74,104.244.76.237,104.244.77.208] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 3"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520002; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.244.78.162,104.244.78.232,104.244.78.233,104.244.79.44,104.244.79.50,104.244.79.61,104.254.90.195,107.174.146.25,107.189.10.175,107.189.1.111] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 4"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520003; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.11.111,107.189.1.160,107.189.1.228,107.189.12.3,107.189.12.7,107.189.12.88,107.189.13.180,107.189.13.253,107.189.13.254,107.189.13.91] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 5"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520004; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.14.4,107.189.14.43,107.189.1.9,107.189.2.108,107.189.29.103,107.189.29.184,107.189.30.236,107.189.30.49,107.189.30.69,107.189.30.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 6"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520005; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.3.11,107.189.31.187,107.189.31.33,107.189.3.148,107.189.3.94,107.189.4.12,107.189.4.209,107.189.5.121,107.189.5.249,107.189.5.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 7"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520006; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.6.124,107.189.7.141,107.189.7.144,107.189.7.168,107.189.8.133,107.189.8.136,107.189.8.16,107.189.8.181,107.189.8.226,107.189.8.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 8"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520007; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.8.65,107.189.8.70,108.59.12.3,108.61.189.136,109.104.153.22,109.169.33.163,109.228.160.190,109.237.27.11,109.69.67.17,109.70.100.1] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 9"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520008; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.70.100.2,109.70.100.3,109.70.100.4,109.70.100.5,109.70.100.6,109.70.100.65,109.70.100.66,109.70.100.67,109.70.100.68,109.70.100.69] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 10"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520009; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.70.100.70,109.70.100.71,109.71.252.182,109.71.252.88,109.71.252.97,114.172.205.8,114.35.245.150,118.163.74.160,118.193.64.139,121.78.28.166] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 11"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520010; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [123.253.35.32,124.198.131.108,124.198.131.223,124.198.131.253,124.198.131.62,124.198.132.13,124.198.132.172,124.198.132.237,124.198.132.52,125.212.241.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 12"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520011; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [125.253.56.119,128.31.0.13,130.193.10.21,130.193.15.186,131.72.79.38,136.244.111.163,138.59.18.110,139.99.172.11,139.99.8.57,141.98.11.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 13"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520012; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [144.126.133.74,144.208.79.169,146.19.254.154,146.19.254.157,146.59.126.232,146.59.231.4,147.45.116.145,148.113.152.91,149.102.153.38,149.202.79.101] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 14"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520013; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [149.202.79.129,149.56.44.47,152.32.206.127,152.53.106.19,152.53.133.14,152.53.53.243,154.41.95.1,154.41.95.2,154.53.58.161,158.174.210.51] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 15"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520014; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [160.119.249.240,160.187.148.71,161.129.68.162,162.19.7.11,162.210.173.17,162.216.18.62,162.220.14.54,162.220.14.78,162.251.5.152,163.172.45.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 16"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520015; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [164.132.172.209,165.73.242.163,166.70.207.2,171.25.193.131,171.25.193.20,171.25.193.234,171.25.193.235,171.25.193.25,171.25.193.35,171.25.193.36] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 17"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520016; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [171.25.193.37,171.25.193.38,171.25.193.39,171.25.193.40,171.25.193.77,171.25.193.78,171.25.193.79,171.25.193.80,172.104.182.84,172.104.186.73] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 18"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520017; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.104.243.155,172.105.174.195,172.105.20.12,172.105.203.121,172.232.209.254,172.233.82.41,172.234.228.174,172.81.131.139,172.81.131.156,172.81.132.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 19"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520018; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [173.0.3.111,173.237.206.68,173.255.198.243,176.118.193.33,176.121.81.51,176.58.100.98,176.58.121.177,176.58.89.182,176.65.148.133,176.65.148.3] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 20"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520019; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.65.149.100,176.65.149.84,176.65.149.87,176.65.149.88,176.65.149.96,176.97.114.202,177.149.128.102,177.153.51.238,177.93.140.66,178.162.175.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 21"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520020; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.17.170.144,178.17.170.23,178.17.171.102,178.17.174.14,178.17.174.164,178.175.148.209,178.175.148.246,178.20.55.16,178.20.55.182,178.218.144.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 22"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520021; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.218.144.51,178.218.144.64,178.218.144.96,178.218.144.99,179.43.128.16,179.43.159.194,179.43.159.195,179.43.159.196,179.43.159.197,179.43.159.198] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 23"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520022; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [179.43.159.199,179.43.159.200,179.43.159.201,179.43.159.78,179.43.182.232,179.43.182.58,179.55.71.11,180.150.226.99,185.100.85.132,185.100.87.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 24"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520023; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.100.87.166,185.100.87.174,185.100.87.41,185.104.120.10,185.104.120.30,185.104.120.40,185.106.102.102,185.112.144.11,185.112.146.167,185.113.128.30] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 25"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520024; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.120.16.176,185.129.61.1,185.129.61.10,185.129.61.129,185.129.61.2,185.129.61.3,185.129.61.4,185.129.61.5,185.129.61.6,185.129.61.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 26"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520025; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.129.61.8,185.129.61.9,185.129.62.62,185.129.62.63,185.130.47.58,185.150.28.13,185.154.110.142,185.154.110.17,185.165.169.239,185.165.171.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 27"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520026; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.170.114.25,185.177.151.34,185.183.157.214,185.183.159.40,185.191.204.254,185.193.52.180,185.195.71.244,185.207.107.130,185.207.107.216,185.220.100.240] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 28"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520027; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.100.241,185.220.100.242,185.220.100.243,185.220.100.244,185.220.100.245,185.220.100.246,185.220.100.247,185.220.100.248,185.220.100.249,185.220.100.250] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 29"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520028; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.100.251,185.220.100.252,185.220.100.253,185.220.100.254,185.220.100.255,185.220.101.100,185.220.101.101,185.220.101.102,185.220.101.103,185.220.101.104] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 30"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520029; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.105,185.220.101.106,185.220.101.107,185.220.101.108,185.220.101.109,185.220.101.110,185.220.101.129,185.220.101.130,185.220.101.131,185.220.101.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 31"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520030; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.133,185.220.101.134,185.220.101.135,185.220.101.136,185.220.101.137,185.220.101.138,185.220.101.139,185.220.101.140,185.220.101.141,185.220.101.142] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 32"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520031; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.143,185.220.101.144,185.220.101.145,185.220.101.146,185.220.101.147,185.220.101.148,185.220.101.149,185.220.101.150,185.220.101.151,185.220.101.152] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 33"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520032; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.153,185.220.101.154,185.220.101.155,185.220.101.156,185.220.101.157,185.220.101.158,185.220.101.160,185.220.101.162,185.220.101.163,185.220.101.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 34"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520033; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.165,185.220.101.166,185.220.101.167,185.220.101.168,185.220.101.169,185.220.101.170,185.220.101.172,185.220.101.173,185.220.101.174,185.220.101.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 35"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520034; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.176,185.220.101.178,185.220.101.179,185.220.101.180,185.220.101.182,185.220.101.183,185.220.101.184,185.220.101.185,185.220.101.186,185.220.101.187] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 36"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520035; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.188,185.220.101.189,185.220.101.190,185.220.101.191,185.220.101.32,185.220.101.33,185.220.101.34,185.220.101.35,185.220.101.36,185.220.101.37] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 37"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520036; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.38,185.220.101.39,185.220.101.40,185.220.101.41,185.220.101.42,185.220.101.43,185.220.101.44,185.220.101.45,185.220.101.46,185.220.101.47] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 38"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520037; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.48,185.220.101.49,185.220.101.50,185.220.101.51,185.220.101.52,185.220.101.53,185.220.101.54,185.220.101.55,185.220.101.56,185.220.101.57] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 39"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520038; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.58,185.220.101.59,185.220.101.60,185.220.101.61,185.220.101.62,185.220.101.63,185.220.101.96,185.220.101.97,185.220.101.98,185.220.101.99] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 40"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520039; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.225.69.187,185.225.69.203,185.225.69.232,185.227.134.106,185.227.68.78,185.231.102.51,185.233.100.23,185.235.146.29,185.240.242.135,185.241.208.115] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 41"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520040; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.241.208.185,185.241.208.202,185.241.208.204,185.241.208.206,185.241.208.54,185.241.208.71,185.241.208.81,185.241.208.82,185.241.208.92,185.244.192.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 42"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520041; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.244.192.184,185.246.128.161,185.246.188.115,185.246.188.149,185.246.188.73,185.246.188.74,185.246.189.99,185.246.84.179,185.247.184.105,185.247.184.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 43"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520042; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.247.226.95,185.252.232.218,185.254.196.141,185.34.33.2,185.35.202.222,185.40.4.100,185.40.4.101,185.40.4.121,185.40.4.127,185.40.4.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 44"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520043; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.40.4.149,185.40.4.150,185.40.4.20,185.40.4.22,185.40.4.29,185.40.4.38,185.40.4.44,185.40.4.64,185.40.4.92,185.42.170.203] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 45"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520044; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.56.171.94,185.56.83.83,185.67.82.114,185.82.219.109,188.214.104.21,188.239.191.25,188.68.36.28,188.68.41.191,188.68.49.235,188.68.52.231] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 46"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520045; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [190.103.179.98,190.120.229.98,190.211.254.97,192.108.48.150,192.159.99.168,192.159.99.74,192.42.116.13,192.42.116.14,192.42.116.15,192.42.116.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 47"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520046; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.173,192.42.116.174,192.42.116.175,192.42.116.176,192.42.116.177,192.42.116.178,192.42.116.179,192.42.116.18,192.42.116.180,192.42.116.181] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 48"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520047; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.182,192.42.116.183,192.42.116.184,192.42.116.185,192.42.116.186,192.42.116.19,192.42.116.191,192.42.116.192,192.42.116.193,192.42.116.194] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 49"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520048; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.195,192.42.116.196,192.42.116.197,192.42.116.198,192.42.116.199,192.42.116.20,192.42.116.200,192.42.116.201,192.42.116.202,192.42.116.203] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 50"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520049; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.208,192.42.116.209,192.42.116.210,192.42.116.211,192.42.116.212,192.42.116.213,192.42.116.214,192.42.116.215,192.42.116.216,192.42.116.217] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 51"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520050; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.218,192.42.116.219,192.42.116.22,192.42.116.23,192.42.116.24,192.42.116.26,192.42.116.27,192.42.116.28,193.105.134.150,193.105.134.155] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 52"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520051; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.189.100.194,193.189.100.195,193.189.100.196,193.189.100.197,193.189.100.198,193.189.100.199,193.189.100.200,193.237.221.228,193.239.232.102,193.26.115.140] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 53"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520052; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.26.115.212,193.26.115.43,193.26.115.61,193.26.115.82,193.32.162.104,193.32.162.96,193.36.132.21,193.70.38.13,194.110.247.121,194.113.38.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 54"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520053; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.15.112.133,194.15.113.118,194.15.115.212,194.15.36.117,194.26.192.77,194.53.137.102,194.53.137.156,194.87.55.98,195.160.220.104,195.176.3.23] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 55"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520054; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.176.3.24,195.246.231.141,195.47.238.176,195.47.238.177,195.47.238.178,195.47.238.44,195.47.238.82,195.47.238.83,195.47.238.84,195.47.238.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 56"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520055; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.47.238.87,195.47.238.88,195.47.238.89,195.47.238.90,195.47.238.91,195.47.238.92,195.47.238.93,195.80.151.242,195.88.74.206,198.167.206.182] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 57"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520056; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.167.206.189,198.167.206.239,198.46.166.157,198.50.212.160,198.58.107.53,198.96.155.3,198.98.48.33,198.98.48.35,198.98.50.199,198.98.51.189] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 58"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520057; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.98.51.249,198.98.57.151,198.98.57.218,198.98.57.74,198.98.61.60,198.98.62.158,199.195.248.168,199.195.249.214,199.195.251.119,199.195.253.124] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 59"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520058; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [199.195.253.156,199.195.253.180,200.122.181.2,202.182.99.129,204.137.14.104,204.137.14.105,204.137.14.106,204.137.14.92,204.194.29.4,204.8.156.142] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 60"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520059; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [204.85.191.7,204.85.191.8,204.85.191.9,204.8.96.120,205.185.113.180,205.185.113.8,205.185.116.215,205.185.116.34,205.185.117.149,205.185.119.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 61"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520060; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [205.185.121.170,205.185.121.177,205.185.123.93,205.185.124.176,206.166.251.193,209.141.32.181,209.141.32.198,209.141.34.15,209.141.37.94,209.141.40.68] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 62"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520061; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [209.141.41.25,209.141.45.141,209.141.45.81,209.141.46.203,209.141.51.180,209.141.51.30,209.141.54.203,209.141.55.26,209.141.58.254,212.192.23.129] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 63"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520062; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.21.66.6,212.38.189.186,212.69.167.80,212.73.134.204,212.95.50.77,216.73.159.101,216.73.159.75,216.9.224.232,217.12.221.131,220.135.36.173] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 64"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520063; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.130,23.129.64.131,23.129.64.132,23.129.64.133,23.129.64.134,23.129.64.135,23.129.64.136,23.129.64.137,23.129.64.138,23.129.64.139] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 65"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520064; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.140,23.129.64.141,23.129.64.142,23.129.64.143,23.129.64.144,23.129.64.145,23.129.64.146,23.129.64.147,23.129.64.148,23.129.64.149] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 66"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520065; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.150,23.129.64.151,23.129.64.152,23.129.64.153,23.129.64.154,23.129.64.155,23.129.64.156,23.129.64.157,23.129.64.158,23.129.64.159] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 67"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520066; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.160,23.129.64.161,23.129.64.162,23.129.64.163,23.129.64.164,23.129.64.165,23.137.248.100,23.137.253.109,23.137.253.254,23.137.253.27] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 68"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520067; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.137.254.244,23.151.8.8,23.155.8.104,23.184.48.78,23.191.200.10,23.191.200.11,23.191.200.12,23.191.200.13,23.191.200.14,23.191.200.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 69"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520068; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.191.200.16,23.191.200.17,23.191.200.18,23.191.200.19,23.191.200.20,23.191.200.21,23.191.200.22,23.191.200.23,23.191.200.24,23.191.200.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 70"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520069; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.191.200.26,23.191.200.7,23.191.200.8,23.191.200.9,23.236.122.193,24.240.72.170,2.56.10.36,2.58.56.220,2.58.56.35,2.58.56.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 71"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520070; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [2.58.56.93,27.255.75.198,31.129.22.65,31.133.0.210,31.184.236.104,31.220.75.237,31.44.238.25,35.0.127.52,37.114.50.124,37.114.50.142] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 72"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520071; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.114.50.18,37.114.50.27,37.114.63.5,37.187.5.192,37.221.208.71,37.228.129.128,37.228.129.162,37.228.129.189,37.228.129.5,37.228.129.63] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 73"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520072; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.77.56.238,38.135.24.30,38.135.24.31,38.135.24.32,38.135.24.33,38.135.24.72,38.135.25.141,38.135.25.142,38.135.25.143,38.135.25.144] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 74"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520073; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [38.135.25.2,38.180.225.239,38.97.116.242,38.97.116.243,38.97.116.244,38.97.116.245,43.160.194.14,45.11.59.28,45.12.3.80,45.128.133.242] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 75"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520074; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.132.246.245,45.13.225.69,45.13.225.78,45.133.74.53,45.134.225.36,45.137.70.158,45.138.16.113,45.138.16.161,45.138.16.164,45.138.16.222] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 76"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520075; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.138.16.230,45.138.16.231,45.138.16.239,45.138.16.240,45.138.16.248,45.138.16.42,45.138.16.69,45.138.16.76,45.141.215.110,45.141.215.111] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 77"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520076; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.141.215.114,45.141.215.167,45.141.215.169,45.141.215.17,45.141.215.19,45.141.215.200,45.141.215.21,45.141.215.28,45.141.215.40,45.141.215.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 78"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520077; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.141.215.61,45.141.215.62,45.141.215.63,45.141.215.80,45.141.215.88,45.141.215.90,45.141.215.95,45.141.215.97,45.143.200.32,45.145.93.133] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 79"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520078; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.148.10.111,45.154.98.33,45.61.185.172,45.61.186.203,45.61.188.15,45.66.35.10,45.66.35.20,45.66.35.21,45.66.35.22,45.66.35.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 80"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520079; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.66.35.32,45.66.35.33,45.66.35.34,45.66.35.35,45.79.144.222,45.80.158.167,45.80.158.23,45.80.158.27,45.80.158.69,45.83.104.137] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 81"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520080; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.83.31.79,45.84.107.101,45.84.107.128,45.84.107.17,45.84.107.172,45.84.107.174,45.84.107.182,45.84.107.198,45.84.107.222,45.84.107.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 82"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520081; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.84.107.47,45.84.107.54,45.84.107.55,45.84.107.74,45.84.107.76,45.84.107.97,45.88.186.89,45.88.186.92,45.90.185.100,45.90.185.101] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 83"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520082; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.90.185.102,45.90.185.103,45.90.185.104,45.90.185.105,45.90.185.106,45.90.185.107,45.90.185.108,45.90.185.109,45.90.185.110,45.90.185.111] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 84"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520083; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.90.185.112,45.90.185.113,45.90.185.114,45.90.185.115,45.90.185.116,45.90.185.117,45.90.185.118,45.90.185.119,45.91.250.107,45.9.148.50] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 85"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520084; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.9.156.101,45.9.168.18,45.9.168.192,45.94.31.68,45.95.169.104,45.95.169.109,45.95.169.110,46.165.243.36,46.23.109.25,46.232.251.191] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 86"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520085; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.234.47.105,46.246.92.34,46.250.243.29,46.38.243.210,5.101.82.22,5.104.84.183,5.104.86.6,51.15.59.15,51.195.166.174,51.222.142.67] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 87"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520086; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.38.225.46,51.81.222.62,5.181.80.107,51.91.18.151,5.196.95.34,5.253.247.27,5.255.100.224,5.255.100.26,5.255.101.10,5.255.101.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 88"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520087; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.103.235,5.255.104.202,5.255.110.120,5.255.111.64,5.255.114.171,5.255.115.58,5.255.117.56,5.255.118.151,5.255.118.218,5.255.123.158] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 89"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520088; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.123.164,5.255.125.196,5.255.127.222,5.255.97.221,5.255.98.151,5.255.98.198,5.255.98.23,5.255.99.124,5.255.99.147,5.255.99.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 90"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520089; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.2.67.226,5.2.72.110,5.2.79.190,5.34.182.203,54.36.101.21,54.36.108.162,5.45.102.93,5.45.104.176,5.45.98.162,57.128.212.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 91"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520090; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [57.128.220.107,57.129.91.235,5.79.66.19,5.8.18.30,5.8.18.99,62.133.45.2,62.171.137.169,62.182.84.146,62.72.47.105,64.190.113.221] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 92"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520091; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.190.76.2,64.190.76.3,64.190.76.4,64.94.85.248,66.146.193.33,66.220.242.222,66.78.40.146,66.78.40.182,66.94.111.228,67.219.109.141] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 93"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520092; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [71.19.144.106,72.14.179.10,72.211.49.235,72.235.129.116,72.5.43.62,74.208.79.7,74.82.47.194,77.246.98.159,77.48.28.193,77.48.28.204] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 94"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520093; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.48.28.237,77.48.28.239,77.81.247.72,78.142.18.219,80.241.60.207,80.253.251.56,80.67.167.81,80.67.172.162,80.82.78.14,80.94.92.106] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 95"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520094; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.94.92.135,80.94.92.92,80.94.92.99,81.16.33.42,81.17.28.95,82.118.248.205,82.153.138.125,82.153.138.241,82.153.138.7,82.221.128.191] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 96"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520095; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.221.131.5,82.221.131.86,82.221.139.190,83.147.17.190,83.217.9.73,83.228.94.69,83.96.213.63,83.97.20.77,84.16.224.227,84.19.182.20] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 97"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520096; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.211.226.13,84.239.46.144,85.239.41.130,85.93.218.204,85.93.31.31,86.54.25.3,86.54.28.49,87.118.110.27,87.118.116.103,87.118.116.12] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 98"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520097; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.118.116.90,87.118.122.30,87.118.122.51,87.120.254.132,88.151.194.24,88.80.20.86,88.80.26.2,88.80.26.3,88.80.26.4,89.110.95.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 99"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520098; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.110.95.200,89.147.108.90,89.147.109.58,89.147.110.118,89.147.110.154,89.147.110.82,89.147.111.87,89.234.157.254,89.32.41.150,89.58.26.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 100"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520099; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.41.156,91.132.144.59,91.149.243.111,91.202.5.104,91.202.5.155,91.203.144.194,91.203.145.116,91.206.26.26,91.208.75.153,91.208.75.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 101"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520100; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.208.75.178,91.208.75.239,91.208.75.3,91.208.75.4,91.219.236.101,91.219.236.91,91.227.114.153,91.92.109.126,91.92.109.43,92.243.24.163] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 102"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520101; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.246.84.133,93.113.25.239,93.123.109.116,93.123.12.112,93.185.165.211,93.88.75.35,93.90.74.28,93.90.74.29,93.95.227.37,93.95.228.125] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 103"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520102; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.95.231.118,93.95.231.14,93.95.231.88,93.99.104.128,93.99.104.18,93.99.104.194,93.99.104.40,94.102.51.15,94.131.2.131,94.142.241.194] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 104"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520103; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.142.244.16,94.16.115.121,94.16.121.91,94.230.208.147,94.230.208.148,94.72.103.33,94.72.104.135,94.74.164.89,95.128.43.164,95.143.193.125] any -> $HOME_NET any (msg:"ET TOR Known Tor Exit Node TCP Traffic group 105"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2520104; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) # Non-Exit Nodes alert tcp [102.130.113.9,102.130.117.167,102.130.127.117,102.211.56.12,102.211.56.200,103.109.101.105,103.146.203.11,103.164.54.199,103.193.179.233,103.20.241.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 1"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522000; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.251.167.10,103.251.167.20,103.253.24.18,103.28.52.93,104.167.241.4,104.167.242.116,104.167.242.117,104.167.242.118,104.192.3.74,104.219.236.100] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 2"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522001; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.244.72.132,104.244.73.136,104.244.73.190,104.244.73.193,104.244.73.43,104.244.74.23,104.244.74.97,104.244.75.140,104.244.75.74,104.244.76.237] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 3"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522002; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.244.77.208,104.244.78.162,104.244.78.232,104.244.78.233,104.244.79.44,104.244.79.50,104.244.79.61,104.254.90.195,107.174.146.25,107.189.10.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 4"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522003; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.1.111,107.189.11.111,107.189.1.160,107.189.1.228,107.189.12.3,107.189.12.7,107.189.12.88,107.189.13.180,107.189.13.253,107.189.13.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 5"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522004; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.13.91,107.189.14.4,107.189.14.43,107.189.1.9,107.189.2.108,107.189.29.103,107.189.29.184,107.189.30.236,107.189.30.49,107.189.30.69] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 6"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522005; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.30.86,107.189.3.11,107.189.31.187,107.189.31.33,107.189.3.148,107.189.3.94,107.189.4.12,107.189.4.209,107.189.5.121,107.189.5.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 7"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522006; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.5.7,107.189.6.124,107.189.7.141,107.189.7.144,107.189.7.168,107.189.8.133,107.189.8.136,107.189.8.16,107.189.8.181,107.189.8.226] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 8"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522007; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.8.56,107.189.8.65,107.189.8.70,108.59.12.3,108.61.189.136,109.104.153.22,109.169.33.163,109.228.160.190,109.237.27.11,109.69.67.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 9"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522008; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.70.100.1,109.70.100.2,109.70.100.3,109.70.100.4,109.70.100.5,109.70.100.6,109.70.100.65,109.70.100.66,109.70.100.67,109.70.100.68] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 10"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522009; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.70.100.69,109.70.100.70,109.70.100.71,109.71.252.182,109.71.252.88,109.71.252.97,114.172.205.8,114.35.245.150,118.163.74.160,118.193.64.139] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 11"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522010; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [121.78.28.166,123.253.35.32,124.198.131.108,124.198.131.223,124.198.131.253,124.198.131.62,124.198.132.13,124.198.132.172,124.198.132.237,124.198.132.52] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 12"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522011; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [125.212.241.131,125.253.56.119,128.31.0.13,130.193.10.21,130.193.15.186,131.72.79.38,136.244.111.163,138.59.18.110,139.99.172.11,139.99.8.57] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 13"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522012; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [141.98.11.62,144.126.133.74,144.208.79.169,146.19.254.154,146.19.254.157,146.59.126.232,146.59.231.4,147.45.116.145,148.113.152.91,149.102.153.38] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 14"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522013; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [149.202.79.101,149.202.79.129,149.56.44.47,152.32.206.127,152.53.106.19,152.53.133.14,152.53.53.243,154.41.95.1,154.41.95.2,154.53.58.161] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 15"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522014; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [158.174.210.51,160.119.249.240,160.187.148.71,161.129.68.162,162.19.7.11,162.210.173.17,162.216.18.62,162.220.14.54,162.220.14.78,162.251.5.152] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 16"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522015; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [163.172.45.102,164.132.172.209,165.73.242.163,166.70.207.2,171.25.193.131,171.25.193.20,171.25.193.234,171.25.193.235,171.25.193.25,171.25.193.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 17"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522016; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [171.25.193.36,171.25.193.37,171.25.193.38,171.25.193.39,171.25.193.40,171.25.193.77,171.25.193.78,171.25.193.79,171.25.193.80,172.104.182.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 18"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522017; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.104.186.73,172.104.243.155,172.105.174.195,172.105.20.12,172.105.203.121,172.232.209.254,172.233.82.41,172.234.228.174,172.81.131.139,172.81.131.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 19"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522018; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.81.132.94,173.0.3.111,173.237.206.68,173.255.198.243,176.118.193.33,176.121.81.51,176.58.100.98,176.58.121.177,176.58.89.182,176.65.148.133] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 20"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522019; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.65.148.3,176.65.149.100,176.65.149.84,176.65.149.87,176.65.149.88,176.65.149.96,176.97.114.202,177.149.128.102,177.153.51.238,177.93.140.66] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 21"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522020; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.162.175.5,178.17.170.144,178.17.170.23,178.17.171.102,178.17.174.14,178.17.174.164,178.175.148.209,178.175.148.246,178.20.55.16,178.20.55.182] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 22"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522021; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.218.144.18,178.218.144.51,178.218.144.64,178.218.144.96,178.218.144.99,179.43.128.16,179.43.159.194,179.43.159.195,179.43.159.196,179.43.159.197] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 23"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522022; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [179.43.159.198,179.43.159.199,179.43.159.200,179.43.159.201,179.43.159.78,179.43.182.232,179.43.182.58,179.55.71.11,180.150.226.99,185.100.85.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 24"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522023; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.100.87.136,185.100.87.166,185.100.87.174,185.100.87.41,185.104.120.10,185.104.120.30,185.104.120.40,185.106.102.102,185.112.144.11,185.112.146.167] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 25"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522024; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.113.128.30,185.120.16.176,185.129.61.1,185.129.61.10,185.129.61.129,185.129.61.2,185.129.61.3,185.129.61.4,185.129.61.5,185.129.61.6] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 26"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522025; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.129.61.7,185.129.61.8,185.129.61.9,185.129.62.62,185.129.62.63,185.130.47.58,185.150.28.13,185.154.110.142,185.154.110.17,185.165.169.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 27"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522026; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.165.171.84,185.170.114.25,185.177.151.34,185.183.157.214,185.183.159.40,185.191.204.254,185.193.52.180,185.195.71.244,185.207.107.130,185.207.107.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 28"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522027; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.100.240,185.220.100.241,185.220.100.242,185.220.100.243,185.220.100.244,185.220.100.245,185.220.100.246,185.220.100.247,185.220.100.248,185.220.100.249] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 29"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522028; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.100.250,185.220.100.251,185.220.100.252,185.220.100.253,185.220.100.254,185.220.100.255,185.220.101.100,185.220.101.101,185.220.101.102,185.220.101.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 30"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522029; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.104,185.220.101.105,185.220.101.106,185.220.101.107,185.220.101.108,185.220.101.109,185.220.101.110,185.220.101.129,185.220.101.130,185.220.101.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 31"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522030; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.132,185.220.101.133,185.220.101.134,185.220.101.135,185.220.101.136,185.220.101.137,185.220.101.138,185.220.101.139,185.220.101.140,185.220.101.141] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 32"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522031; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.142,185.220.101.143,185.220.101.144,185.220.101.145,185.220.101.146,185.220.101.147,185.220.101.148,185.220.101.149,185.220.101.150,185.220.101.151] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 33"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522032; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.152,185.220.101.153,185.220.101.154,185.220.101.155,185.220.101.156,185.220.101.157,185.220.101.158,185.220.101.160,185.220.101.162,185.220.101.163] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 34"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522033; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.164,185.220.101.165,185.220.101.166,185.220.101.167,185.220.101.168,185.220.101.169,185.220.101.170,185.220.101.172,185.220.101.173,185.220.101.174] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 35"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522034; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.175,185.220.101.176,185.220.101.178,185.220.101.179,185.220.101.180,185.220.101.182,185.220.101.183,185.220.101.184,185.220.101.185,185.220.101.186] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 36"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522035; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.187,185.220.101.188,185.220.101.189,185.220.101.190,185.220.101.191,185.220.101.32,185.220.101.33,185.220.101.34,185.220.101.35,185.220.101.36] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 37"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522036; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.37,185.220.101.38,185.220.101.39,185.220.101.40,185.220.101.41,185.220.101.42,185.220.101.43,185.220.101.44,185.220.101.45,185.220.101.46] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 38"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522037; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.47,185.220.101.48,185.220.101.49,185.220.101.50,185.220.101.51,185.220.101.52,185.220.101.53,185.220.101.54,185.220.101.55,185.220.101.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 39"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522038; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.57,185.220.101.58,185.220.101.59,185.220.101.60,185.220.101.61,185.220.101.62,185.220.101.63,185.220.101.96,185.220.101.97,185.220.101.98] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 40"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522039; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.99,185.225.69.187,185.225.69.203,185.225.69.232,185.227.134.106,185.227.68.78,185.231.102.51,185.233.100.23,185.235.146.29,185.240.242.135] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 41"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522040; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.241.208.115,185.241.208.185,185.241.208.202,185.241.208.204,185.241.208.206,185.241.208.54,185.241.208.71,185.241.208.81,185.241.208.82,185.241.208.92] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 42"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522041; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.244.192.175,185.244.192.184,185.246.128.161,185.246.188.115,185.246.188.149,185.246.188.73,185.246.188.74,185.246.189.99,185.246.84.179,185.247.184.105] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 43"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522042; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.247.184.33,185.247.226.95,185.252.232.218,185.254.196.141,185.34.33.2,185.35.202.222,185.40.4.100,185.40.4.101,185.40.4.121,185.40.4.127] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 44"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522043; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.40.4.132,185.40.4.149,185.40.4.150,185.40.4.20,185.40.4.22,185.40.4.29,185.40.4.38,185.40.4.44,185.40.4.64,185.40.4.92] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 45"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522044; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.42.170.203,185.56.171.94,185.56.83.83,185.67.82.114,185.82.219.109,188.214.104.21,188.239.191.25,188.68.36.28,188.68.41.191,188.68.49.235] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 46"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522045; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.68.52.231,190.103.179.98,190.120.229.98,190.211.254.97,192.108.48.150,192.159.99.168,192.159.99.74,192.42.116.13,192.42.116.14,192.42.116.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 47"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522046; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.17,192.42.116.173,192.42.116.174,192.42.116.175,192.42.116.176,192.42.116.177,192.42.116.178,192.42.116.179,192.42.116.18,192.42.116.180] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 48"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522047; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.181,192.42.116.182,192.42.116.183,192.42.116.184,192.42.116.185,192.42.116.186,192.42.116.19,192.42.116.191,192.42.116.192,192.42.116.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 49"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522048; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.194,192.42.116.195,192.42.116.196,192.42.116.197,192.42.116.198,192.42.116.199,192.42.116.20,192.42.116.200,192.42.116.201,192.42.116.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 50"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522049; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.203,192.42.116.208,192.42.116.209,192.42.116.210,192.42.116.211,192.42.116.212,192.42.116.213,192.42.116.214,192.42.116.215,192.42.116.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 51"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522050; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.217,192.42.116.218,192.42.116.219,192.42.116.22,192.42.116.23,192.42.116.24,192.42.116.26,192.42.116.27,192.42.116.28,193.105.134.150] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 52"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522051; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.105.134.155,193.189.100.194,193.189.100.195,193.189.100.196,193.189.100.197,193.189.100.198,193.189.100.199,193.189.100.200,193.237.221.228,193.239.232.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 53"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522052; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.26.115.140,193.26.115.212,193.26.115.43,193.26.115.61,193.26.115.82,193.32.162.104,193.32.162.96,193.36.132.21,193.70.38.13,194.110.247.121] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 54"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522053; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.113.38.5,194.15.112.133,194.15.113.118,194.15.115.212,194.15.36.117,194.26.192.77,194.53.137.102,194.53.137.156,194.87.55.98,195.160.220.104] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 55"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522054; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.176.3.23,195.176.3.24,195.246.231.141,195.47.238.176,195.47.238.177,195.47.238.178,195.47.238.44,195.47.238.82,195.47.238.83,195.47.238.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 56"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522055; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.47.238.86,195.47.238.87,195.47.238.88,195.47.238.89,195.47.238.90,195.47.238.91,195.47.238.92,195.47.238.93,195.80.151.242,195.88.74.206] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 57"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522056; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.167.206.182,198.167.206.189,198.167.206.239,198.46.166.157,198.50.212.160,198.58.107.53,198.96.155.3,198.98.48.33,198.98.48.35,198.98.50.199] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 58"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522057; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.98.51.189,198.98.51.249,198.98.57.151,198.98.57.218,198.98.57.74,198.98.61.60,198.98.62.158,199.195.248.168,199.195.249.214,199.195.251.119] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 59"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522058; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [199.195.253.124,199.195.253.156,199.195.253.180,200.122.181.2,202.182.99.129,204.137.14.104,204.137.14.105,204.137.14.106,204.137.14.92,204.194.29.4] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 60"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522059; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [204.8.156.142,204.85.191.7,204.85.191.8,204.85.191.9,204.8.96.120,205.185.113.180,205.185.113.8,205.185.116.215,205.185.116.34,205.185.117.149] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 61"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522060; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [205.185.119.35,205.185.121.170,205.185.121.177,205.185.123.93,205.185.124.176,206.166.251.193,209.141.32.181,209.141.32.198,209.141.34.15,209.141.37.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 62"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522061; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [209.141.40.68,209.141.41.25,209.141.45.141,209.141.45.81,209.141.46.203,209.141.51.180,209.141.51.30,209.141.54.203,209.141.55.26,209.141.58.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 63"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522062; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.192.23.129,212.21.66.6,212.38.189.186,212.69.167.80,212.73.134.204,212.95.50.77,216.73.159.101,216.73.159.75,216.9.224.232,217.12.221.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 64"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522063; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [220.135.36.173,23.129.64.130,23.129.64.131,23.129.64.132,23.129.64.133,23.129.64.134,23.129.64.135,23.129.64.136,23.129.64.137,23.129.64.138] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 65"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522064; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.139,23.129.64.140,23.129.64.141,23.129.64.142,23.129.64.143,23.129.64.144,23.129.64.145,23.129.64.146,23.129.64.147,23.129.64.148] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 66"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522065; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.149,23.129.64.150,23.129.64.151,23.129.64.152,23.129.64.153,23.129.64.154,23.129.64.155,23.129.64.156,23.129.64.157,23.129.64.158] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 67"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522066; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.129.64.159,23.129.64.160,23.129.64.161,23.129.64.162,23.129.64.163,23.129.64.164,23.129.64.165,23.137.248.100,23.137.253.109,23.137.253.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 68"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522067; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.137.253.27,23.137.254.244,23.151.8.8,23.155.8.104,23.184.48.78,23.191.200.10,23.191.200.11,23.191.200.12,23.191.200.13,23.191.200.14] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 69"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522068; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.191.200.15,23.191.200.16,23.191.200.17,23.191.200.18,23.191.200.19,23.191.200.20,23.191.200.21,23.191.200.22,23.191.200.23,23.191.200.24] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 70"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522069; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.191.200.25,23.191.200.26,23.191.200.7,23.191.200.8,23.191.200.9,23.236.122.193,24.240.72.170,2.56.10.36,2.58.56.220,2.58.56.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 71"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522070; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [2.58.56.43,2.58.56.93,27.255.75.198,31.129.22.65,31.133.0.210,31.184.236.104,31.220.75.237,31.44.238.25,35.0.127.52,37.114.50.124] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 72"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522071; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.114.50.142,37.114.50.18,37.114.50.27,37.114.63.5,37.187.5.192,37.221.208.71,37.228.129.128,37.228.129.162,37.228.129.189,37.228.129.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 73"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522072; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.228.129.63,37.77.56.238,38.135.24.30,38.135.24.31,38.135.24.32,38.135.24.33,38.135.24.72,38.135.25.141,38.135.25.142,38.135.25.143] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 74"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522073; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [38.135.25.144,38.135.25.2,38.180.225.239,38.97.116.242,38.97.116.243,38.97.116.244,38.97.116.245,43.160.194.14,45.11.59.28,45.12.3.80] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 75"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522074; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.128.133.242,45.132.246.245,45.13.225.69,45.13.225.78,45.133.74.53,45.134.225.36,45.137.70.158,45.138.16.113,45.138.16.161,45.138.16.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 76"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522075; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.138.16.222,45.138.16.230,45.138.16.231,45.138.16.239,45.138.16.240,45.138.16.248,45.138.16.42,45.138.16.69,45.138.16.76,45.141.215.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 77"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522076; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.141.215.111,45.141.215.114,45.141.215.167,45.141.215.169,45.141.215.17,45.141.215.19,45.141.215.200,45.141.215.21,45.141.215.28,45.141.215.40] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 78"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522077; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.141.215.56,45.141.215.61,45.141.215.62,45.141.215.63,45.141.215.80,45.141.215.88,45.141.215.90,45.141.215.95,45.141.215.97,45.143.200.32] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 79"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522078; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.145.93.133,45.148.10.111,45.154.98.33,45.61.185.172,45.61.186.203,45.61.188.15,45.66.35.10,45.66.35.20,45.66.35.21,45.66.35.22] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 80"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522079; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.66.35.31,45.66.35.32,45.66.35.33,45.66.35.34,45.66.35.35,45.79.144.222,45.80.158.167,45.80.158.23,45.80.158.27,45.80.158.69] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 81"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522080; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.83.104.137,45.83.31.79,45.84.107.101,45.84.107.128,45.84.107.17,45.84.107.172,45.84.107.174,45.84.107.182,45.84.107.198,45.84.107.222] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 82"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522081; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.84.107.33,45.84.107.47,45.84.107.54,45.84.107.55,45.84.107.74,45.84.107.76,45.84.107.97,45.88.186.89,45.88.186.92,45.90.185.100] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 83"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522082; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.90.185.101,45.90.185.102,45.90.185.103,45.90.185.104,45.90.185.105,45.90.185.106,45.90.185.107,45.90.185.108,45.90.185.109,45.90.185.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 84"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522083; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.90.185.111,45.90.185.112,45.90.185.113,45.90.185.114,45.90.185.115,45.90.185.116,45.90.185.117,45.90.185.118,45.90.185.119,45.91.250.107] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 85"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522084; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.9.148.50,45.9.156.101,45.9.168.18,45.9.168.192,45.94.31.68,45.95.169.104,45.95.169.109,45.95.169.110,46.165.243.36,46.23.109.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 86"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522085; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.232.251.191,46.234.47.105,46.246.92.34,46.250.243.29,46.38.243.210,5.101.82.22,5.104.84.183,5.104.86.6,51.15.59.15,51.195.166.174] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 87"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522086; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.222.142.67,51.38.225.46,51.81.222.62,5.181.80.107,51.91.18.151,5.196.95.34,5.253.247.27,5.255.100.224,5.255.100.26,5.255.101.10] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 88"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522087; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.101.131,5.255.103.235,5.255.104.202,5.255.110.120,5.255.111.64,5.255.114.171,5.255.115.58,5.255.117.56,5.255.118.151,5.255.118.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 89"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522088; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.123.158,5.255.123.164,5.255.125.196,5.255.127.222,5.255.97.221,5.255.98.151,5.255.98.198,5.255.98.23,5.255.99.124,5.255.99.147] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 90"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522089; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.99.5,5.2.67.226,5.2.72.110,5.2.79.190,5.34.182.203,54.36.101.21,54.36.108.162,5.45.102.93,5.45.104.176,5.45.98.162] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 91"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522090; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [57.128.212.103,57.128.220.107,57.129.91.235,5.79.66.19,5.8.18.30,5.8.18.99,62.133.45.2,62.171.137.169,62.182.84.146,62.72.47.105] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 92"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522091; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.190.113.221,64.190.76.2,64.190.76.3,64.190.76.4,64.94.85.248,66.146.193.33,66.220.242.222,66.78.40.146,66.78.40.182,66.94.111.228] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 93"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522092; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [67.219.109.141,71.19.144.106,72.14.179.10,72.211.49.235,72.235.129.116,72.5.43.62,74.208.79.7,74.82.47.194,77.246.98.159,77.48.28.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 94"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522093; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.48.28.204,77.48.28.237,77.48.28.239,77.81.247.72,78.142.18.219,80.241.60.207,80.253.251.56,80.67.167.81,80.67.172.162,80.82.78.14] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 95"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522094; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.94.92.106,80.94.92.135,80.94.92.92,80.94.92.99,81.16.33.42,81.17.28.95,82.118.248.205,82.153.138.125,82.153.138.241,82.153.138.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 96"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522095; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.221.128.191,82.221.131.5,82.221.131.86,82.221.139.190,83.147.17.190,83.217.9.73,83.228.94.69,83.96.213.63,83.97.20.77,84.16.224.227] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 97"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522096; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.19.182.20,84.211.226.13,84.239.46.144,85.239.41.130,85.93.218.204,85.93.31.31,86.54.25.3,86.54.28.49,87.118.110.27,87.118.116.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 98"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522097; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.118.116.12,87.118.116.90,87.118.122.30,87.118.122.51,87.120.254.132,88.151.194.24,88.80.20.86,88.80.26.2,88.80.26.3,88.80.26.4] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 99"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522098; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.110.95.164,89.110.95.200,89.147.108.90,89.147.109.58,89.147.110.118,89.147.110.154,89.147.110.82,89.147.111.87,89.234.157.254,89.32.41.150] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 100"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522099; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.26.216,89.58.41.156,91.132.144.59,91.149.243.111,91.202.5.104,91.202.5.155,91.203.144.194,91.203.145.116,91.206.26.26,91.208.75.153] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 101"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522100; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.208.75.156,91.208.75.178,91.208.75.239,91.208.75.3,91.208.75.4,91.219.236.101,91.219.236.91,91.227.114.153,91.92.109.126,91.92.109.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 102"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522101; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.243.24.163,92.246.84.133,93.113.25.239,93.123.109.116,93.123.12.112,93.185.165.211,93.88.75.35,93.90.74.28,93.90.74.29,93.95.227.37] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 103"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522102; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.95.228.125,93.95.231.118,93.95.231.14,93.95.231.88,93.99.104.128,93.99.104.18,93.99.104.194,93.99.104.40,94.102.51.15,94.131.2.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 104"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522103; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.142.241.194,94.142.244.16,94.16.115.121,94.16.121.91,94.230.208.147,94.230.208.148,94.72.103.33,94.72.104.135,94.74.164.89,95.128.43.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 105"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522104; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.143.193.125,95.163.176.177,95.211.244.28,96.9.125.48,98.128.173.33,98.71.178.101,100.35.197.122,100.35.68.51,100.42.28.64,100.42.28.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 106"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522105; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [100.42.28.66,100.42.28.67,100.42.28.68,100.42.28.69,100.42.28.70,100.42.29.160,100.42.29.161,100.42.29.162,100.42.29.163,100.42.29.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 107"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522106; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [100.42.29.165,100.42.29.166,100.42.29.167,100.42.29.168,100.42.29.169,100.42.29.170,100.42.29.171,100.42.29.172,100.42.29.173,100.42.29.174] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 108"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522107; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [100.8.117.86,101.100.141.137,101.109.205.48,101.176.132.201,101.55.125.10,101.99.91.115,101.99.92.179,101.99.93.112,101.99.94.185,102.130.113.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 109"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522108; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [102.130.113.30,102.130.113.42,102.130.115.59,102.130.117.25,102.130.119.48,102.216.253.33,102.216.253.63,103.100.36.59,103.109.100.207,103.1.184.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 110"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522109; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.1.185.91,103.146.203.222,103.146.203.58,103.147.153.113,103.147.153.178,103.147.153.180,103.147.153.181,103.14.77.30,103.149.168.185,103.149.168.186] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 111"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522110; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.149.168.187,103.149.168.188,103.149.168.189,103.149.168.190,103.149.168.242,103.152.178.42,103.166.156.127,103.167.234.55,103.167.234.56,103.167.235.45] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 112"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522111; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.167.235.55,103.17.153.200,103.17.153.201,103.17.153.202,103.17.153.203,103.17.153.204,103.17.153.205,103.17.153.206,103.17.153.207,103.17.153.208] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 113"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522112; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.17.153.209,103.17.153.210,103.17.153.211,103.17.153.212,103.17.153.213,103.17.153.214,103.17.153.215,103.17.153.216,103.17.153.217,103.17.153.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 114"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522113; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.17.153.219,103.17.153.220,103.17.153.221,103.17.153.222,103.17.153.223,103.17.153.224,103.17.153.225,103.17.154.34,103.17.154.35,103.17.154.36] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 115"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522114; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.17.154.37,103.17.154.38,103.17.154.39,103.17.154.40,103.17.154.41,103.17.154.42,103.17.154.43,103.17.154.44,103.17.154.45,103.17.154.46] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 116"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522115; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.17.154.47,103.17.154.48,103.17.154.49,103.17.154.50,103.17.154.51,103.17.154.52,103.17.154.53,103.17.154.54,103.17.154.55,103.17.154.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 117"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522116; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.17.154.57,103.17.154.58,103.17.154.59,103.17.154.60,103.17.154.61,103.17.154.62,103.174.51.78,103.175.16.53,103.177.248.189,103.177.249.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 118"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522117; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.196.37.111,103.200.210.66,103.204.240.70,103.209.24.218,103.212.223.2,103.219.153.27,103.236.163.80,103.241.51.25,103.241.51.34,103.241.51.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 119"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522118; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.241.51.67,103.251.164.209,103.251.165.125,103.251.166.10,103.251.166.227,103.251.166.50,103.28.53.25,103.70.114.68,103.70.13.227,103.97.125.208] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 120"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522119; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [103.97.125.218,104.130.201.49,104.131.72.61,104.152.209.217,104.152.210.229,104.160.9.42,104.167.241.5,104.168.112.182,104.168.205.106,104.168.28.159] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 121"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522120; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.168.35.199,104.168.87.179,104.168.88.59,104.184.255.246,104.200.17.42,104.200.72.29,104.207.148.50,104.207.158.50,104.219.250.152,104.220.191.127] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 122"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522121; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.234.124.218,104.236.87.90,104.238.167.111,104.238.220.59,104.244.72.188,104.244.75.168,104.244.76.24,104.244.78.210,104.244.79.25,104.245.225.64] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 123"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522122; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [104.252.2.20,104.254.128.202,104.254.130.186,104.3.165.248,104.53.221.159,106.70.251.222,107.139.200.10,107.140.222.107,107.142.43.5,107.152.35.142] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 124"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522123; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.152.35.187,107.152.41.203,107.152.41.240,107.152.45.53,107.152.46.63,107.155.127.2,107.155.81.178,107.172.157.34,107.172.187.89,107.172.190.212] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 125"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522124; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.172.211.22,107.172.233.190,107.172.29.62,107.172.3.5,107.172.51.206,107.172.81.134,107.172.86.203,107.173.101.178,107.173.112.51,107.173.164.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 126"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522125; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.173.167.241,107.173.180.36,107.173.89.174,107.174.127.120,107.174.33.155,107.174.34.7,107.174.55.66,107.174.64.206,107.175.213.147,107.175.28.197] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 127"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522126; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.175.28.214,107.175.59.252,107.175.63.59,107.175.82.189,107.189.1.174,107.189.12.101,107.189.12.136,107.189.12.251,107.189.12.52,107.189.13.112] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 128"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522127; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [107.189.13.151,107.189.6.210,107.189.8.12,107.208.159.58,108.14.116.227,108.181.120.131,108.181.120.133,108.181.132.245,108.181.133.69,108.181.22.201] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 129"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522128; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [108.181.33.185,108.181.57.251,108.181.57.253,108.181.94.150,108.203.171.61,108.211.32.201,108.244.47.41,108.244.47.44,108.249.24.206,108.28.159.250] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 130"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522129; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [108.28.34.95,108.52.49.167,108.62.103.193,108.62.119.77,108.62.211.200,108.62.211.205,109.100.59.186,109.102.193.184,109.104.153.187,109.104.155.161] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 131"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522130; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.104.155.20,109.105.109.162,109.105.29.156,109.107.35.154,109.123.231.54,109.123.241.114,109.123.250.54,109.138.0.42,109.151.48.34,109.158.210.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 132"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522131; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.173.161.111,109.175.247.24,109.183.26.233,109.192.104.34,109.199.103.100,109.199.106.226,109.205.195.217,109.205.195.225,109.205.195.226,109.205.195.227] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 133"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522132; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.209.62.239,109.230.224.174,109.230.236.194,109.236.83.11,109.238.11.6,109.248.163.239,109.250.190.197,109.250.226.152,109.251.55.19,109.69.218.176] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 134"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522133; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [109.69.218.51,109.70.100.245,109.70.100.246,109.73.65.37,109.78.36.77,109.90.31.112,109.91.143.181,109.91.213.9,109.92.177.220,111.249.197.228] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 135"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522134; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [111.69.37.214,111.90.145.140,112.209.32.138,113.20.28.216,113.20.28.243,114.175.95.238,114.190.20.41,114.23.164.80,115.129.60.1,115.130.142.48] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 136"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522135; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [115.131.164.165,1.161.138.92,116.202.150.27,116.202.179.148,116.202.237.212,116.202.6.255,116.203.110.30,116.203.135.195,116.203.17.238,116.203.196.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 137"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522136; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [116.203.222.169,116.203.50.182,116.203.64.212,116.255.1.163,116.255.5.183,117.53.155.113,1.179.173.34,118.210.3.209,118.27.12.40,118.67.199.221] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 138"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522137; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [119.14.110.166,119.18.25.254,119.18.35.197,119.28.139.55,121.160.200.13,121.50.43.135,122.208.194.105,123.208.171.47,123.243.232.64,123.253.34.26] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 139"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522138; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [123.253.34.36,123.255.62.137,124.198.131.138,124.198.132.161,125.133.242.25,125.195.13.68,125.229.3.246,125.244.210.233,125.254.108.144,125.63.30.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 140"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522139; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [126.52.35.132,126.57.124.61,128.0.64.148,128.110.218.246,128.135.164.40,128.140.2.186,128.140.60.104,128.199.131.168,128.199.146.186,128.232.18.58] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 141"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522140; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [128.238.62.37,128.31.0.39,128.31.0.61,128.52.132.189,129.100.38.89,129.13.131.140,129.146.122.189,129.146.43.72,129.151.170.233,129.151.193.106] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 142"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522141; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [129.151.203.69,129.151.206.128,129.151.218.233,129.151.231.183,129.151.254.245,129.152.15.6,129.152.19.236,129.152.8.9,129.153.174.121,129.153.176.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 143"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522142; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [129.153.215.190,129.153.53.94,129.153.55.20,129.159.146.81,129.159.148.184,129.159.42.2,129.224.204.177,129.80.149.163,130.0.44.163,130.162.245.222] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 144"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522143; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [130.162.54.65,130.162.55.37,130.180.63.150,130.193.15.191,130.193.15.49,130.225.244.90,130.51.21.22,130.51.31.202,130.61.168.243,130.61.174.206] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 145"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522144; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [130.61.174.40,130.61.189.174,130.61.22.245,130.61.30.37,130.61.32.148,130.61.37.185,130.61.42.6,130.61.51.183,130.89.149.57,131.153.152.122] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 146"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522145; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [131.153.152.146,131.174.23.228,131.188.40.188,131.188.40.189,131.203.32.146,131.255.4.48,132.145.100.169,132.145.163.250,132.145.216.76,132.145.245.6] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 147"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522146; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [132.145.99.212,132.226.202.222,132.226.230.236,132.248.241.5,132.248.59.73,133.130.235.189,133.130.98.124,133.18.168.48,133.242.146.78,133.242.204.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 148"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522147; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [134.101.43.158,134.102.200.101,134.130.172.229,134.185.83.121,134.195.185.52,134.195.88.66,134.199.173.242,134.199.203.32,134.209.167.158,134.209.225.95] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 149"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522148; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [134.209.240.249,134.209.85.230,134.255.211.228,134.3.129.57,134.41.123.70,134.41.159.159,134.93.49.75,135.125.147.165,135.125.202.252,135.125.239.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 150"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522149; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [135.125.89.25,135.131.32.46,135.148.100.233,135.148.100.84,135.148.100.89,135.148.100.90,135.148.100.92,135.148.103.15,135.148.139.41,135.148.149.23] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 151"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522150; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [135.148.149.90,135.148.150.100,135.148.150.99,135.148.171.158,135.148.27.19,135.148.50.253,135.148.52.88,135.148.54.103,135.148.54.106,135.148.54.98] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 152"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522151; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [135.181.195.203,135.181.25.143,135.181.30.19,135.181.41.38,135.181.63.118,135.181.67.210,135.181.99.59,13.59.175.193,136.243.147.89,136.243.147.91] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 153"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522152; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [136.243.153.169,136.243.154.74,136.243.174.159,136.243.176.148,136.243.176.179,136.243.3.194,136.243.89.124,136.243.92.194,136.243.93.102,136.244.87.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 154"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522153; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [136.244.99.48,136.35.153.73,136.35.254.165,136.37.199.252,136.38.120.201,136.47.213.188,136.61.242.29,136.61.69.233,136.62.2.205,137.220.120.168] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 155"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522154; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [137.220.120.19,137.220.127.139,137.220.37.214,137.226.34.45,137.59.185.179,137.59.56.138,137.74.119.109,137.74.164.213,137.74.5.135,138.124.180.121] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 156"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522155; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [138.197.166.92,138.197.79.129,138.199.152.49,138.199.171.143,138.201.121.103,138.201.19.25,138.201.196.252,138.201.225.177,138.201.247.18,138.201.51.181] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 157"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522156; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [138.201.54.59,138.201.57.234,138.201.58.21,138.201.78.61,138.201.92.183,138.2.129.221,138.2.175.113,138.2.77.99,138.3.243.165,138.3.243.244] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 158"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522157; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [138.48.33.162,138.59.18.105,138.59.18.106,138.68.144.236,138.68.177.233,138.68.9.184,138.74.139.115,138.88.150.120,138.88.219.158,139.144.60.215] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 159"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522158; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [139.162.117.43,139.162.11.98,139.162.162.238,139.162.191.49,139.162.251.70,139.162.63.125,139.180.223.39,139.59.177.238,139.84.237.160,139.84.239.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 160"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522159; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [139.99.156.197,139.99.171.238,139.99.197.44,140.186.63.54,140.235.237.13,140.238.136.96,140.238.145.127,140.238.197.12,140.238.210.128,140.238.215.233] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 161"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522160; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [140.238.218.199,140.238.218.248,140.238.220.10,140.238.97.211,140.78.100.14,140.78.100.15,140.78.100.16,140.78.100.17,140.78.100.18,140.78.100.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 162"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522161; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [140.78.100.20,140.78.100.21,140.78.100.22,140.78.100.23,140.78.100.24,140.78.100.25,140.78.100.26,140.78.100.27,140.78.100.28,140.78.100.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 163"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522162; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [140.78.100.35,140.78.100.36,140.78.100.37,140.78.100.38,140.78.100.39,140.78.100.40,140.78.100.41,140.78.100.42,140.78.100.43,140.82.32.75] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 164"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522163; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [140.82.39.239,140.83.50.92,141.105.130.119,141.105.130.128,141.105.130.172,141.105.130.188,141.105.130.193,141.11.164.4,141.136.0.3,141.136.194.10] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 165"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522164; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [141.14.220.177,141.144.245.205,141.145.150.99,141.145.201.126,141.147.47.233,141.147.54.226,141.148.232.210,141.156.185.183,141.253.98.97,141.255.161.167] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 166"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522165; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [141.3.63.26,141.43.203.237,14.169.247.15,141.76.46.150,141.79.10.16,14.192.203.21,141.95.52.206,141.95.86.17,141.98.11.131,141.98.153.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 167"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522166; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [141.98.233.146,142.11.201.90,14.2.125.1,142.132.151.131,142.132.157.35,142.132.204.112,142.132.204.165,142.132.205.43,142.132.212.158,142.132.230.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 168"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522167; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [142.202.48.102,142.202.51.68,142.204.140.244,142.44.227.24,142.44.234.69,142.44.243.133,142.44.247.102,142.56.244.176,142.91.99.90,142.93.169.197] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 169"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522168; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [142.93.228.59,142.93.54.219,143.177.223.233,143.179.224.77,143.198.38.18,143.198.50.224,143.198.87.111,14.32.49.155,143.47.113.11,144.168.44.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 170"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522169; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [144.168.44.26,144.172.109.166,144.2.101.81,144.217.32.158,144.217.80.12,144.217.81.135,144.217.87.28,144.217.90.187,144.24.17.44,144.24.176.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 171"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522170; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [144.24.178.238,144.24.187.244,144.24.232.2,144.2.65.27,144.6.128.247,144.6.150.213,144.6.189.17,144.6.197.157,144.6.23.197,144.76.104.119] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 172"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522171; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [144.76.140.110,144.76.154.13,144.76.159.218,144.76.162.202,144.76.166.141,144.76.166.199,144.76.168.36,144.76.175.205,144.76.201.253,144.76.248.66] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 173"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522172; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [144.76.26.58,144.76.3.174,144.76.3.182,144.76.56.43,144.76.81.198,144.76.86.5,144.91.125.15,144.91.125.239,144.91.72.184,145.220.0.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 174"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522173; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [145.239.136.129,145.239.1.9,145.239.206.31,145.239.41.102,145.239.76.95,145.239.81.58,145.239.93.202,145.249.109.38,145.40.217.28,145.40.235.26] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 175"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522174; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [146.0.36.87,146.0.40.193,146.185.253.130,146.185.253.53,146.190.132.133,146.190.16.208,146.190.224.96,146.190.251.108,146.190.96.130,146.19.143.166] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 176"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522175; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [146.19.143.202,146.19.168.223,146.19.173.181,146.19.173.215,146.19.213.120,146.19.213.134,146.19.213.237,146.19.254.130,146.19.42.81,146.52.229.88] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 177"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522176; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [146.56.99.34,146.59.1.158,146.59.12.188,146.59.15.186,146.59.19.112,146.59.197.114,146.59.229.225,146.59.44.132,146.59.44.186,146.59.92.133] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 178"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522177; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [146.70.120.58,146.70.233.17,146.70.34.146,146.70.80.101,146.70.80.19,147.12.183.39,147.135.110.109,147.135.112.139,147.135.112.202,147.135.114.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 179"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522178; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [147.135.114.98,147.135.129.138,147.135.16.185,147.135.214.61,147.135.4.68,147.135.54.178,147.135.65.26,147.135.65.87,147.135.6.69,147.135.70.168] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 180"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522179; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [147.148.114.134,147.160.139.190,147.182.202.137,147.189.138.27,147.229.177.166,147.28.87.56,147.45.116.41,147.45.49.56,147.78.240.211,147.78.242.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 181"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522180; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [148.113.183.0,148.113.195.239,148.113.196.47,148.135.101.13,148.135.16.243,148.251.10.237,148.251.136.16,148.251.151.125,148.251.183.205,148.251.208.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 182"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522181; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [148.251.236.209,148.251.242.166,148.251.33.107,148.251.41.235,148.251.46.115,148.251.51.34,148.251.83.53,148.251.85.195,148.251.90.115,148.71.136.248] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 183"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522182; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [148.75.213.197,14.9.101.224,149.102.138.67,149.102.242.15,149.130.185.6,149.130.215.238,149.143.101.143,149.143.87.35,149.154.154.155,149.154.159.177] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 184"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522183; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [149.154.24.13,149.171.156.143,149.202.69.174,149.210.164.228,149.224.155.237,149.248.54.124,149.28.170.126,149.28.174.237,149.28.178.78,149.28.212.142] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 185"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522184; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [149.28.238.153,149.28.58.137,149.50.46.95,149.5.190.60,149.56.126.142,149.56.22.133,149.56.45.200,149.56.47.245,150.136.142.129,150.136.171.160] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 186"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522185; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [150.136.174.143,150.221.28.106,150.230.10.235,150.230.12.55,150.230.20.28,150.230.22.185,150.230.253.242,150.43.248.24,151.115.73.55,151.189.64.113] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 187"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522186; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [151.196.45.212,151.236.23.115,151.237.82.153,151.49.52.63,151.56.246.205,151.71.248.153,151.80.32.172,15.204.11.248,15.204.140.9,15.204.14.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 188"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522187; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [15.204.141.10,15.204.141.14,15.204.141.95,15.204.142.37,15.204.143.192,15.204.183.156,15.204.199.7,15.204.220.109,15.204.223.128,15.204.233.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 189"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522188; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [15.204.247.142,15.204.248.200,15.204.31.220,15.204.57.248,15.204.59.68,15.204.86.235,15.204.87.24,15.235.184.119,15.235.209.150,15.235.29.236] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 190"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522189; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [15.235.39.148,15.235.60.220,152.53.100.209,152.53.102.95,152.53.115.49,152.53.118.246,152.53.123.174,152.53.124.86,152.53.126.108,152.53.128.52] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 191"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522190; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [152.53.15.127,152.53.15.144,152.53.17.175,152.53.176.153,152.53.17.83,152.53.18.121,152.53.18.201,152.53.18.94,152.53.19.3,152.53.224.57] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 192"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522191; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [152.53.246.111,152.53.246.82,152.53.251.172,152.53.251.244,152.53.252.155,152.53.32.145,152.53.34.99,152.53.49.80,152.53.65.169,152.53.67.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 193"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522192; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [152.53.86.165,152.53.88.212,152.53.95.190,152.67.102.228,152.67.108.225,152.67.112.12,152.67.219.161,152.67.230.135,152.67.253.57,152.67.71.206] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 194"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522193; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [152.67.73.234,152.69.183.132,152.69.198.49,152.70.175.13,152.86.6.232,152.89.170.201,152.89.254.46,152.89.92.206,153.121.50.171,153.165.30.195] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 195"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522194; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [153.170.2.142,153.242.202.2,153.33.22.169,154.16.116.61,154.26.154.84,154.26.155.208,154.26.159.157,154.53.164.216,154.90.54.69,155.138.137.144] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 196"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522195; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [155.138.146.249,155.138.194.213,155.248.194.143,155.248.227.210,155.254.60.103,155.254.60.194,155.4.74.117,156.146.62.151,156.229.164.225,156.57.38.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 197"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522196; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [157.131.125.71,157.147.138.49,157.173.113.52,157.173.119.177,157.180.48.152,157.180.74.196,157.180.78.167,157.180.83.64,157.230.17.193,157.230.18.123] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 198"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522197; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [157.245.206.140,157.245.84.78,157.90.112.145,157.90.131.201,157.90.183.103,157.90.212.53,157.90.250.217,157.90.253.60,157.90.77.166,157.90.92.115] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 199"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522198; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [158.101.103.203,158.101.181.77,158.101.203.38,158.101.204.117,158.140.230.233,158.174.211.210,158.179.207.229,158.179.207.66,158.180.25.76,158.220.100.158] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 200"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522199; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [158.220.98.150,158.247.225.136,158.248.34.141,158.255.212.178,158.51.111.120,158.51.125.98,158.69.0.227,158.69.117.214,158.69.205.247,158.69.207.216] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 201"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522200; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [158.69.226.159,158.69.252.116,158.69.48.19,159.117.75.96,159.196.130.39,159.196.184.248,159.196.89.240,159.203.24.145,159.203.29.240,159.203.44.191] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 202"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522201; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [159.203.7.160,159.223.138.107,159.223.170.101,159.223.170.89,159.65.125.72,159.69.11.74,159.69.12.128,159.69.138.31,159.69.146.194,159.69.153.203] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 203"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522202; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [159.69.202.246,159.69.206.86,159.69.21.196,159.69.212.6,159.69.220.27,159.69.36.3,159.69.71.228,159.89.23.116,159.89.236.228,159.89.41.177] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 204"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522203; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [160.119.100.160,160.119.249.24,160.119.253.103,160.119.253.114,160.13.108.41,160.16.122.68,160.16.57.39,160.187.1.243,160.251.136.238,160.251.184.10] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 205"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522204; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [161.22.40.209,161.35.148.205,161.53.160.104,16.171.132.236,161.97.120.125,161.97.142.15,161.97.160.70,161.97.168.99,161.97.184.202,161.97.184.88] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 206"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522205; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [162.0.179.15,162.156.213.92,162.157.210.69,162.19.171.180,162.19.204.163,162.19.244.234,162.19.252.137,162.19.252.175,162.19.79.247,162.206.3.44] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 207"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522206; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [162.210.173.3,162.210.173.5,162.210.173.6,162.210.196.17,162.216.231.39,162.224.115.204,162.226.250.137,162.243.168.143,162.245.237.154,162.247.153.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 208"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522207; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [162.250.189.204,162.250.189.33,162.250.191.15,162.251.116.10,162.251.116.106,162.251.116.18,162.251.116.26,162.251.116.34,162.251.116.50,162.251.116.82] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 209"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522208; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [162.251.117.10,162.251.119.10,162.251.119.2,162.251.156.68,162.251.166.210,162.254.86.36,162.255.84.47,162.43.36.145,162.43.50.80,162.55.107.247] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 210"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522209; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [162.55.131.67,162.55.48.243,162.81.184.62,163.172.251.6,163.172.53.201,163.172.66.95,163.172.70.175,163.172.76.56,163.172.93.6,163.220.236.40] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 211"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522210; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [163.220.236.41,163.44.103.95,163.44.127.171,163.44.98.220,164.132.200.218,164.132.226.30,164.132.23.184,164.132.75.248,164.215.103.126,164.68.106.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 212"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522211; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [164.68.121.40,164.90.131.37,164.90.148.60,164.90.152.167,164.90.164.10,164.92.188.39,164.92.210.128,164.92.216.76,165.22.121.164,165.22.124.177] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 213"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522212; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [165.22.239.19,165.227.17.19,165.227.34.240,165.227.41.75,165.232.130.0,165.73.47.36,166.1.173.49,166.70.98.20,166.84.6.10,166.88.142.114] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 214"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522213; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [166.88.77.33,167.114.103.133,167.160.188.221,167.179.108.20,167.179.71.27,167.179.99.77,167.235.112.134,167.235.131.114,167.235.15.221,167.235.183.140] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 215"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522214; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [167.235.183.173,167.235.249.14,167.235.61.89,167.235.74.7,167.253.78.22,167.71.202.62,167.71.52.174,167.86.122.9,167.86.67.112,167.86.74.109] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 216"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522215; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [167.86.85.117,167.88.51.249,167.99.136.66,167.99.84.67,168.100.10.41,168.103.87.18,168.119.209.97,168.119.2.55,168.138.165.170,168.138.179.192] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 217"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522216; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [168.181.185.147,169.228.66.227,170.117.197.150,170.133.2.81,170.187.164.35,170.64.129.106,170.64.202.213,170.64.203.139,171.22.172.65,171.22.173.221] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 218"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522217; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [171.25.193.9,171.66.3.87,171.97.235.152,172.103.94.104,172.104.20.200,172.104.208.190,172.104.57.51,172.105.161.162,172.105.166.172,172.105.191.16] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 219"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522218; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.105.191.74,172.105.199.155,172.105.6.34,172.111.139.43,172.114.8.83,172.12.112.137,172.127.92.239,172.219.92.78,172.232.134.231,172.232.24.166] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 220"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522219; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.232.54.164,172.233.211.155,172.233.242.114,172.233.27.245,172.234.118.77,172.234.120.87,172.234.123.154,172.234.18.228,172.234.80.181,172.234.94.89] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 221"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522220; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.236.35.135,172.236.61.203,172.237.108.116,172.237.133.225,172.241.140.247,172.241.140.249,172.241.224.145,172.241.229.13,172.241.23.114,172.241.251.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 222"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522221; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.245.106.179,172.245.214.70,172.245.232.239,172.245.234.102,172.245.234.162,172.245.23.98,172.245.251.202,172.245.55.112,172.252.236.56,172.5.27.211] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 223"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522222; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [172.81.131.87,172.81.132.5,172.93.101.181,172.93.102.139,172.93.48.192,172.93.49.243,172.96.172.157,172.98.195.205,173.176.44.101,173.180.13.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 224"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522223; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [173.180.163.162,173.180.93.123,173.18.121.95,173.212.200.241,173.212.236.169,173.212.242.110,173.230.128.232,173.230.134.72,173.230.137.91,173.230.154.90] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 225"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522224; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [173.24.73.213,173.249.195.122,173.249.55.230,173.255.199.49,173.255.228.134,173.255.236.85,173.255.241.85,173.255.245.116,173.75.20.115,173.75.44.96] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 226"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522225; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [173.88.179.79,174.103.209.32,174.136.100.6,174.164.225.34,174.34.132.72,174.83.20.73,174.84.33.39,174.92.118.224,175.118.45.69,175.212.206.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 227"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522226; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [175.215.255.118,175.33.91.103,175.39.102.69,176.100.37.109,176.100.37.88,176.10.107.180,176.102.128.205,176.103.221.211,176.107.157.166,176.107.176.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 228"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522227; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.114.248.225,176.117.59.117,176.118.193.106,176.120.75.187,176.123.1.144,176.123.1.171,176.123.1.67,176.123.2.25,176.123.7.172,176.123.8.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 229"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522228; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.126.241.209,176.126.84.25,176.126.86.109,176.126.86.154,176.126.86.160,176.150.204.179,176.20.143.168,176.206.229.9,176.223.141.106,176.31.35.149] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 230"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522229; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.58.110.66,176.58.121.159,176.58.124.159,176.65.148.149,176.65.149.207,176.65.149.209,176.65.149.57,176.65.149.65,176.84.41.86,176.9.123.122] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 231"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522230; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.9.161.22,176.9.23.30,176.9.38.121,176.9.39.196,176.9.50.140,176.95.255.229,176.9.57.157,176.96.137.184,176.97.117.91,176.97.124.126] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 232"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522231; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [176.97.79.138,176.9.85.41,176.9.91.26,177.100.214.111,177.104.76.97,177.136.102.49,177.153.20.241,177.92.41.154,178.113.163.42,178.128.160.54] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 233"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522232; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.132.0.6,178.143.55.78,178.156.145.195,178.162.132.106,178.162.132.183,178.162.154.226,178.162.221.111,178.162.221.18,178.164.194.74,178.165.126.221] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 234"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522233; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.170.13.43,178.17.170.168,178.17.170.172,178.17.170.254,178.175.148.195,178.18.245.109,178.18.246.108,178.18.246.223,178.19.236.36,178.194.102.194] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 235"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522234; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.194.187.72,178.19.96.125,178.200.143.177,178.200.168.70,178.202.167.73,178.202.51.204,178.208.186.179,178.215.228.25,178.215.228.78,178.218.144.113] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 236"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522235; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.222.250.92,178.235.131.84,178.238.41.67,178.239.17.187,178.248.249.172,178.250.186.44,178.250.186.47,178.254.1.172,178.254.18.186,178.254.18.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 237"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522236; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.254.20.235,178.254.20.38,178.254.2.14,178.254.25.106,178.254.32.33,178.254.33.55,178.254.34.109,178.254.35.2,178.254.35.245,178.254.36.182] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 238"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522237; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.254.41.111,178.254.44.163,178.254.44.54,178.254.45.235,178.254.45.64,178.255.220.24,178.26.105.120,178.32.136.221,178.32.139.118,178.32.143.167] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 239"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522238; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.32.41.33,178.32.42.219,178.32.60.161,178.33.36.64,178.33.45.159,178.33.84.131,178.62.222.199,178.62.24.212,178.62.94.243,178.63.116.157] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 240"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522239; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.63.3.190,178.63.40.99,178.63.41.183,178.63.43.153,178.63.52.50,178.63.68.78,178.73.219.2,178.76.189.97,178.79.134.196,178.79.154.219] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 241"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522240; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [178.79.163.170,178.85.175.222,179.43.134.188,179.43.134.19,179.43.134.242,179.43.141.195,179.43.158.176,179.43.160.164,179.43.172.159,179.43.182.16] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 242"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522241; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [179.43.182.217,179.43.182.235,179.43.182.252,179.43.182.33,179.61.251.32,179.61.251.86,179.61.253.70,180.150.27.133,180.150.71.182,180.150.77.240] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 243"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522242; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [18.101.10.142,181.118.48.162,18.118.173.86,181.214.231.43,181.214.99.212,181.215.226.65,18.130.146.107,181.43.109.224,18.183.169.218,18.18.82.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 244"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522243; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [18.18.82.19,18.18.82.30,18.221.190.248,18.222.193.228,18.227.111.167,183.178.226.6,184.144.165.178,184.144.51.151,184.147.180.121,184.174.38.53] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 245"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522244; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [184.18.93.88,18.4.60.42,184.83.155.179,185.100.233.160,185.100.86.70,185.100.87.141,185.100.87.61,185.101.139.172,185.101.175.102,185.10.16.41] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 246"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522245; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.103.110.14,185.103.110.21,185.103.110.65,185.103.110.86,185.104.131.220,185.104.194.129,185.106.123.50,185.10.68.88,185.107.57.64,185.107.57.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 247"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522246; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.107.57.66,185.107.80.48,185.107.83.1,185.109.91.126,185.112.146.205,185.112.147.96,185.112.249.156,185.116.236.48,185.117.118.142,185.117.82.68] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 248"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522247; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.117.82.71,185.119.117.148,185.119.117.229,185.119.119.63,185.120.137.202,185.120.145.83,185.120.16.171,185.121.12.68,185.122.167.50,185.124.240.109] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 249"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522248; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.124.240.98,185.125.169.25,185.125.169.30,185.125.169.92,185.126.255.22,185.126.65.28,185.126.82.93,185.130.45.103,185.130.45.207,185.130.46.89] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 250"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522249; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.130.47.205,185.130.47.76,185.131.216.23,185.131.217.52,185.132.176.180,185.132.53.121,185.132.53.20,185.135.137.185,185.135.137.211,185.139.228.227] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 251"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522250; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.140.209.158,185.141.216.152,185.141.216.220,185.141.216.238,185.141.216.40,185.141.216.41,185.142.208.226,185.14.30.57,185.143.102.82,185.14.31.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 252"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522251; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.147.35.74,185.148.1.210,185.148.1.242,185.148.1.49,185.148.1.50,185.148.3.38,185.14.97.96,185.150.18.219,185.153.182.11,185.153.55.116] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 253"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522252; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.153.55.203,185.153.55.208,185.153.55.234,185.153.55.240,185.153.55.246,185.161.210.189,185.162.249.126,185.162.250.173,185.162.251.122,185.162.251.94] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 254"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522253; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.163.204.43,185.163.45.212,185.163.45.247,185.163.45.253,185.163.46.83,185.16.39.76,185.165.171.193,185.16.61.178,185.168.195.85,185.169.234.138] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 255"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522254; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.169.242.123,185.170.112.182,185.17.178.132,185.173.93.47,185.174.135.11,185.175.158.198,185.175.56.120,185.177.126.118,185.177.127.34,185.177.229.228] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 256"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522255; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.179.143.91,185.181.60.181,185.181.63.124,185.182.193.16,185.183.194.90,185.184.122.91,185.184.68.123,185.184.69.16,185.184.70.225,185.184.70.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 257"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522256; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.184.71.86,185.184.71.94,185.185.51.29,185.189.125.22,185.189.149.188,185.189.183.143,185.191.239.172,185.191.239.49,185.193.125.208,185.193.126.236] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 258"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522257; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.193.50.122,185.194.142.73,185.194.143.87,185.194.53.138,185.195.236.16,185.196.220.204,185.196.220.82,185.198.56.195,185.204.1.83,185.204.1.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 259"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522258; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.206.146.238,185.207.106.241,185.21.217.32,185.212.44.101,185.212.44.163,185.213.175.236,185.213.24.108,185.216.179.175,185.216.179.206,185.216.214.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 260"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522259; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.216.35.222,185.216.68.42,185.216.68.82,185.218.137.163,185.218.88.66,185.219.220.217,185.219.84.166,185.220.101.171,185.220.101.192,185.220.101.193] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 261"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522260; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.194,185.220.101.195,185.220.101.196,185.220.101.197,185.220.101.198,185.220.101.199,185.220.101.200,185.220.101.201,185.220.101.202,185.220.101.203] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 262"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522261; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.220.101.204,185.220.101.205,185.220.101.206,185.220.101.207,185.220.101.208,185.220.101.209,185.220.101.210,185.220.101.211,185.221.23.201,185.225.112.85] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 263"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522262; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.225.114.22,185.225.114.53,185.225.114.92,185.225.17.105,185.225.18.102,185.225.19.159,185.225.210.34,185.225.68.98,185.225.69.140,185.225.69.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 264"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522263; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.227.70.147,185.227.70.153,185.227.70.177,185.227.70.178,185.227.70.53,185.227.70.60,185.228.138.252,185.228.138.86,185.229.90.81,185.232.68.247] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 265"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522264; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.232.68.32,185.232.69.10,185.233.104.172,185.234.20.132,185.236.24.150,185.238.129.9,185.241.208.64,185.241.220.83,185.241.5.229,185.242.107.224] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 266"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522265; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.242.87.96,185.243.20.70,185.244.129.163,185.244.194.156,185.244.24.40,185.246.128.157,185.246.188.114,185.246.188.116,185.246.188.117,185.246.86.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 267"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522266; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.247.224.151,185.247.224.226,185.249.198.176,185.252.147.236,185.255.122.39,185.255.122.70,185.26.156.186,185.28.47.11,185.28.47.21,185.28.47.22] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 268"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522267; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.32.222.237,185.36.142.175,185.40.199.126,185.40.4.84,185.4.132.148,185.4.134.104,185.44.66.137,185.44.67.59,185.48.250.112,185.49.123.107] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 269"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522268; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.56.107.21,185.56.107.25,185.56.150.244,185.58.123.66,185.62.56.188,185.66.109.249,185.66.91.18,185.69.54.127,185.73.211.9,185.73.220.8] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 270"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522269; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.73.240.205,185.7.78.70,185.80.222.164,185.80.30.102,185.8.165.248,185.82.126.13,185.82.126.230,185.82.126.57,185.82.127.213,185.82.202.3] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 271"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522270; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.82.216.211,185.82.217.49,185.82.219.77,185.82.219.85,185.85.240.191,185.85.241.119,185.85.241.69,185.85.241.92,185.93.89.197,185.98.168.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 272"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522271; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [185.99.2.117,185.99.2.143,185.99.2.160,186.104.117.180,186.206.207.160,186.233.185.59,186.233.185.61,187.207.111.161,188.119.191.172,188.123.212.143] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 273"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522272; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.126.83.38,188.127.197.42,188.132.234.76,188.136.104.64,188.141.60.190,188.154.10.211,188.155.240.245,188.165.0.43,188.165.131.206,188.165.136.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 274"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522273; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.165.136.211,188.165.137.247,188.165.194.209,188.165.222.73,188.165.227.10,188.165.24.84,188.165.26.13,188.165.26.76,188.165.4.146,188.166.136.51] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 275"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522274; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.166.87.136,188.172.228.104,188.172.228.20,188.174.202.16,188.174.48.233,188.192.191.25,188.192.203.234,188.194.191.45,188.194.61.91,188.213.129.118] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 276"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522275; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.213.31.125,188.213.92.88,188.214.104.59,188.214.132.18,188.214.132.49,188.214.88.31,188.214.88.32,188.214.88.33,188.216.109.207,188.226.144.71] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 277"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522276; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.239.22.57,188.245.124.71,188.245.203.234,188.245.217.208,188.245.58.41,188.245.91.213,188.246.204.67,188.251.135.96,188.40.128.246,188.40.238.100] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 278"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522277; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.40.99.69,188.63.152.147,188.68.236.220,188.68.32.174,188.68.32.21,188.68.33.200,188.68.35.156,188.68.40.180,188.68.41.54,188.68.41.74] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 279"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522278; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.68.42.13,188.68.43.192,188.68.45.72,188.68.46.164,188.68.46.245,188.68.50.174,188.68.50.76,188.68.58.105,188.68.60.91,188.91.4.123] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 280"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522279; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [188.97.165.82,189.146.19.99,189.6.125.6,190.103.179.109,190.120.231.13,190.211.254.101,190.211.254.182,190.211.254.192,190.211.254.210,190.211.254.76] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 281"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522280; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [190.2.133.227,190.2.143.50,190.89.104.134,191.113.112.147,191.96.11.38,192.111.150.126,192.119.108.114,192.121.108.119,192.121.108.120,192.121.108.129] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 282"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522281; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.121.108.130,192.121.108.236,192.121.108.237,192.121.108.238,192.121.108.239,192.121.44.26,192.121.44.27,192.124.216.119,192.129.10.18,192.159.99.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 283"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522282; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.162.71.46,192.166.43.125,192.18.144.19,192.18.154.45,192.18.159.101,192.184.93.11,192.186.127.123,192.208.1.65,192.210.233.239,192.210.255.192] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 284"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522283; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.211.48.226,192.227.193.56,192.227.206.36,192.227.212.134,192.227.212.242,192.227.213.246,192.227.225.254,192.234.196.169,192.24.207.200,192.248.186.87] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 285"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522284; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.3.161.227,192.3.173.87,192.34.87.86,192.3.55.4,192.36.38.33,192.42.113.101,192.42.113.102,192.42.115.101,192.42.115.102,192.42.115.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 286"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522285; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.42.116.187,192.42.116.188,192.42.116.189,192.42.132.106,192.68.11.203,192.87.28.28,192.87.28.82,192.9.129.235,192.9.235.157,192.9.249.147] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 287"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522286; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [192.95.29.105,192.99.152.50,192.99.228.114,192.99.6.223,192.99.69.17,193.104.220.35,193.10.49.32,193.105.134.16,193.105.134.18,193.105.134.186] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 288"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522287; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.105.134.187,193.106.166.105,193.108.117.103,193.108.52.87,193.108.52.88,193.108.53.121,193.109.120.3,193.109.69.54,193.11.114.43,193.11.114.45] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 289"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522288; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.11.114.46,193.11.164.243,193.11.166.196,193.1.12.167,193.119.90.209,193.122.142.28,193.123.106.255,193.124.33.242,193.135.10.219,193.142.146.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 290"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522289; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.142.146.43,193.142.147.204,193.142.147.69,193.142.59.232,193.142.59.53,193.160.96.55,193.168.143.107,193.168.144.76,193.182.111.131,193.182.111.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 291"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522290; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.182.111.133,193.182.111.182,193.182.111.41,193.182.111.42,193.182.111.43,193.187.91.79,193.190.168.53,193.200.17.56,193.200.229.34,193.219.97.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 292"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522291; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.226.13.80,193.226.78.213,193.23.244.244,193.233.127.132,193.233.202.131,193.233.202.71,193.233.246.12,193.233.246.140,193.233.246.197,193.233.246.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 293"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522292; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.233.247.77,193.233.247.99,193.238.86.205,193.239.205.90,193.239.86.147,193.24.208.208,193.251.38.130,193.26.156.117,193.30.120.139,193.30.122.222] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 294"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522293; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.30.122.232,193.30.123.113,193.30.123.132,193.31.25.141,193.31.27.109,193.31.27.127,193.31.31.89,193.32.87.151,193.32.87.7,193.42.36.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 295"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522294; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [193.42.36.82,193.43.72.16,193.46.56.106,193.63.58.76,193.70.112.165,193.80.117.213,193.84.71.12,193.84.71.223,193.93.13.174,194.0.252.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 296"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522295; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.103.157.40,194.104.156.50,194.110.5.11,194.110.60.12,194.117.224.50,194.126.173.158,194.126.174.190,194.13.81.26,194.13.83.131,194.140.221.42] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 297"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522296; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.14.0.242,194.14.0.243,194.14.0.245,194.14.0.246,194.14.0.247,194.147.140.101,194.147.140.102,194.147.140.106,194.147.140.107,194.147.140.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 298"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522297; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.15.115.224,194.15.115.91,194.15.115.92,194.15.115.93,194.15.115.94,194.156.103.77,194.163.172.26,194.164.125.213,194.164.127.34,194.164.163.126] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 299"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522298; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.164.16.95,194.164.169.85,194.164.170.101,194.164.173.152,194.164.174.127,194.164.197.45,194.164.202.239,194.164.207.75,194.164.22.145,194.164.245.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 300"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522299; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.164.53.4,194.164.60.113,194.164.62.141,194.164.89.203,194.164.90.13,194.180.191.179,194.180.191.93,194.182.179.34,194.190.152.170,194.233.75.85] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 301"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522300; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.247.182.191,194.26.141.208,194.26.192.186,194.26.27.17,194.34.132.169,194.34.132.51,194.34.134.13,194.35.184.202,194.36.147.51,194.39.207.224] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 302"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522301; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.42.196.35,194.48.248.137,194.48.248.142,194.48.248.99,194.49.71.252,194.5.101.253,194.5.250.250,194.55.12.148,194.55.13.207,194.55.13.49] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 303"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522302; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.55.13.50,194.55.14.114,194.55.15.238,194.58.103.178,194.58.46.192,194.58.66.39,194.59.158.92,194.59.204.74,194.59.207.119,194.62.187.100] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 304"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522303; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [194.87.252.100,194.87.252.214,194.87.31.104,194.88.105.13,194.88.105.30,195.117.36.125,195.122.183.170,195.122.183.171,195.122.183.2,195.123.212.113] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 305"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522304; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.123.228.129,195.123.247.209,195.128.102.227,195.128.102.56,195.133.20.195,195.15.242.113,195.15.242.29,195.15.242.99,195.154.104.174,195.189.226.74] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 306"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522305; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.201.103.59,195.201.137.233,195.201.147.230,195.201.174.108,195.201.226.88,195.201.23.1,195.201.241.87,195.201.34.213,195.201.59.21,195.201.7.164] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 307"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522306; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.20.19.171,195.20.19.180,195.20.19.183,195.201.9.37,195.201.94.113,195.201.95.26,195.20.230.215,195.205.30.250,195.211.99.37,195.22.116.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 308"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522307; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.230.168.83,195.230.23.185,195.230.23.248,195.231.39.28,195.245.203.32,195.246.230.153,195.246.231.14,195.251.211.90,195.34.103.142,195.34.169.11] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 309"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522308; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.34.169.13,195.50.212.15,195.52.156.56,195.52.52.221,195.58.48.183,195.58.58.72,195.88.75.18,195.90.215.10,195.90.215.149,195.90.217.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 310"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522309; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [195.90.223.154,196.200.160.95,198.100.153.18,198.100.153.7,198.12.124.71,198.12.127.201,198.12.71.224,198.12.97.252,198.140.141.51,198.140.141.52] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 311"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522310; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.167.206.130,198.180.150.9,198.199.72.198,198.199.84.111,198.199.85.240,198.199.92.217,198.20.161.82,198.211.103.103,198.211.105.236,198.211.125.179] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 312"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522311; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.23.133.146,198.23.136.206,198.23.211.171,198.23.246.136,198.24.164.98,198.24.168.226,198.244.188.169,198.244.212.57,198.244.229.228,198.244.233.55] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 313"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522312; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.245.53.132,198.245.55.220,198.251.67.184,198.251.76.239,198.251.84.163,198.251.84.237,198.251.88.18,198.251.89.96,198.27.80.188,198.46.189.144] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 314"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522313; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.46.234.171,198.50.191.95,198.50.223.16,198.54.129.52,198.55.102.208,198.71.53.137,198.72.127.222,198.74.58.16,198.84.184.76,198.89.125.121] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 315"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522314; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [198.96.155.9,198.98.49.200,198.98.50.117,198.98.52.83,198.98.57.25,198.98.57.55,198.98.59.102,198.98.60.59,198.98.62.56,199.170.132.80] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 316"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522315; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [199.184.215.11,199.184.246.250,199.188.100.165,199.193.115.2,199.195.248.103,199.233.217.13,199.241.137.60,199.247.31.1,199.58.81.140,200.120.58.166] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 317"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522316; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [200.122.181.78,200.193.171.186,202.169.99.195,20.224.145.181,202.55.71.41,202.59.9.238,202.61.192.215,202.61.193.116,202.61.197.87,202.61.204.198] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 318"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522317; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [202.61.204.53,202.61.205.33,202.61.224.170,202.61.224.179,202.61.236.157,202.61.253.243,202.71.14.100,202.78.160.129,203.12.12.233,203.122.194.115] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 319"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522318; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [203.153.64.151,203.161.61.235,203.217.110.41,203.31.40.236,203.57.114.94,203.86.195.200,204.10.18.131,204.13.164.118,204.137.14.69,204.197.163.133] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 320"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522319; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [204.216.213.200,204.228.156.33,204.44.101.153,204.8.99.166,205.185.113.66,205.185.119.222,205.185.124.164,205.185.125.213,205.185.125.239,205.185.126.225] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 321"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522320; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [205.235.2.2,206.116.52.57,206.189.6.56,206.191.180.116,206.198.210.210,206.217.136.47,206.217.139.100,206.248.146.19,206.251.40.165,206.71.158.27] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 322"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522321; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [206.71.158.48,206.71.158.53,206.71.158.54,206.81.25.191,207.121.63.204,207.153.6.185,207.180.192.66,207.180.216.146,207.180.230.109,207.180.234.231] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 323"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522322; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [207.216.143.114,207.229.65.155,207.231.108.225,207.244.78.230,207.246.62.87,207.34.248.20,207.55.68.171,207.90.194.2,208.109.189.114,208.109.214.243] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 324"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522323; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [208.109.215.188,208.113.128.210,208.113.128.254,208.113.133.68,208.113.200.33,208.113.200.37,208.115.216.54,208.38.228.104,208.38.243.113,208.72.154.158] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 325"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522324; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [208.72.67.118,208.81.129.145,209.114.126.200,209.114.126.201,209.114.126.202,209.114.126.205,209.114.126.206,209.114.126.208,209.114.126.209,209.126.103.140] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 326"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522325; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [209.126.11.213,209.126.3.218,209.127.116.162,209.133.193.6,209.133.196.18,209.133.196.22,209.133.206.38,209.135.170.175,209.141.34.152,209.141.36.145] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 327"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522326; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [209.141.36.7,209.141.48.235,209.141.50.94,209.141.52.110,209.141.54.168,209.148.46.45,209.205.160.229,209.209.10.207,209.209.10.208,209.232.33.22] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 328"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522327; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [209.250.2.254,209.35.33.208,209.35.43.223,209.38.145.86,209.44.114.178,209.58.145.210,209.58.180.236,209.58.180.90,209.59.168.216,209.94.56.96] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 329"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522328; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [2.100.86.77,210.1.203.192,210.139.72.174,210.56.228.46,211.213.64.92,211.49.151.149,212.100.46.201,212.104.214.71,212.129.4.84,212.132.101.102] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 330"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522329; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.132.108.13,212.132.109.56,212.132.119.221,212.132.124.123,212.132.78.65,212.132.97.190,212.132.97.196,212.144.96.29,212.154.101.173,212.159.177.198] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 331"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522330; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.159.69.155,212.162.9.158,212.193.3.59,212.21.66.25,212.227.127.105,212.227.135.112,212.227.135.114,212.227.135.115,212.227.161.35,212.227.165.251] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 332"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522331; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.227.169.190,212.227.170.28,212.227.171.107,212.227.197.40,212.227.224.10,212.227.224.217,212.227.224.245,212.227.228.245,212.227.230.211,212.227.242.115] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 333"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522332; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.227.250.185,212.227.49.169,212.227.58.120,212.227.64.208,212.227.65.236,212.227.65.42,212.227.74.176,212.227.76.91,212.227.83.168,212.227.85.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 334"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522333; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.227.90.228,212.232.23.179,212.232.23.207,212.237.217.108,212.24.100.138,212.47.229.2,212.47.233.86,212.51.149.67,212.51.151.254,212.51.153.12] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 335"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522334; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.51.155.254,212.53.249.167,212.56.48.145,212.73.134.201,212.73.134.242,212.79.125.15,212.79.125.20,212.79.125.21,212.79.125.23,212.79.125.24] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 336"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522335; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [212.83.171.89,212.8.38.115,212.89.225.242,212.95.42.71,213.100.212.161,213.108.108.85,213.109.162.197,213.113.3.203,213.128.141.195,213.135.244.242] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 337"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522336; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [213.136.72.3,213.136.79.16,213.138.109.144,213.139.243.22,213.144.135.21,213.144.135.22,213.144.142.24,213.144.142.26,213.144.67.55,213.145.199.32] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 338"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522337; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [213.152.162.181,213.152.187.205,213.159.76.33,213.162.143.166,213.162.143.90,213.163.196.82,213.163.70.234,213.164.193.245,213.164.218.84,213.165.81.97] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 339"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522338; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [213.165.83.14,213.165.90.169,213.165.93.165,213.165.93.177,213.166.184.113,213.168.190.69,213.169.148.151,213.171.214.222,213.183.48.165,213.183.48.84] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 340"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522339; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [213.183.53.249,213.183.57.47,213.183.63.36,213.183.63.46,213.202.223.75,213.206.184.75,213.210.39.133,213.211.143.94,213.21.241.8,213.219.188.68] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 341"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522340; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [213.239.213.190,213.239.213.220,213.239.215.221,213.245.111.89,213.252.245.153,213.252.245.202,213.255.218.86,213.32.104.213,213.64.109.169,213.64.18.165] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 342"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522341; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [216.122.166.19,216.126.227.83,216.144.233.143,216.197.207.48,216.205.161.171,216.218.219.41,216.227.168.204,216.238.72.199,216.238.87.134,216.238.94.126] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 343"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522342; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [216.239.90.19,216.250.97.167,216.26.97.15,216.73.159.106,216.9.225.156,216.9.227.166,217.100.189.28,217.100.189.29,217.103.30.38,217.116.95.26] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 344"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522343; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.12.202.85,217.12.203.242,217.12.206.128,217.12.221.110,217.12.221.75,217.154.125.15,217.154.125.16,217.154.16.112,217.154.194.208,217.154.198.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 345"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522344; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.154.206.245,217.154.207.61,217.154.210.192,217.154.210.223,217.154.211.3,217.154.2.162,217.154.227.126,217.154.227.216,217.154.51.180,217.154.58.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 346"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522345; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.154.58.238,217.154.59.107,217.154.62.51,217.154.63.133,217.154.64.93,217.154.74.227,217.154.77.154,217.154.79.71,217.154.85.211,217.155.3.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 347"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522346; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.155.40.118,217.155.56.141,217.156.65.4,217.156.67.109,217.156.67.146,217.156.67.156,217.156.67.252,217.156.67.65,217.160.114.102,217.160.114.209] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 348"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522347; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.160.114.94,217.160.126.155,217.160.17.134,217.160.192.232,217.160.194.125,217.160.210.159,217.160.216.38,217.160.22.207,217.160.226.12,217.160.24.47] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 349"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522348; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.160.247.34,217.160.249.50,217.160.250.166,217.160.251.63,217.160.252.208,217.160.255.113,217.160.49.126,217.160.76.78,217.160.79.224,217.160.98.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 350"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522349; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.163.129.42,217.180.225.55,217.182.73.157,217.182.75.0,217.182.79.225,217.195.151.90,217.196.147.77,217.197.162.19,217.199.199.250,217.229.102.214] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 351"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522350; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.23.8.2,217.255.66.23,217.28.130.73,217.28.130.96,217.60.39.94,217.70.189.222,217.76.159.216,217.79.181.76,217.79.181.90,217.79.252.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 352"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522351; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [217.84.235.90,217.95.78.201,218.144.130.245,218.145.93.184,218.236.76.26,220.132.189.102,220.233.73.236,2.204.164.103,2.204.217.100,2.206.255.73] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 353"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522352; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [220.94.240.197,221.113.50.91,223.204.80.7,2.245.132.154,23.105.163.117,23.105.172.1,23.105.174.243,23.106.120.42,23.108.55.71,23.111.143.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 354"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522353; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.111.179.34,23.111.179.98,23.111.189.202,23.126.9.217,23.128.248.132,23.133.88.244,23.134.136.5,23.137.248.69,23.137.249.253,23.137.253.76] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 355"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522354; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.137.253.77,23.137.254.218,23.137.254.235,23.141.40.7,23.151.232.27,23.155.72.138,23.162.200.128,23.163.216.135,23.165.24.4,23.166.40.111] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 356"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522355; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.166.40.143,23.168.24.210,23.171.9.75,23.17.69.81,23.184.48.113,23.184.48.48,23.184.48.69,23.186.168.33,23.188.56.140,23.188.56.141] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 357"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522356; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.188.56.142,23.188.56.143,23.188.56.144,23.188.56.145,23.188.56.146,23.188.56.147,23.188.56.148,23.188.56.149,23.188.56.150,23.188.56.151] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 358"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522357; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.188.56.152,23.188.56.153,23.188.56.154,23.188.56.155,23.188.56.156,23.188.56.157,23.188.56.158,23.188.56.159,23.188.56.160,23.188.56.161] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 359"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522358; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.188.56.162,23.188.56.163,23.188.56.164,23.188.56.165,23.188.56.166,23.188.56.167,23.188.56.168,23.188.56.169,23.190.168.243,23.191.200.2] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 360"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522359; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.191.200.27,23.191.200.28,23.191.200.29,23.191.200.3,23.191.200.30,23.191.200.31,23.191.200.4,23.191.200.5,23.191.200.6,23.227.186.186] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 361"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522360; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.227.186.194,23.236.143.34,23.29.119.122,23.29.124.34,23.81.44.113,23.82.136.14,23.82.136.232,23.82.137.99,23.83.135.203,23.83.135.225] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 362"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522361; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.83.91.155,23.88.110.231,23.88.154.69,23.88.44.26,23.92.19.230,23.92.34.106,23.92.34.107,23.92.34.108,23.92.34.109,23.92.34.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 363"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522362; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.92.34.111,23.92.34.112,23.92.34.113,23.92.34.115,23.92.34.116,23.92.34.118,23.92.34.120,23.92.34.122,23.92.34.41,23.92.34.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 364"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522363; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.92.36.131,23.94.214.156,23.94.2.177,23.94.220.202,23.94.78.252,23.94.83.56,23.94.83.6,23.95.122.119,23.95.221.137,23.95.240.61] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 365"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522364; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [23.95.34.135,23.95.47.185,24.125.17.222,24.128.81.156,24.134.30.65,24.150.94.49,24.152.185.226,24.166.98.66,24.191.62.109,24.196.214.71] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 366"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522365; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [24.21.129.68,24.212.137.85,24.217.229.36,24.247.96.176,24.253.112.148,24.64.90.236,24.80.191.129,24.99.80.199,2.56.10.29,2.56.164.157] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 367"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522366; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [2.56.164.75,2.56.172.108,2.56.172.82,2.56.176.89,2.56.98.121,2.56.98.134,2.57.241.119,2.57.241.40,2.58.203.60,2.58.21.105] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 368"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522367; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [2.58.52.163,2.58.56.15,2.58.56.92,2.59.254.198,2.65.155.42,2.67.227.5,27.123.244.8,27.50.73.210,31.111.98.79,31.11.200.104] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 369"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522368; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [31.13.195.169,31.13.195.248,31.14.238.36,31.14.252.98,31.164.110.176,31.170.22.199,31.171.154.162,31.171.154.165,31.171.154.173,31.172.47.28] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 370"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522369; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [31.178.106.239,31.18.121.69,31.19.97.55,31.201.233.157,31.207.89.76,31.208.22.63,31.21.219.92,31.220.44.105,31.24.227.39,31.25.235.170] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 371"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522370; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [31.41.250.101,31.41.33.53,31.42.177.60,31.42.186.165,31.57.224.200,31.57.56.241,31.59.129.146,31.6.1.23,3.17.205.125,31.97.98.168] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 372"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522371; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [31.97.99.5,32.219.209.185,32.223.248.27,3.38.87.87,34.116.147.74,36.14.5.168,36.225.58.58,36.236.172.90,37.114.33.10,37.114.33.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 373"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522372; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.114.33.3,37.114.33.33,37.114.42.239,37.114.50.133,37.114.53.197,37.114.53.201,37.114.53.36,37.114.53.44,37.114.53.74,37.114.53.9] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 374"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522373; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.114.57.163,37.114.57.182,37.120.144.222,37.120.162.222,37.120.165.175,37.120.168.158,37.120.171.188,37.120.171.208,37.120.171.230,37.120.171.64] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 375"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522374; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.120.174.249,37.120.177.177,37.120.178.238,37.120.179.106,37.120.183.47,37.120.184.36,37.120.185.216,37.120.186.122,37.120.186.229,37.120.187.104] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 376"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522375; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.120.190.6,37.120.194.126,37.120.238.185,37.120.26.229,37.120.28.136,37.1.204.243,37.122.137.148,37.123.183.214,37.14.115.213,37.143.61.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 377"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522376; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.157.197.143,37.187.103.54,37.187.122.8,37.187.149.125,37.187.76.170,37.201.28.133,37.205.8.191,37.205.9.131,37.218.242.26,37.218.245.79] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 378"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522377; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.221.192.121,37.221.193.44,37.221.195.103,37.221.195.19,37.221.195.23,37.221.196.71,37.221.208.133,37.221.208.216,37.221.212.147,37.221.212.150] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 379"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522378; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.221.215.66,37.228.129.163,37.228.129.164,37.228.129.186,37.228.129.193,37.228.129.29,37.228.129.53,37.230.128.47,37.235.48.29,37.24.165.91] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 380"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522379; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.252.187.14,37.252.189.17,37.252.190.176,37.252.191.4,37.252.191.41,37.26.77.58,37.27.122.120,37.27.122.124,37.27.18.214,37.27.187.176] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 381"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522380; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.27.212.21,37.27.2.141,37.27.221.199,37.27.25.133,37.27.255.139,37.27.25.7,37.27.3.199,37.27.41.170,37.27.42.112,37.27.47.98] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 382"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522381; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.27.57.15,37.27.63.175,37.27.70.253,37.27.8.223,37.27.83.112,37.46.208.144,37.46.211.102,37.46.211.122,37.48.120.196,37.48.120.47] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 383"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522382; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [37.48.90.84,37.49.120.204,37.59.107.97,37.59.108.68,37.59.29.77,37.63.101.165,37.63.115.200,37.63.82.23,37.77.56.246,38.102.127.252] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 384"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522383; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [38.102.127.253,38.102.84.190,38.102.84.204,38.102.84.24,38.134.43.225,38.15.64.97,38.175.134.90,38.242.203.107,38.242.218.37,38.242.254.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 385"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522384; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [38.244.132.241,38.43.93.33,38.58.179.138,38.68.135.5,38.84.216.158,38.89.70.34,38.92.167.14,38.96.254.230,40.160.7.222,43.160.202.4] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 386"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522385; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [43.224.181.168,43.228.174.250,43.251.160.81,45.10.100.49,45.10.102.37,45.11.248.196,45.118.133.44,45.12.138.199,45.12.200.208,45.124.53.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 387"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522386; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.124.54.183,45.125.166.58,45.125.65.112,45.125.65.45,45.127.32.203,45.128.133.206,45.129.0.166,45.129.182.225,45.129.185.105,45.13.104.185] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 388"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522387; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.131.138.227,45.133.216.29,45.134.226.157,45.134.39.27,45.134.48.14,45.134.91.219,45.134.91.51,45.135.163.24,45.135.163.40,45.136.28.24] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 389"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522388; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.136.29.138,45.136.29.221,45.137.100.160,45.137.99.147,45.138.16.107,45.139.163.63,45.140.164.182,45.140.164.238,45.140.164.67,45.140.164.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 390"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522389; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.140.165.138,45.140.42.123,45.141.110.68,45.141.153.214,45.141.156.10,45.141.157.50,45.141.215.218,45.141.57.69,45.142.100.30,45.142.104.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 391"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522390; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.142.145.222,45.142.176.32,45.142.177.89,45.142.232.203,45.14.233.151,45.14.233.190,45.14.233.193,45.14.233.204,45.14.233.205,45.14.233.209] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 392"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522391; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.14.233.210,45.14.233.213,45.14.233.246,45.14.233.247,45.14.233.248,45.14.233.249,45.14.233.250,45.14.233.251,45.14.233.252,45.143.200.240] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 393"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522392; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.143.200.54,45.144.209.18,45.145.164.86,45.145.40.181,45.148.121.112,45.148.122.114,45.153.125.40,45.154.28.70,45.155.170.60,45.155.249.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 394"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522393; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.155.53.68,45.157.234.132,45.157.234.148,45.157.234.84,45.166.215.0,45.21.116.144,45.22.57.60,45.249.101.87,45.32.156.131,45.32.156.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 395"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522394; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.32.189.215,45.32.4.66,45.33.114.120,45.33.124.98,45.33.198.147,45.33.198.201,45.33.37.128,45.33.55.238,45.33.57.83,45.33.85.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 396"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522395; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.38.143.222,45.38.20.153,45.41.204.203,45.41.206.176,45.45.216.57,45.45.217.232,45.52.181.235,45.56.107.49,45.59.123.4,45.59.236.90] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 397"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522396; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.61.185.194,45.61.187.139,45.63.15.42,45.66.35.11,45.66.43.220,45.66.43.3,45.67.219.13,45.73.2.211,45.76.48.130,45.76.86.86] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 398"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522397; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.77.112.107,45.77.136.58,45.77.218.103,45.79.108.130,45.79.159.52,45.79.181.228,45.79.76.174,45.79.82.20,45.80.158.103,45.80.168.22] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 399"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522398; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.80.171.18,45.80.171.211,45.80.171.95,45.80.210.20,45.81.35.185,45.82.102.233,45.82.102.234,45.82.122.254,45.82.64.163,45.83.105.223] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 400"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522399; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.83.106.19,45.83.141.65,45.83.20.200,45.83.21.22,45.83.21.241,45.84.107.142,45.84.107.236,45.84.107.44,45.84.107.84,45.85.88.117] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 401"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522400; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.86.125.102,45.86.153.182,45.86.228.153,45.86.86.150,45.86.86.231,45.88.104.74,45.89.107.18,45.89.127.221,45.89.54.11,45.90.13.247] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 402"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522401; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.90.135.141,45.90.187.25,45.90.217.212,45.90.4.235,45.91.101.227,45.9.156.16,45.9.156.32,45.9.168.16,45.91.92.179,45.92.11.136] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 403"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522402; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.92.1.136,45.92.238.246,45.92.33.62,45.92.33.74,45.92.70.126,45.94.31.91,45.94.31.92,45.95.169.164,45.95.169.171,45.95.169.252] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 404"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522403; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [45.95.169.37,45.95.169.40,45.95.169.41,45.95.169.43,45.95.233.53,45.9.60.140,46.101.165.197,46.101.178.190,46.101.79.37,46.105.91.78] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 405"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522404; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.128.27.5,46.142.51.79,46.142.5.215,46.149.125.9,46.165.220.229,46.165.221.207,46.165.242.86,46.165.252.48,46.165.254.40,46.166.187.77] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 406"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522405; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.167.244.237,46.167.244.238,46.167.244.239,46.170.113.46,46.17.40.249,46.17.42.60,46.17.44.19,46.17.96.130,46.18.104.28,46.20.35.112] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 407"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522406; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.22.165.111,46.223.44.85,46.22.4.239,46.226.105.136,46.226.105.163,46.226.106.182,46.226.109.31,46.226.111.65,46.228.199.128,46.228.205.226] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 408"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522407; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.229.55.118,46.229.8.87,46.23.108.166,46.23.108.191,46.23.108.195,46.23.108.248,46.231.240.77,46.231.93.216,46.232.250.163,46.232.250.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 409"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522408; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.232.250.51,46.232.251.183,46.23.72.81,46.23.92.80,46.244.234.227,46.246.126.62,46.246.44.53,46.253.4.208,46.253.4.39,46.28.109.231] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 410"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522409; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.28.109.233,46.29.166.59,46.29.235.106,46.29.235.71,46.29.235.79,46.38.236.250,46.38.237.221,46.38.237.49,46.38.242.6,46.38.250.227] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 411"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522410; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.38.253.161,46.38.254.168,46.4.103.29,46.4.247.63,46.4.32.184,46.4.34.242,46.4.57.75,46.4.66.178,46.4.66.188,46.4.72.214] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 412"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522411; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [46.4.74.237,46.4.78.3,46.4.96.24,46.8.227.169,47.152.202.104,47.155.119.24,47.156.98.56,47.158.240.178,47.188.6.203,47.195.124.96] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 413"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522412; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [47.195.232.156,47.199.42.137,47.201.171.205,47.32.66.234,49.12.224.203,49.12.230.234,49.12.231.230,49.12.5.31,49.12.57.133,49.12.93.240] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 414"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522413; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [49.13.10.149,49.13.133.38,49.13.140.59,49.13.174.202,49.13.209.64,49.13.28.37,49.13.4.123,49.13.76.37,49.13.95.189,49.150.254.226] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 415"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522414; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [50.116.51.101,50.118.225.16,50.118.225.160,50.118.225.161,50.118.225.177,50.118.225.183,50.120.70.235,50.21.71.22,50.230.231.84,50.28.86.149] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 416"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522415; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [50.34.76.139,50.35.44.194,50.35.72.137,50.47.113.223,50.51.61.160,50.5.37.231,50.53.75.227,50.54.204.51,50.65.178.92,50.7.124.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 417"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522416; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.15.116.168,51.15.185.201,51.15.206.7,51.15.232.19,51.15.242.244,51.15.243.22,51.15.246.170,51.15.37.100,51.15.40.38,51.15.54.117] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 418"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522417; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.15.6.176,51.15.76.56,51.158.146.152,51.158.204.114,51.158.204.156,51.15.89.200,51.159.15.176,51.159.181.146,51.159.186.85,51.159.195.41] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 419"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522418; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.159.211.57,51.159.34.131,51.15.95.231,51.159.59.187,51.15.96.2,51.178.131.200,51.178.136.58,51.195.121.102,51.195.148.39,51.195.152.241] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 420"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522419; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.195.201.37,51.195.41.230,51.195.43.58,51.210.148.166,51.210.179.144,51.210.181.252,51.222.13.223,51.222.140.58,51.222.158.255,51.222.207.61] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 421"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522420; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.254.96.208,51.255.170.195,5.132.159.238,5.134.118.41,5.135.156.12,5.135.199.11,5.135.68.65,5.135.83.4,51.38.110.234,51.38.112.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 422"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522421; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.38.124.249,51.38.133.93,51.38.54.48,51.38.65.160,5.146.181.13,5.15.1.56,5.15.3.77,5.1.56.52,5.161.58.27,5.161.60.61] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 423"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522422; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.68.136.44,51.68.152.89,51.68.155.201,51.68.181.54,51.68.185.82,51.68.197.220,51.68.220.65,51.68.231.5,51.68.44.24,51.75.129.204] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 424"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522423; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.75.141.185,51.75.153.22,51.75.171.136,51.75.171.78,51.75.17.236,51.75.18.118,51.75.206.12,51.75.21.187,51.75.26.184,51.75.30.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 425"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522424; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.75.32.31,51.75.70.246,51.75.71.108,51.77.132.82,51.77.210.24,51.77.67.232,51.77.71.247,51.77.90.246,5.178.67.56,51.79.221.8] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 426"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522425; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.79.244.79,51.79.248.11,51.79.50.138,51.79.67.109,5.181.1.221,5.181.134.99,51.81.155.228,51.81.155.229,5.181.156.173,5.181.158.232] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 427"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522426; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.181.158.49,5.181.159.30,5.181.1.83,51.81.201.207,51.81.208.217,51.81.209.101,51.81.209.115,51.81.209.86,51.81.210.232,5.181.2.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 428"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522427; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.81.245.149,51.81.44.31,5.181.51.51,5.181.51.52,5.181.51.6,51.81.56.136,51.81.56.228,51.81.56.229,51.81.56.74,51.81.56.91] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 429"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522428; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.81.57.7,5.181.77.8,5.181.80.101,5.181.80.131,5.181.80.169,5.181.80.181,5.181.80.63,51.81.82.169,51.81.93.108,51.81.93.109] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 430"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522429; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.81.93.37,51.81.93.39,5.182.48.171,5.182.48.172,5.182.48.173,5.182.48.174,5.182.48.175,5.182.48.176,5.182.48.177,5.182.48.178] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 431"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522430; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.182.48.179,5.182.48.180,5.182.48.181,5.182.48.182,5.182.48.183,5.182.48.184,5.182.48.185,5.182.48.186,5.182.48.187,5.182.48.188] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 432"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522431; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.182.48.189,5.182.48.190,51.83.131.171,51.83.132.103,51.83.143.188,5.183.179.247,5.183.179.248,51.83.180.208,51.83.186.85,51.83.237.59] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 433"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522432; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.83.4.81,51.89.106.29,5.189.132.248,5.189.151.142,51.89.17.143,5.189.176.236,5.189.178.241,5.189.181.61,51.89.23.41,51.89.242.29] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 434"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522433; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [51.89.242.31,51.89.2.63,51.89.40.51,51.89.81.247,51.89.95.23,5.196.64.99,5.196.71.24,5.199.162.114,5.199.162.155,5.199.162.73] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 435"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522434; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.22.159.135,5.230.38.108,5.230.38.235,5.250.179.163,5.250.186.160,5.250.186.169,5.250.191.234,5.252.176.19,5.252.178.224,5.252.224.115] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 436"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522435; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.252.226.201,5.252.227.76,5.253.176.99,5.253.43.202,5.253.84.137,5.253.84.142,5.254.118.189,5.254.118.191,5.254.118.192,5.255.101.24] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 437"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522436; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.102.43,5.255.103.153,5.255.104.239,5.255.109.214,5.255.110.89,5.255.111.104,5.255.111.151,5.255.112.208,5.255.113.177,5.255.116.219] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 438"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522437; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.255.117.127,5.255.118.183,5.255.120.205,5.255.121.71,5.255.96.218,5.255.98.186,5.2.78.126,5.34.176.183,5.34.176.184,5.34.210.81] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 439"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522438; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.39.81.102,5.39.81.121,54.159.225.219,54.213.206.148,54.218.255.56,54.242.240.178,54.36.205.38,54.36.99.69,54.37.139.118,54.37.229.22] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 440"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522439; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [54.37.255.75,54.37.80.38,54.38.241.237,54.39.107.185,54.39.118.29,54.39.52.18,54.39.68.9,54.39.83.128,5.44.107.168,5.45.105.12] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 441"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522440; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.45.111.149,5.45.96.188,5.45.98.188,5.45.99.251,5.56.198.130,5.59.248.112,5.59.248.158,5.61.41.12,5.67.200.98,57.128.159.170] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 442"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522441; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [57.128.169.164,57.128.180.74,57.128.180.75,57.128.194.169,57.128.213.121,57.128.219.108,57.128.219.36,57.128.219.99,57.128.220.185,57.128.220.229] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 443"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522442; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [57.128.223.198,57.128.225.153,57.128.228.176,57.129.44.38,5.75.138.100,5.75.165.11,5.75.249.160,5.78.127.13,58.9.110.19,5.9.122.185] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 444"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522443; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [5.9.122.206,5.9.14.25,5.9.14.30,5.9.156.17,5.9.24.169,5.9.56.249,5.9.59.78,5.9.86.236,60.134.219.23,60.141.139.228] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 445"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522444; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [61.4.102.51,61.93.42.193,62.112.10.154,62.112.9.92,62.113.200.81,62.113.214.74,62.133.62.158,62.141.35.212,62.141.36.150,62.141.37.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 446"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522445; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [62.143.136.7,62.144.35.186,62.151.180.251,62.168.3.212,62.169.19.54,62.171.142.119,62.171.142.3,62.182.84.241,62.204.108.204,62.210.122.182] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 447"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522446; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [62.210.123.24,62.210.125.130,62.210.127.37,62.210.181.63,62.210.205.228,62.210.209.208,62.210.231.115,62.210.97.21,62.210.99.238,62.211.104.30] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 448"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522447; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [62.224.204.48,62.238.237.242,62.27.196.20,62.27.207.126,62.3.71.107,62.3.76.243,62.38.144.238,62.63.203.157,62.67.28.110,62.67.28.2] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 449"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522448; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [62.67.28.50,62.72.45.51,62.74.67.105,63.141.234.37,63.141.234.38,63.227.116.162,63.250.63.173,64.135.129.118,64.176.12.138,64.176.3.54] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 450"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522449; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.181.206.253,64.188.97.76,64.225.78.62,64.227.110.29,64.23.171.123,64.235.41.70,64.235.43.104,64.235.61.194,64.250.200.20,64.251.255.9] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 451"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522450; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.253.91.31,64.255.46.18,64.38.158.65,64.42.176.50,64.52.108.69,64.62.148.204,64.62.233.203,64.62.233.204,64.62.233.205,64.62.233.206] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 452"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522451; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.62.233.207,64.62.233.208,64.62.233.209,64.62.233.210,64.62.233.211,64.62.233.212,64.62.233.213,64.65.0.1,64.65.0.10,64.65.0.11] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 453"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522452; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.0.12,64.65.0.15,64.65.0.2,64.65.0.20,64.65.0.22,64.65.0.23,64.65.0.25,64.65.0.3,64.65.0.30,64.65.0.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 454"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522453; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.0.34,64.65.0.35,64.65.0.4,64.65.0.40,64.65.0.44,64.65.0.45,64.65.0.5,64.65.0.50,64.65.0.55,64.65.0.56] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 455"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522454; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.0.6,64.65.0.60,64.65.0.65,64.65.0.66,64.65.0.67,64.65.0.7,64.65.0.70,64.65.0.75,64.65.0.77,64.65.0.78] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 456"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522455; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.0.8,64.65.0.80,64.65.0.85,64.65.0.88,64.65.0.89,64.65.0.9,64.65.0.90,64.65.0.95,64.65.0.98,64.65.1.1] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 457"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522456; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.10,64.65.1.100,64.65.1.101,64.65.1.102,64.65.1.103,64.65.1.104,64.65.1.105,64.65.1.106,64.65.1.107,64.65.1.108] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 458"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522457; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.109,64.65.1.11,64.65.1.110,64.65.1.111,64.65.1.112,64.65.1.113,64.65.1.114,64.65.1.115,64.65.1.116,64.65.1.117] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 459"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522458; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.118,64.65.1.119,64.65.1.12,64.65.1.120,64.65.1.121,64.65.1.122,64.65.1.123,64.65.1.124,64.65.1.125,64.65.1.126] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 460"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522459; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.127,64.65.1.128,64.65.1.129,64.65.1.13,64.65.1.130,64.65.1.131,64.65.1.132,64.65.1.133,64.65.1.134,64.65.1.135] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 461"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522460; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.137,64.65.1.138,64.65.1.139,64.65.1.14,64.65.1.140,64.65.1.141,64.65.1.142,64.65.1.143,64.65.1.144,64.65.1.145] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 462"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522461; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.146,64.65.1.147,64.65.1.148,64.65.1.149,64.65.1.15,64.65.1.150,64.65.1.151,64.65.1.152,64.65.1.153,64.65.1.154] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 463"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522462; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.155,64.65.1.156,64.65.1.157,64.65.1.158,64.65.1.159,64.65.1.16,64.65.1.160,64.65.1.161,64.65.1.162,64.65.1.163] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 464"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522463; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.164,64.65.1.165,64.65.1.166,64.65.1.167,64.65.1.168,64.65.1.169,64.65.1.17,64.65.1.170,64.65.1.171,64.65.1.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 465"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522464; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.177,64.65.1.18,64.65.1.180,64.65.1.181,64.65.1.185,64.65.1.188,64.65.1.19,64.65.1.190,64.65.1.191,64.65.1.195] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 466"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522465; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.199,64.65.1.2,64.65.1.20,64.65.1.200,64.65.1.201,64.65.1.202,64.65.1.203,64.65.1.204,64.65.1.205,64.65.1.206] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 467"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522466; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.207,64.65.1.208,64.65.1.209,64.65.1.21,64.65.1.210,64.65.1.213,64.65.1.22,64.65.1.23,64.65.1.24,64.65.1.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 468"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522467; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.26,64.65.1.27,64.65.1.28,64.65.1.29,64.65.1.3,64.65.1.30,64.65.1.31,64.65.1.32,64.65.1.33,64.65.1.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 469"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522468; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.35,64.65.1.36,64.65.1.37,64.65.1.38,64.65.1.39,64.65.1.4,64.65.1.40,64.65.1.41,64.65.1.42,64.65.1.43] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 470"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522469; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.44,64.65.1.45,64.65.1.46,64.65.1.47,64.65.1.48,64.65.1.49,64.65.1.5,64.65.1.50,64.65.1.51,64.65.1.52] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 471"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522470; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.53,64.65.1.54,64.65.1.55,64.65.1.56,64.65.1.57,64.65.1.58,64.65.1.59,64.65.1.6,64.65.1.60,64.65.1.61] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 472"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522471; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.62,64.65.1.63,64.65.1.64,64.65.1.65,64.65.1.66,64.65.1.67,64.65.1.68,64.65.1.69,64.65.1.7,64.65.1.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 473"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522472; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.71,64.65.1.72,64.65.1.73,64.65.1.74,64.65.1.75,64.65.1.76,64.65.1.77,64.65.1.78,64.65.1.79,64.65.1.8] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 474"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522473; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.80,64.65.1.81,64.65.1.82,64.65.1.83,64.65.1.84,64.65.1.85,64.65.1.86,64.65.1.87,64.65.1.88,64.65.1.89] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 475"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522474; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.9,64.65.1.90,64.65.1.91,64.65.1.92,64.65.1.93,64.65.1.94,64.65.1.95,64.65.1.96,64.65.1.97,64.65.1.98] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 476"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522475; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.1.99,64.65.62.1,64.65.62.10,64.65.62.100,64.65.62.101,64.65.62.105,64.65.62.11,64.65.62.110,64.65.62.111,64.65.62.112] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 477"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522476; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.115,64.65.62.12,64.65.62.120,64.65.62.121,64.65.62.122,64.65.62.123,64.65.62.125,64.65.62.13,64.65.62.130,64.65.62.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 478"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522477; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.133,64.65.62.134,64.65.62.135,64.65.62.14,64.65.62.140,64.65.62.141,64.65.62.144,64.65.62.145,64.65.62.15,64.65.62.150] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 479"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522478; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.151,64.65.62.155,64.65.62.16,64.65.62.160,64.65.62.161,64.65.62.165,64.65.62.166,64.65.62.17,64.65.62.170,64.65.62.171] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 480"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522479; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.175,64.65.62.177,64.65.62.18,64.65.62.180,64.65.62.181,64.65.62.185,64.65.62.188,64.65.62.19,64.65.62.190,64.65.62.191] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 481"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522480; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.195,64.65.62.199,64.65.62.2,64.65.62.20,64.65.62.200,64.65.62.201,64.65.62.202,64.65.62.205,64.65.62.21,64.65.62.210] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 482"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522481; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.211,64.65.62.212,64.65.62.215,64.65.62.22,64.65.62.220,64.65.62.222,64.65.62.225,64.65.62.23,64.65.62.230,64.65.62.232] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 483"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522482; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.233,64.65.62.234,64.65.62.235,64.65.62.24,64.65.62.240,64.65.62.242,64.65.62.244,64.65.62.245,64.65.62.25,64.65.62.250] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 484"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522483; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.252,64.65.62.26,64.65.62.27,64.65.62.28,64.65.62.29,64.65.62.3,64.65.62.30,64.65.62.31,64.65.62.32,64.65.62.33] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 485"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522484; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.34,64.65.62.35,64.65.62.36,64.65.62.37,64.65.62.38,64.65.62.39,64.65.62.4,64.65.62.40,64.65.62.41,64.65.62.42] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 486"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522485; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.43,64.65.62.44,64.65.62.45,64.65.62.46,64.65.62.47,64.65.62.48,64.65.62.49,64.65.62.5,64.65.62.50,64.65.62.51] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 487"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522486; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.52,64.65.62.53,64.65.62.54,64.65.62.55,64.65.62.56,64.65.62.57,64.65.62.58,64.65.62.59,64.65.62.6,64.65.62.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 488"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522487; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.61,64.65.62.62,64.65.62.63,64.65.62.64,64.65.62.65,64.65.62.67,64.65.62.68,64.65.62.69,64.65.62.7,64.65.62.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 489"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522488; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.71,64.65.62.72,64.65.62.74,64.65.62.75,64.65.62.77,64.65.62.78,64.65.62.8,64.65.62.80,64.65.62.85,64.65.62.88] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 490"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522489; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.62.89,64.65.62.9,64.65.62.90,64.65.62.95,64.65.62.99,64.65.63.1,64.65.63.10,64.65.63.11,64.65.63.12,64.65.63.15] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 491"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522490; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.63.2,64.65.63.20,64.65.63.22,64.65.63.23,64.65.63.25,64.65.63.3,64.65.63.30,64.65.63.33,64.65.63.34,64.65.63.4] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 492"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522491; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.63.40,64.65.63.44,64.65.63.45,64.65.63.5,64.65.63.50,64.65.63.55,64.65.63.56,64.65.63.6,64.65.63.60,64.65.63.63] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 493"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522492; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.63.64,64.65.63.65,64.65.63.66,64.65.63.7,64.65.63.70,64.65.63.75,64.65.63.77,64.65.63.8,64.65.63.80,64.65.63.85] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 494"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522493; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [64.65.63.88,64.65.63.9,64.74.160.232,64.95.10.169,64.99.223.239,65.108.136.190,65.108.193.42,65.108.217.34,65.108.220.253,65.108.233.166] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 495"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522494; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [65.108.3.114,65.108.77.19,65.108.82.81,65.109.0.210,65.109.110.235,65.109.13.155,65.109.139.21,65.109.139.224,65.109.161.207,65.109.233.53] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 496"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522495; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [65.109.67.140,65.109.67.160,65.109.67.182,65.109.98.156,65.20.101.86,65.20.103.181,65.21.0.217,65.21.110.38,65.21.180.151,65.21.246.132] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 497"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522496; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [65.21.49.9,65.21.54.19,65.21.62.213,65.21.94.13,65.24.242.46,65.26.123.100,65.38.121.230,65.49.20.10,65.49.20.11,65.49.20.12] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 498"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522497; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [65.87.7.14,66.103.204.121,66.111.2.131,66.111.2.16,66.111.2.20,66.135.16.84,66.165.241.228,66.165.241.230,66.179.189.106,66.179.248.50] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 499"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522498; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [66.179.92.76,66.179.94.91,66.183.173.29,66.183.96.136,66.187.4.132,66.187.76.76,66.187.76.8,66.206.0.138,66.206.0.82,66.206.1.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 500"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522499; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [66.206.4.26,66.214.85.170,66.222.102.232,66.31.227.172,66.33.9.236,66.70.191.210,66.70.211.20,66.70.227.44,66.78.40.183,66.85.128.218] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 501"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522500; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [66.94.127.104,67.168.20.17,67.183.182.120,67.189.49.175,67.198.102.164,67.198.37.16,67.205.139.175,67.207.73.55,67.217.242.117,67.241.35.169] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 502"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522501; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [67.81.164.219,68.171.179.124,68.183.163.215,68.183.200.189,68.183.47.126,68.196.118.127,68.234.73.164,68.253.253.66,68.67.32.31,68.67.32.32] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 503"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522502; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [68.67.32.33,68.67.32.34,68.8.241.30,68.97.183.143,69.12.83.102,69.12.83.106,69.12.83.85,69.12.83.92,69.12.83.95,69.12.83.97] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 504"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522503; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [69.144.132.113,69.148.243.49,69.157.185.39,69.164.210.140,69.174.98.5,69.174.98.59,69.209.100.183,69.218.211.90,69.30.239.126,69.40.21.219] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 505"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522504; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [69.48.186.87,69.48.205.198,69.48.206.137,69.48.206.32,70.110.159.120,70.123.161.167,70.134.238.84,70.134.248.71,70.169.10.61,70.175.76.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 506"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522505; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [70.18.243.146,70.32.195.33,70.34.244.156,70.34.249.203,70.34.250.156,70.34.253.46,70.63.170.86,70.66.179.121,71.11.227.28,71.176.72.160] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 507"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522506; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [71.178.246.208,71.19.144.124,71.19.144.65,71.19.146.15,71.19.148.104,71.19.148.113,71.19.149.21,71.19.157.127,71.195.39.62,71.24.145.6] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 508"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522507; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [71.244.170.31,71.248.161.179,71.42.125.218,72.135.199.51,72.167.47.69,72.2.129.156,72.45.168.60,72.69.168.41,72.76.86.149,73.117.132.138] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 509"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522508; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [73.164.208.85,73.170.126.220,73.18.130.34,73.185.66.46,73.185.76.49,73.200.211.73,73.222.188.24,73.235.15.95,73.35.42.250,73.61.87.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 510"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522509; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [73.63.21.177,73.68.62.87,73.83.116.167,74.106.232.4,74.116.186.120,74.118.77.34,74.123.97.10,74.123.97.26,74.123.98.10,74.123.98.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 511"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522510; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [74.14.21.53,74.196.72.87,74.208.104.100,74.208.178.166,74.208.182.78,74.208.189.124,74.208.194.153,74.208.195.108,74.208.195.208,74.208.198.230] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 512"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522511; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [74.208.201.163,74.208.209.29,74.208.238.90,74.208.242.107,74.208.27.90,74.208.29.99,74.208.45.216,74.208.60.253,74.208.60.50,74.215.154.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 513"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522512; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [74.248.250.11,74.72.105.139,74.91.21.2,74.91.26.170,74.96.98.123,75.119.151.133,75.127.13.29,75.145.166.68,75.145.166.70,75.145.166.75] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 514"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522513; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [75.176.43.62,75.184.13.239,75.223.7.136,75.226.130.69,75.60.97.70,75.75.102.102,76.10.157.54,76.235.207.28,76.252.151.48,76.67.43.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 515"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522514; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.0.66.172,77.109.152.148,77.109.152.87,77.109.97.112,77.160.53.97,77.162.216.182,77.162.249.122,77.164.187.211,77.166.188.222,77.169.65.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 516"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522515; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.172.190.93,77.172.70.151,77.174.164.37,77.174.188.151,77.174.62.158,77.179.37.159,77.181.174.166,77.20.3.30,77.20.42.234,77.220.107.195] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 517"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522516; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.221.134.103,77.22.118.38,77.223.215.105,77.23.200.78,77.234.79.34,77.248.16.45,77.249.170.86,77.48.28.218,77.48.28.219,77.48.28.220] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 518"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522517; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.48.28.240,77.56.120.38,77.68.100.112,77.68.100.49,77.68.111.120,77.68.20.86,77.68.67.193,77.68.74.121,77.73.67.125,77.73.67.21] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 519"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522518; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.73.67.39,77.73.68.100,77.73.68.73,77.73.69.128,77.73.69.181,77.73.70.167,77.73.70.176,77.73.71.241,77.74.96.43,77.83.198.149] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 520"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522519; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.83.198.213,77.8.41.199,77.85.159.177,77.90.19.165,77.90.35.161,77.90.35.165,77.90.41.106,77.90.4.135,77.90.41.87,77.90.4.214] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 521"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522520; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [77.90.4.44,77.90.4.45,77.90.4.48,77.90.4.53,77.90.52.145,78.128.71.39,78.129.240.111,78.129.240.94,78.138.98.42,78.141.211.44] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 522"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522521; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [78.142.18.97,78.153.140.44,78.153.149.48,78.159.117.165,78.159.131.12,78.159.131.131,78.159.131.205,78.159.131.25,78.159.131.28,78.159.131.35] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 523"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522522; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [78.159.131.65,78.159.131.66,78.159.131.8,78.194.158.30,78.31.64.196,78.31.67.127,78.31.67.22,78.43.117.254,78.44.115.254,78.46.123.26] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 524"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522523; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [78.46.162.123,78.46.177.87,78.46.193.215,78.46.209.112,78.46.92.172,78.47.14.99,78.47.161.178,78.47.169.189,78.47.189.21,78.48.213.183] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 525"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522524; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [78.67.129.67,78.80.36.112,78.82.71.141,79.100.137.1,79.107.239.217,79.110.193.183,79.116.206.222,79.116.3.255,79.116.34.139,79.117.113.156] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 526"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522525; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [79.118.200.174,79.119.31.145,79.124.7.11,79.141.165.172,79.141.174.124,79.141.175.229,79.143.177.192,79.144.89.109,79.189.125.171,79.192.209.254] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 527"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522526; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [79.194.249.110,79.195.150.218,79.197.226.145,79.197.54.97,79.199.247.185,79.201.236.130,79.207.157.202,79.213.28.172,79.221.139.77,79.224.38.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 528"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522527; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [79.225.81.183,79.226.155.126,79.230.142.242,79.24.183.199,79.250.224.244,79.250.230.2,79.254.168.40,79.44.220.54,79.72.18.226,79.99.41.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 529"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522528; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.108.222.55,80.109.197.24,80.112.11.27,80.115.102.248,80.129.31.46,80.131.127.48,80.142.176.178,80.144.212.232,80.151.220.220,80.200.4.100] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 530"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522529; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.208.58.219,80.220.186.79,80.221.244.201,80.239.189.76,80.239.189.77,80.239.189.84,80.240.23.106,80.241.220.57,80.43.193.140,80.64.181.152] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 531"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522530; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.66.135.123,80.67.167.86,80.67.176.224,80.76.42.204,80.78.22.189,80.78.23.143,80.78.23.160,80.78.26.130,80.78.31.42,80.79.117.42] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 532"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522531; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [80.82.76.55,80.85.141.186,80.92.204.251,80.97.49.67,81.109.85.125,81.137.179.68,81.152.57.205,81.162.55.28,81.164.127.253,81.164.204.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 533"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522532; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [81.166.246.31,81.166.83.239,81.168.83.101,81.168.83.4,81.169.134.23,81.169.159.28,81.169.186.16,81.169.190.34,81.169.222.158,81.169.240.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 534"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522533; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [81.17.16.58,81.171.6.89,81.17.28.117,81.174.250.136,81.181.245.37,81.187.192.71,81.191.175.59,81.201.202.101,81.20.143.138,81.217.82.246] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 535"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522534; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [81.2.191.34,81.229.149.244,81.230.199.84,81.240.34.228,81.241.188.39,81.4.100.5,81.44.114.254,8.15.185.52,81.56.149.204,81.56.71.129] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 536"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522535; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [81.7.10.193,81.7.18.7,81.7.19.110,81.88.25.230,81.9.147.244,81.98.64.85,82.0.79.230,82.118.21.80,82.130.24.101,82.135.66.49] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 537"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522536; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.139.252.18,82.141.122.156,82.144.36.201,82.149.227.123,82.149.227.124,82.149.227.125,82.149.227.126,82.149.227.236,82.15.181.73,82.153.138.103] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 538"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522537; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.15.56.108,82.165.101.234,82.165.116.173,82.165.132.223,82.165.133.66,82.165.14.201,82.165.142.108,82.165.14.89,82.165.171.134,82.165.177.112] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 539"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522538; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.165.180.96,82.165.196.165,82.165.201.185,82.165.20.161,82.165.206.196,82.165.21.136,82.165.230.191,82.165.239.31,82.165.63.209,82.165.70.65] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 540"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522539; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.165.77.33,82.165.96.172,82.168.32.82,82.168.62.152,82.172.182.1,82.180.160.146,82.196.11.10,82.197.160.67,82.197.68.93,82.198.225.82] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 541"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522540; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.207.214.8,82.213.196.64,82.220.38.150,82.220.91.188,82.221.141.27,82.223.103.104,82.223.39.79,82.223.70.114,82.25.91.245,82.26.113.21] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 542"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522541; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.26.113.6,82.30.0.224,82.36.133.46,82.50.114.250,82.50.7.69,82.55.146.54,82.6.215.191,82.64.135.138,82.64.136.240,82.64.14.137] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 543"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522542; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.64.145.26,82.64.150.101,82.64.20.171,82.64.238.84,82.64.46.143,82.64.75.232,82.65.138.47,82.65.165.202,82.65.3.49,82.66.10.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 544"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522543; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [82.66.197.211,82.66.61.19,82.66.88.54,82.67.103.92,82.67.50.156,82.68.35.15,82.9.104.6,83.0.60.229,83.108.79.37,83.114.38.235] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 545"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522544; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [83.135.4.250,83.136.107.114,83.136.107.38,83.147.3.217,83.148.245.77,83.149.125.241,83.149.70.129,83.159.242.236,83.164.133.45,83.167.224.198] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 546"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522545; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [83.168.108.31,83.168.69.84,83.170.6.70,83.212.100.100,83.212.117.37,83.212.72.189,83.212.81.32,83.212.96.97,83.212.99.108,83.217.208.30] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 547"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522546; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [83.219.162.228,83.236.208.78,83.238.169.159,83.250.35.194,83.251.140.27,83.255.156.57,83.255.58.158,83.28.154.110,83.28.155.134,83.31.31.143] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 548"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522547; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [83.32.146.10,83.43.100.26,83.7.186.212,83.77.30.95,83.9.193.36,83.96.252.102,83.99.35.45,84.115.128.225,84.119.210.212,84.130.251.34] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 549"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522548; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.137.0.163,84.137.11.167,84.144.48.33,84.144.57.71,84.148.164.173,84.153.129.33,84.1.54.242,84.158.12.171,84.159.110.234,84.16.234.150] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 550"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522549; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.165.63.219,84.169.168.215,84.170.128.94,84.172.126.199,84.184.231.252,84.184.31.16,84.187.126.194,84.191.134.109,84.19.176.161,84.196.14.175] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 551"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522550; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.19.65.49,84.198.118.68,84.213.190.214,84.226.186.33,84.227.40.35,84.234.16.18,84.234.19.76,84.238.10.142,84.238.87.214,84.240.60.234] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 552"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522551; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.247.180.248,84.249.202.58,84.251.40.27,84.252.120.131,84.252.120.63,84.252.122.96,84.252.123.112,84.253.252.170,84.254.80.119,84.254.84.202] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 553"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522552; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [8.42.76.68,84.30.47.143,84.31.59.47,84.32.248.227,84.33.244.13,84.38.130.45,84.44.231.94,84.46.71.252,84.46.83.130,84.52.216.169] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 554"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522553; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [84.60.148.189,84.62.138.74,84.62.158.66,84.62.245.125,84.68.190.41,84.82.156.112,85.0.13.156,85.10.187.121,85.10.210.197,85.119.82.131] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 555"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522554; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.119.82.142,85.122.127.90,85.130.157.152,85.148.59.217,85.16.187.154,85.16.193.91,85.167.197.119,85.167.36.242,85.167.76.220,85.167.77.39] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 556"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522555; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.17.127.129,85.183.60.50,85.195.203.210,85.195.221.187,85.195.230.248,85.195.244.251,85.195.253.142,85.204.116.100,85.208.144.164,85.208.69.66] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 557"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522556; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.209.50.10,85.209.51.107,85.209.51.37,85.214.111.133,85.214.12.222,85.214.149.151,85.214.200.184,85.214.54.254,85.215.114.1,85.215.129.4] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 558"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522557; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.215.136.64,85.215.145.68,85.215.148.127,85.215.151.54,85.215.152.106,85.215.153.202,85.215.160.111,85.215.160.128,85.215.181.146,85.215.191.127] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 559"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522558; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.215.200.200,85.215.218.206,85.215.222.151,85.215.249.184,85.215.250.110,85.215.34.3,85.215.42.225,85.215.46.141,85.215.53.227,85.215.63.163] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 560"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522559; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.215.67.230,85.218.174.142,85.228.179.173,85.23.104.222,85.235.64.151,85.235.64.77,85.235.66.227,85.235.67.10,85.239.235.250,85.239.34.239] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 561"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522560; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.239.34.24,85.239.34.6,85.239.41.121,85.24.237.73,85.24.237.74,85.246.192.229,85.2.82.41,85.30.131.60,85.49.11.132,85.50.3.223] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 562"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522561; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [85.72.151.122,85.9.194.190,85.93.31.32,86.106.102.101,86.107.101.101,86.107.168.51,86.111.154.199,86.121.133.81,86.122.108.10,86.124.26.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 563"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522562; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [86.125.65.169,86.126.174.85,86.13.190.107,86.13.252.199,86.14.169.71,86.150.1.103,86.176.15.79,86.17.88.29,86.181.199.134,86.183.140.242] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 564"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522563; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [86.207.7.6,86.2.246.205,86.235.35.27,86.27.45.98,86.29.231.36,86.33.53.157,86.38.175.91,86.43.92.99,86.52.62.47,86.59.21.163] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 565"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522564; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [86.60.130.46,86.60.148.189,86.80.225.203,86.86.126.113,87.100.225.112,87.104.37.132,87.104.76.58,87.106.107.89,87.106.108.118,87.106.129.242] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 566"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522565; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.106.134.107,87.106.135.148,87.106.161.235,87.106.168.172,87.106.173.70,87.106.176.222,87.106.178.237,87.106.199.4,87.106.207.156,87.106.210.134] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 567"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522566; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.106.216.168,87.106.216.230,87.106.216.245,87.106.218.58,87.106.229.129,87.106.229.54,87.106.235.75,87.106.35.94,87.106.69.171,87.106.71.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 568"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522567; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.106.80.166,87.106.82.130,87.106.86.231,87.118.88.94,87.120.237.130,87.120.8.176,87.120.8.91,87.121.52.112,87.121.52.182,87.123.24.18] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 569"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522568; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.123.25.112,87.1.23.89,87.138.152.33,87.142.100.203,87.153.193.181,87.158.138.88,87.162.123.242,87.162.125.225,87.162.238.158,87.162.251.83] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 570"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522569; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.173.167.210,87.177.19.95,87.179.175.38,87.223.224.31,87.227.211.65,87.229.115.23,87.229.85.164,87.229.85.197,87.236.194.23,87.236.195.198] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 571"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522570; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.236.195.203,87.236.195.216,87.236.197.123,87.236.199.239,87.237.165.31,87.4.144.154,87.54.95.17,87.61.100.125,87.79.45.3,87.89.156.178] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 572"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522571; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [87.8.96.26,87.98.237.152,87.98.242.239,87.98.243.204,88.11.143.6,88.113.153.145,88.114.24.66,88.119.165.222,88.120.182.244,88.150.28.241] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 573"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522572; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [88.151.194.118,88.151.194.12,88.151.34.140,88.153.63.51,88.160.74.168,88.177.209.148,88.182.249.144,88.198.101.33,88.198.207.48,88.198.209.95] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 574"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522573; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [88.198.35.49,88.208.196.199,88.214.20.183,88.216.2.90,88.218.94.96,88.80.17.66,88.80.17.67,88.80.17.68,88.80.17.69,88.80.17.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 575"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522574; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [88.80.17.71,88.80.17.72,88.80.17.73,88.80.17.74,88.80.17.75,88.80.17.76,88.80.17.77,88.80.17.78,88.80.17.79,88.80.17.80] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 576"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522575; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [88.80.17.81,88.80.17.82,88.80.17.83,88.80.17.84,88.80.17.85,88.99.102.213,88.99.104.83,88.99.142.177,88.99.144.235,88.99.145.25] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 577"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522576; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [88.99.165.75,88.99.193.108,88.99.2.111,88.99.7.87,88.99.94.231,89.106.42.137,89.110.124.55,89.117.1.123,89.142.59.144,89.145.165.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 578"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522577; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.147.109.13,89.147.109.91,89.150.131.83,89.150.140.164,89.161.26.78,89.163.135.8,89.163.150.143,89.163.211.14,89.163.251.66,89.166.0.93] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 579"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522578; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.168.17.69,89.168.28.192,89.168.34.94,89.182.30.109,89.182.38.113,89.185.109.216,89.185.82.34,89.190.28.195,89.190.6.9,89.191.217.1] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 580"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522579; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.203.249.226,89.212.101.222,89.212.103.241,89.213.174.152,89.217.61.72,89.221.215.23,89.221.215.7,89.221.219.123,89.245.41.198,89.245.41.6] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 581"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522580; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.245.42.3,89.246.51.41,89.248.165.40,89.35.131.44,89.36.161.29,89.36.231.129,89.36.231.204,89.39.105.55,89.46.100.71,89.47.50.223] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 582"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522581; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.0.34,89.58.12.210,89.58.15.178,89.58.17.198,89.58.17.212,89.58.17.228,89.58.26.150,89.58.27.85,89.58.30.165,89.58.3.114] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 583"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522582; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.32.67,89.58.33.214,89.58.34.53,89.58.36.174,89.58.39.226,89.58.43.207,89.58.43.71,89.58.45.45,89.58.47.188,89.58.48.237] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 584"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522583; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.49.77,89.58.49.86,89.58.5.0,89.58.53.213,89.58.54.129,89.58.55.29,89.58.56.112,89.58.58.209,89.58.60.208,89.58.61.40] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 585"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522584; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [89.58.62.138,89.69.180.20,89.80.212.133,90.143.133.202,90.146.182.29,90.155.5.6,90.186.154.68,90.187.113.149,90.190.173.196,90.247.71.108] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 586"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522585; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [90.38.142.222,91.1.18.106,91.121.219.14,91.12.180.17,91.126.217.153,91.127.10.171,91.132.132.100,91.132.145.245,91.132.146.135,91.132.146.190] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 587"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522586; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.132.48.17,91.134.90.21,91.135.7.214,91.143.81.27,91.143.87.51,91.143.88.62,91.143.90.56,91.151.93.46,91.178.159.239,91.184.164.255] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 588"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522587; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.186.57.168,91.192.81.77,91.193.18.143,91.200.100.207,91.203.145.114,91.203.5.141,91.204.6.136,91.205.158.9,91.205.230.113,91.206.142.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 589"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522588; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.206.169.94,91.208.184.123,91.208.197.187,91.208.206.48,91.208.206.56,91.208.75.25,91.211.213.195,91.213.233.138,91.217.10.20,91.217.119.179] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 590"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522589; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.219.236.77,91.219.237.115,91.219.237.160,91.219.237.19,91.219.237.216,91.219.237.218,91.219.237.226,91.219.237.31,91.219.23.77,91.219.238.120] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 591"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522590; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.219.238.221,91.219.60.67,91.224.90.35,91.227.33.149,91.228.52.211,91.228.52.8,91.228.53.49,91.231.182.136,91.231.182.201,91.234.199.90] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 592"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522591; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.239.65.159,91.245.255.87,91.248.252.1,91.250.81.52,91.2.54.209,91.2.58.175,91.37.197.25,91.4.209.55,91.42.231.99,91.4.235.9] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 593"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522592; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.47.35.46,91.47.39.117,91.54.120.223,91.54.252.140,91.63.234.140,91.65.103.214,91.65.109.32,91.7.40.121,91.7.42.193,91.83.13.194] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 594"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522593; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [91.83.13.200,91.84.86.132,91.89.43.18,91.92.109.23,91.99.121.56,92.112.124.132,92.112.124.202,92.112.126.117,92.112.127.116,92.116.235.80] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 595"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522594; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.117.22.173,92.117.22.214,92.117.22.77,92.169.120.121,92.176.200.1,92.204.40.241,92.204.41.234,92.205.108.158,92.205.129.119,92.205.129.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 596"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522595; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.205.161.164,92.222.172.56,92.222.79.186,92.223.105.117,92.223.105.174,92.223.66.12,92.243.20.101,92.243.64.58,92.244.31.28,92.246.130.172] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 597"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522596; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.249.143.119,92.27.11.80,92.27.11.84,92.27.11.85,92.33.155.77,92.35.26.29,92.35.64.65,92.38.162.88,92.60.36.222,92.60.37.105] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 598"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522597; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [92.60.37.143,92.60.37.247,92.60.38.166,92.60.38.94,93.113.25.153,93.113.25.211,93.113.25.241,93.115.21.124,93.115.97.242,93.119.15.82] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 599"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522598; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.123.12.250,93.126.105.202,93.127.222.32,93.127.233.84,93.127.247.161,93.158.213.15,93.160.17.86,93.177.65.182,93.177.73.98,93.180.134.118] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 600"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522599; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.185.165.199,93.185.165.225,93.185.165.247,93.185.165.76,93.185.165.80,93.185.167.247,93.185.97.203,93.186.200.169,93.190.143.41,93.194.111.60] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 601"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522600; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.195.214.95,93.199.93.216,93.200.6.249,93.201.209.69,93.211.243.178,93.215.124.250,93.231.167.245,93.231.169.69,93.231.246.187,93.239.102.53] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 602"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522601; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.244.143.231,93.41.149.117,93.56.117.22,93.88.127.74,93.90.194.106,93.90.200.181,93.90.203.42,93.93.113.144,93.93.117.16,93.93.118.87] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 603"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522602; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [93.95.229.200,93.95.231.110,93.95.231.115,93.95.231.25,93.95.88.13,93.99.104.31,94.100.6.10,94.100.6.11,94.100.6.13,94.100.6.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 604"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522603; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.100.6.30,94.100.77.213,94.103.188.164,94.103.188.190,94.130.10.179,94.130.10.251,94.130.129.15,94.130.133.51,94.130.142.182,94.130.185.68] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 605"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522604; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.130.201.104,94.130.227.162,94.130.36.21,94.130.51.212,94.130.52.190,94.130.69.218,94.130.70.185,94.130.89.176,94.131.104.135,94.131.14.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 606"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522605; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.131.171.105,94.131.2.237,94.131.8.10,94.132.156.122,94.136.83.72,94.140.112.158,94.140.112.98,94.140.114.174,94.140.115.114,94.140.120.130] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 607"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522606; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.141.123.170,94.141.123.66,94.142.140.158,94.142.241.41,94.142.241.43,94.143.137.213,94.154.159.96,94.156.152.21,94.156.152.234,94.158.246.117] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 608"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522607; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.159.106.203,94.159.110.187,94.159.110.198,94.159.111.220,94.159.98.28,94.16.104.159,94.16.105.206,94.16.106.22,94.16.107.178,94.16.109.180] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 609"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522608; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.16.113.135,94.16.113.14,94.16.113.35,94.16.113.89,94.16.114.231,94.16.116.156,94.16.116.86,94.16.117.179,94.16.118.23,94.16.118.250] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 610"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522609; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.16.119.20,94.16.120.204,94.16.122.152,94.16.122.61,94.16.123.171,94.16.123.67,94.16.147.223,94.16.31.131,94.174.83.231,94.176.2.52] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 611"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522610; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.177.8.200,94.199.214.229,94.228.165.35,94.23.121.150,94.23.148.66,94.23.149.136,94.23.150.210,94.23.152.96,94.23.168.79,94.23.170.63] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 612"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522611; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.23.172.32,94.23.216.20,94.23.247.42,94.23.45.103,94.23.68.187,94.23.69.67,94.23.70.32,94.23.76.244,94.23.76.52,94.237.8.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 613"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522612; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [94.23.88.117,94.247.217.230,94.249.231.26,94.26.73.162,94.46.171.151,94.46.171.221,94.46.171.245,94.5.197.17,94.72.111.123,94.74.164.62] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 614"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522613; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.110.254.231,95.111.230.178,95.111.243.215,95.113.177.157,95.119.136.39,95.141.32.200,95.141.83.146,95.141.83.155,95.142.102.58,95.142.102.59] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 615"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522614; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.153.31.202,95.153.31.26,95.153.31.38,95.153.32.22,95.169.191.6,95.179.160.189,95.179.162.106,95.179.223.15,95.211.138.51,95.211.138.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 616"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522615; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.211.194.14,95.211.194.165,95.211.205.138,95.211.208.141,95.211.210.72,95.214.52.187,95.214.53.96,95.216.101.247,95.216.115.85,95.216.11.95] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 617"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522616; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.216.12.30,95.216.13.120,95.216.13.55,95.216.136.46,95.216.140.159,95.216.141.19,95.216.141.24,95.216.159.94,95.216.16.167,95.216.193.39] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 618"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522617; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.216.19.41,95.216.198.252,95.216.202.181,95.216.20.80,95.216.209.129,95.216.212.222,95.216.22.22,95.216.22.24,95.216.22.87,95.216.23.120] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 619"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522618; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.216.27.105,95.216.32.14,95.216.33.30,95.216.33.58,95.216.35.156,95.216.35.84,95.216.96.44,95.216.98.17,95.217.104.226,95.217.112.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 620"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522619; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.217.156.221,95.217.162.68,95.217.164.89,95.217.185.149,95.217.187.19,95.217.2.206,95.217.231.111,95.217.30.201,95.217.39.117,95.217.5.88] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 621"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522620; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.217.6.94,95.217.72.151,95.222.140.85,95.246.245.46,95.246.41.47,95.76.41.164,95.85.19.85,95.85.90.130,95.88.154.27,95.89.13.221] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 622"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522621; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [95.98.150.94,95.98.233.95,96.126.105.219,96.126.98.146,96.20.102.87,96.227.94.92,96.239.102.27,96.244.38.131,96.250.84.167,96.255.94.70] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 623"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522622; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.54.192.183,96.65.68.193,96.9.211.89,96.9.98.1,96.9.98.10,96.9.98.100,96.9.98.101,96.9.98.105,96.9.98.11,96.9.98.110] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 624"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522623; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.111,96.9.98.112,96.9.98.115,96.9.98.12,96.9.98.120,96.9.98.121,96.9.98.122,96.9.98.123,96.9.98.125,96.9.98.13] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 625"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522624; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.130,96.9.98.131,96.9.98.133,96.9.98.134,96.9.98.135,96.9.98.14,96.9.98.140,96.9.98.141,96.9.98.144,96.9.98.145] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 626"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522625; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.15,96.9.98.150,96.9.98.151,96.9.98.155,96.9.98.16,96.9.98.160,96.9.98.161,96.9.98.165,96.9.98.166,96.9.98.17] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 627"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522626; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.170,96.9.98.171,96.9.98.175,96.9.98.177,96.9.98.18,96.9.98.180,96.9.98.181,96.9.98.185,96.9.98.188,96.9.98.19] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 628"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522627; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.190,96.9.98.191,96.9.98.195,96.9.98.199,96.9.98.2,96.9.98.20,96.9.98.200,96.9.98.201,96.9.98.202,96.9.98.205] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 629"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522628; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.21,96.9.98.210,96.9.98.211,96.9.98.212,96.9.98.215,96.9.98.22,96.9.98.220,96.9.98.222,96.9.98.225,96.9.98.23] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 630"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522629; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.230,96.9.98.232,96.9.98.233,96.9.98.234,96.9.98.235,96.9.98.24,96.9.98.240,96.9.98.242,96.9.98.244,96.9.98.245] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 631"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522630; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.25,96.9.98.250,96.9.98.252,96.9.98.26,96.9.98.27,96.9.98.28,96.9.98.29,96.9.98.3,96.9.98.30,96.9.98.31] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 632"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522631; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.32,96.9.98.33,96.9.98.34,96.9.98.35,96.9.98.36,96.9.98.37,96.9.98.38,96.9.98.39,96.9.98.4,96.9.98.40] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 633"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522632; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.41,96.9.98.42,96.9.98.43,96.9.98.44,96.9.98.45,96.9.98.46,96.9.98.47,96.9.98.48,96.9.98.49,96.9.98.5] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 634"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522633; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.50,96.9.98.51,96.9.98.52,96.9.98.53,96.9.98.54,96.9.98.55,96.9.98.56,96.9.98.57,96.9.98.58,96.9.98.59] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 635"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522634; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.6,96.9.98.60,96.9.98.61,96.9.98.62,96.9.98.63,96.9.98.64,96.9.98.65,96.9.98.66,96.9.98.67,96.9.98.7] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 636"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522635; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.70,96.9.98.75,96.9.98.77,96.9.98.78,96.9.98.8,96.9.98.80,96.9.98.85,96.9.98.88,96.9.98.89,96.9.98.9] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 637"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522636; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [96.9.98.90,96.9.98.95,96.9.98.96,96.9.98.98,96.9.98.99,97.107.139.108,97.113.236.64,97.116.10.135,97.120.63.169,97.187.223.125] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 638"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522637; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [97.75.245.199,97.83.0.254,97.87.178.49,97.98.27.66,98.115.87.163,98.116.120.242,98.121.68.25,98.128.173.1,98.128.175.45,98.128.175.69] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 639"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522638; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;) alert tcp [98.168.31.145,98.206.28.99,98.213.187.139,98.216.238.112,98.232.88.235,98.25.152.225,98.30.180.156,98.31.36.230,99.106.143.239,99.125.87.67] any -> $HOME_NET any (msg:"ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 640"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/TorRules; threshold: type limit, track by_src, seconds 60, count 1; classtype:misc-attack; flowbits:set,ET.TorIP; sid:2522639; rev:5970; metadata:affected_product Any, attack_target Any, deployment Perimeter, tag TOR, signature_severity Informational, created_at 2008_12_01, updated_at 2025_08_01;)