|
|
|
payload:
|
|
|
|
# > Dler Cloud
|
|
|
|
- DOMAIN-SUFFIX,dler.cloud
|
|
|
|
|
|
|
|
# > Apple CDN
|
|
|
|
- PROCESS-NAME,storedownloadd
|
|
|
|
# - USER-AGENT,com.apple.appstored*
|
|
|
|
- DOMAIN,aod.itunes.apple.com
|
|
|
|
- DOMAIN,api.smoot.apple.cn
|
|
|
|
- DOMAIN,appldnld.apple.com
|
|
|
|
- DOMAIN,apptrailers.itunes.apple.com
|
|
|
|
- DOMAIN,gs-loc-cn.apple.com
|
|
|
|
- DOMAIN,iosapps.itunes.apple.com
|
|
|
|
- DOMAIN,music.apple.com
|
|
|
|
- DOMAIN,mvod.itunes.apple.com
|
|
|
|
- DOMAIN,osxapps.itunes.apple.com
|
|
|
|
- DOMAIN,supportdownload.apple.com
|
|
|
|
- DOMAIN,swcdn.apple.com
|
|
|
|
- DOMAIN,updates-http.cdn-apple.com
|
|
|
|
- DOMAIN-SUFFIX,ls.apple.com
|
|
|
|
- DOMAIN-SUFFIX,mzstatic.com
|
|
|
|
|
|
|
|
# > Epic
|
|
|
|
- DOMAIN-KEYWORD,epicgames
|
|
|
|
|
|
|
|
# > Google
|
|
|
|
- DOMAIN,safebrowsing.googleapis.com
|
|
|
|
- DOMAIN-SUFFIX,dl.google.com
|
|
|
|
|
|
|
|
# > Microsoft
|
|
|
|
# - USER-AGENT,Microsoft%20Remote%20Desktop*
|
|
|
|
- DOMAIN-SUFFIX,msftconnecttest.com
|
|
|
|
- DOMAIN-SUFFIX,windows.com
|
|
|
|
- DOMAIN-SUFFIX,windows.net
|
|
|
|
- DOMAIN-SUFFIX,windowsupdate.com
|
|
|
|
- DOMAIN-SUFFIX,xbox.com
|
|
|
|
- DOMAIN-SUFFIX,xboxlive.com
|
|
|
|
|
|
|
|
# > Proxy plugin
|
|
|
|
- PROCESS-NAME,v2ray
|
|
|
|
- PROCESS-NAME,ss-local
|
|
|
|
|
|
|
|
# > Steam
|
|
|
|
# - USER-AGENT,Steam*
|
|
|
|
- DOMAIN-SUFFIX,steamcontent.com
|
|
|
|
# - DOMAIN,store.steampowered.com
|
|
|
|
|
|
|
|
- DOMAIN-SUFFIX,steamchina.com
|
|
|
|
|
|
|
|
- DOMAIN,csgo.wmsj.cn
|
|
|
|
- DOMAIN,dota2.wmsj.cn
|
|
|
|
- DOMAIN,wmsjsteam.com
|
|
|
|
|
|
|
|
- DOMAIN,dl.steam.clngaa.com
|
|
|
|
- DOMAIN,dl.steam.ksyna.com
|
|
|
|
|
|
|
|
- DOMAIN,st.dl.bscstorage.net
|
|
|
|
- DOMAIN,st.dl.eccdnx.com
|
|
|
|
- DOMAIN,st.dl.pinyuncloud.com
|
|
|
|
|
|
|
|
- DOMAIN,steampipe.steamcontent.tnkjmec.com
|
|
|
|
|
|
|
|
- DOMAIN,steampowered.com.8686c.com
|
|
|
|
- DOMAIN,steamstatic.com.8686c.com
|
|
|
|
|
|
|
|
- DOMAIN,steambroadcast.akamaized.net
|
|
|
|
- DOMAIN,steamcdn-a.akamaihd.net
|
|
|
|
- DOMAIN,steamcommunity-a.akamaihd.net
|
|
|
|
- DOMAIN,steamstore-a.akamaihd.net
|
|
|
|
- DOMAIN,steamusercontent-a.akamaihd.net
|
|
|
|
- DOMAIN,steamuserimages-a.akamaihd.net
|
|
|
|
|
|
|
|
# > Tesla
|
|
|
|
- DOMAIN,tesla-cdn.thron.cn
|
|
|
|
- DOMAIN,tesla-cdn.thron.com
|
|
|
|
- DOMAIN-SUFFIX,solarcity.com
|
|
|
|
- DOMAIN-SUFFIX,tesla.cn
|
|
|
|
- DOMAIN-SUFFIX,tesla.com
|
|
|
|
- DOMAIN-SUFFIX,tesla.com.cn
|
|
|
|
- DOMAIN-SUFFIX,teslamotors.cn
|
|
|
|
- DOMAIN-SUFFIX,teslamotors.com
|
|
|
|
- DOMAIN-SUFFIX,teslamotors.com.cn
|
|
|
|
- DOMAIN-SUFFIX,ts.la
|
|
|
|
|
|
|
|
# > UUBooster
|
|
|
|
- PROCESS-NAME,UUBooster
|
|
|
|
|
|
|
|
# > Xunlei
|
|
|
|
# - USER-AGENT,%E8%BF%85%E9%9B%B7
|
|
|
|
- DOMAIN-SUFFIX,xunlei.com
|
|
|
|
|
|
|
|
# > Download
|
|
|
|
- PROCESS-NAME,aria2c.exe
|
|
|
|
- PROCESS-NAME,BitComet.exe
|
|
|
|
- PROCESS-NAME,fdm.exe
|
|
|
|
# - PROCESS-NAME,IDMan.exe
|
|
|
|
- PROCESS-NAME,NetTransport.exe
|
|
|
|
- PROCESS-NAME,qbittorrent.exe
|
|
|
|
- PROCESS-NAME,Thunder.exe
|
|
|
|
- PROCESS-NAME,transmission-daemon.exe
|
|
|
|
- PROCESS-NAME,transmission-qt.exe
|
|
|
|
- PROCESS-NAME,uTorrent.exe
|
|
|
|
- PROCESS-NAME,WebTorrent.exe
|
|
|
|
- PROCESS-NAME,aria2c
|
|
|
|
- PROCESS-NAME,fdm
|
|
|
|
- PROCESS-NAME,Folx
|
|
|
|
- PROCESS-NAME,NetTransport
|
|
|
|
- PROCESS-NAME,qbittorrent
|
|
|
|
- PROCESS-NAME,Thunder
|
|
|
|
- PROCESS-NAME,Transmission
|
|
|
|
- PROCESS-NAME,uTorrent
|
|
|
|
- PROCESS-NAME,WebTorrent
|
|
|
|
- PROCESS-NAME,WebTorrent Helper
|
|
|
|
|
|
|
|
# > Private Tracker
|
|
|
|
- DOMAIN-SUFFIX,awesome-hd.me
|
|
|
|
- DOMAIN-SUFFIX,broadcasthe.net
|
|
|
|
- DOMAIN-SUFFIX,chdbits.co
|
|
|
|
- DOMAIN-SUFFIX,classix-unlimited.co.uk
|
|
|
|
- DOMAIN-SUFFIX,empornium.me
|
|
|
|
- DOMAIN-SUFFIX,gazellegames.net
|
|
|
|
- DOMAIN-SUFFIX,hdchina.org
|
|
|
|
- DOMAIN-SUFFIX,hdsky.me
|
|
|
|
- DOMAIN-SUFFIX,icetorrent.org
|
|
|
|
- DOMAIN-SUFFIX,jpopsuki.eu
|
|
|
|
- DOMAIN-SUFFIX,keepfrds.com
|
|
|
|
- DOMAIN-SUFFIX,madsrevolution.net
|
|
|
|
- DOMAIN-SUFFIX,m-team.cc
|
|
|
|
- DOMAIN-SUFFIX,nanyangpt.com
|
|
|
|
- DOMAIN-SUFFIX,ncore.cc
|
|
|
|
- DOMAIN-SUFFIX,open.cd
|
|
|
|
- DOMAIN-SUFFIX,ourbits.club
|
|
|
|
- DOMAIN-SUFFIX,passthepopcorn.me
|
|
|
|
- DOMAIN-SUFFIX,privatehd.to
|
|
|
|
- DOMAIN-SUFFIX,redacted.ch
|
|
|
|
- DOMAIN-SUFFIX,springsunday.net
|
|
|
|
- DOMAIN-SUFFIX,tjupt.org
|
|
|
|
- DOMAIN-SUFFIX,totheglory.im
|
|
|
|
|
|
|
|
- DOMAIN-KEYWORD,announce
|
|
|
|
- DOMAIN-KEYWORD,torrent
|
|
|
|
- DOMAIN-SUFFIX,smtp
|
|
|
|
# - URL-REGEX,(Subject|HELO|SMTP)
|
|
|
|
|