From 159ab5e458cc10bb2b1abe3ae0f772e452a00956 Mon Sep 17 00:00:00 2001 From: junk Date: Mon, 13 Jan 2025 10:11:42 -0500 Subject: [PATCH] Update suricata/[X]waterbear-suricata-20250112.txt --- ...suricata-20250112.txt => [X]waterbear-suricata-20250112.txt} | 2 ++ 1 file changed, 2 insertions(+) rename suricata/{waterbear-suricata-20250112.txt => [X]waterbear-suricata-20250112.txt} (99%) diff --git a/suricata/waterbear-suricata-20250112.txt b/suricata/[X]waterbear-suricata-20250112.txt similarity index 99% rename from suricata/waterbear-suricata-20250112.txt rename to suricata/[X]waterbear-suricata-20250112.txt index 05da30a..82c2ee5 100644 --- a/suricata/waterbear-suricata-20250112.txt +++ b/suricata/[X]waterbear-suricata-20250112.txt @@ -1,3 +1,5 @@ +[X]Updated + alert ip 45.77.181.203 any -> any any (msg:"Suspicious waterbear IP detected Entering Network: 45.77.181.203 (source) - APT Group: BlackTech"; sid:5921737425; rev:1;) alert ip any any -> 45.77.181.203 any (msg:"Suspicious waterbear IP detected Leaving Network: 45.77.181.203 (destination) - APT Group: BlackTech"; sid:5921737426; rev:1;) alert ip 103.40.112.228 any -> any any (msg:"Suspicious waterbear IP detected Entering Network: 103.40.112.228 (source) - APT Group: BlackTech"; sid:3182573330; rev:1;)