From 6fef36d4f0e342a33ac343ebe88314e2e5f4821d Mon Sep 17 00:00:00 2001 From: Matthew Iverson Date: Sun, 12 Jan 2025 22:43:45 -0500 Subject: [PATCH] Delete yara/TsCookie-suricata-20250112.txt --- yara/TsCookie-suricata-20250112.txt | 6 ------ 1 file changed, 6 deletions(-) delete mode 100644 yara/TsCookie-suricata-20250112.txt diff --git a/yara/TsCookie-suricata-20250112.txt b/yara/TsCookie-suricata-20250112.txt deleted file mode 100644 index add9bdb..0000000 --- a/yara/TsCookie-suricata-20250112.txt +++ /dev/null @@ -1,6 +0,0 @@ -alert ip 220.130.216.76 any -> any any (msg:"Suspicious TsCookie IP detected Entering Network: 220.130.216.76 (source) - APT Group: BlackTech"; sid:8166465416; rev:1;) -alert ip any any -> 220.130.216.76 any (msg:"Suspicious TsCookie IP detected Leaving Network: 220.130.216.76 (destination) - APT Group: BlackTech"; sid:8166465417; rev:1;) -alert ip 60.244.52.29 any -> any any (msg:"Suspicious TsCookie IP detected Entering Network: 60.244.52.29 (source) - APT Group: BlackTech"; sid:7569006617; rev:1;) -alert ip any any -> 60.244.52.29 any (msg:"Suspicious TsCookie IP detected Leaving Network: 60.244.52.29 (destination) - APT Group: BlackTech"; sid:7569006618; rev:1;) -alert ip 45.76.102.145 any -> any any (msg:"Suspicious TsCookie IP detected Entering Network: 45.76.102.145 (source) - APT Group: BlackTech"; sid:8497073872; rev:1;) -alert ip any any -> 45.76.102.145 any (msg:"Suspicious TsCookie IP detected Leaving Network: 45.76.102.145 (destination) - APT Group: BlackTech"; sid:8497073873; rev:1;)