From cb491aad0d246bfc11aa488dcacfb121dba21a6c Mon Sep 17 00:00:00 2001 From: junk Date: Mon, 13 Jan 2025 10:03:59 -0500 Subject: [PATCH] Update suricata/[X]TsCookie-suricata-20250112.txt --- ...-suricata-20250112.txt => [X]TsCookie-suricata-20250112.txt} | 2 ++ 1 file changed, 2 insertions(+) rename suricata/{TsCookie-suricata-20250112.txt => [X]TsCookie-suricata-20250112.txt} (98%) diff --git a/suricata/TsCookie-suricata-20250112.txt b/suricata/[X]TsCookie-suricata-20250112.txt similarity index 98% rename from suricata/TsCookie-suricata-20250112.txt rename to suricata/[X]TsCookie-suricata-20250112.txt index add9bdb..8115e19 100644 --- a/suricata/TsCookie-suricata-20250112.txt +++ b/suricata/[X]TsCookie-suricata-20250112.txt @@ -1,3 +1,5 @@ +[X] Updated + alert ip 220.130.216.76 any -> any any (msg:"Suspicious TsCookie IP detected Entering Network: 220.130.216.76 (source) - APT Group: BlackTech"; sid:8166465416; rev:1;) alert ip any any -> 220.130.216.76 any (msg:"Suspicious TsCookie IP detected Leaving Network: 220.130.216.76 (destination) - APT Group: BlackTech"; sid:8166465417; rev:1;) alert ip 60.244.52.29 any -> any any (msg:"Suspicious TsCookie IP detected Entering Network: 60.244.52.29 (source) - APT Group: BlackTech"; sid:7569006617; rev:1;)