# hollowpoint.rules — generated 2026-09-15 09:38 UTC — 2 rules — TLP:CLEAR # source: https://publicmosaic.com/indicators — published for defensive use # scope: host 45.139.104.226 # rev:2 — alert tcp on address and port; alert tls with tls.cert_fingerprint only where the full # certificate SHA-256 is published. REPLACE any rev:1 file (every rule was alert tls) rather than # loading it beside this one: a same-sid different-text pair is a duplicate Suricata refuses. alert tls $HOME_NET any -> 45.139.104.226 49001 (msg:"HOLLOWPOINT C2 pure_rat"; tls.cert_fingerprint; content:"4c12dd5cd3dbf519f29501e4cf4909ba20b8af456b37e0f9c6c7f08d68211de4"; reference:url,publicmosaic.com/indicators; sid:9105128; rev:2;) alert tls $HOME_NET any -> 45.139.104.226 443 (msg:"HOLLOWPOINT C2 pure_rat"; tls.cert_fingerprint; content:"1d3ad35b189a89c1095e0a3e710204b603ef3efa942e93f413a314d904c90307"; reference:url,publicmosaic.com/indicators; sid:9104685; rev:2;)