# hollowpoint.rules — generated 2026-09-15 09:38 UTC — 3 rules — TLP:CLEAR # source: https://publicmosaic.com/indicators — published for defensive use # scope: host 45.38.20.151 # rev:2 — alert tcp on address and port; alert tls with tls.cert_fingerprint only where the full # certificate SHA-256 is published. REPLACE any rev:1 file (every rule was alert tls) rather than # loading it beside this one: a same-sid different-text pair is a duplicate Suricata refuses. alert tls $HOME_NET any -> 45.38.20.151 8443 (msg:"HOLLOWPOINT C2 sliver"; tls.cert_fingerprint; content:"b6e8be28cee97ffe2cce33984e6b68af9d127c1992ade2599928df295d50e6c8"; reference:url,publicmosaic.com/indicators; sid:9106346; rev:2;) alert tls $HOME_NET any -> 45.38.20.151 443 (msg:"HOLLOWPOINT C2 sliver"; tls.cert_fingerprint; content:"71bf5f878553803ff5a97d64bec87f661d1fc56f09fe569ac207e4ee8fd3c97f"; reference:url,publicmosaic.com/indicators; sid:9106347; rev:2;) alert tls $HOME_NET any -> 45.38.20.151 31337 (msg:"HOLLOWPOINT C2 sliver"; tls.cert_fingerprint; content:"de360b3e9f065ecfb0a814154d0a5df764ae11da43f55956875a63d78378bb60"; reference:url,publicmosaic.com/indicators; sid:9106003; rev:2;)