# hollowpoint.rules — generated 2026-09-15 10:08 UTC — 2 rules — TLP:CLEAR # source: https://publicmosaic.com/indicators — published for defensive use # scope: host 52.51.21.68 # rev:2 — alert tcp on address and port; alert tls with tls.cert_fingerprint only where the full # certificate SHA-256 is published. REPLACE any rev:1 file (every rule was alert tls) rather than # loading it beside this one: a same-sid different-text pair is a duplicate Suricata refuses. alert tls $HOME_NET any -> 52.51.21.68 443 (msg:"HOLLOWPOINT C2 sliver"; tls.cert_fingerprint; content:"da19ff4239ad3dbf0733c9ce8da5f1d9e07feea532fac21b89f3c1be1138f8c0"; reference:url,publicmosaic.com/indicators; sid:9104224; rev:2;) alert tls $HOME_NET any -> 52.51.21.68 31337 (msg:"HOLLOWPOINT C2 sliver"; tls.cert_fingerprint; content:"d860bf752f94466474dec8cee6f9f8d9868c5e2ab31c83926a6623ee19202f8b"; reference:url,publicmosaic.com/indicators; sid:9103701; rev:2;)