Skip to content

Commit 49c737c

Browse files
wikijmgithub-actions[bot]
authored andcommitted
Apply automatic changes
1 parent fcaf51a commit 49c737c

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

S1PQ-rules-linux-network_connection/net_connection_lnx_back_connect_shell_dev.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 24-01-2026 01:38:12):
2+
// Translated content (automatically translated on 25-01-2026 01:49:55):
33
(event.category in ("dns","url","ip")) and (endpoint.os="linux" and (src.process.image.path contains "/bin/bash" and (not (dst.ip.address in ("127.0.0.1","0.0.0.0")))))
44
```
55

S1PQ-rules-linux-network_connection/net_connection_lnx_crypto_mining_indicators.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 24-01-2026 01:38:12):
2+
// Translated content (automatically translated on 25-01-2026 01:49:55):
33
(event.category in ("dns","url","ip")) and (endpoint.os="linux" and ((url.address in ("pool.minexmr.com","fr.minexmr.com","de.minexmr.com","sg.minexmr.com","ca.minexmr.com","us-west.minexmr.com","pool.supportxmr.com","mine.c3pool.com","xmr-eu1.nanopool.org","xmr-eu2.nanopool.org","xmr-us-east1.nanopool.org","xmr-us-west1.nanopool.org","xmr-asia1.nanopool.org","xmr-jp1.nanopool.org","xmr-au1.nanopool.org","xmr.2miners.com","xmr.hashcity.org","xmr.f2pool.com","xmrpool.eu","pool.hashvault.pro","moneroocean.stream","monerocean.stream")) or (event.dns.request in ("pool.minexmr.com","fr.minexmr.com","de.minexmr.com","sg.minexmr.com","ca.minexmr.com","us-west.minexmr.com","pool.supportxmr.com","mine.c3pool.com","xmr-eu1.nanopool.org","xmr-eu2.nanopool.org","xmr-us-east1.nanopool.org","xmr-us-west1.nanopool.org","xmr-asia1.nanopool.org","xmr-jp1.nanopool.org","xmr-au1.nanopool.org","xmr.2miners.com","xmr.hashcity.org","xmr.f2pool.com","xmrpool.eu","pool.hashvault.pro","moneroocean.stream","monerocean.stream"))))
44
```
55

S1PQ-rules-linux-network_connection/net_connection_lnx_ngrok_tunnel.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 24-01-2026 01:38:12):
2+
// Translated content (automatically translated on 25-01-2026 01:49:55):
33
(event.category in ("dns","url","ip")) and (endpoint.os="linux" and ((url.address contains "tunnel.us.ngrok.com" or url.address contains "tunnel.eu.ngrok.com" or url.address contains "tunnel.ap.ngrok.com" or url.address contains "tunnel.au.ngrok.com" or url.address contains "tunnel.sa.ngrok.com" or url.address contains "tunnel.jp.ngrok.com" or url.address contains "tunnel.in.ngrok.com") or (event.dns.request contains "tunnel.us.ngrok.com" or event.dns.request contains "tunnel.eu.ngrok.com" or event.dns.request contains "tunnel.ap.ngrok.com" or event.dns.request contains "tunnel.au.ngrok.com" or event.dns.request contains "tunnel.sa.ngrok.com" or event.dns.request contains "tunnel.jp.ngrok.com" or event.dns.request contains "tunnel.in.ngrok.com")))
44
```
55

0 commit comments

Comments
 (0)