NBLock Ransomware Outbound TCP to Tor Relay Ports 9001/9030
This rule detects outbound TCP traffic from internal network hosts to known Tor relay ports (9001, 9030), which is a common communication pattern for the NBLock ransomware strain to establish a command and control channel through the Tor network.
Suricata

