Code:
04/26/2020-10:48:59.208024 [**] [1:2404303:5712] ET CNC Feodo Tracker Reported CnC Server group 4 [**] [Classification: A Network Trojan was Detected] [Prior>
04/26/2020-18:50:29.049005 [**] [1:2404303:5712] ET CNC Feodo Tracker Reported CnC Server group 4 [**] [Classification: A Network Trojan was Detected] [Prior>
At the end of the lines is my Mac IP.
suricata.log do not find it useful.
http.log is a little useful to check the operation.
In particular, I recommend fast.log and stats.log enabled.