For most of these, you shouldn't use Suricata at all but use firewall aliases and rules to block these IPs directly, as it is (said to be) a lot more performant.
In Suricata, only use the following:
abuse.ch/SSL Fingerprint Blacklist
Not sure if this is a rules or IP based list:
abuse.ch/ThreatFox
In Suricata, only use the following:
abuse.ch/SSL Fingerprint Blacklist
Not sure if this is a rules or IP based list:
abuse.ch/ThreatFox
"