With Suricata 7.0 I see those results with your pcaps and this signature:
07/15/2023-15:16:52.219542 [**] [1:2100498:7] GPL ATTACK_RESPONSE id check returned root [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 18.67.93.89:80 -> 192.168.40.161:49795
07/15/2023-15:27:59.828858 [**] [1:2100498:7] GPL ATTACK_RESPONSE id check returned root [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 18.67.93.89:80 -> 192.168.1.15:49915
07/15/2023-15:28:08.823828 [**] [1:2100498:7] GPL ATTACK_RESPONSE id check returned root [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 18.67.93.89:443 -> 172.27.240.2:49916
Same result with 6.0.13 and using vanilla suricata.yaml.
Can you post suricata --build-info and also try with a more recent version?