Back to Rule

Rule History

SID: 906200016 • Source: sslbl/ja3-fingerprints

Versions (3)

Version DetailsCurrent

Rev: 1Jun 25, 2025, 11:40 AM

SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Dridex)

alert tls any any -> any any (msg:"SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Dridex)"; ja3_hash; content:"d6f04b5a910115f4b50ecec09d40a1df"; reference:url, sslbl.abuse.ch/ja3-fingerprints/d6f04b5a910115f4b50ecec09d40a1df/; sid:906200016; rev:1;)

Jun 25, 2025, 11:40 AM

Jun 25, 2025, 11:40 AM

Jul 17, 2025, 2:35 PM

Jul 17, 2025, 2:35 PM

ja3_fingerprints.rules