🐾 - 🚨 Suspicious TLS certificate : CN=server.domain.com

SID: 3300657Rev: 30 views
Sourcepawpatrules
CreatedJuly 29, 2021
UpdatedDecember 3, 2022
Classificationtrojan-activity
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"🐾 - 🚨 Suspicious TLS certificate : CN=server.domain.com"; flow:to_client, stateless; tls.cert_subject; content:"CN=server.domain.com"; nocase; metadata:created_at 2021_07_29, updated_at 2022_12_03; sid:3300657; rev:3; classtype:trojan-activity;)

Metadata

created at2021_07_29
updated at2022_12_03

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!