SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)

SID: 903205494Rev: 149 views
History
Sourcesslbl/ssl-fp-blacklist
CreatedJune 25, 2025
UpdatedJune 25, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls_cert_fingerprint; content:"3a:40:d6:b9:1d:59:d0:2a:5a:9a:9c:51:ce:26:21:e8:96:f4:52:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a40d6b91d59d02a5a9a9c51ce2621e896f45286/; sid:903205494; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!