SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)

SID: 903205722Rev: 151 views
History
Sourcesslbl/ssl-fp-blacklist
CreatedJune 25, 2025
UpdatedJune 25, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls_cert_fingerprint; content:"16:b2:97:fe:39:2a:08:2c:65:3e:d1:59:10:62:53:c7:6c:2e:6b:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16b297fe392a082c653ed159106253c76c2e6b66/; sid:903205722; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!