SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)

SID: 903208158Rev: 10 views
Sourcesslbl/ssl-fp-blacklist
CreatedSeptember 27, 2025
UpdatedSeptember 27, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls_cert_fingerprint; content:"64:f3:67:ef:61:0b:b9:7b:85:a7:03:fa:12:40:de:8d:92:a8:e9:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64f367ef610bb97b85a703fa1240de8d92a8e97f/; sid:903208158; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!