SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)

SID: 903208441Rev: 10 views
Sourcesslbl/ssl-fp-blacklist
CreatedNovember 16, 2025
UpdatedNovember 16, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls_cert_fingerprint; content:"eb:6f:c4:5c:12:b2:9f:4f:72:a3:b2:bc:3b:e2:6d:a2:3e:bb:53:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb6fc45c12b29f4f72a3b2bc3be26da23ebb534c/; sid:903208441; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!