SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)

SID: 903208479Rev: 10 views
Sourcesslbl/ssl-fp-blacklist
CreatedNovember 20, 2025
UpdatedNovember 20, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls_cert_fingerprint; content:"31:00:a4:0b:0b:16:05:0f:4b:ef:df:fd:44:7a:5a:16:c7:bb:23:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3100a40b0b16050f4befdffd447a5a16c7bb23de/; sid:903208479; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!