SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)
Sourcesslbl/ssl-fp-blacklist
CreatedDecember 9, 2025
UpdatedDecember 9, 2025
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls_cert_fingerprint; content:"e4:de:ab:0b:32:f5:22:cd:a9:21:79:ef:e2:29:42:c5:ad:ab:fa:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4deab0b32f522cda92179efe22942c5adabfa87/; sid:903208554; rev:1;)
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!