SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)

SID: 903208956Rev: 10 views
Sourcesslbl/ssl-fp-blacklist
CreatedFebruary 19, 2026
UpdatedFebruary 19, 2026
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls_cert_fingerprint; content:"c9:6e:7c:1c:bf:dc:ff:64:e9:05:57:77:9e:dd:3a:f8:a1:b6:a6:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c96e7c1cbfdcff64e90557779edd3af8a1b6a6c4/; sid:903208956; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!