SSLBL: Malicious SSL certificate detected (RatonRAT C&C)

SID: 903209411Rev: 10 views
Sourcesslbl/ssl-fp-blacklist
CreatedApril 1, 2026
UpdatedApril 1, 2026
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RatonRAT C&C)"; tls_cert_fingerprint; content:"c8:0c:de:ac:49:66:4e:e5:44:2b:e4:18:49:24:29:10:d2:07:04:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c80cdeac49664ee5442be41849242910d2070480/; sid:903209411; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!