SSLBL: Malicious SSL certificate detected (ACRStealer C&C)

SID: 903210495Rev: 1EnabledDerived0 views
Filesslblacklist_tls_cert.rules
CreatedAugust 26, 2026
UpdatedAugust 26, 2026
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ACRStealer C&C)"; tls_cert_fingerprint; content:"0f:40:85:48:2f:b0:66:4e:22:b9:dc:96:2b:d8:71:84:a2:04:8e:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f4085482fb0664e22b9dc962bd87184a2048e28/; sid:903210495; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!