################################################################ # abuse.ch Suricata IDS SSL Certificate Ruleset # # For Suricata 1.4 or newer # # Last updated: 2024-04-23 05:49:41 UTC # # # # Terms Of Use: https://sslbl.abuse.ch/blacklist/ # # For questions please contact sslbl [at] abuse.ch # ################################################################ # alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"b0:8a:49:39:fb:88:f3:75:a2:75:7e:ad:dc:47:b1:fb:8b:55:44:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b08a4939fb88f375a2757eaddc47b1fb8b554439/; sid:902200000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"5a:fc:23:6d:1d:d0:0c:9c:45:45:7b:75:22:6b:50:1b:81:5a:59:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5afc236d1dd00c9c45457b75226b501b815a59c7/; sid:902200001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"86:d6:aa:de:4b:a1:41:4a:91:b1:e7:fb:3c:dd:7d:50:36:92:f4:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86d6aade4ba1414a91b1e7fb3cdd7d503692f410/; sid:902200002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"65:a7:7d:36:d1:b5:36:65:f6:0d:19:71:89:24:50:4f:7d:3f:95:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65a77d36d1b53665f60d19718924504f7d3f9508/; sid:902200003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"21:93:fd:03:3d:69:5c:69:b0:e4:2d:19:08:43:cd:e9:7d:d8:05:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2193fd033d695c69b0e42d190843cde97dd80507/; sid:902200004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"67:98:30:81:90:fb:07:05:36:af:19:02:3a:e8:9b:a4:bd:54:e9:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6798308190fb070536af19023ae89ba4bd54e9b6/; sid:902200005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"8b:e4:db:c9:80:14:e3:2b:ce:03:41:f6:75:4a:23:24:49:c7:7d:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8be4dbc98014e32bce0341f6754a232449c77d3d/; sid:902200006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"b3:ff:91:c3:10:bf:2b:68:73:c9:0b:fc:87:08:06:ef:4e:ae:c4:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b3ff91c310bf2b6873c90bfc870806ef4eaec49a/; sid:902200007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"0d:22:74:58:54:86:af:6a:ac:c8:af:e0:dd:76:60:b9:0a:17:71:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d2274585486af6aacc8afe0dd7660b90a17717b/; sid:902200008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"27:9c:80:7d:e6:cb:27:72:6d:4c:c5:7f:a4:7c:ac:94:50:b9:c6:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/279c807de6cb27726d4cc57fa47cac9450b9c69e/; sid:902200009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"84:90:79:a5:85:5a:6b:6d:50:72:84:45:d1:26:1b:f3:e8:88:5b:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/849079a5855a6b6d50728445d1261bf3e8885bef/; sid:902200010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"28:49:e8:47:e0:d5:ba:85:bf:59:18:2a:92:e5:35:41:d5:5f:a8:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2849e847e0d5ba85bf59182a92e53541d55fa8dc/; sid:902200011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"69:c6:78:70:7b:fd:48:36:29:15:71:fb:ae:40:04:59:c9:0b:9e:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69c678707bfd4836291571fbae400459c90b9eed/; sid:902200012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"79:67:bb:dd:e9:c1:17:46:8d:26:cd:de:db:20:e2:1c:46:63:bd:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7967bbdde9c117468d26cddedb20e21c4663bdd7/; sid:902200013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"04:3a:68:f0:48:e8:ce:74:70:ae:58:86:0c:58:d2:58:79:66:8c:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/043a68f048e8ce7470ae58860c58d25879668c91/; sid:902200014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"38:5f:c0:e4:f3:e0:c9:a7:7a:ea:96:3d:a7:0b:bd:ae:1b:89:09:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/385fc0e4f3e0c9a77aea963da70bbdae1b8909cb/; sid:902200015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"69:a6:70:c5:f6:07:8b:33:c0:1e:1c:a5:97:d6:e8:5b:8d:35:14:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69a670c5f6078b33c01e1ca597d6e85b8d35141e/; sid:902200016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"c6:f8:28:94:77:fb:64:80:f5:85:94:eb:1d:84:09:69:94:fa:d6:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6f8289477fb6480f58594eb1d84096994fad6ee/; sid:902200017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"2a:5d:b0:16:a7:07:8b:ba:81:fb:a8:5d:ac:97:51:f2:1f:93:40:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a5db016a7078bba81fba85dac9751f21f9340bd/; sid:902200018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"cb:98:d0:d2:48:1b:3a:c3:e4:f9:de:53:eb:7f:86:cd:d0:8e:8d:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb98d0d2481b3ac3e4f9de53eb7f86cdd08e8da2/; sid:902200019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"3c:54:69:2d:86:96:90:86:a5:fb:50:fd:4b:88:cb:dc:fa:b5:a6:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c54692d86969086a5fb50fd4b88cbdcfab5a60e/; sid:902200020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"76:40:59:d7:bf:d2:5e:98:fc:66:64:bc:82:82:b7:99:df:63:91:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/764059d7bfd25e98fc6664bc8282b799df639140/; sid:902200021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"27:b9:f5:b7:92:09:d9:5f:1e:70:a7:89:dc:fb:a6:82:31:ea:c1:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27b9f5b79209d95f1e70a789dcfba68231eac10e/; sid:902200022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a9:82:9a:4e:5b:55:83:9e:4b:41:a5:20:37:75:4d:6b:df:21:24:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9829a4e5b55839e4b41a52037754d6bdf212420/; sid:902200023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1c:20:6f:e2:b1:c3:82:f2:21:79:c8:f2:68:d5:6c:97:16:53:1e:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c206fe2b1c382f22179c8f268d56c9716531e49/; sid:902200024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"43:00:63:c6:04:a4:b2:79:d2:16:f9:c2:8a:0b:8d:ef:19:38:e0:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/430063c604a4b279d216f9c28a0b8def1938e00d/; sid:902200025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"8f:0c:95:89:67:4c:20:f8:42:11:cf:27:e7:04:de:fc:07:da:f7:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f0c9589674c20f84211cf27e704defc07daf7b5/; sid:902200026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"aa:c6:4c:aa:32:df:3e:07:84:36:71:3d:83:20:a4:b0:6b:5d:d6:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aac64caa32df3e078436713d8320a4b06b5dd67d/; sid:902200027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"1e:74:0b:1d:ab:c0:40:6d:46:35:92:d0:9e:99:95:30:bb:fd:b4:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e740b1dabc0406d463592d09e999530bbfdb4ea/; sid:902200028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d4:fa:65:54:b5:f6:24:3a:50:eb:14:53:e4:40:bb:a5:8d:a5:6f:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4fa6554b5f6243a50eb1453e440bba58da56f61/; sid:902200029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"9a:04:47:53:da:a1:d6:85:6d:7d:cc:1d:29:42:a1:14:92:1b:6c:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a044753daa1d6856d7dcc1d2942a114921b6c74/; sid:902200030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a8:c7:79:04:f3:e6:1e:6d:18:2d:7a:69:15:25:c4:09:ff:12:ef:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8c77904f3e61e6d182d7a691525c409ff12ef86/; sid:902200031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"44:c0:7a:2f:f9:9b:c1:10:e1:d8:d0:4e:c5:51:33:a6:3e:4d:67:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44c07a2ff99bc110e1d8d04ec55133a63e4d674c/; sid:902200032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"66:5b:56:58:82:2a:40:6d:49:7c:f7:26:a1:45:4c:6e:2e:2f:b9:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/665b5658822a406d497cf726a1454c6e2e2fb913/; sid:902200033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"c5:35:af:d2:43:74:e0:3f:73:9d:08:1d:0d:3c:f9:da:42:d5:83:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c535afd24374e03f739d081d0d3cf9da42d583ba/; sid:902200034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"9d:28:3f:39:3e:ff:dc:af:fb:1a:65:1f:d1:bb:dc:3c:43:b5:44:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d283f393effdcaffb1a651fd1bbdc3c43b544eb/; sid:902200035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a9:24:0e:12:4a:b9:4f:16:74:4d:54:c2:50:f2:df:46:1d:dc:39:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9240e124ab94f16744d54c250f2df461ddc392b/; sid:902200036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"1e:88:57:08:ec:79:94:80:8f:1d:37:3d:2c:3a:c3:4d:2d:27:f5:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e885708ec7994808f1d373d2c3ac34d2d27f5de/; sid:902200037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"72:ce:ed:55:39:c6:0f:e7:ef:db:c8:7e:77:7f:73:1c:75:d3:ff:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72ceed5539c60fe7efdbc87e777f731c75d3ffea/; sid:902200038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"78:0e:3b:97:7f:c1:19:e7:a0:e1:cd:51:92:90:9b:a0:ba:95:c8:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/780e3b977fc119e7a0e1cd5192909ba0ba95c8c7/; sid:902200039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"ab:16:63:e4:a6:cb:03:80:ed:98:bb:d5:71:5c:db:65:b2:d6:69:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab1663e4a6cb0380ed98bbd5715cdb65b2d669b8/; sid:902200040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"9b:3f:d7:d4:0e:bb:5e:60:b1:c3:d7:59:83:b4:b7:56:c3:2e:95:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b3fd7d40ebb5e60b1c3d75983b4b756c32e9560/; sid:902200041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"3c:9a:92:56:40:3d:8a:27:7b:40:2f:d1:ac:d3:77:bf:33:1a:6d:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c9a9256403d8a277b402fd1acd377bf331a6d3b/; sid:902200042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"13:33:31:6e:0c:e9:8c:e7:72:61:13:f8:da:52:1e:79:4c:a0:3f:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1333316e0ce98ce7726113f8da521e794ca03f9a/; sid:902200043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7f:10:2b:cc:0a:6f:da:d4:d1:61:77:3b:aa:bb:08:43:17:3e:a7:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f102bcc0a6fdad4d161773baabb0843173ea76f/; sid:902200044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"0b:b0:85:d5:61:df:07:c8:89:e5:ba:d5:1c:84:63:71:d4:fc:fd:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bb085d561df07c889e5bad51c846371d4fcfd61/; sid:902200045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"f1:e6:0b:d9:3b:0a:19:a6:39:9d:76:7e:10:7f:2d:02:ad:ac:d6:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1e60bd93b0a19a6399d767e107f2d02adacd66a/; sid:902200046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b4:91:37:1e:62:d5:4a:bf:94:22:59:e1:42:b0:26:55:34:0e:e6:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b491371e62d54abf942259e142b02655340ee663/; sid:902200047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"97:a1:2f:da:4e:08:49:7e:fc:13:4e:81:03:92:12:fe:55:d7:7f:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97a12fda4e08497efc134e81039212fe55d77f21/; sid:902200048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"70:13:79:68:5c:86:34:db:58:07:04:6b:49:71:ed:4c:8d:4d:7f:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/701379685c8634db5807046b4971ed4c8d4d7f31/; sid:902200049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cb:cf:9e:26:9d:60:35:12:8c:95:36:04:10:97:13:b9:1e:50:7a:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cbcf9e269d6035128c953604109713b91e507a91/; sid:902200050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"bc:08:3e:da:9c:3a:84:fa:bf:6d:39:23:7e:bb:7a:d8:65:54:0b:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc083eda9c3a84fabf6d39237ebb7ad865540b56/; sid:902200051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoWall C&C)"; tls.fingerprint:"a7:da:82:eb:15:e9:87:09:ba:62:5c:84:3d:bb:e7:ad:d3:24:6a:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7da82eb15e98709ba625c843dbbe7add3246ac9/; sid:902200052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"18:60:c1:1a:22:26:ba:9d:25:4b:5d:e2:57:31:97:be:9d:0c:66:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1860c11a2226ba9d254b5de2573197be9d0c6644/; sid:902200053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoWall C&C)"; tls.fingerprint:"0e:dd:72:24:52:c1:2c:68:6f:16:a7:ee:7b:e7:4b:56:e8:9a:6d:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0edd722452c12c686f16a7ee7be74b56e89a6db5/; sid:902200054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f7:41:76:2e:a8:09:4a:8d:95:ad:84:ba:ea:0d:42:e8:0c:e5:84:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f741762ea8094a8d95ad84baea0d42e80ce584d0/; sid:902200055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"19:56:b7:ff:84:f6:f8:41:f5:b5:8d:63:76:88:59:b6:d5:f0:3d:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1956b7ff84f6f841f5b58d63768859b6d5f03d3c/; sid:902200056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"0b:2b:84:87:3f:70:64:d6:3e:52:74:14:45:4f:62:7d:c8:88:10:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b2b84873f7064d63e527414454f627dc8881006/; sid:902200057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4f:b4:c8:1e:f5:c1:bf:0e:2e:53:3d:8c:46:63:40:67:a1:5f:25:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4fb4c81ef5c1bf0e2e533d8c46634067a15f25fe/; sid:902200058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"df:d8:98:e9:2b:ea:e0:6c:3b:47:96:73:67:66:43:be:c4:33:19:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfd898e92beae06c3b479673676643bec433199f/; sid:902200059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cb:fa:15:96:b1:8d:b5:57:d3:f1:a7:2d:0a:4f:67:eb:94:cb:98:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cbfa1596b18db557d3f1a72d0a4f67eb94cb98f7/; sid:902200060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1a:3f:a8:f8:56:d4:da:64:83:f0:7b:29:40:41:cf:84:2e:b4:e9:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a3fa8f856d4da6483f07b294041cf842eb4e9b5/; sid:902200061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ab:92:db:cc:12:05:45:36:1d:3a:cc:c5:50:d4:e5:79:67:d4:85:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab92dbcc120545361d3accc550d4e57967d48571/; sid:902200062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"31:fa:8d:4f:b9:07:ed:28:21:94:b1:97:c0:49:d4:83:42:c2:60:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31fa8d4fb907ed282194b197c049d48342c26072/; sid:902200063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6b:3e:3b:e7:be:8c:f3:83:bd:f4:b0:91:97:32:23:11:46:d6:b2:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b3e3be7be8cf383bdf4b0919732231146d6b28e/; sid:902200064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c7:0e:2a:54:f2:e0:02:36:66:b9:5f:67:50:15:41:3a:a5:8e:58:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c70e2a54f2e0023666b95f675015413aa58e58f2/; sid:902200065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5f:94:d5:8a:9c:98:ce:49:48:55:e6:bf:4f:a2:0c:e9:d7:69:8a:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f94d58a9c98ce494855e6bf4fa20ce9d7698a3e/; sid:902200066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c9:b0:97:d6:2d:6f:7b:36:5f:88:fc:ec:1d:a9:4d:ed:5e:d9:32:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9b097d62d6f7b365f88fcec1da94ded5ed9321f/; sid:902200067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"57:1f:c6:e9:d1:fc:25:e1:c0:16:a4:8c:fa:68:d0:90:1c:ef:9f:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/571fc6e9d1fc25e1c016a48cfa68d0901cef9f77/; sid:902200068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"9d:5f:4b:bd:00:81:77:0e:67:43:31:e9:a0:db:e7:45:c9:85:e8:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d5f4bbd0081770e674331e9a0dbe745c985e850/; sid:902200069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fa:a4:0c:d8:5f:e4:f3:14:36:37:d4:37:2d:fb:ae:ad:0a:24:26:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/faa40cd85fe4f3143637d4372dfbaead0a242688/; sid:902200070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"82:c0:1d:a1:b8:8b:9f:3a:1c:ea:2e:04:47:90:71:10:ea:80:24:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82c01da1b88b9f3a1cea2e0447907110ea8024c6/; sid:902200071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"80:ec:69:70:97:91:51:ca:e8:3c:e1:a4:1e:26:40:d8:9e:c7:46:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80ec6970979151cae83ce1a41e2640d89ec746d1/; sid:902200072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8b:d3:8c:0a:32:1d:b5:52:7f:59:de:d4:8e:b0:11:ba:7e:a6:93:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bd38c0a321db5527f59ded48eb011ba7ea69365/; sid:902200073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"3f:b1:8e:1a:73:74:f2:c2:4b:4e:40:44:14:d1:c0:93:93:5d:d7:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3fb18e1a7374f2c24b4e404414d1c093935dd724/; sid:902200074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"34:8e:8f:a3:05:d8:b1:e5:fe:d5:3c:07:1e:dd:58:e7:a0:c9:d9:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/348e8fa305d8b1e5fed53c071edd58e7a0c9d9d4/; sid:902200075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"0b:f5:47:c6:01:50:59:da:bb:10:f7:af:8f:e3:88:e3:14:bd:fa:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bf547c6015059dabb10f7af8fe388e314bdfada/; sid:902200076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"64:44:0f:f2:d7:a0:bf:97:9d:47:8a:93:3a:ab:00:a6:87:4f:17:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64440ff2d7a0bf979d478a933aab00a6874f1762/; sid:902200077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c6:18:bb:b6:68:fb:c1:d8:3e:b7:d5:b7:ae:c7:c6:d6:95:7b:2f:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c618bbb668fbc1d83eb7d5b7aec7c6d6957b2f16/; sid:902200078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"97:af:5c:c8:e7:27:96:f4:fa:e4:87:04:45:36:95:8a:8c:6d:68:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97af5cc8e72796f4fae487044536958a8c6d68f6/; sid:902200079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5b:24:18:9a:79:a3:96:2d:a8:89:a2:e8:f9:cb:33:73:83:c2:0e:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b24189a79a3962da889a2e8f9cb337383c20e95/; sid:902200080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"b0:03:44:3e:f1:2b:5f:f4:4b:5a:00:a2:68:d2:09:5b:43:d2:a8:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b003443ef12b5ff44b5a00a268d2095b43d2a86f/; sid:902200081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"20:9a:83:7a:36:8b:be:a8:83:bc:b8:d5:79:8c:24:74:8c:41:b8:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/209a837a368bbea883bcb8d5798c24748c41b8e4/; sid:902200082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"74:06:45:7d:94:2e:bc:79:e4:91:45:4c:d5:7d:fc:f9:bc:c8:95:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7406457d942ebc79e491454cd57dfcf9bcc895af/; sid:902200083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"1b:cc:ac:6e:7f:39:5c:5a:30:c6:ec:51:b8:fa:05:5a:64:1a:0d:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1bccac6e7f395c5a30c6ec51b8fa055a641a0d68/; sid:902200084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"4b:1d:64:c1:63:7a:ae:42:7a:a0:7d:6c:75:6c:13:b9:77:71:56:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b1d64c1637aae427aa07d6c756c13b977715603/; sid:902200085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"f9:86:e8:fa:b5:55:bb:db:96:9f:f2:4c:48:8c:d9:66:09:43:5e:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f986e8fab555bbdb969ff24c488cd96609435eec/; sid:902200086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"6a:ec:d8:4a:d1:ab:ba:45:cb:2d:bb:6f:26:59:bd:78:bf:5a:88:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6aecd84ad1abba45cb2dbb6f2659bd78bf5a88b2/; sid:902200087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"86:bc:a8:33:e8:c2:80:56:25:a0:b9:0a:0f:ac:c4:5c:7f:19:8f:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86bca833e8c2805625a0b90a0facc45c7f198f56/; sid:902200088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"2e:14:0f:07:4b:ff:ad:e9:c9:20:7e:3c:60:d2:7b:27:16:fe:6a:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e140f074bffade9c9207e3c60d27b2716fe6a63/; sid:902200089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f5:e2:b6:7a:1e:92:49:ab:ac:d0:4f:68:36:9b:2a:0d:fb:0b:4f:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5e2b67a1e9249abacd04f68369b2a0dfb0b4fd7/; sid:902200090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"59:c1:d3:55:1c:d5:43:55:39:10:72:03:0d:21:57:7a:c6:5a:49:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59c1d3551cd54355391072030d21577ac65a4983/; sid:902200091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cb:f6:8e:89:9c:14:cd:be:d2:5b:20:d3:98:ce:67:24:d6:0d:e0:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cbf68e899c14cdbed25b20d398ce6724d60de0a6/; sid:902200092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c8:7e:eb:70:75:75:e5:23:8d:77:73:10:2d:f1:73:07:2a:bb:bf:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c87eeb707575e5238d7773102df173072abbbf0b/; sid:902200093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"df:9c:32:dd:ba:0b:e9:6f:08:52:bc:59:3d:a3:d7:82:12:b1:d5:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df9c32ddba0be96f0852bc593da3d78212b1d545/; sid:902200094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4d:0f:1f:0f:96:85:ef:f1:24:e5:6a:31:19:2a:2b:ea:e7:88:d8:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d0f1f0f9685eff124e56a31192a2beae788d88b/; sid:902200095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"18:d2:a1:63:f6:7d:6e:cb:68:fa:e4:3c:53:72:6b:4c:75:41:dd:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18d2a163f67d6ecb68fae43c53726b4c7541dda4/; sid:902200096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b7:5e:ae:2b:4f:10:69:d4:c5:a4:02:e8:77:d6:2d:39:78:2d:1e:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b75eae2b4f1069d4c5a402e877d62d39782d1e17/; sid:902200097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"97:69:f3:1a:c0:43:0f:24:d9:71:db:5d:02:2a:f0:56:83:f1:78:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9769f31ac0430f24d971db5d022af05683f178a4/; sid:902200098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"03:1b:9a:b1:15:b9:23:06:f8:ab:ee:8f:bb:42:20:d2:86:cf:44:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/031b9ab115b92306f8abee8fbb4220d286cf4497/; sid:902200099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d7:b1:19:96:6c:5b:41:dd:99:b2:e1:e1:c8:74:5f:cb:65:f8:09:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7b119966c5b41dd99b2e1e1c8745fcb65f809de/; sid:902200100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4e:ac:f7:ce:46:3d:ff:ae:b2:40:cb:d9:7a:09:f0:dd:42:08:e7:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4eacf7ce463dffaeb240cbd97a09f0dd4208e748/; sid:902200101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"df:4b:2f:32:9f:19:f8:a5:02:33:e4:f5:1e:e1:61:6e:b8:0d:c7:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df4b2f329f19f8a50233e4f51ee1616eb80dc7f1/; sid:902200102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"51:4c:27:56:06:f0:49:1b:66:00:89:2c:7e:52:78:52:d9:43:2c:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/514c275606f0491b6600892c7e527852d9432c2d/; sid:902200103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"a3:2f:a1:ea:3b:5d:64:a3:5d:22:b0:58:9d:14:e6:c3:ce:60:8b:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a32fa1ea3b5d64a35d22b0589d14e6c3ce608b27/; sid:902200104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"1c:1c:14:19:08:30:be:d5:ba:8a:f1:24:5c:f1:cb:d7:31:3b:bf:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c1c14190830bed5ba8af1245cf1cbd7313bbf3f/; sid:902200105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"9e:da:7e:5c:c4:e1:cb:c0:b5:21:3f:bb:71:82:2c:f9:57:4d:fc:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9eda7e5cc4e1cbc0b5213fbb71822cf9574dfc63/; sid:902200106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"ba:e6:e4:56:b7:23:9d:2e:01:cd:2a:bb:6a:10:13:9d:96:3c:73:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bae6e456b7239d2e01cd2abb6a10139d963c7314/; sid:902200107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4c:1c:1a:aa:58:80:31:74:58:79:8a:04:db:76:42:8e:ce:55:f1:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c1c1aaa5880317458798a04db76428ece55f140/; sid:902200108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"25:c3:39:6d:47:d5:df:12:fa:af:dd:06:68:7e:7e:69:f8:fc:6f:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25c3396d47d5df12faafdd06687e7e69f8fc6fe8/; sid:902200109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"d7:55:96:ad:b6:04:92:05:42:0f:f5:ae:8e:67:1c:45:c7:3e:42:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d75596adb6049205420ff5ae8e671c45c73e42b2/; sid:902200110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"eb:84:13:3c:89:78:54:1c:09:ac:e6:04:47:28:e6:21:ad:d3:07:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb84133c8978541c09ace6044728e621add30726/; sid:902200111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7e:07:b1:ff:c2:4b:29:5e:e8:07:12:4f:79:ff:43:db:53:cf:d8:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e07b1ffc24b295ee807124f79ff43db53cfd885/; sid:902200112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e1:8a:83:80:94:9a:ec:89:30:5d:f7:b6:ee:4b:00:07:af:30:52:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e18a8380949aec89305df7b6ee4b0007af3052d3/; sid:902200113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fc:17:8b:e5:34:0e:49:c4:27:78:f3:63:5a:6d:28:9c:a2:24:48:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc178be5340e49c42778f3635a6d289ca22448db/; sid:902200114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"80:ac:8f:7c:a8:c6:dd:1b:5b:23:17:63:e9:09:50:52:40:a9:d1:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80ac8f7ca8c6dd1b5b231763e909505240a9d1a6/; sid:902200115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"36:ae:19:7c:21:ca:c2:56:0f:6d:6e:dc:a5:0c:46:3e:a0:49:f1:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36ae197c21cac2560f6d6edca50c463ea049f152/; sid:902200116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"46:de:ba:70:b2:f5:e1:7b:a8:54:cf:02:26:ec:5b:df:8f:b0:06:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46deba70b2f5e17ba854cf0226ec5bdf8fb0067b/; sid:902200117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"0e:03:44:08:34:6e:2c:66:fa:ec:a8:f8:97:24:ea:1f:f6:c7:5a:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e034408346e2c66faeca8f89724ea1ff6c75a5e/; sid:902200118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"b2:1e:b5:fc:2f:3a:a1:1e:5d:9f:f6:43:a5:b3:c2:ce:70:f8:b2:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b21eb5fc2f3aa11e5d9ff643a5b3c2ce70f8b250/; sid:902200119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1f:02:e5:25:13:04:15:32:61:96:c9:a3:94:65:58:d6:62:fe:8c:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f02e525130415326196c9a3946558d662fe8cbd/; sid:902200120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"72:38:82:27:58:be:10:e5:44:50:75:20:03:53:12:21:5d:b4:04:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7238822758be10e544507520035312215db40460/; sid:902200121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"b6:02:85:17:c1:0f:e9:e3:10:48:f0:2e:58:53:e5:c1:74:1f:ef:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6028517c10fe9e31048f02e5853e5c1741fefb8/; sid:902200122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"e8:52:a3:e8:cd:0b:eb:2d:28:df:62:2e:2c:a4:d5:4d:f4:3c:cc:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e852a3e8cd0beb2d28df622e2ca4d54df43ccc9f/; sid:902200123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"dd:bd:80:27:40:3b:bd:f2:17:e6:34:53:0b:ee:72:40:ce:d6:8a:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddbd8027403bbdf217e634530bee7240ced68a8e/; sid:902200124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"ff:15:52:d1:df:5c:d0:0e:c5:69:00:31:9e:9f:24:80:4a:e6:0c:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff1552d1df5cd00ec56900319e9f24804ae60c63/; sid:902200125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"61:f6:0a:65:b6:1a:5b:e7:b3:18:69:54:eb:cf:89:ba:2c:0e:a9:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61f60a65b61a5be7b3186954ebcf89ba2c0ea963/; sid:902200126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"3e:94:59:33:e9:ee:8b:33:04:ee:2c:9b:f9:06:87:a4:31:68:5c:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e945933e9ee8b3304ee2c9bf90687a431685c3b/; sid:902200127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"91:da:28:13:75:73:71:33:e7:6b:4a:02:f6:dc:56:ff:41:da:69:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91da281375737133e76b4a02f6dc56ff41da6936/; sid:902200128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"3b:5b:76:80:24:3d:3e:09:49:a7:f8:fc:59:72:2b:b5:37:be:cb:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b5b7680243d3e0949a7f8fc59722bb537becbb5/; sid:902200129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"09:f0:c1:86:37:73:63:98:2c:19:7a:ed:2a:ca:60:2d:ce:4f:cf:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09f0c186377363982c197aed2aca602dce4fcf16/; sid:902200130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"43:cb:f3:ff:69:9b:3d:dc:58:29:17:bd:ff:41:ed:59:13:c7:39:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43cbf3ff699b3ddc582917bdff41ed5913c7398a/; sid:902200131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4e:c9:74:44:8f:e0:4a:b3:69:7a:c7:08:cc:65:42:ef:d4:b3:e4:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ec974448fe04ab3697ac708cc6542efd4b3e46c/; sid:902200132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"82:e2:15:a9:6a:60:b2:ef:fd:68:d8:9c:35:e4:ae:f0:f8:ca:63:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82e215a96a60b2effd68d89c35e4aef0f8ca6349/; sid:902200133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"be:1a:58:4a:85:c8:79:f8:55:5d:98:4f:c3:6b:ef:69:db:6d:8a:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be1a584a85c879f8555d984fc36bef69db6d8ad5/; sid:902200134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"27:fc:1e:59:18:1f:38:78:8c:49:87:08:6c:33:38:c1:af:10:78:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27fc1e59181f38788c4987086c3338c1af107820/; sid:902200135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"85:a8:d8:0b:16:83:29:3a:8d:3a:24:94:e0:45:e1:e4:44:f5:ed:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85a8d80b1683293a8d3a2494e045e1e444f5edd3/; sid:902200136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fc:8e:82:09:ef:08:ca:4a:66:d1:f5:04:5a:2e:21:0c:28:d6:14:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc8e8209ef08ca4a66d1f5045a2e210c28d61493/; sid:902200137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"75:02:e5:5d:eb:4d:19:b9:6e:a9:61:26:34:82:4b:2f:b6:ad:96:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7502e55deb4d19b96ea9612634824b2fb6ad966d/; sid:902200138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fc:0b:6f:b8:e2:b3:b6:38:9f:4c:c2:a8:43:0a:bd:24:32:8f:03:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc0b6fb8e2b3b6389f4cc2a8430abd24328f03fb/; sid:902200139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d4:86:1e:9b:06:e0:7d:34:ad:12:5d:88:03:c4:61:a6:a7:a3:7e:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4861e9b06e07d34ad125d8803c461a6a7a37e21/; sid:902200140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cf:7d:c0:ae:08:ac:82:ca:c3:0a:fc:c9:a7:66:d7:b4:7a:b8:ab:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf7dc0ae08ac82cac30afcc9a766d7b47ab8abfe/; sid:902200141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"10:ea:24:97:d8:fa:21:b8:12:5b:da:72:0c:98:c4:79:9c:f2:16:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10ea2497d8fa21b8125bda720c98c4799cf21624/; sid:902200142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"87:92:e6:87:41:47:f5:3b:4b:6d:f6:d5:2d:ba:7d:dd:56:bf:24:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8792e6874147f53b4b6df6d52dba7ddd56bf2464/; sid:902200143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (URLzone C&C)"; tls.fingerprint:"d7:fe:8e:b3:8b:ab:d3:4e:3e:f8:47:12:e7:2f:87:35:e7:74:fd:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7fe8eb38babd34e3ef84712e72f8735e774fdcf/; sid:902200144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1e:0f:3d:14:42:f9:52:2b:24:25:15:cb:69:68:a1:0b:08:f4:85:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e0f3d1442f9522b242515cb6968a10b08f4857c/; sid:902200145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a9:2a:fb:a1:2b:15:14:3b:09:0d:cd:83:2f:60:a9:88:79:fa:30:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a92afba12b15143b090dcd832f60a98879fa30dd/; sid:902200146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"47:46:41:98:fc:47:5a:2e:a1:76:18:38:b1:f8:0d:ea:e7:99:d0:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47464198fc475a2ea1761838b1f80deae799d05f/; sid:902200147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS MITM)"; tls.fingerprint:"b6:d7:85:2a:e1:ca:32:5f:77:28:d4:64:12:44:8b:01:41:94:0b:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6d7852ae1ca325f7728d46412448b0141940bc9/; sid:902200148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cd:bc:8b:c2:e9:63:ee:6c:e5:18:e0:6a:92:42:a5:4a:28:19:eb:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cdbc8bc2e963ee6ce518e06a9242a54a2819eb7f/; sid:902200149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ca:82:6a:ae:ef:5b:98:45:fe:bb:18:ca:45:05:25:3b:12:76:95:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca826aaeef5b9845febb18ca4505253b127695b7/; sid:902200150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Spambot C&C)"; tls.fingerprint:"05:9e:0e:19:e3:67:bd:56:67:24:ae:49:6d:fa:73:47:84:6b:b8:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/059e0e19e367bd566724ae496dfa7347846bb8e6/; sid:902200151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (URLzone C&C)"; tls.fingerprint:"50:ad:f0:20:3f:3d:91:02:a6:42:48:19:ea:36:e4:dd:5e:38:02:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50adf0203f3d9102a6424819ea36e4dd5e38025a/; sid:902200152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cf:65:71:b1:92:56:0b:27:33:a9:03:8d:b2:e1:bb:aa:5b:1a:77:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf6571b192560b2733a9038db2e1bbaa5b1a77f3/; sid:902200153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e7:d7:8b:56:b7:93:4e:74:fb:77:b4:73:e5:40:7d:40:d4:08:3c:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7d78b56b7934e74fb77b473e5407d40d4083c19/; sid:902200154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"bd:4b:79:f7:da:d6:cb:0c:08:25:59:af:02:5b:e1:ef:89:ca:65:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd4b79f7dad6cb0c082559af025be1ef89ca6548/; sid:902200155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8f:37:76:15:40:99:b6:c2:dc:34:b8:c3:7f:f5:21:17:21:44:a9:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f3776154099b6c2dc34b8c37ff521172144a9a4/; sid:902200156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c2:31:55:e7:15:34:ff:5b:1d:cb:09:a5:97:91:47:ee:7f:ea:14:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c23155e71534ff5b1dcb09a5979147ee7fea1461/; sid:902200157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"84:69:75:0b:a5:9f:d8:26:17:49:d7:af:6e:7f:a1:ad:c9:d3:4c:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8469750ba59fd8261749d7af6e7fa1adc9d34cbd/; sid:902200158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c9:ad:5c:d2:87:7f:35:4f:75:d5:d4:2b:56:4c:ab:a8:0f:70:5e:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9ad5cd2877f354f75d5d42b564caba80f705e7d/; sid:902200159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"ea:ab:3c:a3:76:94:c8:9d:57:b9:21:b4:f3:93:0b:af:de:02:2d:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eaab3ca37694c89d57b921b4f3930bafde022de0/; sid:902200160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"ca:2e:43:5b:b8:83:60:81:ff:a6:1c:90:2d:b0:5a:4e:0e:11:c7:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca2e435bb8836081ffa61c902db05a4e0e11c78f/; sid:902200161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e5:0e:e9:90:a3:12:b9:e2:e6:8c:46:d1:89:e1:e9:23:81:74:1b:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e50ee990a312b9e2e68c46d189e1e92381741bf9/; sid:902200162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e6:d3:0c:d0:41:d1:9d:3a:3e:9c:82:e0:b9:e3:e1:67:ad:0f:ee:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6d30cd041d19d3a3e9c82e0b9e3e167ad0fee9f/; sid:902200163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"88:c0:22:bd:88:75:be:b6:43:9a:c1:d8:be:85:92:e1:3e:f3:d9:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88c022bd8875beb6439ac1d8be8592e13ef3d918/; sid:902200164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7e:57:f5:17:78:61:4c:bb:57:2d:28:fb:a2:45:b8:7d:0b:c5:f9:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e57f51778614cbb572d28fba245b87d0bc5f9b3/; sid:902200165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b5:ff:48:e0:d2:15:2e:04:83:f1:8d:50:60:41:46:7a:55:d1:fb:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5ff48e0d2152e0483f18d506041467a55d1fba8/; sid:902200166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoWall C&C)"; tls.fingerprint:"a8:5e:b1:7f:49:8c:6f:5e:b4:bb:a8:06:70:76:6a:af:c3:06:06:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a85eb17f498c6f5eb4bba80670766aafc3060600/; sid:902200167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"48:30:df:5d:da:22:0b:59:6e:13:31:62:14:74:ba:89:fb:aa:5f:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4830df5dda220b596e1331621474ba89fbaa5f81/; sid:902200168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"35:66:21:93:91:b9:56:61:88:b4:c8:02:1e:a3:eb:c6:1c:97:35:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3566219391b9566188b4c8021ea3ebc61c9735c3/; sid:902200169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoWall C&C)"; tls.fingerprint:"29:4f:53:c0:1b:59:8d:6f:3e:e9:63:e9:c0:1f:3d:b9:86:1b:f7:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/294f53c01b598d6f3ee963e9c01f3db9861bf7bc/; sid:902200170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"94:f1:27:e6:45:d4:a5:7e:4d:7d:33:bc:a0:26:4e:55:73:d1:5e:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94f127e645d4a57e4d7d33bca0264e5573d15ee1/; sid:902200171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS MITM)"; tls.fingerprint:"c0:9a:e4:8d:fd:b9:86:cb:c3:4a:09:6d:3e:b3:68:e0:ae:4c:d5:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c09ae48dfdb986cbc34a096d3eb368e0ae4cd521/; sid:902200172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoWall C&C)"; tls.fingerprint:"c3:c4:d6:15:60:0a:da:76:d5:90:85:96:71:d2:f2:26:a9:a9:5f:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3c4d615600ada76d590859671d2f226a9a95fde/; sid:902200173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"bc:c8:b2:e2:01:8c:e5:13:88:79:75:1b:d0:06:53:a8:c2:7f:1c:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcc8b2e2018ce5138879751bd00653a8c27f1c48/; sid:902200174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak MITM)"; tls.fingerprint:"33:ec:b0:cd:e6:59:8b:79:f9:82:a3:7a:eb:54:fe:e0:f1:d1:d1:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33ecb0cde6598b79f982a37aeb54fee0f1d1d173/; sid:902200175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"99:f9:f7:e5:71:8c:4d:46:76:e3:b3:8c:a1:bd:5d:bc:ed:b6:9f:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99f9f7e5718c4d4676e3b38ca1bd5dbcedb69f61/; sid:902200176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d1:37:10:8c:b2:4d:52:6f:6c:17:7c:9c:bb:a7:f0:e5:56:ac:27:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d137108cb24d526f6c177c9cbba7f0e556ac273c/; sid:902200177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1a:b3:3d:50:41:e4:17:65:09:92:3d:12:12:13:33:43:86:04:27:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ab33d5041e4176509923d1212133343860427b3/; sid:902200178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f6:fc:60:88:f9:49:b3:41:f4:72:e1:52:d7:18:20:af:45:ea:8b:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6fc6088f949b341f472e152d71820af45ea8b6b/; sid:902200179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"16:7a:cd:80:68:09:e5:ea:36:a0:26:73:39:30:f2:d7:6a:82:41:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/167acd806809e5ea36a026733930f2d76a824113/; sid:902200180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b7:dc:f4:08:fd:ca:09:4d:d1:7f:5b:ae:03:fc:9b:b8:46:6f:51:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7dcf408fdca094dd17f5bae03fc9bb8466f51dc/; sid:902200181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"39:0d:c2:b0:5f:3a:bb:70:68:a1:0d:f8:d3:0f:fc:d3:3b:34:c3:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/390dc2b05f3abb7068a10df8d30ffcd33b34c3e3/; sid:902200182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c1:a1:e8:71:a0:86:a3:12:33:a1:7d:24:ae:4c:fd:89:fa:76:18:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1a1e871a086a31233a17d24ae4cfd89fa7618ef/; sid:902200183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"68:ee:30:19:4f:35:b7:93:68:82:ba:b1:2d:f5:98:11:d7:55:3c:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68ee30194f35b7936882bab12df59811d7553cd4/; sid:902200184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5e:33:7a:b1:cc:16:d9:bf:3a:76:be:37:ec:09:27:ba:ad:25:6f:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e337ab1cc16d9bf3a76be37ec0927baad256f26/; sid:902200185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"24:42:9c:6f:ec:f2:c9:25:b9:96:ab:0a:bb:db:7e:2c:92:be:0c:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24429c6fecf2c925b996ab0abbdb7e2c92be0c9c/; sid:902200186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"78:8d:24:64:0f:a0:77:f2:22:66:21:98:43:b2:fa:85:1b:58:5e:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/788d24640fa077f22266219843b2fa851b585e9b/; sid:902200187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"35:4f:08:df:b9:fe:a2:e2:42:3d:c7:62:ea:09:66:56:ae:b1:25:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/354f08dfb9fea2e2423dc762ea096656aeb12551/; sid:902200188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1f:3f:e6:90:29:e8:0d:06:70:de:01:55:2e:86:0a:2d:b9:b3:76:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f3fe69029e80d0670de01552e860a2db9b37684/; sid:902200189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"41:f2:38:2b:b2:12:a3:43:cc:99:2f:70:c0:f1:de:97:e8:6b:4c:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41f2382bb212a343cc992f70c0f1de97e86b4c0b/; sid:902200190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b2:b3:a1:fc:d2:30:1f:0c:e0:4c:ea:0a:b7:0e:30:68:87:9e:fc:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2b3a1fcd2301f0ce04cea0ab70e3068879efcb6/; sid:902200191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"94:93:54:e6:f4:5d:8f:56:7e:0f:a8:32:20:40:e9:c2:9e:30:b2:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/949354e6f45d8f567e0fa8322040e9c29e30b271/; sid:902200192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"4c:0c:eb:09:14:d9:3e:a8:57:05:46:0e:cd:77:2d:86:5b:cb:a3:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c0ceb0914d93ea85705460ecd772d865bcba3a1/; sid:902200193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"62:f7:1c:f2:b7:a4:d2:16:cb:04:1f:10:bf:43:7d:00:93:35:8b:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62f71cf2b7a4d216cb041f10bf437d0093358be1/; sid:902200194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"0b:47:b3:c4:1b:3f:19:b0:ba:79:fc:5f:ca:b0:ce:81:40:2e:00:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b47b3c41b3f19b0ba79fc5fcab0ce81402e0030/; sid:902200195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"62:ac:62:8d:4c:ca:f8:5d:b9:18:43:cf:30:ca:cb:2d:66:52:f3:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62ac628d4ccaf85db91843cf30cacb2d6652f3d6/; sid:902200196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"77:61:9e:10:35:ec:37:9d:9c:3b:76:eb:dd:61:fc:ca:37:13:ce:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77619e1035ec379d9c3b76ebdd61fcca3713ce84/; sid:902200197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"9e:77:fb:7a:5f:9c:9d:cc:bc:4e:ec:f6:b6:6f:91:1f:52:5a:01:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e77fb7a5f9c9dccbc4eecf6b66f911f525a010c/; sid:902200198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"26:b9:b5:66:44:16:b5:6e:8f:61:71:78:3b:e8:1c:af:b4:11:b8:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26b9b5664416b56e8f6171783be81cafb411b8e3/; sid:902200199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"79:44:a3:49:39:ef:b5:ae:88:26:dc:51:af:2b:1d:9f:3d:b4:10:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7944a34939efb5ae8826dc51af2b1d9f3db4105b/; sid:902200200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e4:03:8d:79:c9:89:9d:58:46:bb:96:b8:b1:61:5a:c6:a1:28:c8:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4038d79c9899d5846bb96b8b1615ac6a128c86c/; sid:902200201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a0:ce:c9:60:51:5d:32:4a:34:97:05:5b:e2:6e:f1:67:7d:95:a4:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0cec960515d324a3497055be26ef1677d95a4f0/; sid:902200202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f9:98:72:4c:aa:ff:a6:65:43:e2:85:0f:52:5e:af:19:1e:af:1d:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f998724caaffa66543e2850f525eaf191eaf1d47/; sid:902200203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7f:fc:cb:88:7e:7f:10:c3:f6:bf:43:73:6e:a8:6d:1a:91:f4:a3:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ffccb887e7f10c3f6bf43736ea86d1a91f4a3e8/; sid:902200204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"2b:14:02:a1:75:37:d4:5d:ab:39:cf:c1:24:17:3d:77:65:0a:77:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b1402a17537d45dab39cfc124173d77650a772c/; sid:902200205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"90:9f:c2:97:de:60:76:2b:f4:86:7b:d2:7b:f6:4c:0a:cf:91:4c:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/909fc297de60762bf4867bd27bf64c0acf914c97/; sid:902200206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d5:df:6e:cb:23:0a:6c:3e:80:a8:41:21:b6:67:c6:99:6e:49:d1:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5df6ecb230a6c3e80a84121b667c6996e49d18a/; sid:902200207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f1:53:3c:0e:c8:44:fa:de:12:8d:25:76:9d:ad:0c:a8:2e:d3:38:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1533c0ec844fade128d25769dad0ca82ed338bd/; sid:902200208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"9b:c8:51:4e:8c:b8:00:28:58:00:51:9a:b3:a7:de:05:8f:c7:46:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bc8514e8cb800285800519ab3a7de058fc7466b/; sid:902200209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ca:fb:35:4d:e9:5a:9a:72:53:e0:cd:fe:80:78:e2:4d:8f:73:a1:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cafb354de95a9a7253e0cdfe8078e24d8f73a167/; sid:902200210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7f:68:5a:e4:16:ef:ef:9d:65:28:a6:80:b1:ac:a6:69:9f:12:f4:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f685ae416efef9d6528a680b1aca6699f12f484/; sid:902200211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"94:9b:65:50:47:44:fe:bf:f8:20:37:4f:89:a2:a8:33:b5:4e:c6:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/949b65504744febff820374f89a2a833b54ec611/; sid:902200212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"2e:09:6e:b5:5c:49:ac:90:70:fc:20:38:c3:c0:2a:62:6f:47:2f:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e096eb55c49ac9070fc2038c3c02a626f472fdb/; sid:902200213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ed:08:7e:5e:8b:6e:e0:8c:50:a2:0b:0b:35:75:f1:bd:c1:ca:59:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed087e5e8b6ee08c50a20b0b3575f1bdc1ca59f5/; sid:902200214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"66:f7:34:5d:67:18:f2:54:83:4d:75:29:87:8f:58:e2:d3:dd:b4:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66f7345d6718f254834d7529878f58e2d3ddb431/; sid:902200215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2d:dc:4c:0d:f2:4e:e9:54:df:fe:62:d7:9b:a4:ff:5f:98:6b:c6:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ddc4c0df24ee954dffe62d79ba4ff5f986bc691/; sid:902200216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ed:65:2d:41:0d:5b:d7:26:34:fc:26:60:98:2e:d2:da:16:94:d4:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed652d410d5bd72634fc2660982ed2da1694d4b5/; sid:902200217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"57:d2:8c:a6:b5:58:44:40:fb:f1:fe:be:87:62:e7:72:3b:f1:1e:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57d28ca6b5584440fbf1febe8762e7723bf11e8c/; sid:902200218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"74:ab:9c:e7:9f:5a:fd:bd:64:04:6a:11:cd:34:ae:41:41:82:2b:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/74ab9ce79f5afdbd64046a11cd34ae4141822bda/; sid:902200219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"aa:d0:d8:ff:51:db:fc:07:03:21:57:e3:e0:52:16:da:9e:7c:b5:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aad0d8ff51dbfc07032157e3e05216da9e7cb5b2/; sid:902200220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"81:57:cb:4b:e0:60:29:34:ce:30:2e:d0:6f:47:9e:28:ff:37:f3:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8157cb4be0602934ce302ed06f479e28ff37f3d6/; sid:902200221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8a:3e:a6:27:9a:7f:8e:40:e9:e2:23:b7:46:a3:5b:52:a3:f3:6d:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a3ea6279a7f8e40e9e223b746a35b52a3f36ddd/; sid:902200222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"58:f2:71:bd:58:7f:8e:0e:25:94:76:9e:e8:43:5b:49:d2:f8:ef:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58f271bd587f8e0e2594769ee8435b49d2f8ef5a/; sid:902200223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b8:19:21:1e:7a:69:3e:6e:01:6d:f5:c8:de:60:44:9e:b3:56:85:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b819211e7a693e6e016df5c8de60449eb3568578/; sid:902200224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"88:b6:12:28:95:2b:f3:ad:1e:59:7f:de:77:be:8a:66:75:d3:c5:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88b61228952bf3ad1e597fde77be8a6675d3c508/; sid:902200225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f2:25:e3:43:f0:0e:fe:c2:91:51:5b:68:b0:47:db:70:51:95:20:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f225e343f00efec291515b68b047db70519520bd/; sid:902200226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Teslacrypt C&C)"; tls.fingerprint:"3b:f9:3e:ff:d4:77:a7:26:e6:6d:39:23:f0:c8:09:ad:c6:b6:88:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bf93effd477a726e66d3923f0c809adc6b688e2/; sid:902200227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ff:e3:9a:de:1d:93:16:9a:5f:3d:17:ee:98:00:df:8f:c5:4d:05:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ffe39ade1d93169a5f3d17ee9800df8fc54d05da/; sid:902200228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"88:de:16:f4:4a:04:d2:f6:7a:3b:1e:81:17:2f:d8:2b:85:0e:71:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88de16f44a04d2f67a3b1e81172fd82b850e713c/; sid:902200229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d8:24:30:44:55:4c:90:e8:d9:4e:70:ec:9c:8a:10:7f:69:f3:8c:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8243044554c90e8d94e70ec9c8a107f69f38c00/; sid:902200230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"30:34:80:f0:3a:f1:31:12:cb:a9:7d:26:bd:99:96:e2:2e:0a:9d:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/303480f03af13112cba97d26bd9996e22e0a9d78/; sid:902200231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c1:d9:ae:76:42:7e:ae:cd:c5:23:12:6a:1e:2d:20:33:59:22:b1:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1d9ae76427eaecdc523126a1e2d20335922b154/; sid:902200232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"73:b1:ac:5c:4d:9d:a2:75:34:29:c7:58:f3:44:c2:7b:de:9f:3c:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73b1ac5c4d9da2753429c758f344c27bde9f3c25/; sid:902200233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6c:e2:4d:b4:58:6c:48:8b:9c:29:f9:a2:a7:b6:0d:a1:0c:3e:12:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ce24db4586c488b9c29f9a2a7b60da10c3e1272/; sid:902200234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"ec:e4:29:41:d0:04:48:37:9d:a1:2b:f1:e5:32:f3:b9:68:d2:8e:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ece42941d00448379da12bf1e532f3b968d28e95/; sid:902200235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"69:9e:18:50:23:1b:ae:b2:e5:87:10:54:f4:e1:93:f1:e2:61:c7:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/699e1850231baeb2e5871054f4e193f1e261c7b3/; sid:902200236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ef:94:f0:54:98:c7:bf:ac:aa:f3:74:56:68:70:32:cb:2b:01:82:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef94f05498c7bfacaaf37456687032cb2b018238/; sid:902200237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b0:00:80:d0:04:ca:5f:05:81:38:32:a2:2c:44:25:21:bf:58:ff:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b00080d004ca5f05813832a22c442521bf58ff0b/; sid:902200238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fe:22:69:6e:02:28:f9:1a:5a:fe:da:78:7a:df:22:ab:cf:49:61:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe22696e0228f91a5afeda787adf22abcf4961e8/; sid:902200239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8d:62:41:2c:9c:23:03:a4:73:e6:cc:e7:2b:94:38:f0:40:5e:36:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d62412c9c2303a473e6cce72b9438f0405e36e3/; sid:902200240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"0e:22:5c:f9:41:fd:1e:7b:e0:f5:e9:fe:21:dd:13:c3:73:10:0e:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e225cf941fd1e7be0f5e9fe21dd13c373100e44/; sid:902200241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Upatre C&C)"; tls.fingerprint:"0e:e1:e1:9b:75:5a:24:f4:97:e4:5b:e3:08:60:84:13:ab:34:ca:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ee1e19b755a24f497e45be308608413ab34ca90/; sid:902200242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"cc:90:86:37:d1:3e:34:a8:b9:74:25:23:41:39:68:d9:17:23:50:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc908637d13e34a8b9742523413968d9172350bd/; sid:902200243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d1:d7:c6:99:b9:f2:90:13:33:62:69:63:4f:99:b5:af:91:dc:3f:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1d7c699b9f29013336269634f99b5af91dc3fa1/; sid:902200244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"72:1f:63:51:c5:47:80:af:14:72:42:47:fe:44:20:83:81:78:24:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/721f6351c54780af14724247fe44208381782446/; sid:902200245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4b:c8:d6:62:48:dd:64:b6:f3:55:58:c3:32:97:a4:76:02:d8:5a:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4bc8d66248dd64b6f35558c33297a47602d85a9c/; sid:902200246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"dd:0b:68:1f:32:6e:e4:71:72:56:9a:5d:68:ce:0c:a7:86:c3:c3:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd0b681f326ee47172569a5d68ce0ca786c3c366/; sid:902200247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"75:67:0e:16:b0:57:4f:3e:61:8b:73:76:66:28:db:d3:b7:a0:80:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75670e16b0574f3e618b73766628dbd3b7a0806a/; sid:902200248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"37:a3:a1:4b:4e:cb:ac:5e:32:14:7c:0d:dd:a5:e9:d6:bd:db:b4:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37a3a14b4ecbac5e32147c0ddda5e9d6bddbb4b9/; sid:902200249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"46:c0:ba:68:47:eb:c7:66:cc:16:ff:c1:d9:5d:9d:fc:df:8e:f3:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46c0ba6847ebc766cc16ffc1d95d9dfcdf8ef33a/; sid:902200250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"83:4f:8f:2f:5c:d9:74:95:43:22:7d:7f:ed:e9:ee:9e:5e:07:c9:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/834f8f2f5cd9749543227d7fede9ee9e5e07c9e8/; sid:902200251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fe:19:de:10:89:80:39:3a:b9:1f:28:24:ce:96:b8:ca:b0:f8:41:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe19de108980393ab91f2824ce96b8cab0f84163/; sid:902200252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"82:3c:a6:c8:68:b1:c6:b7:dc:99:5c:d2:42:4d:b8:a7:a7:6f:3c:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/823ca6c868b1c6b7dc995cd2424db8a7a76f3c2c/; sid:902200253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"43:ba:13:8a:61:b9:7d:f7:78:e2:92:16:25:2e:ec:ef:9a:5c:2b:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43ba138a61b97df778e29216252eecef9a5c2b2b/; sid:902200254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f8:9b:fc:5c:43:a2:d8:2b:62:9f:ff:36:02:37:88:65:df:67:0f:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f89bfc5c43a2d82b629fff3602378865df670f4e/; sid:902200255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"85:09:b1:f8:00:60:9c:ce:ee:7f:13:61:79:ca:0f:53:2b:8e:1a:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8509b1f800609cceee7f136179ca0f532b8e1a19/; sid:902200256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"72:bd:d3:b7:5f:4a:bb:8d:9d:a0:ac:9f:ca:98:af:77:2f:c7:70:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72bdd3b75f4abb8d9da0ac9fca98af772fc7703d/; sid:902200257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"29:29:3a:3f:0d:fd:2f:1f:f2:9c:5d:6a:d0:f6:89:1b:a0:c3:bf:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29293a3f0dfd2f1ff29c5d6ad0f6891ba0c3bf58/; sid:902200258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"2c:4e:b1:f1:5a:4a:41:00:20:67:26:b5:c8:f9:e2:b8:d3:72:ac:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c4eb1f15a4a4100206726b5c8f9e2b8d372ac06/; sid:902200259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"06:d5:05:4b:ee:1b:52:df:c4:32:99:48:89:33:3d:a3:ba:74:bd:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06d5054bee1b52dfc432994889333da3ba74bd78/; sid:902200260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"bc:74:0f:b3:5c:31:87:2e:de:78:dd:85:19:2d:e4:d1:9b:93:01:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc740fb35c31872ede78dd85192de4d19b9301c8/; sid:902200261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"da:ab:66:9c:bd:eb:35:41:9e:76:e9:fb:4a:14:38:88:0a:67:46:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/daab669cbdeb35419e76e9fb4a1438880a67467b/; sid:902200262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e1:bf:9e:9f:22:cd:fb:1f:05:f6:f3:ee:c8:10:0f:15:9b:07:50:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1bf9e9f22cdfb1f05f6f3eec8100f159b07503c/; sid:902200263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"db:44:ff:75:33:4b:43:4a:e5:40:ca:41:25:df:ec:29:9e:85:8d:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db44ff75334b434ae540ca4125dfec299e858db7/; sid:902200264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d1:9f:90:1f:4f:9f:f3:a0:99:39:a3:79:bd:77:0d:dc:97:f2:1d:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d19f901f4f9ff3a09939a379bd770ddc97f21ddd/; sid:902200265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5f:69:c6:98:b2:37:7d:63:49:4c:3d:b9:f9:c4:a2:61:96:4d:c4:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f69c698b2377d63494c3db9f9c4a261964dc4a1/; sid:902200266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c9:26:7f:47:e4:43:b1:30:d6:ac:e1:6c:fc:61:e7:5b:11:02:ea:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9267f47e443b130d6ace16cfc61e75b1102eaeb/; sid:902200267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"43:b9:85:8b:94:57:cc:10:a0:21:a4:fb:da:d1:d2:90:f7:8a:02:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43b9858b9457cc10a021a4fbdad1d290f78a0213/; sid:902200268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e0:f2:b5:0a:25:10:a1:d6:75:e8:bb:48:99:4b:18:dc:2a:08:57:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0f2b50a2510a1d675e8bb48994b18dc2a08578b/; sid:902200269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"62:0a:06:25:e7:9e:3a:ee:c7:b7:7a:bf:4e:d6:34:59:94:c3:c1:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/620a0625e79e3aeec7b77abf4ed6345994c3c14b/; sid:902200270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"13:b6:56:37:1e:83:02:2e:26:ac:7c:82:e3:91:bb:2b:34:de:53:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/13b656371e83022e26ac7c82e391bb2b34de53bf/; sid:902200271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6a:ad:4d:9b:0e:a4:a2:ff:8b:25:03:7a:5b:17:0d:54:ff:f7:5e:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6aad4d9b0ea4a2ff8b25037a5b170d54fff75e7f/; sid:902200272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e3:22:77:ba:58:42:21:85:86:ee:c7:bc:72:56:05:f3:f3:fa:6f:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e32277ba5842218586eec7bc725605f3f3fa6f2b/; sid:902200273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b0:2b:3d:3d:90:a0:e0:2b:10:87:07:08:1e:1b:1b:4f:67:34:c0:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b02b3d3d90a0e02b108707081e1b1b4f6734c0d0/; sid:902200274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e5:54:ae:e3:e2:bc:fc:33:46:a6:b0:46:7d:16:76:63:aa:c9:f6:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e554aee3e2bcfc3346a6b0467d167663aac9f6e0/; sid:902200275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (URLzone C&C)"; tls.fingerprint:"41:5a:58:6a:12:11:58:60:23:92:d5:63:94:a5:90:3d:fe:22:2a:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/415a586a121158602392d56394a5903dfe222a0c/; sid:902200276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"9f:61:eb:e4:e9:af:3a:a9:fd:34:f8:f3:ee:82:a3:ff:b3:0d:0f:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f61ebe4e9af3aa9fd34f8f3ee82a3ffb30d0f5a/; sid:902200277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"62:04:98:2e:47:f5:db:cc:b4:45:3a:6e:5d:3f:79:96:f0:58:6d:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6204982e47f5dbccb4453a6e5d3f7996f0586de3/; sid:902200278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"17:2d:e1:d1:15:c4:12:69:61:ea:d6:10:9f:8b:4f:85:33:70:d5:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/172de1d115c4126961ead6109f8b4f853370d54c/; sid:902200279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"97:63:d9:62:a9:c6:ba:ab:bc:5c:c9:45:ef:11:d2:15:20:6f:f3:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9763d962a9c6baabbc5cc945ef11d215206ff3ba/; sid:902200280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"30:44:73:9c:06:ea:1d:c1:b3:ce:54:b7:f6:e0:0e:c2:5d:6e:36:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3044739c06ea1dc1b3ce54b7f6e00ec25d6e36da/; sid:902200281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"25:12:1a:7e:32:e2:9e:a2:ea:4e:29:3a:45:f1:c3:aa:4e:d8:2c:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25121a7e32e29ea2ea4e293a45f1c3aa4ed82cfa/; sid:902200282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"37:22:b4:e0:63:82:08:03:19:e0:a3:26:a5:45:ad:af:43:56:50:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3722b4e06382080319e0a326a545adaf43565022/; sid:902200283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8c:d7:59:5c:e7:e7:9c:1d:7d:88:31:eb:e8:7f:1a:42:14:17:b1:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8cd7595ce7e79c1d7d8831ebe87f1a421417b113/; sid:902200284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1d:5e:2f:62:83:f4:7a:5e:27:94:b5:48:41:bd:45:12:5d:e8:9e:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d5e2f6283f47a5e2794b54841bd45125de89e77/; sid:902200285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"83:c3:f8:6d:50:79:e5:cb:5a:8e:f6:b9:c4:ad:a5:45:69:32:4e:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83c3f86d5079e5cb5a8ef6b9c4ada54569324ee4/; sid:902200286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6a:7e:d6:58:ec:d0:4e:8d:38:ed:8b:31:4e:3f:a4:c7:b2:67:00:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a7ed658ecd04e8d38ed8b314e3fa4c7b26700c7/; sid:902200287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"81:a9:2c:f2:47:9e:7d:54:7a:ef:7c:ef:42:aa:d4:68:b9:75:52:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81a92cf2479e7d547aef7cef42aad468b9755224/; sid:902200288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"fc:e3:37:e0:e5:71:d9:38:4c:71:41:e9:39:0c:36:72:d9:3e:3a:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fce337e0e571d9384c7141e9390c3672d93e3a4b/; sid:902200289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"29:69:9b:84:9f:96:3c:b7:fe:bd:e1:59:08:7e:b1:d7:18:41:ae:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29699b849f963cb7febde159087eb1d71841aef0/; sid:902200290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e4:62:ab:3c:9d:f3:b7:b7:3e:15:65:22:93:5b:72:d7:02:8b:6a:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e462ab3c9df3b7b73e156522935b72d7028b6a11/; sid:902200291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6a:9f:7c:59:90:fb:4d:30:82:65:8b:0e:92:19:47:86:f4:e7:5d:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a9f7c5990fb4d3082658b0e92194786f4e75d4f/; sid:902200292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b7:02:07:35:3e:59:15:ff:28:75:cd:d7:ad:d9:d4:60:90:e5:8b:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b70207353e5915ff2875cdd7add9d46090e58bd5/; sid:902200293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CryptoLocker C&C)"; tls.fingerprint:"09:19:6f:48:ad:7c:4d:14:f4:3e:87:d7:8f:7f:10:40:f5:17:8c:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09196f48ad7c4d14f43e87d78f7f1040f5178c9f/; sid:902200294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"98:d9:e6:2e:6d:2b:66:cd:30:08:d4:c9:3d:c9:a1:b6:5e:18:c7:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98d9e62e6d2b66cd3008d4c93dc9a1b65e18c7c6/; sid:902200295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c8:55:7c:64:19:a8:69:ab:7a:b2:7e:50:a0:93:54:dd:a8:87:f4:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8557c6419a869ab7ab27e50a09354dda887f4d6/; sid:902200296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f8:96:ce:86:54:34:a5:cf:b5:97:8f:05:4f:2a:a9:49:d0:5a:ec:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f896ce865434a5cfb5978f054f2aa949d05aece2/; sid:902200297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c2:1a:07:55:87:8a:55:f9:40:7a:36:4d:21:01:4f:e8:99:f2:17:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c21a0755878a55f9407a364d21014fe899f21770/; sid:902200298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8f:2c:03:95:6c:26:39:5b:0d:d2:16:d1:66:7c:84:0e:a3:ac:de:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f2c03956c26395b0dd216d1667c840ea3acde55/; sid:902200299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"e5:7a:82:a8:a3:81:58:19:43:39:c4:43:61:be:38:5d:3a:fc:74:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e57a82a8a38158194339c44361be385d3afc74d4/; sid:902200300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"df:ce:aa:12:4f:dc:c0:51:15:d3:58:9c:6e:2f:49:36:20:df:59:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfceaa124fdcc05115d3589c6e2f493620df59b9/; sid:902200301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7a:3f:9f:31:4e:4d:99:e0:41:ff:c8:0c:8e:d8:b1:b4:2f:ff:32:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a3f9f314e4d99e041ffc80c8ed8b1b42fff321b/; sid:902200302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5b:03:d8:de:93:10:ac:1b:2b:6f:ed:92:07:49:44:36:fb:82:c2:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b03d8de9310ac1b2b6fed9207494436fb82c21c/; sid:902200303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"65:6b:00:be:7f:39:b4:37:3c:f8:f5:36:32:44:da:84:2d:d4:3f:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/656b00be7f39b4373cf8f5363244da842dd43fb0/; sid:902200304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8f:e0:35:28:d4:6a:fd:e9:e6:e3:e9:52:1c:6e:9d:be:8d:aa:92:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fe03528d46afde9e6e3e9521c6e9dbe8daa92bc/; sid:902200305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"33:f9:91:63:63:58:30:25:79:fd:fb:11:c0:74:ee:00:4c:8f:2a:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33f991636358302579fdfb11c074ee004c8f2a43/; sid:902200306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"d8:af:2f:6a:1a:2b:a2:b1:b6:e1:a2:60:e7:91:fc:ab:88:cc:2c:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8af2f6a1a2ba2b1b6e1a260e791fcab88cc2c8d/; sid:902200307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d4:73:ab:95:f7:4d:75:90:d5:aa:0d:ed:fc:f7:de:64:90:37:1a:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d473ab95f74d7590d5aa0dedfcf7de6490371abc/; sid:902200308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d2:c5:42:57:60:24:a7:46:d4:71:3d:a9:cb:26:38:06:ff:62:f8:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2c542576024a746d4713da9cb263806ff62f8bd/; sid:902200309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"80:38:3b:3a:06:ed:08:15:96:9c:53:56:fb:34:31:94:5f:ac:19:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80383b3a06ed0815969c5356fb3431945fac19b2/; sid:902200310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d5:27:9c:60:9f:96:ab:1e:28:69:83:1a:f5:5f:69:5b:88:e1:15:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5279c609f96ab1e2869831af55f695b88e11552/; sid:902200311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"33:22:7d:25:c8:34:db:b0:73:c5:8c:96:21:6d:0a:6a:6f:8a:e1:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33227d25c834dbb073c58c96216d0a6a6f8ae183/; sid:902200312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"da:a3:1b:ce:58:4f:16:42:50:0b:7a:e2:eb:6f:ed:5b:04:0a:95:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/daa31bce584f1642500b7ae2eb6fed5b040a95c6/; sid:902200313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"34:2d:42:8b:8c:06:1d:e3:5c:3f:5c:5c:ed:44:12:4d:7f:20:fd:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/342d428b8c061de35c3f5c5ced44124d7f20fdc0/; sid:902200314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f1:01:c9:85:f5:3d:55:e5:90:37:e3:2a:90:ca:13:d3:a8:85:53:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f101c985f53d55e59037e32a90ca13d3a8855318/; sid:902200315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"d6:2e:06:53:11:df:fc:ec:ad:9f:8e:92:c3:16:aa:fb:60:19:39:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d62e065311dffcecad9f8e92c316aafb6019394b/; sid:902200316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"8f:9a:5e:3a:7a:21:5a:18:50:14:77:0d:7d:5d:6b:53:7f:49:a1:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f9a5e3a7a215a185014770d7d5d6b537f49a172/; sid:902200317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"96:6c:7b:a7:62:e3:57:d2:47:88:81:76:fd:1d:33:6b:8e:fb:e5:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/966c7ba762e357d247888176fd1d336b8efbe544/; sid:902200318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Upatre C&C)"; tls.fingerprint:"db:2c:df:31:71:d9:2d:90:f1:1f:ec:d2:11:63:59:9f:3c:5f:b7:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db2cdf3171d92d90f11fecd21163599f3c5fb7c4/; sid:902200319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"52:aa:c1:54:07:15:82:b3:2f:b4:e9:f2:ca:19:37:fa:a2:de:d4:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52aac154071582b32fb4e9f2ca1937faa2ded4fb/; sid:902200320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a8:d1:eb:83:6f:40:b6:c9:f4:26:10:29:7e:99:e3:b6:8d:10:66:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8d1eb836f40b6c9f42610297e99e3b68d1066a3/; sid:902200321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"d5:70:21:bf:03:61:6b:89:cd:24:09:b2:3b:36:c6:a4:af:a2:6b:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d57021bf03616b89cd2409b23b36c6a4afa26bd4/; sid:902200322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a6:20:37:da:82:ab:89:61:2d:df:bb:31:50:bb:08:e6:bb:58:a3:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a62037da82ab89612ddfbb3150bb08e6bb58a332/; sid:902200323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"94:81:e6:10:f0:51:8e:48:9c:33:ef:0b:fa:08:b5:65:91:ba:dd:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9481e610f0518e489c33ef0bfa08b56591baddef/; sid:902200324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"82:c7:fe:a2:a9:3a:d0:be:ab:78:41:dc:4a:28:3e:65:ee:90:57:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82c7fea2a93ad0beab7841dc4a283e65ee905736/; sid:902200325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"60:45:18:1f:02:47:74:9d:a4:40:7d:d2:7c:4e:01:2f:b6:ab:4a:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6045181f0247749da4407dd27c4e012fb6ab4a9c/; sid:902200326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"c7:1a:e2:3d:0c:02:23:a2:b2:22:8b:fe:8c:9e:0b:c7:51:57:08:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c71ae23d0c0223a2b2228bfe8c9e0bc75157086a/; sid:902200327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"b4:6e:5c:69:c4:e7:ef:f1:71:8e:0a:9c:b2:18:94:d6:e0:7b:e1:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b46e5c69c4e7eff1718e0a9cb21894d6e07be10e/; sid:902200328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"0d:34:e3:ba:96:35:25:7c:93:56:fb:1d:d9:be:64:b0:c7:a0:8e:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d34e3ba9635257c9356fb1dd9be64b0c7a08ef3/; sid:902200329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a0:c4:d5:41:d7:55:53:fe:96:51:2f:22:99:98:96:b0:ed:fc:73:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0c4d541d75553fe96512f22999896b0edfc735b/; sid:902200330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"0d:8e:5b:2c:b2:2c:0c:3b:1b:b4:cc:9e:ef:3f:a7:47:88:35:11:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d8e5b2cb22c0c3b1bb4cc9eef3fa74788351165/; sid:902200331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"bb:2c:ab:20:d4:7b:84:ff:96:43:2f:51:6d:72:eb:ba:5a:a0:90:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb2cab20d47b84ff96432f516d72ebba5aa09067/; sid:902200332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"9e:1d:7b:d8:6f:bc:e6:09:d0:18:3c:28:27:e4:8b:4c:56:10:7e:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e1d7bd86fbce609d0183c2827e48b4c56107eeb/; sid:902200333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Bebloh C&C)"; tls.fingerprint:"a7:0c:1c:d9:a9:01:28:e6:d5:9a:a0:4b:80:d3:1d:79:01:38:1f:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a70c1cd9a90128e6d59aa04b80d31d7901381f9e/; sid:902200334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"91:6c:55:cb:a3:aa:72:bd:00:00:85:e9:52:f8:e7:f5:fa:f4:38:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/916c55cba3aa72bd000085e952f8e7f5faf438b3/; sid:902200335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"74:72:24:74:09:3f:09:9b:0d:e7:30:77:c5:f2:2d:25:76:07:7c:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/74722474093f099b0de73077c5f22d2576077c3d/; sid:902200336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"07:7c:73:8a:10:d0:ad:2f:7a:74:9a:d4:c9:49:21:bc:b2:97:3e:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/077c738a10d0ad2f7a749ad4c94921bcb2973ed0/; sid:902200337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"4f:32:17:0b:76:e7:a3:93:a6:93:06:bc:dd:e0:27:d2:9c:89:24:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f32170b76e7a393a69306bcdde027d29c8924ec/; sid:902200338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:25:21:2f:60:da:80:90:77:1b:27:40:3c:7f:49:e7:0b:ab:53:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4325212f60da8090771b27403c7f49e70bab53aa/; sid:902200339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d7:91:8e:e6:ee:f0:1a:3c:71:36:de:17:5b:4f:62:eb:45:3b:09:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7918ee6eef01a3c7136de175b4f62eb453b09ed/; sid:902200340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6b:59:04:8f:16:e2:a5:0b:a6:e4:60:1b:42:ba:99:a3:19:5d:2d:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b59048f16e2a50ba6e4601b42ba99a3195d2d1f/; sid:902200341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"07:17:35:e3:46:e3:68:67:f6:bc:89:75:25:d6:db:13:98:c8:65:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/071735e346e36867f6bc897525d6db1398c865b7/; sid:902200342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"75:d1:03:11:e4:0d:bf:0f:a7:fe:4d:de:14:b5:af:8b:3c:ac:77:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75d10311e40dbf0fa7fe4dde14b5af8b3cac77ee/; sid:902200343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7e:fa:f5:f1:db:b6:33:97:57:f5:21:53:93:a5:f1:73:13:48:cd:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7efaf5f1dbb6339757f5215393a5f1731348cdee/; sid:902200344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c5:31:06:8c:e6:27:5a:a3:11:47:5b:f9:ba:54:89:7f:03:db:34:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c531068ce6275aa311475bf9ba54897f03db3498/; sid:902200345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f0:db:8b:dc:4a:5f:12:5b:ea:ca:d8:a3:c6:f2:0e:7f:01:81:54:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0db8bdc4a5f125beacad8a3c6f20e7f018154ba/; sid:902200346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:b7:cd:8a:35:a3:36:d6:5b:db:9b:84:c9:cb:d8:56:ee:84:f7:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ab7cd8a35a336d65bdb9b84c9cbd856ee84f7b0/; sid:902200347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b8:1e:db:ff:b8:89:f6:ca:c8:84:32:fa:15:cb:86:99:eb:3f:42:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b81edbffb889f6cac88432fa15cb8699eb3f42aa/; sid:902200348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"63:c2:1a:c1:aa:d8:dd:be:82:2e:e5:8b:62:56:90:27:19:0e:e3:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63c21ac1aad8ddbe822ee58b62569027190ee3a2/; sid:902200349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"79:24:18:c2:97:20:33:44:55:9c:6a:74:a1:17:5d:33:67:ff:48:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/792418c297203344559c6a74a1175d3367ff4810/; sid:902200350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"33:af:e6:2d:c5:0b:6d:53:05:4b:7d:b3:e8:20:5c:48:ab:53:88:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33afe62dc50b6d53054b7db3e8205c48ab538895/; sid:902200351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b7:8f:69:a4:96:58:dc:63:40:5c:19:82:9f:8d:1c:20:f9:80:11:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b78f69a49658dc63405c19829f8d1c20f98011da/; sid:902200352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5b:1b:69:fc:d2:38:17:df:99:45:05:9b:2e:5d:6f:8a:6a:77:14:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b1b69fcd23817df9945059b2e5d6f8a6a7714d7/; sid:902200353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d8:0a:79:c1:3a:7d:6a:86:9e:e6:59:d9:7c:17:24:53:89:ba:d3:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d80a79c13a7d6a869ee659d97c17245389bad338/; sid:902200354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9e:07:64:b6:a3:8c:a0:0b:41:3e:41:57:40:b9:26:87:26:3b:6e:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e0764b6a38ca00b413e415740b92687263b6e23/; sid:902200355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"54:08:d2:2b:17:86:24:67:23:bd:60:fe:82:fc:f9:30:b4:2b:10:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5408d22b1786246723bd60fe82fcf930b42b10e3/; sid:902200356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:46:0a:72:f8:86:11:c1:fc:d7:f4:d6:93:8c:da:80:c9:4f:9c:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c7460a72f88611c1fcd7f4d6938cda80c94f9c71/; sid:902200357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b9:ea:1c:3b:6b:0e:35:7c:a8:e0:7c:21:47:5d:a3:47:bd:58:31:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9ea1c3b6b0e357ca8e07c21475da347bd5831e1/; sid:902200358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7b:f1:fd:8b:0d:dd:ed:dc:ba:4b:88:1b:d8:b8:d4:e0:fe:42:f3:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7bf1fd8b0dddeddcba4b881bd8b8d4e0fe42f39c/; sid:902200359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"68:17:d3:c8:67:09:96:5f:05:7c:46:54:e9:46:66:ea:bd:28:71:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6817d3c86709965f057c4654e94666eabd2871e4/; sid:902200360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:71:f8:eb:8b:bd:fe:04:05:32:33:27:73:2f:fe:d2:f9:49:23:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0671f8eb8bbdfe0405323327732ffed2f949239a/; sid:902200361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"d5:f0:34:95:3c:a1:c9:e5:0a:6c:0c:45:47:3a:e0:21:d6:fe:7e:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5f034953ca1c9e50a6c0c45473ae021d6fe7e93/; sid:902200362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c6:31:7f:34:1b:09:08:01:e0:2d:81:53:c9:0b:ab:22:c6:6d:a9:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6317f341b090801e02d8153c90bab22c66da9fc/; sid:902200363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ae:67:49:0c:a3:4a:6d:49:48:39:8d:85:c1:a6:b0:30:90:9a:e3:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae67490ca34a6d4948398d85c1a6b030909ae336/; sid:902200364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fe:6c:4a:e2:f3:4e:b1:90:2c:b9:b5:00:63:9b:e4:b2:a1:92:35:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe6c4ae2f34eb1902cb9b500639be4b2a1923540/; sid:902200365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:1b:a6:d9:25:df:f8:4b:63:55:7c:2c:7d:32:d9:ff:5f:a9:30:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d1ba6d925dff84b63557c2c7d32d9ff5fa930c9/; sid:902200366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4a:e4:bf:b1:37:f1:76:a9:ef:e0:7c:07:34:9d:d9:c1:8a:c3:0b:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ae4bfb137f176a9efe07c07349dd9c18ac30bf1/; sid:902200367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7d:2b:10:41:35:40:ac:41:fe:fa:93:30:12:9f:56:c8:cc:51:c9:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d2b10413540ac41fefa9330129f56c8cc51c9ac/; sid:902200368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"40:a5:58:b1:d4:36:ee:b6:be:5f:6a:93:82:84:f4:68:cc:30:a7:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40a558b1d436eeb6be5f6a938284f468cc30a725/; sid:902200369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:48:6e:1b:49:90:a1:e0:f5:4c:29:b5:d6:1e:32:b7:2a:4b:94:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52486e1b4990a1e0f54c29b5d61e32b72a4b94d7/; sid:902200370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:fe:08:46:06:cd:64:5e:20:03:91:ac:52:51:4c:53:05:14:51:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6fe084606cd645e200391ac52514c5305145121/; sid:902200371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"29:78:e9:7b:cc:2d:50:7d:04:d6:4d:f9:31:55:fc:f3:78:a2:29:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2978e97bcc2d507d04d64df93155fcf378a2295d/; sid:902200372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Teslacrypt C&C)"; tls.fingerprint:"a0:af:f4:d8:92:57:8e:75:4b:e0:39:98:62:41:ee:42:4f:dd:56:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0aff4d892578e754be039986241ee424fdd561f/; sid:902200373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"7b:62:ef:2b:59:9c:70:02:be:f6:c9:a6:c0:c8:33:a5:5e:65:fc:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b62ef2b599c7002bef6c9a6c0c833a55e65fcfc/; sid:902200374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5f:98:7a:b1:75:7e:82:af:e2:0f:24:ec:27:18:ff:1e:29:44:67:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f987ab1757e82afe20f24ec2718ff1e294467c5/; sid:902200375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5f:15:b5:0e:24:f1:4e:09:7d:f4:5b:fc:67:d6:c4:4b:a1:31:d6:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f15b50e24f14e097df45bfc67d6c44ba131d673/; sid:902200376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:2c:8b:5a:06:28:52:b5:ea:20:5e:f0:48:22:b5:fc:a9:96:97:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/312c8b5a062852b5ea205ef04822b5fca99697da/; sid:902200377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:84:c7:22:43:01:42:d8:1a:77:1d:0b:ad:6a:0b:33:b9:4b:e9:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a484c722430142d81a771d0bad6a0b33b94be95f/; sid:902200378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c0:b0:6e:ce:e5:d1:ac:b1:a7:f7:b0:7f:9e:a7:50:3c:9e:a5:f4:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0b06ecee5d1acb1a7f7b07f9ea7503c9ea5f4af/; sid:902200379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"30:27:2e:19:92:4b:32:af:5d:e2:3c:b2:95:ec:e5:86:11:78:dd:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30272e19924b32af5de23cb295ece5861178dd2e/; sid:902200380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"86:b7:5b:29:79:87:0b:b5:71:ec:b9:57:34:9f:5e:3c:e1:c9:c2:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86b75b2979870bb571ecb957349f5e3ce1c9c26b/; sid:902200381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"76:0b:b4:76:5c:67:1e:0c:05:7b:77:8d:67:f5:b5:ea:94:70:84:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/760bb4765c671e0c057b778d67f5b5ea947084f9/; sid:902200382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"13:97:72:97:7c:43:96:a9:47:40:49:3c:6a:8e:fc:33:9a:35:16:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/139772977c4396a94740493c6a8efc339a3516c6/; sid:902200383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2b:44:7b:89:61:17:f2:8c:ba:93:6b:56:02:17:0c:78:cf:9c:3b:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b447b896117f28cba936b5602170c78cf9c3b77/; sid:902200384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"6d:8d:d8:af:a5:8b:69:8a:00:d6:3e:51:bd:01:ce:14:6b:0c:c6:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d8dd8afa58b698a00d63e51bd01ce146b0cc67b/; sid:902200385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e3:0c:67:8e:4f:ed:a1:78:83:f8:7f:9f:68:72:6f:6d:3b:30:f1:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e30c678e4feda17883f87f9f68726f6d3b30f151/; sid:902200386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ce:27:0b:de:79:7d:93:85:96:ef:d7:4f:98:34:61:f6:2b:f0:40:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce270bde797d938596efd74f983461f62bf04069/; sid:902200387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ee:b1:80:10:fb:1a:82:61:ed:1a:a5:1a:20:2c:59:a5:77:50:45:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eeb18010fb1a8261ed1aa51a202c59a577504583/; sid:902200388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:f1:79:90:b7:74:1a:84:f0:1a:90:5d:bd:b2:10:32:c1:de:ed:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32f17990b7741a84f01a905dbdb21032c1deeded/; sid:902200389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"89:b0:ee:08:a5:8d:1d:3b:96:2e:9f:f9:62:d1:16:ce:cd:da:fe:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89b0ee08a58d1d3b962e9ff962d116cecddafe06/; sid:902200390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:72:ac:43:cf:28:e6:69:16:27:5b:c2:1b:d8:74:b5:0e:e7:91:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a672ac43cf28e66916275bc21bd874b50ee791f2/; sid:902200391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b0:93:aa:01:28:57:b3:dd:4d:5b:b3:0d:2d:98:b7:c9:77:47:47:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b093aa012857b3dd4d5bb30d2d98b7c9774747ab/; sid:902200392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"49:5d:aa:71:be:4c:93:36:12:72:eb:bb:ce:f6:00:9a:46:fd:de:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/495daa71be4c93361272ebbbcef6009a46fddeaa/; sid:902200393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cb:03:d4:5f:c2:36:6a:1c:c4:b5:66:e3:e0:bb:29:08:40:b9:46:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb03d45fc2366a1cc4b566e3e0bb290840b946f8/; sid:902200394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:97:52:cb:14:be:2d:f6:f2:84:ec:7b:25:15:84:a2:35:34:fd:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a49752cb14be2df6f284ec7b251584a23534fd69/; sid:902200395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"24:c3:bb:e5:42:a9:21:06:a0:e7:31:23:17:11:c3:87:1a:07:c6:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24c3bbe542a92106a0e731231711c3871a07c6a6/; sid:902200396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cc:76:f1:95:7e:9e:aa:f2:01:d6:f1:53:c9:f5:a8:62:b1:7b:92:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc76f1957e9eaaf201d6f153c9f5a862b17b9216/; sid:902200397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0b:0d:83:8a:e8:86:41:2b:31:a3:f6:f0:e9:75:6d:4c:27:5d:be:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b0d838ae886412b31a3f6f0e9756d4c275dbe6c/; sid:902200398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"94:4a:f8:c1:83:6e:b6:71:78:bf:64:f7:79:5b:52:8e:91:3b:e7:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/944af8c1836eb67178bf64f7795b528e913be790/; sid:902200399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"80:dc:ab:9a:1b:68:7f:8f:71:8b:70:07:1c:21:47:7b:62:59:cb:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80dcab9a1b687f8f718b70071c21477b6259cb38/; sid:902200400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a7:e0:7b:ca:12:8b:36:b9:f1:e4:3d:5b:fa:5b:28:eb:74:21:da:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7e07bca128b36b9f1e43d5bfa5b28eb7421dab7/; sid:902200401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"95:0c:b0:cf:d0:a0:86:9a:db:19:fa:00:9d:b7:4b:83:ea:6d:a4:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/950cb0cfd0a0869adb19fa009db74b83ea6da4dd/; sid:902200402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:74:e1:e3:a4:1a:aa:41:1c:b7:53:16:f6:84:59:14:0e:a3:47:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8574e1e3a41aaa411cb75316f68459140ea34798/; sid:902200403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"11:bd:be:13:ce:a3:5d:51:61:4d:f7:cb:ab:70:cc:0a:5b:ce:b3:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11bdbe13cea35d51614df7cbab70cc0a5bceb343/; sid:902200404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:0e:54:4e:3c:27:8a:10:b7:17:f0:d7:91:01:62:1b:a1:99:af:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/770e544e3c278a10b717f0d79101621ba199af27/; sid:902200405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"96:f2:44:cc:92:9e:2d:15:20:2b:c3:4c:df:c2:59:e0:76:e6:08:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96f244cc929e2d15202bc34cdfc259e076e60807/; sid:902200406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ac:b9:6e:00:e0:d8:11:74:2d:72:81:bb:61:61:98:cc:80:3c:37:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acb96e00e0d811742d7281bb616198cc803c371b/; sid:902200407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e3:28:f4:62:dc:20:a7:fa:2c:72:25:ea:8d:08:c4:e5:28:09:9c:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e328f462dc20a7fa2c7225ea8d08c4e528099c34/; sid:902200408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:1e:11:14:f1:78:3a:4a:9a:66:84:31:b0:d6:ac:ea:ca:69:d4:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/311e1114f1783a4a9a668431b0d6aceaca69d4db/; sid:902200409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:16:9e:67:47:3f:6f:ee:d0:c1:fc:48:21:07:e0:83:12:5d:2d:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c7169e67473f6feed0c1fc482107e083125d2dad/; sid:902200410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8d:ab:f9:1f:5c:68:62:35:87:1c:b2:63:aa:4d:70:ac:27:be:53:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dabf91f5c686235871cb263aa4d70ac27be5316/; sid:902200411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:4f:e8:34:a2:e4:cd:b4:3c:f5:c9:2e:a4:8d:4d:84:48:7e:ea:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c14fe834a2e4cdb43cf5c92ea48d4d84487eea5b/; sid:902200412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2a:1b:79:49:57:61:dc:5b:b0:cc:20:10:06:0c:5b:d7:a4:7f:11:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a1b79495761dc5bb0cc2010060c5bd7a47f1129/; sid:902200413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5e:fd:89:f9:dd:a9:bb:ec:ec:26:6c:f0:a5:c5:dd:65:8f:c8:4b:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5efd89f9dda9bbecec266cf0a5c5dd658fc84b03/; sid:902200414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:9d:05:bc:51:e2:53:d6:d2:86:75:63:0d:1e:ac:2f:1e:1f:f4:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/859d05bc51e253d6d28675630d1eac2f1e1ff4ae/; sid:902200415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ac:5c:1f:1a:a5:75:3d:f8:2a:1d:58:7d:3c:d8:41:50:69:61:3b:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac5c1f1aa5753df82a1d587d3cd8415069613b61/; sid:902200416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e8:0d:4f:88:e3:02:96:41:a4:4b:02:3a:5f:da:1f:95:d5:0d:5e:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e80d4f88e3029641a44b023a5fda1f95d50d5e40/; sid:902200417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"17:ff:78:8a:e0:4c:e1:0d:27:8a:40:d0:e1:e8:cc:ab:1d:0d:c8:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17ff788ae04ce10d278a40d0e1e8ccab1d0dc8f8/; sid:902200418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"66:c8:25:a3:64:01:15:b3:00:ea:ac:b7:8b:6d:09:8f:d1:43:92:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66c825a3640115b300eaacb78b6d098fd14392a6/; sid:902200419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:23:5d:bb:db:7a:42:ad:7c:01:9a:53:2e:41:3d:69:f4:10:a5:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4235dbbdb7a42ad7c019a532e413d69f410a512/; sid:902200420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:50:df:98:2f:35:fa:42:85:de:8c:7e:c8:31:e1:13:34:e8:70:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7750df982f35fa4285de8c7ec831e11334e87067/; sid:902200421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8d:9d:aa:2c:bc:90:6d:69:2f:8f:5d:40:e2:9c:4d:ec:b2:63:b9:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d9daa2cbc906d692f8f5d40e29c4decb263b979/; sid:902200422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"53:36:38:1a:24:6b:84:8e:4d:ab:1f:24:8f:c7:5c:d4:b5:ce:71:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5336381a246b848e4dab1f248fc75cd4b5ce71f3/; sid:902200423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"db:cc:6a:0b:a2:f3:6e:c9:0e:83:ae:df:59:d5:1d:49:52:53:30:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbcc6a0ba2f36ec90e83aedf59d51d4952533021/; sid:902200424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"65:05:8a:2a:00:3f:61:57:2c:da:96:11:79:7f:59:6a:20:39:e1:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65058a2a003f61572cda9611797f596a2039e104/; sid:902200425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dd:ab:8f:63:91:e8:55:c7:51:ee:82:56:62:bd:83:c9:cf:2d:9b:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddab8f6391e855c751ee825662bd83c9cf2d9bc3/; sid:902200426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"62:58:62:1f:ec:54:d5:04:f5:1a:16:67:85:da:5a:53:69:c0:ad:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6258621fec54d504f51a166785da5a5369c0ad72/; sid:902200427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"70:bf:60:e1:72:c4:3d:07:65:71:cf:af:bb:a3:a6:ba:69:a2:50:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70bf60e172c43d076571cfafbba3a6ba69a25084/; sid:902200428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:6d:4a:34:93:83:50:62:51:ff:d9:00:21:46:d2:a3:82:17:ba:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c76d4a349383506251ffd9002146d2a38217bacd/; sid:902200429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d1:a2:e7:ae:91:82:1e:3e:ba:c4:61:a0:8d:c0:dd:cf:6b:3c:a5:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1a2e7ae91821e3ebac461a08dc0ddcf6b3ca5ae/; sid:902200430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:66:cb:87:70:90:cf:88:42:0b:34:14:a3:bf:01:b4:fa:50:fb:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d66cb877090cf88420b3414a3bf01b4fa50fb47/; sid:902200431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:07:22:8a:2e:bf:2c:43:b4:41:5f:33:71:77:a8:25:ee:8f:e1:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3707228a2ebf2c43b4415f337177a825ee8fe108/; sid:902200432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"da:6f:f7:d6:34:3c:a2:18:e7:1f:ce:ff:e1:c8:44:98:15:5f:26:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da6ff7d6343ca218e71fceffe1c84498155f2671/; sid:902200433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"1c:3b:c6:ee:bb:13:6c:6c:cc:af:bd:2f:86:f6:92:10:d3:50:1a:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c3bc6eebb136c6cccafbd2f86f69210d3501ade/; sid:902200434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"a0:60:d4:3f:58:4a:7d:2f:83:8b:6d:64:af:f4:07:6d:f7:66:a1:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a060d43f584a7d2f838b6d64aff4076df766a1b9/; sid:902200435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e4:38:5d:6d:86:14:c0:19:e9:20:b8:b3:65:0b:aa:36:54:b6:f1:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4385d6d8614c019e920b8b3650baa3654b6f17b/; sid:902200436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a4:8a:dd:c4:95:83:a5:fa:52:a2:34:b1:48:f8:16:13:38:e2:76:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a48addc49583a5fa52a234b148f8161338e27617/; sid:902200437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:49:77:b9:06:34:9c:aa:ad:8a:fa:2a:88:84:dd:29:50:ef:da:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef4977b906349caaad8afa2a8884dd2950efda5f/; sid:902200438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c5:16:d4:4f:19:2c:7e:72:9f:f9:31:55:f3:57:cc:58:2c:f3:b5:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c516d44f192c7e729ff93155f357cc582cf3b57b/; sid:902200439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6f:c7:fe:77:aa:ac:09:d0:78:cb:50:03:9e:c5:07:f9:64:08:25:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fc7fe77aaac09d078cb50039ec507f964082583/; sid:902200440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"80:00:f0:35:54:af:7c:c9:fe:d8:35:1f:33:e4:21:b0:bd:37:09:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8000f03554af7cc9fed8351f33e421b0bd37095d/; sid:902200441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b5:84:2e:89:2e:61:be:e8:44:e3:0e:18:2c:76:24:3f:26:af:3e:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5842e892e61bee844e30e182c76243f26af3eed/; sid:902200442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1f:ca:dc:65:37:b3:65:be:3a:e9:fb:fb:7d:60:09:8b:9e:2d:e3:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fcadc6537b365be3ae9fbfb7d60098b9e2de3d2/; sid:902200443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (URLzone C&C)"; tls.fingerprint:"88:79:53:50:50:fd:1e:97:2c:eb:9c:42:b7:17:e6:6a:c6:c6:77:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8879535050fd1e972ceb9c42b717e66ac6c677ea/; sid:902200444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:66:5d:2d:cd:5b:06:c8:c1:3d:aa:53:d2:f0:e0:8b:0d:27:39:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9665d2dcd5b06c8c13daa53d2f0e08b0d27398f/; sid:902200445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f9:95:d2:f8:ae:c2:f6:1d:f3:a2:0c:1f:79:3f:c3:be:d7:ad:8b:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f995d2f8aec2f61df3a20c1f793fc3bed7ad8b17/; sid:902200446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:04:0d:10:2d:b2:f8:6e:04:0c:59:ba:39:07:d5:87:47:66:c2:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06040d102db2f86e040c59ba3907d5874766c2fe/; sid:902200447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"22:83:5d:47:11:26:0c:fc:cf:64:4e:12:0f:00:72:22:ca:02:89:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22835d4711260cfccf644e120f007222ca02896a/; sid:902200448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:3f:ff:43:29:96:f0:50:cf:f7:30:4b:0b:74:f5:24:8c:e0:c0:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/453fff432996f050cff7304b0b74f5248ce0c036/; sid:902200449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"99:d9:d0:1f:47:81:e0:e4:d1:b2:a7:3c:fd:d6:aa:02:6a:8d:2c:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99d9d01f4781e0e4d1b2a73cfdd6aa026a8d2ca9/; sid:902200450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"9d:95:f5:40:06:41:b5:77:38:00:e4:ad:17:7a:04:ca:d2:3f:cb:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d95f5400641b5773800e4ad177a04cad23fcb0e/; sid:902200451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"e9:06:41:28:b5:5d:fa:f0:7a:cb:7a:ae:0f:cd:76:28:09:00:82:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9064128b55dfaf07acb7aae0fcd7628090082e2/; sid:902200452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"a8:fb:10:cb:9a:22:23:72:64:6f:0b:7b:3a:6e:4d:22:8e:f2:54:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8fb10cb9a222372646f0b7b3a6e4d228ef254d3/; sid:902200453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"9e:dc:51:f3:bc:90:0c:7e:ff:23:42:76:d5:d9:8b:58:05:64:4e:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9edc51f3bc900c7eff234276d5d98b5805644e12/; sid:902200454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"66:a6:06:ec:3f:33:58:d2:c0:59:1f:cb:67:c2:31:15:0c:6e:0c:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66a606ec3f3358d2c0591fcb67c231150c6e0cff/; sid:902200455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"79:c5:db:e0:7d:5e:14:a3:82:98:79:16:a2:d9:ee:af:c4:1d:14:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79c5dbe07d5e14a382987916a2d9eeafc41d1441/; sid:902200456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:66:36:72:e3:46:b9:1c:83:c3:bc:e7:4c:fa:14:09:8c:7e:44:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77663672e346b91c83c3bce74cfa14098c7e445c/; sid:902200457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"eb:30:fa:30:a7:67:2b:b5:9f:d5:f8:18:68:4f:5a:17:05:47:8f:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb30fa30a7672bb59fd5f818684f5a1705478f8a/; sid:902200458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"74:5d:36:f3:e1:ca:7f:ec:7f:b3:a4:9e:cf:05:77:b9:58:4f:26:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/745d36f3e1ca7fec7fb3a49ecf0577b9584f2611/; sid:902200459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ab:97:71:87:48:d7:9a:4c:f9:00:b0:35:4b:e1:ae:9a:81:b4:d0:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab97718748d79a4cf900b0354be1ae9a81b4d05a/; sid:902200460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"62:48:f3:db:15:be:70:ce:eb:c2:1c:91:62:fb:af:71:4b:1b:c8:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6248f3db15be70ceebc21c9162fbaf714b1bc828/; sid:902200461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"90:44:95:e3:01:22:d3:7a:39:06:3b:cb:10:ba:ee:db:3b:ca:3a:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/904495e30122d37a39063bcb10baeedb3bca3ae8/; sid:902200462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b4:95:26:5f:c8:f9:96:6e:bd:9d:f7:58:9a:14:65:9e:91:ea:e6:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b495265fc8f9966ebd9df7589a14659e91eae6e4/; sid:902200463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"28:d4:1a:17:8f:3b:b4:56:35:57:59:c2:f2:fe:97:28:d1:32:6d:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28d41a178f3bb456355759c2f2fe9728d1326d89/; sid:902200464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"15:cc:6b:ca:1f:1e:ee:15:76:92:4b:ca:a9:3d:8a:f2:9f:25:95:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15cc6bca1f1eee1576924bcaa93d8af29f259512/; sid:902200465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c9:be:dd:d9:e8:61:e8:01:f9:db:a5:36:d6:64:2b:03:35:fa:9a:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9beddd9e861e801f9dba536d6642b0335fa9ae2/; sid:902200466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ab:e4:dc:7a:9c:30:07:9a:7c:3a:ff:46:03:f9:b1:fb:28:75:65:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abe4dc7a9c30079a7c3aff4603f9b1fb28756548/; sid:902200467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5f:0d:1d:72:50:d7:be:fb:91:8b:b4:7e:fa:9c:75:ed:05:6d:e1:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f0d1d7250d7befb918bb47efa9c75ed056de188/; sid:902200468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f0:f4:f4:39:f6:4b:13:a4:4c:2a:74:9f:0e:95:21:5a:bb:29:4d:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0f4f439f64b13a44c2a749f0e95215abb294de0/; sid:902200469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f7:5f:18:9d:71:ea:ba:d8:7e:b8:88:18:f5:66:a1:ea:96:da:0c:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f75f189d71eabad87eb88818f566a1ea96da0c67/; sid:902200470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"97:ff:7b:e1:c1:d9:ac:2b:ea:ce:12:2d:d4:63:a2:f7:aa:2d:f5:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97ff7be1c1d9ac2beace122dd463a2f7aa2df5d7/; sid:902200471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d9:19:06:10:dd:07:25:db:8e:d2:25:89:e5:16:f5:40:78:a0:84:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9190610dd0725db8ed22589e516f54078a08402/; sid:902200472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d8:6d:c7:2a:a6:41:bb:dc:ee:8e:f7:ea:c4:a8:7a:67:cb:6d:eb:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d86dc72aa641bbdcee8ef7eac4a87a67cb6deb71/; sid:902200473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:77:70:50:b2:8f:31:b8:4b:d2:78:05:1e:9e:4a:39:1a:14:52:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15777050b28f31b84bd278051e9e4a391a145237/; sid:902200474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e0:43:57:f4:44:91:51:ec:42:01:13:ca:90:96:64:57:9c:cc:2b:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e04357f4449151ec420113ca909664579ccc2b45/; sid:902200475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"de:98:0d:b3:a9:f4:c4:fe:34:d8:ab:ed:0e:ae:96:53:cc:83:20:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de980db3a9f4c4fe34d8abed0eae9653cc83206e/; sid:902200476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ad:09:e4:2a:d8:62:e9:f6:b5:3f:ee:3d:f0:aa:bd:9b:0c:b9:33:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad09e42ad862e9f6b53fee3df0aabd9b0cb933c7/; sid:902200477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1f:f6:15:65:f9:df:63:c8:53:01:5b:b2:30:58:18:6b:6c:60:a2:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ff61565f9df63c853015bb23058186b6c60a221/; sid:902200478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"33:fe:78:09:ab:2d:77:cc:ea:19:e1:12:5f:b3:64:63:22:a9:40:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33fe7809ab2d77ccea19e1125fb3646322a940de/; sid:902200479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"c8:40:1f:25:32:2f:66:07:e5:bc:12:2c:de:ce:95:c2:cc:b8:15:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8401f25322f6607e5bc122cdece95c2ccb8157b/; sid:902200480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:b8:61:6d:11:6b:0b:cf:ee:fc:3a:1b:15:dd:e6:e0:04:f8:cc:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ceb8616d116b0bcfeefc3a1b15dde6e004f8cc1a/; sid:902200481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:6a:4e:a8:03:df:4d:10:e6:61:eb:b5:6d:80:11:91:f1:36:1f:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a6a4ea803df4d10e661ebb56d801191f1361f85/; sid:902200482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ed:cc:10:3b:b4:e4:6e:06:33:5f:27:c6:a1:7a:4d:90:19:b5:30:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edcc103bb4e46e06335f27c6a17a4d9019b5303f/; sid:902200483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"35:d5:b5:e8:2c:f6:3f:0c:d4:7f:61:54:da:2e:98:41:1c:11:8d:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35d5b5e82cf63f0cd47f6154da2e98411c118d7c/; sid:902200484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"35:83:d5:1f:40:32:9a:49:28:2b:52:ba:fc:82:51:d5:55:31:fa:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3583d51f40329a49282b52bafc8251d55531faa1/; sid:902200485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b1:0e:88:78:f9:db:24:8f:76:33:d3:56:9d:37:e4:83:c9:f9:6a:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b10e8878f9db248f7633d3569d37e483c9f96a7c/; sid:902200486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"40:e7:43:05:79:0c:9e:5b:76:11:56:74:61:26:d9:61:d0:29:23:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40e74305790c9e5b761156746126d961d029231c/; sid:902200487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"24:33:7a:9f:03:cf:23:b9:64:52:b1:9c:0d:1f:2e:10:5e:ea:f3:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24337a9f03cf23b96452b19c0d1f2e105eeaf3f2/; sid:902200488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"10:ee:62:a1:a2:d3:69:e3:a5:b5:5f:7c:71:27:3a:fd:42:4f:08:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10ee62a1a2d369e3a5b55f7c71273afd424f08d0/; sid:902200489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"09:1e:d0:a8:eb:aa:cf:33:67:75:5c:39:a0:4b:e6:9f:d7:aa:fc:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/091ed0a8ebaacf3367755c39a04be69fd7aafc57/; sid:902200490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3a:b5:71:e1:e3:dd:b3:c0:b7:17:5d:75:eb:23:8e:6c:69:39:0b:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ab571e1e3ddb3c0b7175d75eb238e6c69390b4b/; sid:902200491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ee:14:e4:ab:0b:24:3b:39:73:15:e0:94:93:5f:5b:74:a6:7a:1b:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee14e4ab0b243b397315e094935f5b74a67a1bc7/; sid:902200492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fa:ae:5e:0e:b6:41:f1:eb:53:02:1a:6d:1b:38:b9:fd:ce:be:a8:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/faae5e0eb641f1eb53021a6d1b38b9fdcebea8a4/; sid:902200493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b2:1c:95:17:c2:f5:3c:eb:db:f1:f0:a1:a7:82:52:a4:75:b7:9d:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b21c9517c2f53cebdbf1f0a1a78252a475b79d61/; sid:902200494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:ab:47:e5:22:c3:b5:60:06:18:42:7d:b5:c5:70:a0:cf:2f:1d:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45ab47e522c3b5600618427db5c570a0cf2f1db7/; sid:902200495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"93:d8:98:7e:b1:ca:50:c3:33:6a:a7:82:58:50:3f:8f:24:b1:6b:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93d8987eb1ca50c3336aa78258503f8f24b16bb7/; sid:902200496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1e:a6:cd:bb:0e:9f:e7:84:f4:82:b3:30:ea:1d:ab:af:de:31:c8:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ea6cdbb0e9fe784f482b330ea1dabafde31c80f/; sid:902200497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0b:f4:17:e3:aa:ee:82:0b:c6:3a:92:b3:d7:56:aa:cd:d5:ab:3b:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bf417e3aaee820bc63a92b3d756aacdd5ab3b6b/; sid:902200498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"23:1a:ba:69:dc:9e:f4:b0:c6:1c:9f:c0:3e:ef:37:f6:e7:8d:8b:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/231aba69dc9ef4b0c61c9fc03eef37f6e78d8b07/; sid:902200499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:23:b6:60:99:9d:e4:2f:be:72:b0:40:a4:dd:48:9e:46:2a:64:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c723b660999de42fbe72b040a4dd489e462a6407/; sid:902200500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"7b:33:53:c2:05:15:5b:2a:a6:53:35:12:74:a4:bf:a8:3b:1c:2b:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b3353c205155b2aa653351274a4bfa83b1c2b62/; sid:902200501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"db:49:fc:d4:49:e1:b2:14:df:69:39:e1:69:16:de:f5:06:cc:aa:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db49fcd449e1b214df6939e16916def506ccaacb/; sid:902200502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"f2:6e:1b:10:fd:c4:1c:56:9a:7f:ae:19:b8:f8:46:43:64:12:97:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f26e1b10fdc41c569a7fae19b8f84643641297a0/; sid:902200503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"81:7f:60:e0:ce:d4:15:d1:7a:26:9d:b2:f9:b7:b3:0f:25:b1:10:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/817f60e0ced415d17a269db2f9b7b30f25b110d1/; sid:902200504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0b:2d:46:9d:03:93:71:c3:bc:c2:be:00:c9:a9:f4:17:84:09:2c:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b2d469d039371c3bcc2be00c9a9f41784092ced/; sid:902200505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"df:62:ac:9a:fd:be:a3:06:ff:d2:ce:eb:c9:cf:11:84:66:71:3e:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df62ac9afdbea306ffd2ceebc9cf118466713e6e/; sid:902200506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c0:34:ba:b6:7b:6d:cb:77:63:89:b7:74:4d:78:ab:14:82:de:4c:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c034bab67b6dcb776389b7744d78ab1482de4cfb/; sid:902200507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e7:ca:9d:1b:7f:12:68:b7:a8:b5:18:00:9c:db:7b:01:cd:04:bf:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7ca9d1b7f1268b7a8b518009cdb7b01cd04bf7d/; sid:902200508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"74:2d:e1:81:8c:41:b6:63:96:ed:96:28:6e:60:1c:3a:58:33:69:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/742de1818c41b66396ed96286e601c3a58336950/; sid:902200509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:b0:ff:55:4b:64:9e:e6:db:9f:e6:bc:23:ec:2b:7d:56:1a:72:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32b0ff554b649ee6db9fe6bc23ec2b7d561a7276/; sid:902200510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:9d:5e:e8:0e:79:05:8e:35:ca:9d:ae:77:52:fe:40:7d:60:f8:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c79d5ee80e79058e35ca9dae7752fe407d60f8c6/; sid:902200511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:b0:e8:96:42:bb:b6:0b:69:8f:16:61:c1:53:6c:0e:46:72:9d:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6b0e89642bbb60b698f1661c1536c0e46729d8c/; sid:902200512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:7b:76:81:f2:a8:5d:9c:8d:f7:e8:0b:8d:ea:f1:ac:2b:92:e5:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a67b7681f2a85d9c8df7e80b8deaf1ac2b92e5cb/; sid:902200513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d0:b3:d0:f1:04:33:9b:b2:8e:f3:f1:6e:6a:32:1f:44:61:34:11:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0b3d0f104339bb28ef3f16e6a321f44613411a7/; sid:902200514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ba:a0:45:6c:53:39:b1:d1:f8:8a:92:b0:77:ce:09:b4:2c:69:15:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/baa0456c5339b1d1f88a92b077ce09b42c6915c4/; sid:902200515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"83:53:6e:03:92:e3:bf:a7:8a:09:0f:74:9e:00:71:6a:ee:47:f1:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83536e0392e3bfa78a090f749e00716aee47f192/; sid:902200516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e1:bc:1a:01:09:68:a6:54:9f:67:c3:08:ef:77:9d:49:99:e0:c6:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1bc1a010968a6549f67c308ef779d4999e0c687/; sid:902200517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c0:d8:ce:57:5c:67:97:35:65:17:d8:49:1a:83:d3:06:1d:b6:32:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0d8ce575c6797356517d8491a83d3061db6323b/; sid:902200518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5b:8a:6e:1e:07:14:fd:71:83:60:92:fb:be:bf:49:24:3a:97:a3:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b8a6e1e0714fd71836092fbbebf49243a97a376/; sid:902200519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:de:99:5a:24:69:c6:fd:5f:43:4b:1e:9a:32:87:99:55:89:26:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52de995a2469c6fd5f434b1e9a328799558926c9/; sid:902200520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"55:ac:d5:43:d5:6a:be:c1:95:6f:2d:5a:0b:29:e1:19:bd:d8:a0:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55acd543d56abec1956f2d5a0b29e119bdd8a0e6/; sid:902200521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b1:0c:7d:8d:08:29:5f:4f:67:38:64:6d:a8:c1:dc:d0:c3:bb:fd:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b10c7d8d08295f4f6738646da8c1dcd0c3bbfd5f/; sid:902200522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"18:ba:0e:66:d5:ee:92:1e:ae:0c:ee:4d:2e:d0:bb:fa:9a:6a:5b:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18ba0e66d5ee921eae0cee4d2ed0bbfa9a6a5b07/; sid:902200523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"3e:34:0d:99:e7:4c:1f:8d:ee:34:11:c6:4d:d6:ea:81:09:93:2a:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e340d99e74c1f8dee3411c64dd6ea8109932af6/; sid:902200524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"8c:8e:66:96:1f:f0:98:41:52:9b:b7:bc:1f:09:1f:1e:7e:d8:ef:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c8e66961ff09841529bb7bc1f091f1e7ed8ef7a/; sid:902200525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:b8:b7:ab:d0:7e:7d:b8:75:d5:c2:49:5f:50:74:d1:bc:14:97:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43b8b7abd07e7db875d5c2495f5074d1bc1497c9/; sid:902200526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0d:ee:2d:a9:fc:68:30:90:18:44:64:da:30:44:ff:12:96:9e:76:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dee2da9fc683090184464da3044ff12969e76d8/; sid:902200527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dc:9d:fd:a5:14:6d:ce:11:bd:46:bc:47:52:79:8e:43:a5:ed:f9:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc9dfda5146dce11bd46bc4752798e43a5edf9d1/; sid:902200528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e8:4a:7f:1d:e9:75:66:78:ae:f5:10:89:4b:4e:5d:6d:5c:10:ee:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e84a7f1de9756678aef510894b4e5d6d5c10ee3c/; sid:902200529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3d:74:1f:f6:72:58:60:f0:b4:06:f4:34:be:a7:8c:f9:ea:71:05:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d741ff6725860f0b406f434bea78cf9ea71059b/; sid:902200530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"26:62:e2:32:d7:da:6e:f5:21:3e:36:22:75:a0:5f:c2:36:ad:9e:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2662e232d7da6ef5213e362275a05fc236ad9e95/; sid:902200531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5a:c8:25:9f:39:89:ba:8c:51:5f:6c:a9:70:61:36:8f:5b:ab:21:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ac8259f3989ba8c515f6ca97061368f5bab216d/; sid:902200532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"80:ff:fe:d8:49:f6:15:fd:53:1d:74:e5:e6:b3:26:e4:f0:18:df:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80fffed849f615fd531d74e5e6b326e4f018dfc6/; sid:902200533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"9e:86:13:8b:10:96:0d:54:b3:f7:1b:87:d6:bf:c1:59:82:da:9c:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e86138b10960d54b3f71b87d6bfc15982da9c71/; sid:902200534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dc:0b:37:2e:de:bd:eb:bf:28:29:99:87:4e:91:a1:39:e0:53:80:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc0b372edebdebbf282999874e91a139e0538006/; sid:902200535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"72:89:4e:2a:58:90:e7:60:5e:82:ef:bd:83:ea:b6:93:c3:1a:e3:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72894e2a5890e7605e82efbd83eab693c31ae363/; sid:902200536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a1:95:7e:2d:fc:19:e1:bb:4c:00:7c:af:29:92:3f:79:f4:27:a4:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1957e2dfc19e1bb4c007caf29923f79f427a454/; sid:902200537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"09:82:f8:4f:7b:7f:a7:c4:3a:01:2c:62:c3:ee:a6:a9:6c:08:1a:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0982f84f7b7fa7c43a012c62c3eea6a96c081a54/; sid:902200538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9a:27:ca:bc:e7:43:85:be:bf:0e:9e:41:d8:34:e9:c1:ed:22:39:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a27cabce74385bebf0e9e41d834e9c1ed223985/; sid:902200539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"83:a4:19:c1:b4:9a:13:f1:34:a8:0f:c8:af:96:88:69:16:3f:80:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83a419c1b49a13f134a80fc8af968869163f8022/; sid:902200540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"61:17:28:f5:23:c6:32:70:4d:53:75:1a:5c:42:ba:f6:51:77:d3:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/611728f523c632704d53751a5c42baf65177d30d/; sid:902200541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f9:c0:6e:bd:72:8d:0a:14:0e:4d:89:9a:db:95:d9:76:93:44:5c:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9c06ebd728d0a140e4d899adb95d97693445c2b/; sid:902200542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"de:ae:cc:4f:ca:be:ab:05:a4:fd:7a:8e:2f:63:16:c9:74:be:6a:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/deaecc4fcabeab05a4fd7a8e2f6316c974be6a40/; sid:902200543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"6d:98:de:4a:ab:c3:3b:d1:05:28:b7:3b:63:3a:d4:9c:e2:4f:57:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d98de4aabc33bd10528b73b633ad49ce24f5704/; sid:902200544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a0:34:09:58:22:b2:cf:fb:eb:96:35:32:1d:c5:24:a5:7e:03:bb:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a034095822b2cffbeb9635321dc524a57e03bb64/; sid:902200545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"8d:68:01:db:f5:3b:1e:0e:90:42:b6:d4:63:b5:18:00:f4:32:5d:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d6801dbf53b1e0e9042b6d463b51800f4325d42/; sid:902200546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"17:b2:d2:6a:23:5d:92:f3:1a:99:2f:85:f2:48:3d:7f:fa:6d:21:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17b2d26a235d92f31a992f85f2483d7ffa6d2109/; sid:902200547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"af:c7:31:e5:e4:e6:36:a7:0e:20:78:38:2c:ce:17:0e:f8:3d:93:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/afc731e5e4e636a70e2078382cce170ef83d93f6/; sid:902200548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"68:f0:a2:ef:0a:7e:ad:c2:e0:55:20:33:27:30:9b:a7:ab:db:8b:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68f0a2ef0a7eadc2e055203327309ba7abdb8b61/; sid:902200549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"33:3e:21:5f:80:54:80:e6:de:39:23:1b:96:fe:6a:64:e9:61:1a:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/333e215f805480e6de39231b96fe6a64e9611a22/; sid:902200550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"df:78:b0:19:bc:29:8b:c9:72:17:be:e6:23:27:fc:c6:97:0a:e4:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df78b019bc298bc97217bee62327fcc6970ae454/; sid:902200551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ec:e7:82:a8:8b:93:78:cb:bf:de:68:e0:4c:05:dd:38:d3:a0:c0:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ece782a88b9378cbbfde68e04c05dd38d3a0c083/; sid:902200552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:4d:11:4b:d3:4c:45:31:d0:29:9c:45:68:de:78:82:58:27:62:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/064d114bd34c4531d0299c4568de78825827622b/; sid:902200553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8e:ed:a1:8c:f9:78:e7:8b:71:c6:79:f3:7b:d4:88:69:f0:c6:fd:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8eeda18cf978e78b71c679f37bd48869f0c6fd2a/; sid:902200554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"af:8a:fb:ec:4b:5d:44:13:db:8d:55:cc:db:53:53:62:80:c9:0e:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af8afbec4b5d4413db8d55ccdb53536280c90eca/; sid:902200555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f7:21:1b:18:8b:6a:23:41:b6:19:d6:0e:99:be:44:89:18:98:aa:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7211b188b6a2341b619d60e99be44891898aacd/; sid:902200556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0e:da:9c:1b:f5:f4:ac:1f:5b:d4:4e:b9:3d:8e:7b:f0:ac:f3:a6:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0eda9c1bf5f4ac1f5bd44eb93d8e7bf0acf3a691/; sid:902200557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e1:44:d9:51:84:b1:3e:6f:3b:86:a7:ad:d4:d4:68:7d:ec:ef:b7:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e144d95184b13e6f3b86a7add4d4687decefb775/; sid:902200558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"90:e1:fa:60:b7:2f:0a:d0:e0:96:4e:d4:0c:dc:ba:c7:5b:4c:53:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90e1fa60b72f0ad0e0964ed40cdcbac75b4c53ee/; sid:902200559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"f9:3a:7f:2c:a1:46:31:40:ca:6d:7e:f4:cd:6b:11:67:4e:86:9f:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f93a7f2ca1463140ca6d7ef4cd6b11674e869fb5/; sid:902200560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"16:a9:f4:dd:4f:35:98:b6:cf:ed:52:bf:b1:07:6c:99:0c:cd:b4:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16a9f4dd4f3598b6cfed52bfb1076c990ccdb451/; sid:902200561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"18:39:8c:aa:d8:e2:f8:68:a6:9d:e8:dc:e0:7f:1e:cc:07:55:a3:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18398caad8e2f868a69de8dce07f1ecc0755a32c/; sid:902200562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1e:3a:36:9a:a3:16:16:2e:31:b7:7d:67:90:37:0f:a9:91:3b:81:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e3a369aa316162e31b77d6790370fa9913b8129/; sid:902200563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"74:9a:64:dc:10:32:e0:b0:e7:33:37:07:52:e3:5c:0e:61:50:b3:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/749a64dc1032e0b0e733370752e35c0e6150b36e/; sid:902200564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"eb:f5:c5:c6:13:40:0d:9b:16:8b:71:13:95:e8:c5:a6:a1:64:7e:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebf5c5c613400d9b168b711395e8c5a6a1647e6a/; sid:902200565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4b:05:9a:6d:dd:ed:fc:62:a0:05:84:47:86:72:fa:cb:d9:f2:e3:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b059a6dddedfc62a00584478672facbd9f2e3fc/; sid:902200566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5e:7c:23:95:41:ad:a7:23:0e:39:b6:fc:2e:61:b6:7f:fd:e9:10:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e7c239541ada7230e39b6fc2e61b67ffde91007/; sid:902200567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"69:dd:95:de:03:db:de:5e:b2:0f:ef:55:99:65:fe:d5:2f:7d:e1:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69dd95de03dbde5eb20fef559965fed52f7de1a6/; sid:902200568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ad:93:01:53:6b:b9:4d:13:21:1c:f3:f7:ed:3e:13:0d:29:51:19:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad9301536bb94d13211cf3f7ed3e130d295119bb/; sid:902200569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"99:b5:cd:c1:50:38:99:e6:53:2e:e8:2d:dc:2e:42:d5:9b:cb:62:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99b5cdc1503899e6532ee82ddc2e42d59bcb6284/; sid:902200570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dc:dc:9d:5c:a9:4a:aa:2b:39:78:8c:7b:67:5e:b2:43:12:72:60:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dcdc9d5ca94aaa2b39788c7b675eb243127260ee/; sid:902200571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3c:77:21:8c:95:f0:42:53:02:92:b8:41:a2:88:77:23:e0:d0:21:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c77218c95f042530292b841a2887723e0d02140/; sid:902200572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6c:31:e6:10:3f:87:93:43:55:f7:dc:02:ef:9e:d4:86:bf:52:e2:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c31e6103f87934355f7dc02ef9ed486bf52e2da/; sid:902200573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"e1:b8:af:16:6d:6e:0e:1c:89:9a:97:d5:05:18:da:ff:e6:95:12:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1b8af166d6e0e1c899a97d50518daffe69512d1/; sid:902200574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"09:64:b8:56:b1:cb:35:9a:fb:5a:f8:7f:d6:f7:31:c8:70:c4:8d:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0964b856b1cb359afb5af87fd6f731c870c48d00/; sid:902200575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"d3:51:60:25:e2:4d:d3:fd:8f:d4:4a:91:15:82:43:cc:53:f0:c5:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3516025e24dd3fd8fd44a91158243cc53f0c547/; sid:902200576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"2e:f0:06:ec:84:c0:e6:ba:ac:9a:bb:9c:58:5a:97:d4:c4:32:13:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ef006ec84c0e6baac9abb9c585a97d4c43213f6/; sid:902200577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"86:7f:3d:92:48:28:f9:3b:0b:d3:06:41:df:b0:1d:51:35:1a:ea:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/867f3d924828f93b0bd30641dfb01d51351aeac9/; sid:902200578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7c:6b:fe:ac:60:44:09:17:13:8d:95:72:57:1e:ad:8a:77:2c:18:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c6bfeac60440917138d9572571ead8a772c184e/; sid:902200579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"71:0a:38:7e:98:a6:02:ca:0b:30:97:ff:d3:ee:f2:13:5c:23:e5:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/710a387e98a602ca0b3097ffd3eef2135c23e5fb/; sid:902200580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:17:2a:66:a2:a6:d7:e9:9a:31:73:90:b7:5c:6a:d9:a9:bd:b8:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38172a66a2a6d7e99a317390b75c6ad9a9bdb8e7/; sid:902200581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d9:f5:2c:1e:e0:27:70:88:b7:14:1e:d9:7f:86:ea:0b:9f:b6:f1:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9f52c1ee0277088b7141ed97f86ea0b9fb6f1ce/; sid:902200582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f3:54:fb:31:b5:0a:0d:8c:d1:4d:1a:d0:12:e5:d3:5d:e0:7e:02:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f354fb31b50a0d8cd14d1ad012e5d35de07e021a/; sid:902200583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ae:c5:04:81:bf:00:a4:b4:c3:b5:69:5e:ce:99:2c:b0:34:50:7b:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aec50481bf00a4b4c3b5695ece992cb034507bd4/; sid:902200584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"48:b9:56:40:72:a6:16:60:bb:62:0b:ba:e4:31:55:85:24:cd:a7:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48b9564072a61660bb620bbae431558524cda74f/; sid:902200585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"9c:c9:3e:0a:dd:5e:fd:f4:3b:c5:66:83:6e:56:66:d7:04:97:01:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cc93e0add5efdf43bc566836e5666d7049701ed/; sid:902200586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Redyms C&C)"; tls.fingerprint:"d3:9d:27:d2:26:7c:5e:3c:26:38:26:99:e0:38:be:6e:92:70:dc:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d39d27d2267c5e3c26382699e038be6e9270dc13/; sid:902200587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"57:0d:fd:12:b4:07:69:5c:2a:04:6c:d2:ca:f5:ce:a4:11:42:06:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/570dfd12b407695c2a046cd2caf5cea41142066e/; sid:902200588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4f:7f:85:31:cf:37:5b:27:59:da:14:d3:a3:a2:ba:b3:0b:cc:ff:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f7f8531cf375b2759da14d3a3a2bab30bccffad/; sid:902200589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"08:da:58:00:56:f6:ac:08:67:6a:41:74:68:65:8e:ff:21:1f:02:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08da580056f6ac08676a417468658eff211f02db/; sid:902200590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:ce:b8:4d:e2:d5:05:eb:74:88:de:ce:12:86:e4:17:a8:8b:01:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1ceb84de2d505eb7488dece1286e417a88b016a/; sid:902200591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fd:17:ec:09:74:13:3c:75:df:d9:74:62:1c:25:20:97:be:33:a7:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd17ec0974133c75dfd974621c252097be33a71a/; sid:902200592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"39:ad:79:bf:72:41:47:5b:72:54:30:05:34:92:ed:28:ba:cd:c9:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39ad79bf7241475b725430053492ed28bacdc9f9/; sid:902200593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ee:de:ee:24:4a:d5:8b:b6:2a:9e:a0:2c:77:9e:fa:b8:cb:ec:c4:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eedeee244ad58bb62a9ea02c779efab8cbecc4c0/; sid:902200594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f6:96:b1:94:3c:15:27:bf:1e:c6:c7:03:46:a6:f0:a8:20:e7:3c:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f696b1943c1527bf1ec6c70346a6f0a820e73cd3/; sid:902200595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:e5:5c:3c:54:59:11:a8:ff:f9:3a:32:8b:98:5c:a9:2c:fb:50:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4e55c3c545911a8fff93a328b985ca92cfb5045/; sid:902200596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"6f:b2:3d:09:fa:94:6b:5f:ef:10:90:f9:52:70:29:33:41:45:47:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fb23d09fa946b5fef1090f952702933414547f9/; sid:902200597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"a5:82:2f:2b:ea:bc:6f:ac:c3:69:32:8e:3d:81:36:d1:10:61:46:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5822f2beabc6facc369328e3d8136d110614635/; sid:902200598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a7:09:c2:5c:60:7b:05:0b:2a:cb:b9:89:96:c6:3b:8e:91:3a:70:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a709c25c607b050b2acbb98996c63b8e913a7082/; sid:902200599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:71:f1:a7:01:01:3b:48:af:ea:90:8c:f6:a2:fc:4b:b8:b4:10:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8571f1a701013b48afea908cf6a2fc4bb8b410fa/; sid:902200600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex)"; tls.fingerprint:"a6:d8:1e:31:cc:fd:c5:eb:a7:4a:ce:29:02:ca:f2:3d:9d:9a:91:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6d81e31ccfdc5eba74ace2902caf23d9d9a912f/; sid:902200601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"81:4c:ae:81:0c:29:fd:37:d7:5c:a2:65:7d:73:a0:d3:5c:28:40:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/814cae810c29fd37d75ca2657d73a0d35c2840d8/; sid:902200602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:65:59:9c:76:15:10:f9:9b:95:98:7f:42:b6:20:9e:5e:6f:44:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e265599c761510f99b95987f42b6209e5e6f4485/; sid:902200603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:d0:50:94:69:39:f8:4c:48:ac:24:9b:cb:c6:e1:65:51:b5:c9:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31d050946939f84c48ac249bcbc6e16551b5c9fd/; sid:902200604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8b:14:c8:c8:42:40:89:82:15:cf:30:6e:66:88:fd:a4:38:74:1a:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b14c8c84240898215cf306e6688fda438741ae1/; sid:902200605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1d:9d:3a:a6:21:b6:cc:83:8d:31:d0:b2:68:8f:a0:4a:0d:03:06:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d9d3aa621b6cc838d31d0b2688fa04a0d030669/; sid:902200606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"83:7c:72:56:f9:42:bd:56:3c:6c:16:7b:40:84:02:5a:4a:e1:0b:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/837c7256f942bd563c6c167b4084025a4ae10bae/; sid:902200607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cb:7e:fc:25:c9:71:bc:44:a5:68:af:3d:66:51:d8:a2:24:43:9f:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb7efc25c971bc44a568af3d6651d8a224439f62/; sid:902200608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0e:cb:00:b9:fb:08:5b:96:71:05:8d:f0:90:09:56:d8:ca:e9:8c:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ecb00b9fb085b9671058df0900956d8cae98c3f/; sid:902200609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"18:39:1d:14:16:4e:a2:ba:c3:b2:a8:62:98:ba:54:e9:ac:4d:12:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18391d14164ea2bac3b2a86298ba54e9ac4d128a/; sid:902200610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"34:b8:d2:b0:9c:ed:8e:d1:83:d8:9a:df:af:2c:1b:40:bb:2d:0e:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34b8d2b09ced8ed183d89adfaf2c1b40bb2d0e64/; sid:902200611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1e:99:67:d3:e5:dc:bd:e8:de:bd:27:a7:92:22:a0:93:ef:8e:4e:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e9967d3e5dcbde8debd27a79222a093ef8e4e65/; sid:902200612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"84:0f:a7:44:94:3b:03:c7:81:20:c6:64:91:2b:26:ac:51:ed:1e:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/840fa744943b03c78120c664912b26ac51ed1e74/; sid:902200613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6a:35:13:d6:09:ea:9b:59:53:6b:cb:86:75:dc:3a:22:b6:89:86:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a3513d609ea9b59536bcb8675dc3a22b689861b/; sid:902200614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bd:74:f3:6b:99:c2:2b:c3:11:38:87:c8:14:d8:31:cd:99:ac:12:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd74f36b99c22bc3113887c814d831cd99ac1223/; sid:902200615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"53:39:71:78:7f:4a:42:c8:b4:c3:0b:13:22:05:8d:83:38:aa:61:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/533971787f4a42c8b4c30b1322058d8338aa6144/; sid:902200616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f8:e9:97:67:30:d2:d4:ef:b2:22:6c:ce:b6:b6:41:7f:f5:89:d4:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8e9976730d2d4efb2226cceb6b6417ff589d411/; sid:902200617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b1:af:aa:f4:10:03:bc:8b:cc:b4:95:1f:89:b0:35:f6:ae:c7:83:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1afaaf41003bc8bccb4951f89b035f6aec78373/; sid:902200618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"96:9c:33:c3:26:9f:34:9a:78:fd:b9:f8:58:9b:c5:dd:a3:14:93:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/969c33c3269f349a78fdb9f8589bc5dda314930f/; sid:902200619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"be:c4:80:58:87:ed:c1:28:07:3c:39:17:48:89:36:85:27:61:67:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bec4805887edc128073c39174889368527616761/; sid:902200620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"20:18:6c:e2:50:bb:de:dd:67:6c:45:8e:61:ae:9c:24:5b:1b:ff:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20186ce250bbdedd676c458e61ae9c245b1bff0c/; sid:902200621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fd:ba:cd:06:0f:6a:e2:a2:8b:41:c7:6e:9b:d9:93:4f:c6:d0:b3:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdbacd060f6ae2a28b41c76e9bd9934fc6d0b329/; sid:902200622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7a:04:d2:da:1d:f0:81:6f:7a:b6:59:5d:5b:cf:f8:41:6e:36:e1:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a04d2da1df0816f7ab6595d5bcff8416e36e140/; sid:902200623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"79:d8:55:04:a4:d0:4b:48:6b:d1:56:d4:9c:f7:12:d3:30:0c:0c:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79d85504a4d04b486bd156d49cf712d3300c0c68/; sid:902200624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4b:8b:11:e5:bc:fd:80:5c:f0:7e:64:f8:23:de:37:ee:eb:6d:7e:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b8b11e5bcfd805cf07e64f823de37eeeb6d7ea9/; sid:902200625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"34:0f:be:80:0a:2e:93:73:f4:c8:6e:8d:b8:a8:88:ec:d3:0c:c3:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/340fbe800a2e9373f4c86e8db8a888ecd30cc317/; sid:902200626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KINS C&C)"; tls.fingerprint:"5f:66:d8:e9:11:02:fc:2e:03:d5:5f:90:bd:6f:59:8b:12:3d:0a:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f66d8e91102fc2e03d55f90bd6f598b123d0aa7/; sid:902200627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:06:be:29:ae:63:19:0c:4e:cd:69:e7:2f:0d:fa:4d:70:37:ad:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7706be29ae63190c4ecd69e72f0dfa4d7037ad3e/; sid:902200628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7d:bf:a2:18:ce:fe:83:6e:16:c3:9d:79:fc:56:67:0d:23:7d:9c:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dbfa218cefe836e16c39d79fc56670d237d9c58/; sid:902200629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"af:19:27:d2:14:0e:3d:1f:5d:a4:6a:58:b9:af:06:4b:9c:cb:4e:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af1927d2140e3d1f5da46a58b9af064b9ccb4e4b/; sid:902200630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"71:ef:80:bd:c6:20:3b:26:e4:5f:ee:fc:c4:ed:69:69:5a:ef:0a:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71ef80bdc6203b26e45feefcc4ed69695aef0a51/; sid:902200631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"97:3f:cf:9e:f8:d1:bd:26:e9:81:c9:89:31:b0:1d:9f:c9:dd:d6:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/973fcf9ef8d1bd26e981c98931b01d9fc9ddd60e/; sid:902200632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"73:3b:2e:b4:9c:5d:19:03:55:d0:cb:cd:86:cd:01:50:85:de:51:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/733b2eb49c5d190355d0cbcd86cd015085de517d/; sid:902200633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8f:fe:38:ac:42:1c:cc:b1:7e:62:2f:0f:77:63:47:f5:7d:eb:ba:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ffe38ac421cccb17e622f0f776347f57debba3e/; sid:902200634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"3d:f4:30:35:b3:d1:c6:65:d5:5a:33:4e:41:c5:bc:d3:a6:a5:fc:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3df43035b3d1c665d55a334e41c5bcd3a6a5fc67/; sid:902200635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e3:43:83:49:70:df:db:63:1a:79:45:9d:95:89:85:07:61:8c:15:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e343834970dfdb631a79459d95898507618c1524/; sid:902200636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"16:9f:ca:fd:6f:04:e3:f0:17:94:83:e1:02:81:bc:fb:bb:ed:f7:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/169fcafd6f04e3f0179483e10281bcfbbbedf773/; sid:902200637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"76:f4:7d:39:9e:a1:b6:28:a9:58:7a:2f:6d:41:28:72:30:4d:40:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76f47d399ea1b628a9587a2f6d412872304d40bd/; sid:902200638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"e1:bc:f4:7e:9a:e4:07:0c:d8:70:64:77:72:24:83:f0:cb:ee:60:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1bcf47e9ae4070cd8706477722483f0cbee60ca/; sid:902200639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e1:c8:49:9d:c6:82:9e:b9:a2:76:f3:8a:0b:3a:f5:b7:78:7b:ef:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1c8499dc6829eb9a276f38a0b3af5b7787bef1b/; sid:902200640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"43:28:58:02:5a:19:d6:a9:bc:b4:7e:c3:72:c9:10:5b:f3:46:6f:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/432858025a19d6a9bcb47ec372c9105bf3466f31/; sid:902200641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d0:1a:12:db:ff:ef:c6:c9:4a:3b:33:64:ab:1a:ee:9a:b1:d9:b5:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d01a12dbffefc6c94a3b3364ab1aee9ab1d9b598/; sid:902200642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"da:15:e7:3d:14:a6:e4:ef:12:2c:62:84:52:a9:7c:0b:14:08:f5:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da15e73d14a6e4ef122c628452a97c0b1408f518/; sid:902200643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"0b:8b:47:b4:b2:94:47:98:5d:42:5d:90:a6:90:26:2a:b7:33:fe:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b8b47b4b29447985d425d90a690262ab733fe94/; sid:902200644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Rovnix C&C)"; tls.fingerprint:"d9:39:15:54:00:49:40:51:d7:85:fb:ea:e3:39:33:f6:4a:2d:6c:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d939155400494051d785fbeae33933f64a2d6cce/; sid:902200645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"38:f4:fd:16:4c:c4:38:50:8c:42:4f:2e:44:d9:0f:69:95:da:df:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38f4fd164cc438508c424f2e44d90f6995dadf9e/; sid:902200646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"85:9e:91:18:b8:7e:44:2e:e3:49:76:0f:17:77:b9:65:6f:57:2a:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/859e9118b87e442ee349760f1777b9656f572ad1/; sid:902200647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"95:26:51:83:f3:0a:41:1a:17:98:d9:34:4a:07:7a:c5:e9:59:e1:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95265183f30a411a1798d9344a077ac5e959e1fa/; sid:902200648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"52:78:31:ab:f9:ec:62:b0:8c:75:9c:9c:14:6f:e9:c3:8b:8c:69:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/527831abf9ec62b08c759c9c146fe9c38b8c694a/; sid:902200649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5c:25:f5:dc:34:c1:4e:aa:54:44:61:86:43:62:26:ba:fa:24:c9:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c25f5dc34c14eaa54446186436226bafa24c96a/; sid:902200650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"59:99:6a:91:fc:cc:36:65:50:7b:53:e0:38:17:bf:b1:92:2b:31:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59996a91fccc3665507b53e03817bfb1922b31a5/; sid:902200651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c1:f8:7b:ec:7c:d3:6d:b0:28:55:52:7a:8b:47:55:54:25:c1:50:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1f87bec7cd36db02855527a8b47555425c1504e/; sid:902200652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"02:47:cd:18:09:77:61:be:58:6d:21:6f:6f:22:96:63:93:28:4a:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0247cd18097761be586d216f6f22966393284a52/; sid:902200653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a1:a5:d7:c2:34:0e:e8:9d:cf:9d:a7:ed:68:f2:51:1e:5f:f0:ea:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1a5d7c2340ee89dcf9da7ed68f2511e5ff0ea6e/; sid:902200654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"21:96:77:36:36:9c:f9:3d:ea:a3:f1:8c:c4:de:66:47:e5:7a:09:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21967736369cf93deaa3f18cc4de6647e57a0931/; sid:902200655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c1:38:3e:78:1e:a1:83:07:5a:e9:77:f6:fd:b8:4c:af:7e:20:22:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1383e781ea183075ae977f6fdb84caf7e20226e/; sid:902200656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"ab:54:05:30:f1:e1:fb:0c:e9:8c:69:80:05:3b:9d:09:10:0a:b6:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab540530f1e1fb0ce98c6980053b9d09100ab6e5/; sid:902200657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"1b:00:2f:4e:a7:5a:30:d5:a6:30:f0:80:a3:25:ed:ff:70:f8:0e:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b002f4ea75a30d5a630f080a325edff70f80e69/; sid:902200658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"3b:8d:8d:86:99:39:91:04:37:d9:e2:60:28:33:b6:ff:9d:92:c5:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b8d8d869939910437d9e2602833b6ff9d92c5df/; sid:902200659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5d:85:36:de:1f:50:74:1b:84:08:a7:20:14:02:89:ec:38:be:b8:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d8536de1f50741b8408a720140289ec38beb8c2/; sid:902200660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"97:4c:47:4b:1a:1e:76:bd:58:e8:94:e5:a2:db:8b:c5:76:41:2d:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/974c474b1a1e76bd58e894e5a2db8bc576412dd6/; sid:902200661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d1:45:d8:27:5b:ae:96:2f:46:73:fe:7f:62:b0:59:45:79:d1:b9:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d145d8275bae962f4673fe7f62b0594579d1b95e/; sid:902200662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d3:e8:93:a4:4a:04:46:e5:59:16:8f:de:5b:33:1e:c4:4d:64:94:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3e893a44a0446e559168fde5b331ec44d64944c/; sid:902200663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"46:3e:04:4c:0a:df:20:fc:82:67:fe:c7:f6:48:d8:a6:19:5b:71:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/463e044c0adf20fc8267fec7f648d8a6195b7187/; sid:902200664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3b:a7:14:51:9b:3e:f3:dd:3c:75:f1:cb:e9:91:9e:15:06:4f:60:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ba714519b3ef3dd3c75f1cbe9919e15064f606d/; sid:902200665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"35:fa:1d:3f:1b:03:24:07:47:2a:76:39:65:4b:33:80:1c:12:4c:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35fa1d3f1b032407472a7639654b33801c124cea/; sid:902200666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fc:c4:1f:77:ed:1a:ef:50:dc:f2:79:2d:58:05:62:bf:df:8a:39:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcc41f77ed1aef50dcf2792d580562bfdf8a3955/; sid:902200667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"64:ae:bd:ab:0f:ca:ec:d9:67:1e:e8:36:ab:f0:9d:52:28:dd:36:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64aebdab0fcaecd9671ee836abf09d5228dd368b/; sid:902200668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6c:f7:05:57:03:02:2f:18:dc:33:28:19:23:14:be:94:da:23:7b:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cf7055703022f18dc3328192314be94da237b04/; sid:902200669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b8:75:e2:57:ca:8c:cf:1a:aa:e2:53:6d:a4:e5:39:b4:7e:f8:48:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b875e257ca8ccf1aaae2536da4e539b47ef84835/; sid:902200670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ff:42:e4:58:74:2b:ae:07:bf:f6:96:c1:7f:39:66:28:e1:19:28:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff42e458742bae07bff696c17f396628e1192821/; sid:902200671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1b:cf:27:3e:38:e5:5a:8d:42:a4:f1:1a:e0:1e:27:58:a8:93:4a:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1bcf273e38e55a8d42a4f11ae01e2758a8934a17/; sid:902200672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:6c:c2:cd:23:5a:23:1b:f3:17:e4:3a:bd:3e:be:ef:87:0e:ea:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d6cc2cd235a231bf317e43abd3ebeef870eea83/; sid:902200673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f7:76:07:7e:93:7d:b2:80:ce:77:ea:cd:06:12:1c:73:68:da:99:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f776077e937db280ce77eacd06121c7368da99d5/; sid:902200674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:01:c2:65:00:f6:3a:bc:d4:9e:b5:57:3c:2a:ea:1c:da:ed:ff:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c101c26500f63abcd49eb5573c2aea1cdaedff8e/; sid:902200675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Teslacrypt C&C)"; tls.fingerprint:"79:84:5a:4e:02:fa:72:42:32:12:0e:67:c0:48:00:0a:9d:c7:42:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79845a4e02fa724232120e67c048000a9dc74239/; sid:902200676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"84:8c:e4:35:30:97:2c:4a:ec:6c:57:d2:f0:0e:fe:b7:98:5b:9e:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/848ce43530972c4aec6c57d2f00efeb7985b9eed/; sid:902200677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:a6:37:c1:99:7f:86:f2:c3:ed:fd:cc:f1:2f:d8:1e:f4:54:09:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32a637c1997f86f2c3edfdccf12fd81ef4540970/; sid:902200678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"95:67:a4:91:c3:a3:80:5c:48:4b:46:d6:a8:26:ea:a2:54:c3:bc:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9567a491c3a3805c484b46d6a826eaa254c3bc93/; sid:902200679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"3f:3d:22:65:11:27:5a:3c:f9:b5:f1:7e:a5:83:22:03:0d:f7:92:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f3d226511275a3cf9b5f17ea58322030df79298/; sid:902200680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f0:88:25:ae:fa:a2:96:a6:41:7e:87:ae:67:cf:04:af:75:58:e3:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f08825aefaa296a6417e87ae67cf04af7558e3e1/; sid:902200681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2f:82:8e:bb:21:a6:2d:88:88:7b:c0:97:8d:b7:3d:00:7d:cd:36:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f828ebb21a62d88887bc0978db73d007dcd36b7/; sid:902200682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2c:c3:ef:4a:c0:86:9d:a8:55:46:e2:f4:87:ab:72:2f:91:d8:3c:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2cc3ef4ac0869da85546e2f487ab722f91d83c0f/; sid:902200683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"34:4c:90:fd:31:f7:11:da:b2:e4:27:0b:06:17:18:1c:ec:50:91:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/344c90fd31f711dab2e4270b0617181cec5091c1/; sid:902200684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1d:9d:45:2d:95:88:6d:ef:36:65:9e:04:01:fd:66:f2:3f:72:77:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d9d452d95886def36659e0401fd66f23f727754/; sid:902200685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"a4:e7:53:68:68:63:9b:8c:1d:94:0f:72:a7:40:0c:23:33:24:07:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4e7536868639b8c1d940f72a7400c2333240704/; sid:902200686; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0b:4a:26:6e:b2:13:b6:41:76:92:00:72:9e:c0:6b:fc:1f:da:02:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b4a266eb213b641769200729ec06bfc1fda028b/; sid:902200687; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:5d:e0:8d:65:ed:06:29:fc:7b:95:bf:fa:22:c2:c6:27:92:d3:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef5de08d65ed0629fc7b95bffa22c2c62792d3dd/; sid:902200688; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a9:ed:d0:d9:7c:fb:f1:cd:dd:6b:10:19:38:14:01:40:b8:b3:6b:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9edd0d97cfbf1cddd6b101938140140b8b36be3/; sid:902200689; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"73:33:36:c3:82:6c:84:c4:d0:ba:3a:3d:43:12:78:d3:ba:50:63:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/733336c3826c84c4d0ba3a3d431278d3ba5063dc/; sid:902200690; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"12:06:c8:14:7f:d7:2b:7e:41:b6:f7:e6:3b:f0:67:c1:55:cf:ae:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1206c8147fd72b7e41b6f7e63bf067c155cfae0a/; sid:902200691; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:4c:80:04:ed:1e:f9:a5:02:c9:df:c7:25:24:15:7c:7b:6b:13:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/314c8004ed1ef9a502c9dfc72524157c7b6b134c/; sid:902200692; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:48:0e:2e:f7:0a:a9:1d:f7:3c:72:26:d4:12:95:7b:5d:e4:ba:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85480e2ef70aa91df73c7226d412957b5de4ba67/; sid:902200693; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"55:29:1c:87:ab:70:08:b4:a2:31:0e:22:35:74:df:89:28:c7:5d:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55291c87ab7008b4a2310e223574df8928c75db2/; sid:902200694; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:2b:99:cb:b7:c9:3b:d1:b1:f9:7c:aa:be:60:28:19:78:e2:f1:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/062b99cbb7c93bd1b1f97caabe60281978e2f1e0/; sid:902200695; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"03:a3:b4:cb:7b:4e:d1:ed:a7:b4:cd:46:35:03:83:e9:e3:0a:22:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03a3b4cb7b4ed1eda7b4cd46350383e9e30a2260/; sid:902200696; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"aa:1b:c5:42:36:5b:ca:c7:4c:3e:0f:8b:19:5c:e1:6f:96:33:02:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa1bc542365bcac74c3e0f8b195ce16f963302a3/; sid:902200697; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"7f:f2:f1:35:b2:8a:a1:da:69:35:56:de:b5:3c:d8:ab:cd:65:2d:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ff2f135b28aa1da693556deb53cd8abcd652d9e/; sid:902200698; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8f:49:54:02:10:fa:db:c6:d6:73:65:c1:1c:53:90:31:79:28:af:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f49540210fadbc6d67365c11c5390317928afd7/; sid:902200699; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d1:0c:ad:ba:6a:a8:47:ff:c7:09:84:6f:17:78:c7:9c:42:34:15:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d10cadba6aa847ffc709846f1778c79c42341558/; sid:902200700; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"02:fc:ce:97:c6:a9:c0:15:4e:06:9c:1c:5f:78:0e:af:e5:3d:67:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02fcce97c6a9c0154e069c1c5f780eafe53d6766/; sid:902200701; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"0c:5c:0b:11:42:67:59:09:39:59:2a:6d:4a:81:9d:89:17:09:7f:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c5c0b114267590939592a6d4a819d8917097f73/; sid:902200702; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bc:53:2d:05:59:00:6d:89:89:d6:67:d5:42:1a:3b:7a:2b:d9:13:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc532d0559006d8989d667d5421a3b7a2bd913fb/; sid:902200703; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"57:91:fe:fc:48:08:c7:3d:fa:29:7d:6d:a6:78:c0:c7:3d:cb:f7:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5791fefc4808c73dfa297d6da678c0c73dcbf70c/; sid:902200704; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c3:de:7a:f6:2d:b8:a1:54:73:eb:12:eb:5f:4f:71:61:00:05:04:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3de7af62db8a15473eb12eb5f4f716100050469/; sid:902200705; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b0:0e:b8:2e:af:df:6f:03:51:c7:31:d6:1e:d7:79:9d:3b:a4:e5:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b00eb82eafdf6f0351c731d61ed7799d3ba4e541/; sid:902200706; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"87:31:48:80:0a:8b:b1:c0:9c:41:71:34:c2:9e:aa:c6:32:5d:ec:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/873148800a8bb1c09c417134c29eaac6325decc0/; sid:902200707; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:5b:62:5b:66:a2:1a:07:32:05:58:cd:ce:87:d6:fc:d1:55:c6:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a65b625b66a21a07320558cdce87d6fcd155c6ab/; sid:902200708; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fb:67:9d:30:4a:02:bf:0b:f5:04:0a:a7:03:c9:1b:72:38:cd:eb:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb679d304a02bf0bf5040aa703c91b7238cdebb6/; sid:902200709; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"08:b1:ab:fd:16:e6:b5:69:c2:91:2f:7d:38:27:52:a1:4b:63:82:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08b1abfd16e6b569c2912f7d382752a14b638298/; sid:902200710; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"30:61:69:20:ac:76:99:7a:7e:a0:80:45:a7:d3:3b:8f:d9:cb:bd:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30616920ac76997a7ea08045a7d33b8fd9cbbd83/; sid:902200711; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:e1:b3:2b:a4:18:53:30:a3:05:82:b9:8d:a9:63:94:45:74:ee:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77e1b32ba4185330a30582b98da963944574ee54/; sid:902200712; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4b:fb:d8:d9:a5:71:9c:9b:1f:19:41:5e:e9:40:e6:f2:b4:e8:51:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4bfbd8d9a5719c9b1f19415ee940e6f2b4e851c0/; sid:902200713; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (URLzone C&C)"; tls.fingerprint:"e3:bc:92:32:57:29:e8:df:8a:09:7b:5b:9d:ea:f8:5f:d1:48:4a:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3bc92325729e8df8a097b5b9deaf85fd1484a29/; sid:902200714; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"eb:5a:22:da:95:2b:36:78:2d:45:16:4e:66:e9:de:9c:f3:d7:92:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb5a22da952b36782d45164e66e9de9cf3d79226/; sid:902200715; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"59:52:7a:7c:3b:12:31:c7:29:88:58:5a:57:77:f5:09:76:96:85:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59527a7c3b1231c72988585a5777f50976968561/; sid:902200716; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5f:bd:d8:2f:54:d3:8f:98:eb:94:a6:9c:14:c8:2f:93:f7:9c:ff:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fbdd82f54d38f98eb94a69c14c82f93f79cffb6/; sid:902200717; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cb:18:cf:0f:6c:64:19:a0:19:9c:ec:92:94:79:ae:34:d5:42:3f:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb18cf0f6c6419a0199cec929479ae34d5423f6d/; sid:902200718; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"cc:1c:9f:c8:42:01:24:6c:71:50:de:88:f6:5a:0d:6f:14:cc:2a:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc1c9fc84201246c7150de88f65a0d6f14cc2a78/; sid:902200719; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fa:69:20:25:3a:93:83:bd:b0:26:dc:29:3a:84:6a:ad:6e:75:6a:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa6920253a9383bdb026dc293a846aad6e756a23/; sid:902200720; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e7:11:b0:02:bb:dc:bc:2a:e5:18:e5:48:db:fb:0d:20:a0:af:b0:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e711b002bbdcbc2ae518e548dbfb0d20a0afb0a6/; sid:902200721; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"ca:99:d2:b2:f9:bf:4d:45:08:3f:f8:78:3f:55:89:32:47:55:10:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca99d2b2f9bf4d45083ff8783f5589324755104f/; sid:902200722; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"8d:a5:60:2a:a7:f9:48:43:2f:7a:ff:15:41:b0:02:bf:f4:ae:d4:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8da5602aa7f948432f7aff1541b002bff4aed46d/; sid:902200723; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"94:07:c6:f0:2a:1b:99:58:fc:ce:89:2d:60:a6:6a:2b:10:ce:42:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9407c6f02a1b9958fcce892d60a66a2b10ce42cc/; sid:902200724; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"40:9f:65:d3:6a:d6:7c:47:e2:0e:3d:b1:20:50:f8:f6:43:a5:19:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/409f65d36ad67c47e20e3db12050f8f643a519f7/; sid:902200725; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1c:99:53:97:6e:24:e6:b7:59:12:53:64:74:41:98:8a:71:b3:ae:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c9953976e24e6b7591253647441988a71b3aea9/; sid:902200726; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b1:af:ea:24:33:14:7d:38:04:3d:7b:05:d4:cb:6c:4a:29:a7:79:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1afea2433147d38043d7b05d4cb6c4a29a779f1/; sid:902200727; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5c:9e:f8:d3:87:ed:9b:39:93:f0:71:ab:07:49:fd:3b:a5:ea:b6:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c9ef8d387ed9b3993f071ab0749fd3ba5eab6ae/; sid:902200728; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"f2:59:78:bd:8f:6c:89:7b:ea:29:bc:be:b5:da:a0:df:8b:b5:7f:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f25978bd8f6c897bea29bcbeb5daa0df8bb57f36/; sid:902200729; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"68:b1:5d:44:c8:2a:c5:2f:a0:08:af:20:23:da:1a:74:d5:5d:b8:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68b15d44c82ac52fa008af2023da1a74d55db8d6/; sid:902200730; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d4:92:51:a9:a7:86:23:c0:f6:0b:3a:e5:ec:b8:22:5a:ec:9d:c6:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d49251a9a78623c0f60b3ae5ecb8225aec9dc6bf/; sid:902200731; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8f:72:08:2f:fe:a6:86:40:e7:7d:18:5a:d0:30:1e:8f:98:c0:4d:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f72082ffea68640e77d185ad0301e8f98c04d52/; sid:902200732; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8e:09:af:5a:08:0e:ac:fa:45:1f:3b:1a:d3:cd:e0:c5:01:1b:5a:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e09af5a080eacfa451f3b1ad3cde0c5011b5a6e/; sid:902200733; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6f:47:c3:1a:7a:b7:b0:d3:23:4c:d6:17:d5:f4:af:0b:01:6d:cf:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f47c31a7ab7b0d3234cd617d5f4af0b016dcfa9/; sid:902200734; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:0a:2d:b7:00:2e:9d:0e:66:c8:2f:d7:39:55:a1:d4:70:26:3b:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/320a2db7002e9d0e66c82fd73955a1d470263b7e/; sid:902200735; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8f:39:ba:6a:c8:aa:e9:59:c2:6d:ec:e6:5d:f1:78:dc:69:ea:1a:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f39ba6ac8aae959c26dece65df178dc69ea1a12/; sid:902200736; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:51:1b:00:01:ae:c7:af:20:b6:1a:ff:f7:ff:93:b3:0f:db:1d:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef511b0001aec7af20b61afff7ff93b30fdb1d66/; sid:902200737; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:ae:db:db:8b:d0:20:44:0c:93:6c:b2:5a:b7:75:fb:0d:42:f0:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15aedbdb8bd020440c936cb25ab775fb0d42f098/; sid:902200738; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d7:74:43:01:5e:be:92:c6:9f:f4:59:e6:20:f8:54:46:24:10:20:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d77443015ebe92c69ff459e620f85446241020e0/; sid:902200739; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b5:97:be:b8:d4:cf:6e:05:6c:f6:b0:d9:43:39:8e:ac:db:dd:cc:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b597beb8d4cf6e056cf6b0d943398eacdbddcc0a/; sid:902200740; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7d:ea:4f:93:56:c8:47:0f:f9:5c:c8:50:af:22:09:04:74:f9:de:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dea4f9356c8470ff95cc850af22090474f9deeb/; sid:902200741; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e4:af:ee:41:db:f6:e5:c5:e4:a2:9f:ed:9c:ed:d9:88:c8:d7:09:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4afee41dbf6e5c5e4a29fed9cedd988c8d709f7/; sid:902200742; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"67:32:f7:4d:e6:a0:4c:d9:75:17:6f:3b:87:c8:a3:b2:a6:5e:0b:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6732f74de6a04cd975176f3b87c8a3b2a65e0b41/; sid:902200743; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"55:ff:21:47:79:42:a2:ad:af:bc:0a:dc:d4:ab:58:57:b2:4a:71:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55ff21477942a2adafbc0adcd4ab5857b24a71d5/; sid:902200744; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fd:2b:0f:98:85:cb:30:25:f2:c3:54:40:d6:87:f9:2d:e0:82:e4:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd2b0f9885cb3025f2c35440d687f92de082e40a/; sid:902200745; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0a:a0:c9:0b:65:24:19:2b:0b:07:8e:92:79:b3:ca:1a:0e:1e:76:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0aa0c90b6524192b0b078e9279b3ca1a0e1e7625/; sid:902200746; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"80:fb:1c:50:e8:08:81:ca:4e:07:b1:2b:19:11:35:ef:a1:0d:37:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80fb1c50e80881ca4e07b12b191135efa10d37be/; sid:902200747; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"92:a0:b1:da:aa:7f:cd:4e:e0:75:93:97:d8:c3:8c:35:03:c6:ce:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92a0b1daaa7fcd4ee0759397d8c38c3503c6ce01/; sid:902200748; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"19:5f:73:4d:14:4f:fb:90:8f:92:cb:ef:3e:ed:5c:65:87:08:46:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/195f734d144ffb908f92cbef3eed5c658708468c/; sid:902200749; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"62:7b:8c:ce:95:73:b2:09:21:83:ff:84:72:fe:e0:68:a2:e8:46:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/627b8cce9573b2092183ff8472fee068a2e84627/; sid:902200750; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:06:3d:83:47:0b:70:a1:77:0b:9c:a5:7f:b7:5b:bc:1c:01:aa:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9063d83470b70a1770b9ca57fb75bbc1c01aa15/; sid:902200751; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"0e:63:75:95:75:63:3c:b2:62:6c:fe:23:f0:ac:5f:67:50:6c:ff:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e63759575633cb2626cfe23f0ac5f67506cff1b/; sid:902200752; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f7:99:e4:82:21:b5:cd:b6:fb:ca:a4:6f:19:21:a4:5f:d0:c1:5b:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f799e48221b5cdb6fbcaa46f1921a45fd0c15b84/; sid:902200753; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1e:0a:26:9d:ac:50:5f:8a:c2:fc:13:c2:fb:57:d4:3b:e5:2b:17:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e0a269dac505f8ac2fc13c2fb57d43be52b1728/; sid:902200754; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ProxyChanger C&C)"; tls.fingerprint:"63:ef:da:45:06:df:0e:6e:04:78:fb:9d:ad:44:9e:c4:75:60:c6:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63efda4506df0e6e0478fb9dad449ec47560c630/; sid:902200755; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ProxyChanger C&C)"; tls.fingerprint:"0d:bf:c8:d8:26:5b:86:04:f7:23:0d:58:90:cf:99:2d:74:a4:5d:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dbfc8d8265b8604f7230d5890cf992d74a45d3a/; sid:902200756; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5b:6e:13:1e:f5:77:4f:dd:27:f7:9e:cf:cc:9a:fd:7b:ff:7c:8a:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b6e131ef5774fdd27f79ecfcc9afd7bff7c8a71/; sid:902200757; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"56:56:4c:88:ff:f3:39:a7:73:09:d3:9f:97:fc:a5:61:8c:a8:5e:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56564c88fff339a77309d39f97fca5618ca85ecb/; sid:902200758; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VMZeuS C&C)"; tls.fingerprint:"2c:5b:14:04:83:ca:cc:2f:05:39:eb:86:65:74:ee:f1:18:2b:fe:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c5b140483cacc2f0539eb866574eef1182bfe13/; sid:902200759; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"be:1e:0d:97:60:42:91:97:25:59:4f:46:e7:ba:91:45:a7:ab:46:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be1e0d976042919725594f46e7ba9145a7ab46f2/; sid:902200760; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"70:82:20:8f:27:9b:69:5c:53:e3:c5:b5:8b:07:44:aa:c7:45:85:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7082208f279b695c53e3c5b58b0744aac7458531/; sid:902200761; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e4:39:e4:7d:dd:f9:bc:6b:db:61:78:3e:f0:65:9e:32:e4:bd:a8:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e439e47dddf9bc6bdb61783ef0659e32e4bda86d/; sid:902200762; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"db:9f:2f:ad:df:00:61:a6:d8:c6:3a:13:8c:2a:af:14:e9:75:b2:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db9f2faddf0061a6d8c63a138c2aaf14e975b21d/; sid:902200763; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"79:b1:d8:16:6a:5c:c7:fa:8d:b6:96:b6:a3:b8:da:53:a8:4c:b0:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79b1d8166a5cc7fa8db696b6a3b8da53a84cb066/; sid:902200764; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"bc:d9:5c:b6:68:a7:d0:f1:cb:d6:9c:08:21:ce:af:bf:5c:c9:35:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcd95cb668a7d0f1cbd69c0821ceafbf5cc9354e/; sid:902200765; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"d6:94:1b:24:a3:0d:f5:c4:8f:e9:62:43:88:41:20:aa:3c:16:41:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6941b24a30df5c48fe96243884120aa3c1641c4/; sid:902200766; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"07:92:49:32:6f:a6:fe:9f:d6:06:6b:7b:00:b5:1e:a6:58:cc:c4:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/079249326fa6fe9fd6066b7b00b51ea658ccc453/; sid:902200767; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a8:38:ff:d6:95:03:39:08:b3:a3:f0:ba:d7:65:3c:38:ed:ce:eb:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a838ffd695033908b3a3f0bad7653c38edceebb4/; sid:902200768; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"35:7d:83:ca:c3:a1:16:7d:83:87:d4:e7:3d:31:96:fe:84:5e:ac:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/357d83cac3a1167d8387d4e73d3196fe845eacdb/; sid:902200769; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"60:9d:68:66:ef:00:1b:94:11:fe:9a:95:e4:72:95:7f:ef:28:2e:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/609d6866ef001b9411fe9a95e472957fef282e38/; sid:902200770; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"f0:79:2a:65:9b:32:fc:57:0a:ad:fc:cc:db:8d:93:09:12:cc:f8:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0792a659b32fc570aadfcccdb8d930912ccf852/; sid:902200771; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"14:13:3d:53:ce:26:bf:94:c0:39:7c:41:0d:af:b6:75:c3:ab:62:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14133d53ce26bf94c0397c410dafb675c3ab62d6/; sid:902200772; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"36:6f:27:27:c6:a2:86:a8:78:19:a7:64:e4:ed:bf:bc:5a:b4:bc:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/366f2727c6a286a87819a764e4edbfbc5ab4bca1/; sid:902200773; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"5c:8e:ef:8f:30:af:ae:b9:27:52:21:7c:3e:d1:82:0f:93:e8:05:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c8eef8f30afaeb92752217c3ed1820f93e80551/; sid:902200774; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"26:fc:57:25:d6:6c:4b:a7:67:ad:07:65:bb:b9:49:66:67:2a:13:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26fc5725d66c4ba767ad0765bbb94966672a13ee/; sid:902200775; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"c4:68:c4:fc:30:77:d3:c5:12:ed:e9:04:0b:c6:0a:b2:ad:b3:18:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c468c4fc3077d3c512ede9040bc60ab2adb318d8/; sid:902200776; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:86:10:b6:e4:89:7a:29:a1:82:82:46:61:94:be:ef:68:27:83:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a38610b6e4897a29a18282466194beef68278337/; sid:902200777; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"02:e6:87:c4:4d:a4:46:7f:c7:76:39:ab:ba:9b:a9:1e:0a:c1:0d:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02e687c44da4467fc77639abba9ba91e0ac10d65/; sid:902200778; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"9a:7d:ab:d7:d2:e4:62:02:d3:37:02:e9:a9:0b:aa:02:bb:fe:89:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a7dabd7d2e46202d33702e9a90baa02bbfe8940/; sid:902200779; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Downloder-Bot C&C)"; tls.fingerprint:"84:c4:d0:12:ae:29:02:4e:d3:7d:46:80:fa:e2:9e:16:63:b3:ab:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84c4d012ae29024ed37d4680fae29e1663b3abcf/; sid:902200780; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"9a:d9:da:05:9c:a7:99:44:fd:d0:29:00:e1:83:55:eb:e4:dd:3a:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ad9da059ca79944fdd02900e18355ebe4dd3acc/; sid:902200781; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d9:32:fe:11:f6:e2:0d:5c:59:e4:5c:ea:25:47:d8:a5:59:0b:26:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d932fe11f6e20d5c59e45cea2547d8a5590b269a/; sid:902200782; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"22:32:82:38:ec:37:48:21:38:3f:0e:3e:59:cf:48:57:c2:91:4e:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22328238ec374821383f0e3e59cf4857c2914e36/; sid:902200783; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b8:40:3c:a5:31:a4:d6:23:94:d4:32:76:3c:57:6c:e6:78:f9:1d:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8403ca531a4d62394d432763c576ce678f91d17/; sid:902200784; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:74:a4:18:a7:60:d4:30:41:bf:d9:50:2b:4b:6a:2c:e8:83:5b:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e974a418a760d43041bfd9502b4b6a2ce8835b82/; sid:902200785; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"af:f3:4f:fd:f3:57:60:c6:69:97:02:2c:82:a0:a3:f5:23:ab:80:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aff34ffdf35760c66997022c82a0a3f523ab80c4/; sid:902200786; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"2b:83:fa:06:ef:38:ad:cf:63:a3:c8:9f:f0:d5:95:37:58:47:ab:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b83fa06ef38adcf63a3c89ff0d595375847ab4f/; sid:902200787; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"fc:10:4d:36:d3:dd:a9:8c:c0:51:07:43:79:cf:48:32:ac:04:89:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc104d36d3dda98cc051074379cf4832ac048998/; sid:902200788; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"0e:66:f3:d4:15:a6:e8:3a:25:ce:59:5e:40:9a:8c:8b:e4:e8:7a:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e66f3d415a6e83a25ce595e409a8c8be4e87af8/; sid:902200789; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"83:fd:75:27:33:df:42:35:32:ae:30:41:b8:25:d0:b7:b9:23:ca:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83fd752733df423532ae3041b825d0b7b923cad4/; sid:902200790; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"38:47:44:47:e1:8b:e8:bc:f2:52:0b:89:37:ca:a6:1a:bf:3c:cd:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38474447e18be8bcf2520b8937caa61abf3ccddb/; sid:902200791; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"39:da:9c:24:02:f9:da:3f:5c:44:61:6e:3c:ea:43:9c:f1:85:ff:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39da9c2402f9da3f5c44616e3cea439cf185ff71/; sid:902200792; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"bd:a7:93:90:ac:da:19:9c:d4:62:ad:56:94:1b:32:0d:30:fc:8e:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bda79390acda199cd462ad56941b320d30fc8e55/; sid:902200793; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"02:f5:e6:37:3b:0d:c0:af:d8:b7:e2:c9:cb:75:09:bc:b9:1c:76:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02f5e6373b0dc0afd8b7e2c9cb7509bcb91c7622/; sid:902200794; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"90:10:06:fb:67:aa:be:a7:c7:40:4e:78:46:da:57:80:b7:71:aa:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/901006fb67aabea7c7404e7846da5780b771aaba/; sid:902200795; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a0:92:97:9f:dc:86:be:59:f6:0f:b6:9c:6e:35:39:f3:6c:ba:65:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a092979fdc86be59f60fb69c6e3539f36cba6599/; sid:902200796; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"eb:92:99:08:c5:6e:fb:f6:d9:ef:1a:60:6f:15:af:f7:28:cf:cc:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb929908c56efbf6d9ef1a606f15aff728cfcc77/; sid:902200797; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"80:cb:d6:82:51:61:3e:2a:b1:d9:8c:f7:c1:fb:e0:59:a4:a7:be:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80cbd68251613e2ab1d98cf7c1fbe059a4a7be46/; sid:902200798; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"80:01:3e:03:9d:9b:45:e0:f0:5a:aa:f9:41:d5:db:a9:f7:f5:b4:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80013e039d9b45e0f05aaaf941d5dba9f7f5b452/; sid:902200799; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:db:ac:5a:c9:3b:59:d6:9f:fe:b0:ea:eb:21:10:a5:0b:c8:6b:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31dbac5ac93b59d69ffeb0eaeb2110a50bc86beb/; sid:902200800; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"09:c1:2a:d9:ac:2d:e7:d3:01:4a:6b:08:dd:eb:77:b4:23:82:1b:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09c12ad9ac2de7d3014a6b08ddeb77b423821b27/; sid:902200801; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"cb:76:1e:89:0e:74:94:af:d0:51:f9:76:1e:7a:cf:4b:55:39:69:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb761e890e7494afd051f9761e7acf4b553969b3/; sid:902200802; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9c:53:81:e6:68:9f:0a:cc:f3:78:c0:10:73:6a:e6:d2:1f:31:1d:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c5381e6689f0accf378c010736ae6d21f311d57/; sid:902200803; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b6:c0:46:95:b7:13:e3:f6:f2:42:8d:30:3d:c7:7b:d0:88:ca:ae:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c04695b713e3f6f2428d303dc77bd088caaeb3/; sid:902200804; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ba:7f:b5:50:47:59:55:74:e5:e9:d8:e7:6f:d6:81:28:4d:b7:a5:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba7fb55047595574e5e9d8e76fd681284db7a506/; sid:902200805; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d6:5f:32:e7:a6:f1:c3:b3:9f:dc:d5:ea:42:60:a4:fc:7e:d9:9a:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d65f32e7a6f1c3b39fdcd5ea4260a4fc7ed99ab4/; sid:902200806; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"f3:3e:94:d1:43:f2:20:76:d2:03:38:2c:01:1d:12:9d:93:a0:19:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f33e94d143f22076d203382c011d129d93a01968/; sid:902200807; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"bd:e7:37:9c:4f:45:97:37:7e:b0:92:00:ea:45:20:b2:e4:30:57:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bde7379c4f4597377eb09200ea4520b2e4305704/; sid:902200808; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"9c:fa:5b:74:92:8b:9e:a4:47:b9:38:15:3e:db:3e:52:16:32:b1:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cfa5b74928b9ea447b938153edb3e521632b17f/; sid:902200809; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"20:59:70:cf:e0:65:bb:c3:d0:31:de:d9:f7:29:1c:0f:5e:16:9f:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/205970cfe065bbc3d031ded9f7291c0f5e169f94/; sid:902200810; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Retefe C&C)"; tls.fingerprint:"a6:35:d2:21:29:e6:eb:47:ee:2e:e9:f1:84:24:b6:e7:ae:b6:ae:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a635d22129e6eb47ee2ee9f18424b6e7aeb6ae26/; sid:902200811; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"89:d6:80:a4:96:5f:d6:5a:ec:35:4e:e7:6a:8c:cb:cd:37:76:29:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89d680a4965fd65aec354ee76a8ccbcd377629ed/; sid:902200812; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"da:3f:73:1e:1f:54:cb:a1:1c:01:dd:4e:b3:c4:8e:fe:35:4c:6f:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da3f731e1f54cba11c01dd4eb3c48efe354c6ff9/; sid:902200813; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"27:8a:38:97:2a:62:a8:c2:6c:f0:17:ab:61:ae:74:74:17:a5:e6:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/278a38972a62a8c26cf017ab61ae747417a5e687/; sid:902200814; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"cf:d1:09:e4:8f:a5:46:4e:66:59:43:88:dc:81:09:2e:ee:67:1a:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfd109e48fa5464e66594388dc81092eee671a59/; sid:902200815; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"de:5e:17:c7:f2:20:ac:ba:eb:8d:be:b4:ef:5c:8b:36:c1:dd:c1:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de5e17c7f220acbaeb8dbeb4ef5c8b36c1ddc12e/; sid:902200816; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e5:bf:ef:e6:6b:52:e3:89:03:37:e5:5d:93:d9:59:53:ba:ea:8f:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e5bfefe66b52e3890337e55d93d95953baea8f10/; sid:902200817; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a5:40:1a:41:21:b0:59:30:f9:ad:a2:f9:f2:fa:ea:0f:31:98:79:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5401a4121b05930f9ada2f9f2faea0f3198793c/; sid:902200818; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d9:ef:3d:c9:64:b6:7f:5a:99:bf:cd:61:88:24:8e:2a:64:1c:2b:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9ef3dc964b67f5a99bfcd6188248e2a641c2b6c/; sid:902200819; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3e:db:18:a6:ac:f7:43:70:46:1a:fd:11:c6:44:21:ac:0f:b1:d3:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3edb18a6acf74370461afd11c64421ac0fb1d370/; sid:902200820; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"90:73:e7:1b:44:ed:8a:51:87:a6:10:12:e0:0d:40:cd:7a:93:23:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9073e71b44ed8a5187a61012e00d40cd7a932339/; sid:902200821; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"11:8c:05:5a:b8:83:7c:bf:ad:16:70:26:2d:a0:46:e6:8f:fe:fe:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/118c055ab8837cbfad1670262da046e68ffefeba/; sid:902200822; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"dd:2b:51:ae:50:c8:ba:78:f1:5e:48:39:d6:79:a1:49:d2:0f:5c:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd2b51ae50c8ba78f15e4839d679a149d20f5c5a/; sid:902200823; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ee:b5:6d:5c:76:d0:c5:45:5c:34:b4:47:e3:0d:20:0d:b6:7c:98:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eeb56d5c76d0c5455c34b447e30d200db67c982a/; sid:902200824; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"da:74:a9:7a:9f:62:e4:71:c1:2f:a3:62:b3:6e:5b:cc:66:43:cf:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da74a97a9f62e471c12fa362b36e5bcc6643cf51/; sid:902200825; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"96:a3:45:a2:3a:e8:26:bb:a3:c4:da:24:70:ac:02:b4:0c:07:8e:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96a345a23ae826bba3c4da2470ac02b40c078ec6/; sid:902200826; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"b8:21:b9:9a:94:5a:8a:b0:5a:85:18:c4:c1:ec:2f:45:f1:ed:60:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b821b99a945a8ab05a8518c4c1ec2f45f1ed6065/; sid:902200827; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f5:cf:90:5b:05:cd:e4:a4:8c:0f:52:5f:12:3c:8b:fb:f0:8c:c3:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5cf905b05cde4a48c0f525f123c8bfbf08cc366/; sid:902200828; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"96:85:19:d8:05:c9:85:b4:57:be:0a:2a:fe:98:a0:d0:44:ef:99:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/968519d805c985b457be0a2afe98a0d044ef99c2/; sid:902200829; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e7:a1:44:37:16:f9:ad:88:eb:28:5d:c6:b6:9f:67:4f:e7:33:72:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7a1443716f9ad88eb285dc6b69f674fe733727d/; sid:902200830; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e0:18:44:c6:a6:06:3b:62:35:65:31:27:cc:54:ab:38:4e:34:ce:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e01844c6a6063b6235653127cc54ab384e34cec2/; sid:902200831; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"56:a9:aa:61:d3:66:7c:96:a3:ff:eb:94:1c:ff:22:ee:9e:a8:da:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56a9aa61d3667c96a3ffeb941cff22ee9ea8da10/; sid:902200832; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"33:60:e0:e0:e9:4c:0f:d6:fe:d4:e0:93:93:d6:e9:bd:b6:b3:87:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3360e0e0e94c0fd6fed4e09393d6e9bdb6b38754/; sid:902200833; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e8:2c:2c:be:ec:95:4a:6d:47:bc:aa:e8:fd:23:b9:a8:09:95:e4:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e82c2cbeec954a6d47bcaae8fd23b9a80995e450/; sid:902200834; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:ea:d4:e0:18:f6:c1:fe:24:97:20:22:c1:d4:ac:55:27:50:3e:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32ead4e018f6c1fe24972022c1d4ac5527503eb4/; sid:902200835; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3e:c6:35:e0:0f:20:b5:e2:88:ff:f4:83:41:9d:e7:25:dd:42:f4:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ec635e00f20b5e288fff483419de725dd42f497/; sid:902200836; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"61:7f:1e:68:b4:fe:fe:1d:9d:a8:43:f9:0b:4d:f7:da:d7:44:d6:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/617f1e68b4fefe1d9da843f90b4df7dad744d677/; sid:902200837; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7d:da:9a:b4:38:a3:b2:d4:7b:4a:b0:7e:d5:06:07:3f:b8:81:23:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dda9ab438a3b2d47b4ab07ed506073fb8812373/; sid:902200838; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3f:c4:67:43:e6:f6:c3:48:9e:0b:fe:ce:cc:98:cf:c6:34:cd:cb:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3fc46743e6f6c3489e0bfececc98cfc634cdcb95/; sid:902200839; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"58:c4:c5:d0:87:30:94:ae:15:53:fa:3d:7b:5a:03:3d:75:bb:de:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58c4c5d0873094ae1553fa3d7b5a033d75bbdeb9/; sid:902200840; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a7:4d:ab:7a:38:ff:f1:12:76:72:80:63:29:12:ba:03:70:90:48:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a74dab7a38fff112767280632912ba0370904801/; sid:902200841; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b2:2e:b2:d8:68:12:47:bc:fc:51:53:bf:3a:7b:da:f5:11:e5:5a:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b22eb2d8681247bcfc5153bf3a7bdaf511e55af5/; sid:902200842; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"42:b2:af:ac:eb:4d:27:0a:19:4b:83:97:80:20:fd:47:11:e9:28:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42b2afaceb4d270a194b83978020fd4711e928e2/; sid:902200843; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"24:09:e4:86:93:a4:ca:3a:f7:0d:d9:44:d8:77:33:27:e6:a8:51:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2409e48693a4ca3af70dd944d8773327e6a8516c/; sid:902200844; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c9:c9:63:ce:2a:f6:15:13:7c:5b:07:e1:22:96:8e:95:95:b7:7d:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9c963ce2af615137c5b07e122968e9595b77d58/; sid:902200845; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b0:77:c0:bb:cf:d6:39:7e:f7:34:1f:91:27:6f:ae:da:59:2b:7f:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b077c0bbcfd6397ef7341f91276faeda592b7ff3/; sid:902200846; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3e:e0:53:d3:8a:7f:3d:80:a4:7a:ee:37:4b:2d:49:1e:06:b6:26:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ee053d38a7f3d80a47aee374b2d491e06b62609/; sid:902200847; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7a:66:8d:51:bf:57:bd:86:b0:da:61:6e:f4:1b:e1:a1:d4:47:42:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a668d51bf57bd86b0da616ef41be1a1d44742f3/; sid:902200848; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9c:03:35:5e:c0:ec:54:85:0b:a3:26:d0:85:42:bf:f5:c2:4e:20:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c03355ec0ec54850ba326d08542bff5c24e207b/; sid:902200849; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e7:2a:db:6e:9b:c7:ef:cc:29:88:88:dc:f5:70:ef:96:37:2e:51:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e72adb6e9bc7efcc298888dcf570ef96372e510b/; sid:902200850; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"d7:e3:f2:f1:a4:5f:01:78:fa:93:29:1b:c8:e0:9c:58:14:53:5f:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7e3f2f1a45f0178fa93291bc8e09c5814535f11/; sid:902200851; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fe:89:6f:ca:5f:12:a0:f6:5a:12:e2:ae:39:58:8a:50:5c:f6:d0:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe896fca5f12a0f65a12e2ae39588a505cf6d035/; sid:902200852; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"78:3e:a8:dd:f7:49:4c:c9:36:0b:b0:35:f2:df:c4:5a:d0:60:47:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/783ea8ddf7494cc9360bb035f2dfc45ad06047ab/; sid:902200853; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"20:0d:e4:9d:4e:09:40:cc:38:c9:ea:ae:24:d5:65:2c:40:43:c5:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/200de49d4e0940cc38c9eaae24d5652c4043c5f8/; sid:902200854; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f1:0c:0a:99:cc:1e:1e:5b:8f:dc:89:13:40:97:64:a8:dc:21:35:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f10c0a99cc1e1e5b8fdc8913409764a8dc213547/; sid:902200855; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b5:df:7e:e7:88:cf:69:d8:9b:2e:dc:8a:50:44:80:63:10:c6:bc:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5df7ee788cf69d89b2edc8a5044806310c6bcd8/; sid:902200856; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"87:4d:24:58:df:13:8c:b3:4e:4a:ef:b8:9b:11:a8:e4:99:b1:ab:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/874d2458df138cb34e4aefb89b11a8e499b1abec/; sid:902200857; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fd:70:15:04:79:5d:85:f9:c6:9f:a0:89:0f:f1:e1:33:c8:07:48:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd701504795d85f9c69fa0890ff1e133c807480b/; sid:902200858; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"23:96:cf:6f:9d:9f:75:f9:14:86:1b:50:44:6f:38:10:4d:18:9f:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2396cf6f9d9f75f914861b50446f38104d189f74/; sid:902200859; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0c:1b:32:bb:67:bf:6b:3b:30:fd:d4:0c:4a:17:f6:21:4a:ef:a8:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c1b32bb67bf6b3b30fdd40c4a17f6214aefa866/; sid:902200860; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e3:8e:16:28:f6:76:8a:d5:77:1e:07:de:a4:25:65:3b:54:ba:85:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e38e1628f6768ad5771e07dea425653b54ba85d4/; sid:902200861; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"43:8d:55:ce:36:72:16:ce:4c:83:47:f5:59:bc:3b:15:3f:aa:fa:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/438d55ce367216ce4c8347f559bc3b153faafae5/; sid:902200862; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:41:d9:9a:c7:9f:2c:b5:90:e7:53:2b:13:ff:64:b2:9b:7c:80:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a341d99ac79f2cb590e7532b13ff64b29b7c80c3/; sid:902200863; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2e:4a:91:28:ea:31:dd:8c:6a:78:9f:47:75:78:47:ba:89:ca:d2:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e4a9128ea31dd8c6a789f47757847ba89cad228/; sid:902200864; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"95:c9:d9:c3:e8:e0:4f:3b:74:79:f1:58:ba:f0:ea:27:14:0f:bf:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95c9d9c3e8e04f3b7479f158baf0ea27140fbf61/; sid:902200865; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"43:20:62:f5:0c:4e:a9:79:b8:a5:ce:d1:5a:e8:6f:26:1e:d7:07:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/432062f50c4ea979b8a5ced15ae86f261ed707f4/; sid:902200866; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"6f:f3:32:35:bf:a8:59:4c:ac:5b:f6:78:da:5a:b5:79:05:bf:8d:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ff33235bfa8594cac5bf678da5ab57905bf8dc5/; sid:902200867; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0b:5e:e1:11:66:cd:7a:48:90:3d:fb:1f:4b:b5:f2:7a:65:b8:66:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b5ee11166cd7a48903dfb1f4bb5f27a65b86600/; sid:902200868; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"23:29:a3:59:e7:6f:51:d3:8d:13:06:97:a2:63:22:cc:2c:fc:9d:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2329a359e76f51d38d130697a26322cc2cfc9d17/; sid:902200869; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"be:a9:36:41:9e:54:8d:67:a7:90:30:f4:0a:d4:be:ed:00:8b:18:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bea936419e548d67a79030f40ad4beed008b1898/; sid:902200870; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"19:94:a0:b0:34:b0:2d:a7:3b:2f:e9:a1:70:f8:ce:52:71:40:c9:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1994a0b034b02da73b2fe9a170f8ce527140c9f0/; sid:902200871; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3a:ef:43:1f:8b:b8:bb:f3:8b:9f:f7:4e:7f:a2:36:95:cb:b6:76:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3aef431f8bb8bbf38b9ff74e7fa23695cbb676e6/; sid:902200872; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3e:89:48:72:30:8a:e7:01:24:5f:2c:d8:eb:b0:30:b1:39:f7:93:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e894872308ae701245f2cd8ebb030b139f79352/; sid:902200873; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6a:94:ed:cb:9f:47:ee:5a:ee:6b:28:dd:a5:98:61:20:3f:60:21:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a94edcb9f47ee5aee6b28dda59861203f602190/; sid:902200874; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"26:ee:21:af:cf:20:56:7f:80:d6:d2:f8:35:67:2c:9c:57:83:f1:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26ee21afcf20567f80d6d2f835672c9c5783f1bf/; sid:902200875; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"14:cc:ca:98:6c:4b:83:66:1d:db:f1:fb:3b:73:51:f2:16:f3:a0:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14ccca986c4b83661ddbf1fb3b7351f216f3a007/; sid:902200876; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cc:a0:28:8e:dd:2e:6e:2d:7a:15:e2:2e:31:ad:fb:ab:69:8e:ab:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cca0288edd2e6e2d7a15e22e31adfbab698eab71/; sid:902200877; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c0:dc:f4:41:91:f4:e4:10:0b:a5:3e:97:0a:0b:2f:9d:c5:26:5b:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0dcf44191f4e4100ba53e970a0b2f9dc5265b53/; sid:902200878; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"01:87:15:5d:a8:7a:d3:6a:f4:38:04:28:c2:87:94:c0:ce:2d:6c:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0187155da87ad36af4380428c28794c0ce2d6c03/; sid:902200879; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c5:3d:fc:e6:3e:c4:c1:bc:d4:46:19:6f:f3:63:9a:fe:e9:3d:a0:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c53dfce63ec4c1bcd446196ff3639afee93da024/; sid:902200880; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7e:f9:fa:16:b9:15:42:f4:09:aa:62:db:1b:93:2e:c1:32:58:55:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ef9fa16b91542f409aa62db1b932ec1325855b1/; sid:902200881; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"90:2a:46:fe:66:2e:84:f1:37:f5:8c:7b:eb:73:f4:4b:dd:49:98:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/902a46fe662e84f137f58c7beb73f44bdd499835/; sid:902200882; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"75:90:1d:7f:a7:13:b3:61:5c:f0:dd:0a:1e:e9:1f:91:7f:28:0d:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75901d7fa713b3615cf0dd0a1ee91f917f280d5c/; sid:902200883; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b0:f3:12:2c:1a:b2:8f:cd:3f:a5:6e:7d:88:73:7b:c0:5e:09:58:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0f3122c1ab28fcd3fa56e7d88737bc05e095854/; sid:902200884; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c3:11:9e:04:9e:97:20:72:67:5b:cc:40:8c:49:66:33:a6:0f:30:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3119e049e972072675bcc408c496633a60f305d/; sid:902200885; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4c:aa:72:70:8a:c9:86:39:ee:06:7a:2a:11:b8:64:fa:c1:82:f0:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4caa72708ac98639ee067a2a11b864fac182f0a8/; sid:902200886; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ab:f9:ea:90:a6:e2:fd:62:ad:c0:97:33:c0:30:7a:79:ba:e8:81:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abf9ea90a6e2fd62adc09733c0307a79bae881c6/; sid:902200887; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ad:e6:61:19:82:c4:0d:11:84:c9:c2:b8:71:07:87:fc:a4:f4:b9:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ade6611982c40d1184c9c2b8710787fca4f4b9cc/; sid:902200888; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"30:46:18:64:27:2d:38:d8:dc:de:a0:3d:2b:35:06:1a:7d:47:14:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30461864272d38d8dcdea03d2b35061a7d471434/; sid:902200889; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1e:0d:5a:48:14:e0:76:94:0d:60:26:38:38:50:82:d8:6b:56:78:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e0d5a4814e076940d602638385082d86b5678ec/; sid:902200890; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c4:94:1b:3a:4a:e9:0a:b2:93:a7:78:77:ff:76:18:b5:0c:9f:11:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4941b3a4ae90ab293a77877ff7618b50c9f1196/; sid:902200891; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"31:26:2c:bb:37:7c:ce:57:12:3f:cb:4d:c8:bd:37:ae:84:dd:5e:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31262cbb377cce57123fcb4dc8bd37ae84dd5ec6/; sid:902200892; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e2:8a:48:04:ab:bc:42:42:9d:b8:9e:e4:fa:68:82:54:6d:38:ad:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e28a4804abbc42429db89ee4fa6882546d38ad16/; sid:902200893; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b2:86:16:ec:ac:37:a3:df:a1:3b:56:c7:54:70:0c:d5:b5:96:41:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b28616ecac37a3dfa13b56c754700cd5b5964117/; sid:902200894; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:1c:c7:8f:86:bc:ca:3d:a5:74:28:14:c5:12:a0:ca:0e:ed:6f:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/431cc78f86bcca3da5742814c512a0ca0eed6f3c/; sid:902200895; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ed:28:a9:c7:6b:5b:20:60:5b:2d:e6:61:dd:64:e6:43:d7:a0:29:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed28a9c76b5b20605b2de661dd64e643d7a0290a/; sid:902200896; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1d:8f:c2:98:b9:b8:32:5a:64:ad:fe:28:44:fe:45:b0:5b:60:b6:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d8fc298b9b8325a64adfe2844fe45b05b60b6fc/; sid:902200897; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"dd:ea:a7:f2:df:2b:38:e3:64:ed:38:ed:82:1b:d7:66:b6:1d:5f:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddeaa7f2df2b38e364ed38ed821bd766b61d5fe8/; sid:902200898; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b2:f7:84:c1:ca:50:79:01:bb:08:c6:06:fe:df:99:9e:db:bc:7a:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2f784c1ca507901bb08c606fedf999edbbc7ac6/; sid:902200899; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"34:aa:83:72:7f:2b:e5:43:fe:cc:45:f4:74:fc:5a:f4:6c:c7:72:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34aa83727f2be543fecc45f474fc5af46cc77287/; sid:902200900; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0e:ea:47:b5:89:df:cf:39:8f:87:59:37:5d:7e:d1:2c:1a:e0:3b:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0eea47b589dfcf398f8759375d7ed12c1ae03b54/; sid:902200901; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2f:46:39:d4:3d:4d:e2:8a:bb:27:ad:d8:b9:3f:e7:17:6d:0c:2d:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f4639d43d4de28abb27add8b93fe7176d0c2d37/; sid:902200902; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7c:29:b5:12:f5:2f:63:53:60:5c:f4:23:2e:f8:d8:61:f2:ab:8e:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c29b512f52f6353605cf4232ef8d861f2ab8e61/; sid:902200903; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"91:24:76:50:e0:75:eb:5a:0c:de:45:58:b7:c5:37:59:60:97:05:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91247650e075eb5a0cde4558b7c53759609705e8/; sid:902200904; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"94:04:a1:e8:15:f3:f0:10:ac:d0:8a:8c:9e:e7:a8:2f:3e:fc:02:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9404a1e815f3f010acd08a8c9ee7a82f3efc0289/; sid:902200905; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f6:98:f1:0d:b0:75:b6:40:76:e7:41:61:10:9e:33:20:bb:1e:a9:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f698f10db075b64076e74161109e3320bb1ea92f/; sid:902200906; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1e:09:60:1c:15:4e:7a:fe:df:a3:31:ca:30:32:57:8f:77:e2:60:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e09601c154e7afedfa331ca3032578f77e260d5/; sid:902200907; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f2:46:46:0f:04:8c:74:e5:14:ed:c8:cb:63:73:e1:bc:de:34:81:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f246460f048c74e514edc8cb6373e1bcde348197/; sid:902200908; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"42:ff:09:b1:69:b3:6e:48:72:fa:91:c3:34:8a:8f:c1:74:87:85:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42ff09b169b36e4872fa91c3348a8fc174878568/; sid:902200909; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"73:ec:e1:b6:4a:6d:c9:0a:4d:e2:7d:74:88:4c:57:a6:7d:8d:09:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73ece1b64a6dc90a4de27d74884c57a67d8d09ef/; sid:902200910; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e7:68:58:cc:69:64:b1:0d:c4:0f:c2:9d:ac:bc:11:f9:7b:6a:25:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e76858cc6964b10dc40fc29dacbc11f97b6a25e1/; sid:902200911; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:f2:d0:b8:20:33:3e:e2:82:ac:14:77:52:c9:b1:67:1b:ac:39:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37f2d0b820333ee282ac147752c9b1671bac39e8/; sid:902200912; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"f5:3a:5c:0e:2c:9f:9f:17:08:b1:cf:27:af:cd:72:cc:16:7e:84:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f53a5c0e2c9f9f1708b1cf27afcd72cc167e842d/; sid:902200913; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bb:e9:ee:9d:5c:04:b4:ae:df:00:58:6a:52:6b:50:01:03:e1:76:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbe9ee9d5c04b4aedf00586a526b500103e176bf/; sid:902200914; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"99:a2:69:8a:14:19:89:ad:69:c5:d4:29:5b:1c:ef:08:c1:f3:51:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99a2698a141989ad69c5d4295b1cef08c1f35117/; sid:902200915; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"79:4d:0f:0f:f4:ad:a9:74:36:72:2c:92:02:0d:1b:d3:c5:3a:ee:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/794d0f0ff4ada97436722c92020d1bd3c53aee55/; sid:902200916; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"15:13:e1:07:0a:63:53:40:8c:cd:f5:50:f8:cf:b9:28:29:e2:ce:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1513e1070a6353408ccdf550f8cfb92829e2ce38/; sid:902200917; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"68:d9:04:5b:9a:e8:96:ed:4e:26:d1:d0:e3:e1:a6:82:5a:f1:d9:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68d9045b9ae896ed4e26d1d0e3e1a6825af1d977/; sid:902200918; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4d:14:3a:5b:5f:5f:e1:42:8f:a1:5b:94:4e:13:a7:9f:14:ab:a9:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d143a5b5f5fe1428fa15b944e13a79f14aba985/; sid:902200919; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4c:5d:cd:6a:01:67:4a:5c:3f:14:1e:97:0a:a5:b1:1c:bd:8d:f7:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c5dcd6a01674a5c3f141e970aa5b11cbd8df778/; sid:902200920; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6b:cd:24:dc:af:e8:eb:bf:49:55:ae:55:9a:72:0a:21:89:ed:0b:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bcd24dcafe8ebbf4955ae559a720a2189ed0be2/; sid:902200921; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5e:f7:32:aa:d1:33:94:6a:27:5f:e4:91:e3:1e:77:54:fa:95:f6:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ef732aad133946a275fe491e31e7754fa95f607/; sid:902200922; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"d2:1d:32:3e:19:d7:5d:1f:d7:b8:5c:0b:4a:50:f0:6c:92:71:15:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d21d323e19d75d1fd7b85c0b4a50f06c9271159a/; sid:902200923; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"11:47:94:74:33:f2:61:bc:d2:cd:8f:50:84:61:e0:18:98:c3:96:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1147947433f261bcd2cd8f508461e01898c3960b/; sid:902200924; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:f0:59:b0:fb:d2:a4:a8:68:e5:65:d1:62:e6:15:26:59:4f:02:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4f059b0fbd2a4a868e565d162e61526594f026c/; sid:902200925; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"41:38:20:20:25:25:ec:61:22:ad:b5:87:a2:15:a9:dd:d2:ef:86:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/413820202525ec6122adb587a215a9ddd2ef86f0/; sid:902200926; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"75:10:1b:de:05:22:22:42:a1:ca:5b:08:04:2c:a4:0d:b7:40:e1:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75101bde05222242a1ca5b08042ca40db740e1c2/; sid:902200927; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"50:ce:57:06:3f:81:52:7b:32:57:f4:76:92:4b:7a:78:3c:91:6c:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50ce57063f81527b3257f476924b7a783c916ce8/; sid:902200928; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"63:bf:ab:cf:d3:45:f9:4e:c9:9a:fd:5f:62:00:fa:3d:44:87:f7:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63bfabcfd345f94ec99afd5f6200fa3d4487f764/; sid:902200929; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"18:69:a4:09:c3:62:8c:c3:ec:d7:b6:f6:14:10:cb:3d:16:be:f1:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1869a409c3628cc3ecd7b6f61410cb3d16bef14d/; sid:902200930; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"44:69:3a:76:05:38:0b:9d:a9:f6:4e:52:7e:2b:0e:38:22:02:d9:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44693a7605380b9da9f64e527e2b0e382202d9c3/; sid:902200931; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9a:80:f1:1c:bf:c7:b0:94:be:ab:c0:3a:84:64:4f:72:52:d7:8a:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a80f11cbfc7b094beabc03a84644f7252d78a5e/; sid:902200932; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"60:36:13:e9:d4:7b:a1:25:57:8d:83:37:71:d3:82:2a:65:3f:ef:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/603613e9d47ba125578d833771d3822a653fef21/; sid:902200933; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5f:6d:61:8c:e9:06:e0:66:6c:14:a9:49:6f:29:d6:6c:7d:d1:36:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f6d618ce906e0666c14a9496f29d66c7dd13692/; sid:902200934; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ae:fd:38:c5:55:44:01:59:a6:fb:d7:69:6a:7c:f3:db:3c:98:23:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aefd38c555440159a6fbd7696a7cf3db3c982341/; sid:902200935; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"31:7b:01:97:ce:59:19:6e:f6:8f:01:cb:88:fa:86:ae:05:5b:40:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/317b0197ce59196ef68f01cb88fa86ae055b4072/; sid:902200936; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Send-Safe C&C)"; tls.fingerprint:"b0:bb:e3:da:e1:eb:45:80:64:c6:19:80:1d:05:a8:dc:5e:23:39:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0bbe3dae1eb458064c619801d05a8dc5e233934/; sid:902200937; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"76:9b:c6:c0:89:c0:34:3a:d1:f7:bd:17:96:7e:e8:0d:e8:23:dd:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/769bc6c089c0343ad1f7bd17967ee80de823dd29/; sid:902200938; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"6d:41:79:00:03:63:e8:a7:15:aa:cc:db:be:28:93:89:64:fb:58:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d4179000363e8a715aaccdbbe28938964fb58de/; sid:902200939; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6f:ed:d7:7d:dd:f2:dc:6b:63:6a:6d:30:63:a4:4c:6d:8d:43:e1:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fedd77dddf2dc6b636a6d3063a44c6d8d43e124/; sid:902200940; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1c:83:57:ec:56:4e:a1:f6:38:16:58:01:22:47:01:f5:65:f1:d3:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c8357ec564ea1f638165801224701f565f1d3d8/; sid:902200941; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4b:96:aa:73:71:b9:d5:5d:f6:f9:2e:9e:c8:07:5d:93:a3:11:55:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b96aa7371b9d55df6f92e9ec8075d93a31155f7/; sid:902200942; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e3:53:d2:3f:26:d9:3a:a0:26:74:1c:9c:dd:a3:8b:16:fc:aa:a7:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e353d23f26d93aa026741c9cdda38b16fcaaa77b/; sid:902200943; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"0d:41:87:12:21:70:67:91:a2:62:03:f9:61:7b:85:97:23:ff:b2:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d41871221706791a26203f9617b859723ffb243/; sid:902200944; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"5f:bd:f2:63:05:6f:b0:af:93:e7:7e:71:88:4a:a6:2c:c3:7f:bd:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fbdf263056fb0af93e77e71884aa62cc37fbd3a/; sid:902200945; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"40:d4:fe:fe:24:51:04:20:a9:7a:1d:7d:34:ec:5c:47:43:cf:1e:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40d4fefe24510420a97a1d7d34ec5c4743cf1e86/; sid:902200946; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d1:c7:40:82:fa:51:37:90:5b:86:75:aa:05:4a:0b:ae:fa:5f:76:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1c74082fa5137905b8675aa054a0baefa5f7650/; sid:902200947; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"8f:7e:4e:31:ce:31:6e:3f:ab:9b:a5:34:6c:f4:2e:bb:0f:ed:2d:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f7e4e31ce316e3fab9ba5346cf42ebb0fed2d85/; sid:902200948; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"20:5c:00:27:1c:9c:2d:ce:dc:37:15:9b:c4:44:25:63:6c:83:7d:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/205c00271c9c2dcedc37159bc44425636c837d89/; sid:902200949; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:39:15:2c:6f:05:28:20:44:4b:2c:84:44:30:48:d8:d3:6d:86:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c739152c6f052820444b2c84443048d8d36d862a/; sid:902200950; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"23:ea:bd:a9:c6:7f:0a:0d:ee:3a:12:fd:ce:f1:fd:e5:84:a0:0f:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23eabda9c67f0a0dee3a12fdcef1fde584a00f44/; sid:902200951; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9f:47:cb:1f:50:dc:e2:bd:73:ce:db:97:6c:21:d6:19:9a:e6:eb:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f47cb1f50dce2bd73cedb976c21d6199ae6ebe7/; sid:902200952; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"59:80:32:0f:98:88:1d:4b:53:f6:0f:82:2f:d1:49:fb:08:4a:55:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5980320f98881d4b53f60f822fd149fb084a5538/; sid:902200953; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"61:70:cb:38:ea:ab:de:35:c9:36:fe:42:2a:51:e4:85:cf:12:47:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6170cb38eaabde35c936fe422a51e485cf1247a5/; sid:902200954; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"70:e9:0c:3e:40:fd:b8:b0:04:f9:a5:ec:13:f3:f2:8f:d0:0c:aa:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70e90c3e40fdb8b004f9a5ec13f3f28fd00caa44/; sid:902200955; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:b6:6d:0d:5a:70:94:88:ab:7f:d4:fe:e3:8e:27:ee:a2:8e:b4:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77b66d0d5a709488ab7fd4fee38e27eea28eb402/; sid:902200956; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cf:9c:47:c1:b2:a0:3a:61:8c:09:b7:f9:a2:0f:32:ef:3b:0d:83:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf9c47c1b2a03a618c09b7f9a20f32ef3b0d8337/; sid:902200957; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"c8:6e:4f:26:df:15:86:16:14:ca:9b:d4:73:6c:b9:ad:29:c4:b6:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c86e4f26df15861614ca9bd4736cb9ad29c4b647/; sid:902200958; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"eb:c2:9e:39:37:8a:fa:48:0a:ef:79:4b:bb:6e:89:b4:ab:d5:e5:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebc29e39378afa480aef794bbb6e89b4abd5e516/; sid:902200959; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"73:33:25:89:f7:b9:5b:d3:ae:f2:8d:ab:94:a4:10:1f:16:9d:3b:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73332589f7b95bd3aef28dab94a4101f169d3b41/; sid:902200960; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1d:4b:e8:f1:25:61:9b:be:6e:d8:15:35:79:e8:78:de:bf:73:69:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d4be8f125619bbe6ed8153579e878debf7369a4/; sid:902200961; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4c:17:e1:73:f7:46:b6:8c:bc:68:eb:38:e6:a3:58:c0:54:4e:c7:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c17e173f746b68cbc68eb38e6a358c0544ec718/; sid:902200962; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:04:d0:bd:b3:94:44:39:67:a8:b6:5d:43:21:a0:8f:5c:f1:24:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e904d0bdb394443967a8b65d4321a08f5cf124c6/; sid:902200963; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"47:e5:12:d9:b8:b3:78:01:fc:0b:ed:77:f2:a1:0d:61:d5:4a:e5:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47e512d9b8b37801fc0bed77f2a10d61d54ae572/; sid:902200964; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b5:86:80:d6:a6:c2:c8:68:de:0f:ca:1d:4a:b6:f3:d3:60:cf:5d:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b58680d6a6c2c868de0fca1d4ab6f3d360cf5dc9/; sid:902200965; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:00:08:2b:ee:55:ae:92:82:5f:94:f5:fa:f4:fe:3e:43:3a:72:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4300082bee55ae92825f94f5faf4fe3e433a723c/; sid:902200966; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2e:cb:96:97:2a:ff:84:a8:65:37:aa:3d:75:c2:58:e3:00:f4:d7:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ecb96972aff84a86537aa3d75c258e300f4d767/; sid:902200967; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"19:da:07:60:77:84:b4:bb:3b:d1:50:9b:c8:e8:0c:a4:b9:1e:59:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19da07607784b4bb3bd1509bc8e80ca4b91e59ee/; sid:902200968; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2f:ac:ee:cc:fe:2d:d3:d7:4d:aa:ba:ff:af:00:1f:1b:ae:ed:3b:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2faceeccfe2dd3d74daabaffaf001f1baeed3b25/; sid:902200969; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"19:3d:f8:7a:a0:1c:36:2b:4d:d2:6f:0c:db:9c:a3:b1:95:8e:b9:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/193df87aa01c362b4dd26f0cdb9ca3b1958eb965/; sid:902200970; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"52:bf:e9:b1:3e:5c:ba:c4:97:94:cc:83:e1:f3:4c:3c:53:80:83:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52bfe9b13e5cbac49794cc83e1f34c3c538083a0/; sid:902200971; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"60:15:02:2b:12:f4:f1:37:b4:5d:72:38:ef:cd:32:9b:27:7f:77:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6015022b12f4f137b45d7238efcd329b277f7736/; sid:902200972; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"fc:8e:bd:31:14:76:7c:33:5c:5b:85:c3:f7:b5:de:ff:44:9d:aa:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc8ebd3114767c335c5b85c3f7b5deff449daaf5/; sid:902200973; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2e:8e:3e:0d:51:c3:dd:ae:f3:a0:91:27:24:d9:ce:83:75:02:61:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e8e3e0d51c3ddaef3a0912724d9ce837502612f/; sid:902200974; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"e2:75:ed:91:3d:9f:04:08:8e:20:67:d4:1b:49:ca:90:f4:98:f2:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e275ed913d9f04088e2067d41b49ca90f498f235/; sid:902200975; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"34:a9:2e:41:d4:cf:61:f1:fc:51:0e:40:af:d3:62:d2:dd:c0:0f:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34a92e41d4cf61f1fc510e40afd362d2ddc00ff7/; sid:902200976; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"43:63:59:9d:a4:1d:93:47:e8:2e:9c:a9:3c:2e:1a:90:0e:ba:0b:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4363599da41d9347e82e9ca93c2e1a900eba0b2b/; sid:902200977; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6b:ce:6b:d7:fa:5d:26:8b:32:e3:43:2d:28:6c:24:67:90:a3:08:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bce6bd7fa5d268b32e3432d286c246790a30833/; sid:902200978; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b8:0d:52:b8:29:67:b9:43:d6:32:8b:b2:70:06:74:12:d1:9a:3a:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b80d52b82967b943d6328bb270067412d19a3a78/; sid:902200979; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5a:2c:d9:79:b7:e3:a8:19:4d:e4:23:65:e1:d6:4f:7f:09:6b:e7:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a2cd979b7e3a8194de42365e1d64f7f096be7d8/; sid:902200980; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fc:49:13:72:e2:53:cf:8e:b5:9a:0b:90:fa:72:5a:0d:ce:31:eb:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc491372e253cf8eb59a0b90fa725a0dce31eb9a/; sid:902200981; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c8:d9:fc:ad:7e:eb:b3:a7:a9:fa:b9:74:78:b1:99:34:bb:98:bd:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8d9fcad7eebb3a7a9fab97478b19934bb98bdfa/; sid:902200982; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2a:0a:86:07:0b:e3:2a:4b:d2:24:3d:54:75:35:4b:7d:65:2f:de:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a0a86070be32a4bd2243d5475354b7d652fde3c/; sid:902200983; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"de:e6:1e:7d:12:22:3c:b2:d0:fc:9c:30:fa:7e:4a:d1:c8:e0:75:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dee61e7d12223cb2d0fc9c30fa7e4ad1c8e07518/; sid:902200984; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"35:42:c9:f3:be:f6:cd:ac:e6:9a:35:f5:6a:1b:94:65:e2:6e:d7:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3542c9f3bef6cdace69a35f56a1b9465e26ed712/; sid:902200985; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"38:ae:a7:09:04:79:5d:cb:af:1c:be:95:10:07:5e:3d:9c:e4:fc:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38aea70904795dcbaf1cbe9510075e3d9ce4fc02/; sid:902200986; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"39:db:50:ef:01:84:10:2a:26:6c:a2:e3:ca:d0:f9:8f:ef:b8:9c:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39db50ef0184102a266ca2e3cad0f98fefb89c82/; sid:902200987; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"fb:08:b6:29:de:fd:12:9a:46:99:77:4e:c6:0b:50:05:80:9e:ab:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb08b629defd129a4699774ec60b5005809eabad/; sid:902200988; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d6:e1:46:db:65:1d:3d:37:e2:d0:73:e8:d8:2d:e6:f2:25:0b:97:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6e146db651d3d37e2d073e8d82de6f2250b9791/; sid:902200989; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f2:a6:19:75:cb:54:1e:6a:62:ed:8c:a5:21:40:20:10:8d:92:2a:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2a61975cb541e6a62ed8ca5214020108d922a14/; sid:902200990; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"21:ac:11:e8:f3:cf:cc:86:cf:79:d7:89:e7:45:1b:df:95:b5:14:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21ac11e8f3cfcc86cf79d789e7451bdf95b5140a/; sid:902200991; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ec:c6:58:86:2a:d7:2d:fa:14:3d:7c:24:26:52:1a:54:f6:66:b9:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecc658862ad72dfa143d7c2426521a54f666b9df/; sid:902200992; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"68:2c:c8:69:54:4e:6b:ee:be:37:15:9b:de:d9:b2:f6:15:91:37:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/682cc869544e6beebe37159bded9b2f61591378f/; sid:902200993; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"94:cf:c5:8c:0a:6d:44:53:27:cf:45:89:53:10:2b:56:17:e7:fe:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94cfc58c0a6d445327cf458953102b5617e7fe29/; sid:902200994; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:3f:e5:08:cb:81:f3:44:b9:d0:d1:e6:1c:88:ec:e9:bb:9c:8c:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a33fe508cb81f344b9d0d1e61c88ece9bb9c8cbd/; sid:902200995; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"53:3d:b5:0c:5b:cd:82:d7:2d:07:9c:2a:a8:43:aa:57:cf:e6:9d:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/533db50c5bcd82d72d079c2aa843aa57cfe69d01/; sid:902200996; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"68:78:b4:78:3c:f1:ab:68:47:16:1e:bb:10:1a:63:84:3f:06:a9:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6878b4783cf1ab6847161ebb101a63843f06a98e/; sid:902200997; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"cf:66:ea:3b:60:88:b8:10:0b:69:9e:31:6f:84:cd:7d:e7:fc:76:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf66ea3b6088b8100b699e316f84cd7de7fc76ab/; sid:902200998; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"7a:0b:0f:ca:51:e4:97:c9:aa:0d:c4:da:aa:14:2f:56:37:05:fe:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a0b0fca51e497c9aa0dc4daaa142f563705fe43/; sid:902200999; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"82:26:83:ca:ec:7d:fe:13:7b:f4:7b:f9:ca:17:6a:9e:94:d9:dc:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/822683caec7dfe137bf47bf9ca176a9e94d9dc8b/; sid:902201000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"35:ba:f2:9f:7f:a2:3e:3d:46:fb:16:e7:9f:b0:23:54:05:a1:99:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35baf29f7fa23e3d46fb16e79fb0235405a1998a/; sid:902201001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"7f:48:d4:aa:cf:79:49:e3:de:64:6c:61:0b:9c:59:79:c6:8e:c5:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f48d4aacf7949e3de646c610b9c5979c68ec52f/; sid:902201002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"eb:86:5a:d6:ff:29:40:55:52:f7:68:c3:3c:3a:cc:4c:b8:d9:b7:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb865ad6ff29405552f768c33c3acc4cb8d9b7dd/; sid:902201003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bb:e1:6a:1c:d4:69:b6:d1:ab:99:bc:5d:c4:b2:43:8f:b6:80:1e:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbe16a1cd469b6d1ab99bc5dc4b2438fb6801e60/; sid:902201004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d2:8b:e4:34:6e:fc:d8:7d:17:d3:59:5d:0d:8c:86:d2:22:e0:54:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d28be4346efcd87d17d3595d0d8c86d222e05420/; sid:902201005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d4:fc:c5:a2:02:85:30:22:a6:1c:bf:06:f3:5d:c5:20:25:de:de:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4fcc5a202853022a61cbf06f35dc52025dede3a/; sid:902201006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"35:2c:39:c3:b8:0f:00:f7:7b:49:a0:d3:f9:16:b7:a0:a6:e8:56:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/352c39c3b80f00f77b49a0d3f916b7a0a6e856f8/; sid:902201007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ec:5b:81:f7:e1:ea:b3:7f:d7:d6:61:72:d8:8e:f6:91:fd:dd:ff:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec5b81f7e1eab37fd7d66172d88ef691fdddff06/; sid:902201008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fc:3f:b5:57:67:2e:17:94:e4:d7:9f:eb:7d:d7:cc:e5:b5:22:ce:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc3fb557672e1794e4d79feb7dd7cce5b522ce36/; sid:902201009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"38:17:74:d7:7d:04:ae:c0:79:63:b6:5c:c2:c9:c5:94:5f:9d:43:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/381774d77d04aec07963b65cc2c9c5945f9d432b/; sid:902201010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b6:c2:df:a6:71:2c:2d:55:ae:f0:71:61:c4:5f:bf:3b:a8:7a:a4:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c2dfa6712c2d55aef07161c45fbf3ba87aa4ed/; sid:902201011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"08:c3:95:a9:2e:1b:23:46:79:3f:71:fc:69:2e:9b:78:bf:ec:e0:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08c395a92e1b2346793f71fc692e9b78bfece072/; sid:902201012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5a:66:3b:6a:0a:ab:e4:47:bb:52:ab:b9:e0:cb:c8:b7:da:f0:5e:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a663b6a0aabe447bb52abb9e0cbc8b7daf05e7b/; sid:902201013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0f:3c:8f:f0:2d:1c:b8:03:77:f8:e5:dd:33:41:7a:18:17:4e:40:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f3c8ff02d1cb80377f8e5dd33417a18174e4099/; sid:902201014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0e:44:c7:aa:ad:d1:18:6c:17:f4:f1:36:4e:37:22:c1:72:a7:ce:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e44c7aaadd1186c17f4f1364e3722c172a7ce2e/; sid:902201015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1d:6d:1f:2b:fb:ca:de:17:be:42:33:c8:8d:ed:d2:ce:b8:02:60:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d6d1f2bfbcade17be4233c88dedd2ceb802602e/; sid:902201016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c4:26:79:3f:8b:04:33:55:9e:10:39:6d:37:69:e4:c2:06:cf:10:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c426793f8b0433559e10396d3769e4c206cf10d3/; sid:902201017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"63:75:b2:82:75:fa:7c:95:91:2c:a1:20:0c:9e:02:87:a6:5a:ad:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6375b28275fa7c95912ca1200c9e0287a65aadef/; sid:902201018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"08:ca:6e:54:08:95:38:df:6b:3d:c4:71:d4:51:af:89:2e:86:31:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08ca6e54089538df6b3dc471d451af892e8631dc/; sid:902201019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"fe:76:6e:a5:72:67:b8:d9:fa:e9:78:8b:02:65:30:7b:53:d6:59:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe766ea57267b8d9fae9788b0265307b53d659cf/; sid:902201020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bd:d7:80:30:c8:94:db:d5:d7:2c:d6:3e:d8:c2:8d:55:de:a6:dd:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdd78030c894dbd5d72cd63ed8c28d55dea6dd3f/; sid:902201021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7b:5a:8f:28:9d:bd:70:8e:98:a7:f8:df:1e:05:fd:0a:b4:e2:8f:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b5a8f289dbd708e98a7f8df1e05fd0ab4e28fec/; sid:902201022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c3:ca:0b:70:d9:1e:d8:4b:aa:00:bc:59:6a:7d:64:b8:8d:71:e9:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3ca0b70d91ed84baa00bc596a7d64b88d71e92e/; sid:902201023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"49:39:8e:9d:0b:17:16:c0:67:f5:46:b3:5d:c2:f6:c2:b3:2d:1a:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49398e9d0b1716c067f546b35dc2f6c2b32d1a7f/; sid:902201024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:6d:e6:95:15:dc:79:07:8a:91:84:78:a1:ba:35:26:52:65:2f:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d6de69515dc79078a918478a1ba352652652f5e/; sid:902201025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fb:78:dc:77:f6:db:e6:c1:72:c2:0d:9c:a9:ac:d6:2e:08:f2:3f:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb78dc77f6dbe6c172c20d9ca9acd62e08f23fac/; sid:902201026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:db:eb:f3:f0:9c:23:87:3a:a2:5c:78:cf:5a:ac:95:e2:9e:a7:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efdbebf3f09c23873aa25c78cf5aac95e29ea7e6/; sid:902201027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"40:21:5a:e3:76:a7:0f:62:2c:c4:2e:53:2c:38:7a:8c:12:56:96:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40215ae376a70f622cc42e532c387a8c125696e1/; sid:902201028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f5:fe:9f:02:ba:6e:b3:5a:f4:3c:cd:16:88:a9:ef:6a:40:3f:8c:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5fe9f02ba6eb35af43ccd1688a9ef6a403f8cfb/; sid:902201029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"65:1f:ce:4f:01:fb:51:71:fe:68:fa:cf:2b:24:5d:9e:3e:6d:8c:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/651fce4f01fb5171fe68facf2b245d9e3e6d8c47/; sid:902201030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8d:ce:aa:6c:43:39:4c:f8:a9:c3:cc:3c:3f:eb:9b:a3:c2:6a:64:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dceaa6c43394cf8a9c3cc3c3feb9ba3c26a64c8/; sid:902201031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"95:8b:5f:15:4d:c1:91:3e:cf:de:28:09:b0:62:25:9a:a7:07:b9:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/958b5f154dc1913ecfde2809b062259aa707b9f6/; sid:902201032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"cf:27:cc:e5:3a:52:00:81:d0:5c:a4:dc:28:a8:99:0b:74:f6:03:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf27cce53a520081d05ca4dc28a8990b74f60380/; sid:902201033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"91:45:d9:97:96:3a:50:b9:10:7c:45:f0:57:d9:51:07:a6:32:96:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9145d997963a50b9107c45f057d95107a63296c3/; sid:902201034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4e:37:fc:e8:59:65:65:78:9f:d8:73:42:2f:b7:74:27:22:76:70:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e37fce8596565789fd873422fb7742722767064/; sid:902201035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"63:eb:bb:74:f1:b0:b6:6f:94:2b:11:3d:ef:39:27:e8:5a:3a:24:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63ebbb74f1b0b66f942b113def3927e85a3a2491/; sid:902201036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e1:8c:66:d7:33:02:24:4d:15:8e:bd:d0:f1:41:dc:39:5a:48:8e:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e18c66d73302244d158ebdd0f141dc395a488ed4/; sid:902201037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"af:f4:f3:a7:28:f1:65:be:e5:ca:7c:dc:1f:94:71:d1:7d:49:1a:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aff4f3a728f165bee5ca7cdc1f9471d17d491a62/; sid:902201038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f6:ad:cf:0d:68:26:5b:5f:f0:27:ca:f5:2c:eb:ab:00:a6:64:b7:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6adcf0d68265b5ff027caf52cebab00a664b7e5/; sid:902201039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:f9:2a:f9:23:29:5b:89:4b:f7:b9:a6:65:78:49:32:bd:73:e8:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eff92af923295b894bf7b9a665784932bd73e81c/; sid:902201040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:95:04:c3:07:58:13:83:03:31:60:16:c1:f7:c8:fd:71:c1:46:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c19504c30758138303316016c1f7c8fd71c146ea/; sid:902201041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b7:ca:92:19:f3:ff:f0:9c:e2:d8:ac:6a:03:22:df:3f:21:b0:bc:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7ca9219f3fff09ce2d8ac6a0322df3f21b0bcf3/; sid:902201042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"63:d1:6c:e6:20:7e:16:c7:3b:38:68:ef:ef:f3:03:2b:92:90:f3:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63d16ce6207e16c73b3868efeff3032b9290f3c6/; sid:902201043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"72:e6:13:64:d9:f0:fe:15:e5:cd:0f:d6:af:c4:b2:12:cf:cd:64:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72e61364d9f0fe15e5cd0fd6afc4b212cfcd6470/; sid:902201044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:50:74:00:79:31:00:3c:76:ae:51:dc:74:13:03:b8:6b:e6:fa:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e25074007931003c76ae51dc741303b86be6fa06/; sid:902201045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"b5:08:31:a1:d3:19:9b:41:d5:2d:43:76:c5:ca:ea:ce:e0:5a:4a:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b50831a1d3199b41d52d4376c5caeacee05a4ae3/; sid:902201046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"93:82:0f:72:18:11:62:9f:f0:d3:51:0a:5a:e3:ec:72:f2:f9:26:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93820f721811629ff0d3510a5ae3ec72f2f926ef/; sid:902201047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1c:b5:36:f2:bb:f0:7c:9c:6d:97:b1:58:aa:81:b2:ef:ec:ec:03:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cb536f2bbf07c9c6d97b158aa81b2efecec0330/; sid:902201048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"18:62:c7:77:ba:bf:29:8f:e5:a9:34:06:e4:dc:84:56:d7:18:ab:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1862c777babf298fe5a93406e4dc8456d718abcf/; sid:902201049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"1b:3f:95:27:55:d5:14:33:ae:04:1d:28:2e:a0:48:32:cc:6d:e6:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b3f952755d51433ae041d282ea04832cc6de62d/; sid:902201050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Worm.Dorkbot C&C)"; tls.fingerprint:"73:1c:58:9f:f2:87:4c:29:da:6b:93:7d:23:ae:cb:2d:c9:02:c5:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/731c589ff2874c29da6b937d23aecb2dc902c5f7/; sid:902201051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f6:85:d3:97:2d:c7:c5:7e:11:aa:54:33:22:38:af:1f:e6:e8:32:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f685d3972dc7c57e11aa54332238af1fe6e83275/; sid:902201052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9d:9a:36:1d:a8:12:ec:3f:2e:53:58:29:6f:4c:e3:00:04:57:2e:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d9a361da812ec3f2e5358296f4ce30004572e09/; sid:902201053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"93:74:79:06:0f:4e:a9:36:17:58:78:49:b2:58:b4:fd:89:13:34:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/937479060f4ea93617587849b258b4fd891334d5/; sid:902201054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"37:29:80:33:35:df:a5:e6:27:ab:ab:2b:bb:bb:fc:bb:c3:0a:c2:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3729803335dfa5e627abab2bbbbbfcbbc30ac29f/; sid:902201055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7e:4d:40:66:c5:5d:43:bf:6b:d6:03:70:3a:49:2a:30:12:5a:c4:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e4d4066c55d43bf6bd603703a492a30125ac42d/; sid:902201056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f3:cb:ce:dc:bd:89:b6:11:6e:f5:d6:1c:a3:70:b6:59:58:a0:76:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3cbcedcbd89b6116ef5d61ca370b65958a076a8/; sid:902201057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"d3:44:31:0c:0f:fc:00:c4:3b:24:83:d6:2b:58:0b:1e:cc:3a:74:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d344310c0ffc00c43b2483d62b580b1ecc3a74ed/; sid:902201058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9d:af:ef:75:1e:f9:be:79:4e:97:b3:aa:a5:e0:bf:e5:1f:ed:e7:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9dafef751ef9be794e97b3aaa5e0bfe51fede7b9/; sid:902201059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"36:8e:6b:eb:6f:8d:2f:60:49:83:1f:e2:5d:d3:97:28:78:23:c5:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/368e6beb6f8d2f6049831fe25dd397287823c5e6/; sid:902201060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"79:e1:0a:84:01:7c:36:a7:89:0f:49:fc:ab:7d:c7:cf:19:28:26:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79e10a84017c36a7890f49fcab7dc7cf192826d8/; sid:902201061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"48:25:f4:a2:cb:22:4d:11:74:be:a7:10:04:35:6b:94:3e:42:a2:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4825f4a2cb224d1174bea71004356b943e42a2a4/; sid:902201062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f4:67:2f:c4:46:ef:2d:54:26:5a:20:c3:90:13:4a:24:14:19:99:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4672fc446ef2d54265a20c390134a241419999a/; sid:902201063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"79:66:ac:af:e2:f5:a9:5b:b0:ef:bc:22:4b:a1:13:3b:2e:61:3c:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7966acafe2f5a95bb0efbc224ba1133b2e613cf3/; sid:902201064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ed:11:61:f8:1d:db:d9:a0:26:42:d4:56:10:b2:7d:ae:d2:a4:c5:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed1161f81ddbd9a02642d45610b27daed2a4c5d7/; sid:902201065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4f:fa:3b:ad:4e:19:ab:b8:f2:88:16:d3:8f:8f:a2:12:8f:4e:46:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ffa3bad4e19abb8f28816d38f8fa2128f4e46b7/; sid:902201066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ac:ad:78:6c:c0:4e:b0:77:50:2b:da:9f:49:c9:d5:94:82:78:58:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acad786cc04eb077502bda9f49c9d5948278582e/; sid:902201067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"a8:93:ec:d6:17:c0:24:ae:e5:44:e6:a6:b2:8b:7c:25:69:19:8e:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a893ecd617c024aee544e6a6b28b7c2569198e73/; sid:902201068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b7:eb:cb:b5:35:3f:f4:c6:db:73:2c:1b:39:be:ee:59:1f:b9:eb:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7ebcbb5353ff4c6db732c1b39beee591fb9eb6e/; sid:902201069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"54:56:8c:96:7d:5d:5c:df:30:20:61:41:38:72:11:da:6b:a8:6f:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54568c967d5d5cdf30206141387211da6ba86fb4/; sid:902201070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"12:c7:aa:3e:41:69:ff:25:82:c2:82:45:ff:a5:b3:62:69:73:92:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12c7aa3e4169ff2582c28245ffa5b362697392c7/; sid:902201071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"fe:70:95:63:01:28:be:29:75:23:27:6a:0f:af:af:5c:38:66:79:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe7095630128be297523276a0fafaf5c3866799d/; sid:902201072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"87:f2:a4:24:a7:02:d0:a2:39:6e:60:70:53:49:17:4f:8d:59:44:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87f2a424a702d0a2396e60705349174f8d59440a/; sid:902201073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"39:8b:91:3a:da:3f:59:62:e9:24:48:6d:ba:e6:68:cd:f9:c0:dc:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/398b913ada3f5962e924486dbae668cdf9c0dc72/; sid:902201074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"de:2f:cb:51:5c:44:96:8f:d3:24:70:f8:e1:e3:73:fe:fa:8b:fb:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de2fcb515c44968fd32470f8e1e373fefa8bfb60/; sid:902201075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b0:45:be:c6:fb:61:22:b0:74:7b:c2:74:38:50:aa:ab:78:68:e6:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b045bec6fb6122b0747bc2743850aaab7868e62a/; sid:902201076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:b8:96:03:6e:33:46:1b:43:1f:f4:a0:4f:73:c3:bc:22:d4:7b:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38b896036e33461b431ff4a04f73c3bc22d47b76/; sid:902201077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"13:d6:3d:e5:20:4a:6c:35:18:27:87:93:5c:85:16:46:6b:1f:cd:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/13d63de5204a6c35182787935c8516466b1fcdd3/; sid:902201078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:6e:3c:06:9c:39:76:c3:f2:e9:7d:2a:96:4c:1f:c1:9d:38:b3:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/156e3c069c3976c3f2e97d2a964c1fc19d38b3fa/; sid:902201079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"7d:f5:35:64:76:19:f3:8f:5f:e9:a9:f4:13:90:6a:b4:e3:55:90:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7df535647619f38f5fe9a9f413906ab4e355909a/; sid:902201080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"11:53:e6:91:d5:41:23:4d:43:4e:a1:54:31:06:ec:c4:75:f3:06:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1153e691d541234d434ea1543106ecc475f30693/; sid:902201081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"00:a9:3f:c7:4e:d0:00:bd:d1:d9:f0:dd:4f:5b:0e:d7:5a:f3:08:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00a93fc74ed000bdd1d9f0dd4f5b0ed75af30870/; sid:902201082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"05:3d:41:cd:f0:74:9d:69:3a:79:2c:36:94:7c:16:a6:24:8b:b0:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/053d41cdf0749d693a792c36947c16a6248bb028/; sid:902201083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f8:f7:06:09:91:e7:39:30:cd:56:4e:54:01:39:66:37:f9:5c:92:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8f7060991e73930cd564e5401396637f95c92d4/; sid:902201084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"df:fb:56:f3:20:7d:f4:d4:86:5a:3b:49:ed:bf:8f:27:d6:c7:1a:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dffb56f3207df4d4865a3b49edbf8f27d6c71a8e/; sid:902201085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"64:f2:42:0c:fa:4b:ba:c2:e9:9d:18:b9:68:0a:17:90:ab:4d:da:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64f2420cfa4bbac2e99d18b9680a1790ab4ddaaf/; sid:902201086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1f:73:41:b0:52:d1:f2:7b:19:76:3c:d0:c8:26:5a:f8:a1:31:05:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f7341b052d1f27b19763cd0c8265af8a13105d2/; sid:902201087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d4:24:41:08:f9:4b:69:31:14:1c:13:b2:ae:e8:3d:b3:25:ee:05:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4244108f94b6931141c13b2aee83db325ee05bb/; sid:902201088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2a:e6:52:44:aa:20:d9:92:d7:74:d4:af:37:01:65:43:e7:ff:46:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ae65244aa20d992d774d4af37016543e7ff460c/; sid:902201089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"39:65:1d:d1:be:23:36:9f:80:1b:47:79:ac:2d:7d:b8:65:e7:a2:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39651dd1be23369f801b4779ac2d7db865e7a246/; sid:902201090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e3:f9:5e:ef:ca:a5:d6:d2:c5:82:95:31:ca:02:f9:f3:8c:da:12:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3f95eefcaa5d6d2c5829531ca02f9f38cda12dc/; sid:902201091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"73:cb:76:a3:cb:40:b8:31:0d:13:e8:2f:aa:df:58:f6:28:a1:96:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73cb76a3cb40b8310d13e82faadf58f628a1966d/; sid:902201092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3f:64:b4:f1:24:67:b6:28:0e:7f:eb:46:82:8e:0b:a2:8e:5d:d1:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f64b4f12467b6280e7feb46828e0ba28e5dd132/; sid:902201093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"ff:79:aa:5a:96:00:09:d8:be:dd:89:0a:ba:98:19:36:bf:df:05:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff79aa5a960009d8bedd890aba981936bfdf0563/; sid:902201094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"eb:4b:94:a0:ca:9a:0e:a2:67:5f:19:9d:dd:f3:8f:b7:dc:8c:95:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb4b94a0ca9a0ea2675f199dddf38fb7dc8c9524/; sid:902201095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f7:73:47:64:58:ee:9b:27:25:f2:c0:a9:38:04:82:8b:44:69:0c:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f773476458ee9b2725f2c0a93804828b44690c7c/; sid:902201096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8f:81:f1:8c:ee:57:c4:43:8a:8b:8d:ae:9f:34:ee:84:6c:61:92:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f81f18cee57c4438a8b8dae9f34ee846c61922f/; sid:902201097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"dc:e3:02:80:28:02:8e:5b:2c:d6:ff:51:a6:b6:e5:65:9a:b1:d7:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dce3028028028e5b2cd6ff51a6b6e5659ab1d748/; sid:902201098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6d:f3:da:62:54:fe:88:4f:56:32:0a:e2:8a:ca:a7:88:07:48:ea:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6df3da6254fe884f56320ae28acaa7880748ea96/; sid:902201099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"41:d6:62:03:15:36:fd:5a:29:7e:c9:3a:ed:5e:d1:82:ee:cc:22:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41d662031536fd5a297ec93aed5ed182eecc2262/; sid:902201100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f8:65:e1:67:29:af:45:8b:4a:1e:d8:32:36:9c:31:4b:ad:e9:48:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f865e16729af458b4a1ed832369c314bade948bf/; sid:902201101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7a:90:9e:cc:ac:2b:cd:d2:41:e1:83:94:2b:46:ff:61:41:dd:17:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a909eccac2bcdd241e183942b46ff6141dd17af/; sid:902201102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ea:84:51:0c:e3:b3:13:1f:42:c4:43:b9:8e:17:f2:7a:87:6e:cb:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea84510ce3b3131f42c443b98e17f27a876ecbea/; sid:902201103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2e:83:00:eb:08:31:fa:63:a3:fd:bd:4f:2a:a9:8c:f6:c9:9c:23:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e8300eb0831fa63a3fdbd4f2aa98cf6c99c23e9/; sid:902201104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1e:5e:c7:fa:ed:c4:b3:16:c1:6a:b3:39:23:b7:79:c1:03:0c:e8:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e5ec7faedc4b316c16ab33923b779c1030ce8c0/; sid:902201105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:7c:6c:d3:03:0a:68:77:6b:b8:44:ba:b1:cc:dc:c5:ed:8f:d5:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e97c6cd3030a68776bb844bab1ccdcc5ed8fd5cf/; sid:902201106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"55:ae:98:5b:a6:45:3d:5c:d7:43:37:f0:ff:c8:07:53:ba:ec:f4:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55ae985ba6453d5cd74337f0ffc80753baecf441/; sid:902201107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1f:2a:30:ef:c5:fd:50:3a:a7:ef:1f:0f:8e:f4:13:9c:c7:7f:b4:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f2a30efc5fd503aa7ef1f0f8ef4139cc77fb48c/; sid:902201108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1a:94:d2:8c:20:94:79:6b:53:6d:30:31:70:9d:e0:fe:71:2a:13:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a94d28c2094796b536d3031709de0fe712a132a/; sid:902201109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0b:c1:17:f5:02:4a:ab:93:84:29:84:83:72:06:ef:b8:50:25:8e:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bc117f5024aab93842984837206efb850258ecb/; sid:902201110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5f:a1:98:59:c4:df:2f:76:92:d0:68:a1:7d:77:21:e3:0f:51:2b:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fa19859c4df2f7692d068a17d7721e30f512b3c/; sid:902201111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d0:67:d9:98:ee:a2:47:d9:24:f0:cb:b5:30:ce:87:a0:56:ff:59:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d067d998eea247d924f0cbb530ce87a056ff5933/; sid:902201112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5c:5c:05:c4:95:83:42:0f:36:5a:08:74:8b:3f:77:af:6d:0e:10:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c5c05c49583420f365a08748b3f77af6d0e1093/; sid:902201113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6d:de:75:ca:5c:fb:c0:fd:a3:b1:85:79:f5:d8:49:27:74:32:af:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6dde75ca5cfbc0fda3b18579f5d849277432af78/; sid:902201114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"17:14:ea:54:c7:f0:d5:e8:01:c9:82:21:37:a7:94:b6:55:e4:45:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1714ea54c7f0d5e801c9822137a794b655e44529/; sid:902201115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cf:20:0a:4e:cc:09:53:05:9b:cb:27:97:cc:70:fa:d6:e4:b7:f8:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf200a4ecc0953059bcb2797cc70fad6e4b7f818/; sid:902201116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5c:18:50:56:e7:5d:41:b7:1a:fd:76:64:fd:ed:33:79:5d:f1:ed:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c185056e75d41b71afd7664fded33795df1edb5/; sid:902201117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:b4:31:0a:34:54:3c:69:30:b1:c1:7a:bc:d7:3a:5b:45:c5:9f:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85b4310a34543c6930b1c17abcd73a5b45c59f5d/; sid:902201118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"92:b8:64:81:9e:ae:20:f7:55:d7:09:23:87:25:3b:ba:59:04:13:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92b864819eae20f755d7092387253bba59041346/; sid:902201119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"30:15:29:74:71:3e:1a:64:ea:8b:e4:7d:26:de:2d:aa:16:e2:49:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30152974713e1a64ea8be47d26de2daa16e249d2/; sid:902201120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c0:c5:62:9b:2a:90:6a:67:b0:56:61:7c:01:58:b0:fc:b1:dc:3a:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0c5629b2a906a67b056617c0158b0fcb1dc3ad7/; sid:902201121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0c:af:29:e9:a5:d3:8c:49:7b:13:64:06:d6:b0:25:52:a9:86:b8:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0caf29e9a5d38c497b136406d6b02552a986b88c/; sid:902201122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:d9:94:1c:b6:27:b7:1f:0d:74:9e:5d:9d:b8:61:8c:4f:77:23:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06d9941cb627b71f0d749e5d9db8618c4f772327/; sid:902201123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ee:19:5b:bb:70:b4:ba:a1:06:7d:f4:b3:63:ae:58:a7:e4:29:f5:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee195bbb70b4baa1067df4b363ae58a7e429f53a/; sid:902201124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3f:ee:5c:28:b2:8e:f0:67:82:aa:18:89:9b:e1:16:c9:ab:0b:4f:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3fee5c28b28ef06782aa18899be116c9ab0b4ffc/; sid:902201125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bf:5f:36:fc:13:0b:9e:14:3a:44:55:cb:82:3d:46:9d:d7:e9:a8:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf5f36fc130b9e143a4455cb823d469dd7e9a8d1/; sid:902201126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:fb:d8:b6:0b:56:4f:49:36:82:4d:c8:22:6b:5c:52:50:5d:dd:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52fbd8b60b564f4936824dc8226b5c52505ddddb/; sid:902201127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5e:48:8a:46:82:6e:e4:18:e6:bb:a5:6a:d9:03:72:90:d3:f8:be:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e488a46826ee418e6bba56ad9037290d3f8be52/; sid:902201128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d7:7d:5c:09:f6:04:68:87:96:cc:60:26:33:df:e5:08:6d:2a:87:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d77d5c09f604688796cc602633dfe5086d2a87f3/; sid:902201129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f8:e7:7b:39:6c:9e:89:d5:84:ec:ee:41:81:7b:40:54:1e:95:7a:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8e77b396c9e89d584ecee41817b40541e957af0/; sid:902201130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"87:d4:dd:71:55:3a:81:5c:ee:2c:71:b6:45:18:87:68:09:08:77:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87d4dd71553a815cee2c71b645188768090877a9/; sid:902201131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2e:55:56:4a:1b:31:a9:92:93:2e:21:88:00:86:cc:a5:df:72:91:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e55564a1b31a992932e21880086cca5df72916b/; sid:902201132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bb:14:ff:39:82:ae:18:b4:6a:e3:50:32:ff:44:ca:ed:0b:a1:d0:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb14ff3982ae18b46ae35032ff44caed0ba1d05a/; sid:902201133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:e8:c5:9b:88:46:a0:16:b2:c0:0e:7d:07:c9:f0:9f:50:f7:0b:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52e8c59b8846a016b2c00e7d07c9f09f50f70b81/; sid:902201134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"13:f3:00:e4:b4:33:97:fb:95:50:e3:24:e3:b0:4e:98:b4:d2:70:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/13f300e4b43397fb9550e324e3b04e98b4d270f7/; sid:902201135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f9:8d:fa:31:74:ff:9c:4d:46:55:29:e7:e6:1f:53:9c:22:67:48:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f98dfa3174ff9c4d465529e7e61f539c22674835/; sid:902201136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5e:17:82:5e:fe:d0:e6:d9:c4:03:a0:17:53:6a:ed:b1:be:5d:eb:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e17825efed0e6d9c403a017536aedb1be5deb58/; sid:902201137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0e:a5:88:34:72:68:74:9a:d8:31:a7:18:8a:cc:6d:f0:0e:44:38:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ea588347268749ad831a7188acc6df00e443863/; sid:902201138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e9:a1:28:3d:36:d1:79:0a:4d:a7:23:f3:18:3d:20:61:ec:09:9b:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9a1283d36d1790a4da723f3183d2061ec099b37/; sid:902201139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5e:65:43:0b:ec:c5:c5:b1:11:33:2b:6f:57:da:36:f2:60:be:13:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e65430becc5c5b111332b6f57da36f260be13b9/; sid:902201140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ac:64:85:38:41:1e:f8:73:fe:49:09:37:28:e8:36:ba:51:92:3f:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac648538411ef873fe49093728e836ba51923ffe/; sid:902201141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"71:66:65:78:9c:85:bc:ae:38:43:30:9b:61:99:4d:2e:6c:b9:29:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/716665789c85bcae3843309b61994d2e6cb92975/; sid:902201142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"bd:d3:52:d9:0e:b1:ba:49:34:73:24:de:b0:20:f7:15:4e:be:c1:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdd352d90eb1ba49347324deb020f7154ebec18d/; sid:902201143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"56:1e:b4:87:16:28:5b:bb:84:ce:04:c9:bd:1a:15:31:b9:f3:e0:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/561eb48716285bbb84ce04c9bd1a1531b9f3e0bd/; sid:902201144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9c:c2:3c:94:02:d1:8a:e6:74:1e:0b:d2:bf:ad:79:d0:ff:57:10:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cc23c9402d18ae6741e0bd2bfad79d0ff5710f1/; sid:902201145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"28:b5:11:d0:9f:7a:0f:65:4d:22:0b:9b:04:9f:92:ab:3b:b5:13:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28b511d09f7a0f654d220b9b049f92ab3bb513fa/; sid:902201146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"14:e9:7c:0d:73:dd:b4:94:ab:11:47:68:21:b4:99:9e:ed:99:6e:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14e97c0d73ddb494ab11476821b4999eed996ed8/; sid:902201147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"51:d6:64:3c:f4:68:54:98:10:17:5e:e4:9f:83:79:f7:60:6a:eb:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51d6643cf468549810175ee49f8379f7606aebd0/; sid:902201148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0d:a0:45:61:36:76:e3:ae:73:8d:ef:ab:e9:76:de:56:c3:43:84:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0da045613676e3ae738defabe976de56c3438489/; sid:902201149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"09:a8:18:c7:a0:2c:dd:e9:94:84:96:49:7e:37:05:80:6a:d7:ec:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09a818c7a02cdde9948496497e3705806ad7ecc9/; sid:902201150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"43:ad:82:f2:bb:31:f4:4c:9d:43:df:fa:17:01:39:c9:f3:41:8e:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43ad82f2bb31f44c9d43dffa170139c9f3418ed2/; sid:902201151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"48:84:f7:5f:6b:4c:31:8a:fc:86:63:2d:f4:bf:d6:57:30:8a:36:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4884f75f6b4c318afc86632df4bfd657308a3628/; sid:902201152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"20:a0:61:39:2e:5a:4d:0b:0e:9b:02:73:e1:84:74:aa:25:e1:5b:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20a061392e5a4d0b0e9b0273e18474aa25e15b59/; sid:902201153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"95:6f:15:c0:04:5f:84:c0:91:42:09:41:a5:b9:5d:be:e7:2e:4b:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/956f15c0045f84c091420941a5b95dbee72e4b6d/; sid:902201154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"74:1f:79:25:49:9a:be:46:89:e6:1f:c0:68:1a:49:1e:48:c4:58:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/741f7925499abe4689e61fc0681a491e48c45815/; sid:902201155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c8:f2:80:d0:12:f3:39:a9:92:09:2a:3c:ba:72:98:86:1f:7b:11:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8f280d012f339a992092a3cba7298861f7b1148/; sid:902201156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"36:d0:b9:f7:c0:ce:f3:c2:7b:32:07:3d:cc:19:ba:07:67:94:e0:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36d0b9f7c0cef3c27b32073dcc19ba076794e0ed/; sid:902201157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:1e:76:ef:83:85:f7:f2:51:df:d7:86:e9:0d:d8:c4:98:2e:aa:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/371e76ef8385f7f251dfd786e90dd8c4982eaa82/; sid:902201158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c9:22:41:7e:8c:bc:fe:6a:82:46:75:a8:e2:ed:e1:c8:e2:05:2a:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c922417e8cbcfe6a824675a8e2ede1c8e2052a8b/; sid:902201159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1a:09:ee:00:f6:7b:01:70:d7:ab:13:8c:9b:a5:14:cf:7a:f5:50:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a09ee00f67b0170d7ab138c9ba514cf7af55085/; sid:902201160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9b:71:13:0e:30:1e:d4:50:a8:bd:2a:ba:3a:7f:8c:eb:80:8c:b6:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b71130e301ed450a8bd2aba3a7f8ceb808cb626/; sid:902201161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d6:86:41:1c:69:9c:d8:42:00:4f:6b:d6:89:57:1f:1e:bb:c8:50:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d686411c699cd842004f6bd689571f1ebbc8501a/; sid:902201162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a9:cd:c9:f7:4a:9d:66:9a:9f:51:10:95:c0:99:6a:c2:0f:9d:cf:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9cdc9f74a9d669a9f511095c0996ac20f9dcf7f/; sid:902201163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"eb:95:20:fc:ba:10:66:dc:55:65:8b:c8:b1:bb:81:25:58:22:a6:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb9520fcba1066dc55658bc8b1bb81255822a605/; sid:902201164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0a:b8:fc:10:ea:5a:42:fe:df:43:08:fe:70:fb:5f:8a:a3:cc:95:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ab8fc10ea5a42fedf4308fe70fb5f8aa3cc9577/; sid:902201165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:7b:b4:7f:bc:e6:34:b6:22:97:8f:02:49:66:68:1c:7d:71:08:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/527bb47fbce634b622978f024966681c7d71082b/; sid:902201166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:4e:79:c7:0b:f7:74:54:60:74:e0:f3:29:3f:ec:87:72:c1:b8:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e24e79c70bf774546074e0f3293fec8772c1b8a2/; sid:902201167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"30:c1:39:e4:c9:47:0d:78:c5:29:c5:08:33:92:59:1b:f1:e6:f7:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30c139e4c9470d78c529c5083392591bf1e6f79d/; sid:902201168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"24:10:a7:81:3a:2d:22:83:5c:72:d3:06:2c:a8:9a:b2:eb:d2:ec:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2410a7813a2d22835c72d3062ca89ab2ebd2ec48/; sid:902201169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e6:04:80:1b:82:6d:b8:dc:01:84:3e:d2:bc:1c:71:43:74:66:63:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e604801b826db8dc01843ed2bc1c7143746663a4/; sid:902201170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0d:ee:94:cc:a8:a8:5c:6b:6d:e1:6d:88:9b:90:58:4b:05:6c:ff:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dee94cca8a85c6b6de16d889b90584b056cff74/; sid:902201171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"13:ff:7f:d5:3d:92:e1:85:65:72:14:a7:a4:7c:09:0e:26:f5:29:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/13ff7fd53d92e185657214a7a47c090e26f529d1/; sid:902201172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5c:e4:2b:1e:73:a0:9f:7a:74:df:f8:e2:89:70:07:ad:8b:08:d9:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ce42b1e73a09f7a74dff8e2897007ad8b08d979/; sid:902201173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"bf:45:52:7a:cf:51:83:9e:80:36:95:01:0d:c7:7e:ca:56:f2:cd:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf45527acf51839e803695010dc77eca56f2cda5/; sid:902201174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1f:b7:63:39:b0:75:19:8c:34:d2:ee:2c:96:fb:55:d1:4d:f2:18:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fb76339b075198c34d2ee2c96fb55d14df218ba/; sid:902201175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e7:b2:eb:15:5c:98:d1:e7:1c:a0:9d:68:8c:de:06:e7:9d:77:41:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7b2eb155c98d1e71ca09d688cde06e79d7741da/; sid:902201176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"98:7c:f9:9d:2b:22:c0:51:1a:e9:2e:a5:34:dc:bb:3a:29:fb:5e:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/987cf99d2b22c0511ae92ea534dcbb3a29fb5eec/; sid:902201177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"89:a1:3b:5a:9f:5e:95:f6:8a:7a:de:54:15:78:60:e9:f0:57:8e:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89a13b5a9f5e95f68a7ade54157860e9f0578e71/; sid:902201178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"48:00:50:73:18:a6:dc:98:54:96:a5:46:3f:86:49:90:96:ab:10:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4800507318a6dc985496a5463f86499096ab10f3/; sid:902201179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1a:44:fa:70:e5:6a:20:a4:54:b3:bf:72:cd:be:77:2e:53:8a:50:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a44fa70e56a20a454b3bf72cdbe772e538a50cd/; sid:902201180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ad:f0:ae:94:a3:d1:ca:30:f0:cb:c2:3b:ff:fb:93:b5:d0:1c:6f:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/adf0ae94a3d1ca30f0cbc23bfffb93b5d01c6fda/; sid:902201181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:5e:0f:5d:3c:53:53:c1:58:a8:26:2b:6e:cf:0c:9d:96:34:a6:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/155e0f5d3c5353c158a8262b6ecf0c9d9634a627/; sid:902201182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:d1:aa:1a:b8:a1:43:92:04:40:41:a2:0a:d8:01:3f:20:7a:a1:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5dd1aa1ab8a14392044041a20ad8013f207aa18f/; sid:902201183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ea:6b:22:f8:82:d4:88:6d:e4:4d:28:f9:7f:63:aa:80:e7:39:a4:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea6b22f882d4886de44d28f97f63aa80e739a4fb/; sid:902201184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"05:27:3e:6f:cf:79:d4:7b:38:41:d4:36:9b:1c:e3:04:1f:75:61:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05273e6fcf79d47b3841d4369b1ce3041f756163/; sid:902201185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4f:fb:ee:30:13:a4:64:df:8a:d3:42:3b:dc:0a:ad:40:b1:b1:12:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ffbee3013a464df8ad3423bdc0aad40b1b112f2/; sid:902201186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1f:d0:8b:6d:c5:64:cb:35:5c:79:fa:05:19:29:0d:ad:5f:23:23:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fd08b6dc564cb355c79fa0519290dad5f23238d/; sid:902201187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c8:3c:f2:2f:63:24:af:29:aa:62:2c:e1:a3:da:4e:b2:3a:f1:bd:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c83cf22f6324af29aa622ce1a3da4eb23af1bd2f/; sid:902201188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e0:21:43:88:a7:94:38:3b:4e:41:fd:fa:ce:69:12:b3:32:b0:45:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0214388a794383b4e41fdface6912b332b0457b/; sid:902201189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"a3:93:d2:01:ba:27:f5:5b:3c:d9:86:15:1d:02:f8:68:15:97:60:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a393d201ba27f55b3cd986151d02f8681597602c/; sid:902201190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"10:53:0d:c9:14:51:b4:77:50:17:c9:5f:dd:11:76:30:11:f9:50:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10530dc91451b4775017c95fdd11763011f95004/; sid:902201191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7c:5b:e4:57:98:6a:c6:a7:d7:6d:20:a4:8f:38:fc:da:f4:86:3d:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c5be457986ac6a7d76d20a48f38fcdaf4863dab/; sid:902201192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"7e:fc:b5:20:ca:d9:ac:92:6a:65:3d:4d:ba:a8:fa:ee:59:fa:f9:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7efcb520cad9ac926a653d4dbaa8faee59faf927/; sid:902201193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"a0:4b:2e:a9:75:dd:4d:e3:be:aa:35:d0:8a:9c:60:9d:5b:47:15:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a04b2ea975dd4de3beaa35d08a9c609d5b4715a1/; sid:902201194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"a9:65:0a:45:22:14:0d:42:e5:ca:45:29:da:54:80:56:25:ee:be:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9650a4522140d42e5ca4529da54805625eebe64/; sid:902201195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b7:9a:fa:34:a7:e7:72:8d:48:bc:5a:bc:0e:e9:a6:43:b1:8f:44:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b79afa34a7e7728d48bc5abc0ee9a643b18f44ca/; sid:902201196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"46:26:3f:94:5d:8e:c0:d2:d1:e2:cf:97:e9:08:3e:fa:b2:1c:d8:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46263f945d8ec0d2d1e2cf97e9083efab21cd81e/; sid:902201197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f2:a1:18:7d:0e:02:b4:38:74:a9:4e:37:a6:36:4e:c5:cf:ea:d8:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2a1187d0e02b43874a94e37a6364ec5cfead80a/; sid:902201198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c6:33:21:c0:e7:20:ce:00:52:ab:08:cd:5c:39:3a:5d:e7:ca:ce:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c63321c0e720ce0052ab08cd5c393a5de7caceda/; sid:902201199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5e:45:80:76:91:5a:38:20:06:c5:f2:2c:f6:d6:20:51:d8:ea:6e:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e458076915a382006c5f22cf6d62051d8ea6e7b/; sid:902201200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"fa:c2:3c:75:88:97:f5:90:24:56:6a:fd:da:8d:9e:6c:98:bb:2d:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fac23c758897f59024566afdda8d9e6c98bb2d60/; sid:902201201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2b:b8:ba:23:9c:86:93:cb:0f:48:d8:85:f2:12:eb:c3:00:a8:eb:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bb8ba239c8693cb0f48d885f212ebc300a8eb56/; sid:902201202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"76:8e:fe:87:e0:b9:5e:97:52:62:af:b3:5e:03:50:c5:fe:10:c8:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/768efe87e0b95e975262afb35e0350c5fe10c868/; sid:902201203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"74:8a:29:1d:d8:3f:4a:e3:a1:e4:8d:35:20:f2:5d:7b:40:01:d9:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/748a291dd83f4ae3a1e48d3520f25d7b4001d928/; sid:902201204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"13:5f:bc:73:c6:0d:e8:67:82:b0:50:78:b5:bc:44:3a:26:10:e9:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/135fbc73c60de86782b05078b5bc443a2610e95d/; sid:902201205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6b:01:9f:cd:64:e1:e1:c8:a3:9e:03:be:07:46:08:f1:bc:df:25:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b019fcd64e1e1c8a39e03be074608f1bcdf253c/; sid:902201206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c2:6e:2c:33:ff:f6:57:21:ed:de:a5:e6:32:ce:12:4e:9e:71:29:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c26e2c33fff65721eddea5e632ce124e9e7129b2/; sid:902201207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"44:6e:cf:82:fa:1a:ec:7f:00:a0:47:ff:e2:4b:2b:59:7c:9a:c0:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/446ecf82fa1aec7f00a047ffe24b2b597c9ac08e/; sid:902201208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"94:2a:32:30:34:a8:0e:06:70:d3:69:7b:6e:6e:1f:18:e3:74:55:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/942a323034a80e0670d3697b6e6e1f18e37455bc/; sid:902201209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1b:72:dd:e6:90:11:e4:99:e5:ec:f4:01:e4:93:2b:b4:c5:cb:3f:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b72dde69011e499e5ecf401e4932bb4c5cb3f6e/; sid:902201210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c3:f7:45:af:14:b0:fe:22:02:54:f3:72:60:0c:32:36:7a:d4:ea:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3f745af14b0fe220254f372600c32367ad4eab8/; sid:902201211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"99:38:97:4f:71:d1:71:54:79:dc:6d:db:5b:58:31:1c:17:7a:f0:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9938974f71d1715479dc6ddb5b58311c177af08e/; sid:902201212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"90:4b:f7:87:4a:d3:93:0f:e5:74:73:d0:0c:e8:53:8b:4a:4f:31:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/904bf7874ad3930fe57473d00ce8538b4a4f31a8/; sid:902201213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"10:fe:db:94:7e:fc:90:06:06:23:b0:8d:a6:60:33:0c:4b:37:22:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10fedb947efc90060623b08da660330c4b3722f6/; sid:902201214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1a:d2:cd:b4:58:67:cb:90:40:bf:20:ab:53:f2:88:c1:d5:29:a0:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ad2cdb45867cb9040bf20ab53f288c1d529a0ac/; sid:902201215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6a:13:91:7d:aa:4e:c2:02:77:cb:50:9d:af:14:3d:15:f4:04:8d:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a13917daa4ec20277cb509daf143d15f4048d8f/; sid:902201216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f6:8b:61:24:1b:49:e3:7c:f0:a1:75:47:ce:f7:42:f1:6a:59:5f:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f68b61241b49e37cf0a17547cef742f16a595fea/; sid:902201217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cf:b7:bd:1b:08:66:19:a1:fa:1b:3b:68:b9:88:3a:3b:75:d0:10:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfb7bd1b086619a1fa1b3b68b9883a3b75d010b2/; sid:902201218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b5:70:92:f7:ef:bb:48:a1:21:87:e7:a4:56:f1:b0:12:d2:07:18:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b57092f7efbb48a12187e7a456f1b012d207184f/; sid:902201219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"49:48:cd:47:1f:d2:93:a9:2d:4f:b6:8d:87:0c:b0:be:54:5d:b9:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4948cd471fd293a92d4fb68d870cb0be545db926/; sid:902201220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3c:9b:8d:e7:69:21:83:09:13:64:40:16:a9:3b:09:a6:7f:b0:d8:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c9b8de76921830913644016a93b09a67fb0d8f4/; sid:902201221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:67:e9:a7:90:0f:42:74:92:cd:fe:09:a1:4d:bd:20:a5:2d:17:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce67e9a7900f427492cdfe09a14dbd20a52d1765/; sid:902201222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"01:7b:f6:e2:7b:aa:42:95:f2:1d:e7:5c:af:20:96:16:d5:ee:77:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/017bf6e27baa4295f21de75caf209616d5ee779b/; sid:902201223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"b2:0d:20:ac:3b:24:92:f1:1a:27:75:d8:00:fd:72:6e:14:fc:6f:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b20d20ac3b2492f11a2775d800fd726e14fc6fa6/; sid:902201224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e7:ad:52:8a:97:a4:80:86:cc:d5:3a:37:bc:dd:91:d4:6d:fe:b2:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7ad528a97a48086ccd53a37bcdd91d46dfeb2d0/; sid:902201225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"63:4b:da:13:1a:93:32:8a:e6:98:b6:28:e7:56:cc:a6:f5:69:61:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/634bda131a93328ae698b628e756cca6f56961d7/; sid:902201226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"21:1e:0b:2e:2b:50:62:d3:6d:57:00:0f:00:68:b3:9b:3e:6f:ba:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/211e0b2e2b5062d36d57000f0068b39b3e6fba13/; sid:902201227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:58:7b:07:c7:08:62:56:d8:cc:52:e3:c5:24:e7:91:28:90:b3:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a587b07c7086256d8cc52e3c524e7912890b359/; sid:902201228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4d:97:3d:26:3e:f9:78:8a:cf:4e:bc:cf:bc:5a:fb:96:0e:25:a9:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d973d263ef9788acf4ebccfbc5afb960e25a903/; sid:902201229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c9:0b:3c:d4:d5:17:db:4a:de:4f:65:bb:e3:5b:0e:1d:a1:51:85:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c90b3cd4d517db4ade4f65bbe35b0e1da151856a/; sid:902201230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d7:8d:84:73:60:95:b5:1c:91:4c:63:ab:a8:06:51:c4:b2:8b:d8:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d78d84736095b51c914c63aba80651c4b28bd8b0/; sid:902201231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8f:af:a9:9c:73:14:e9:eb:3c:64:26:9f:dc:f3:42:b6:17:5b:01:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fafa99c7314e9eb3c64269fdcf342b6175b019e/; sid:902201232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5c:55:d2:f5:1c:af:87:1c:95:6a:13:7b:f6:1c:47:4a:14:be:a8:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c55d2f51caf871c956a137bf61c474a14bea854/; sid:902201233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ad:81:03:b5:e6:15:06:60:ed:b3:17:ad:69:a9:3e:80:37:0b:a9:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad8103b5e6150660edb317ad69a93e80370ba9c9/; sid:902201234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"36:d2:86:99:e1:6b:62:96:61:e4:30:f8:88:c7:a7:c3:05:48:4e:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36d28699e16b629661e430f888c7a7c305484e4a/; sid:902201235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fd:97:51:4a:5f:2b:bd:20:05:2a:52:27:07:d1:cf:d4:c4:05:0f:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd97514a5f2bbd20052a522707d1cfd4c4050feb/; sid:902201236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"46:5b:e3:dd:ee:3c:51:4e:51:ae:98:77:ba:54:d1:65:22:d9:ae:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/465be3ddee3c514e51ae9877ba54d16522d9ae8c/; sid:902201237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dd:7e:3c:fb:31:2e:f1:b2:0d:61:08:b9:e2:fb:d5:45:1b:99:71:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd7e3cfb312ef1b20d6108b9e2fbd5451b997157/; sid:902201238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"16:85:ba:03:51:56:50:a1:c2:a1:33:8b:f9:42:1e:a0:0a:7c:03:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1685ba03515650a1c2a1338bf9421ea00a7c0362/; sid:902201239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5c:d7:39:98:6a:d9:cf:12:8d:4b:ad:03:17:dc:d0:ab:81:c2:cf:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5cd739986ad9cf128d4bad0317dcd0ab81c2cf2b/; sid:902201240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f2:a8:3f:92:7a:ed:31:c0:bc:38:48:84:f9:32:ea:4a:a9:6b:21:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2a83f927aed31c0bc384884f932ea4aa96b2182/; sid:902201241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7e:62:5c:53:31:bc:09:5a:2a:09:d7:39:f0:1d:ee:d7:b8:2e:ec:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e625c5331bc095a2a09d739f01deed7b82eec4a/; sid:902201242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"45:e3:f9:5f:3b:01:ca:79:81:ce:44:f4:15:39:6b:5d:53:ea:2f:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45e3f95f3b01ca7981ce44f415396b5d53ea2f37/; sid:902201243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"73:b2:5a:f5:8c:1f:fc:52:19:0c:62:d3:b6:0e:3a:88:d7:eb:ea:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73b25af58c1ffc52190c62d3b60e3a88d7ebea24/; sid:902201244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3c:0f:57:09:3d:80:0d:e7:5f:32:a1:ee:a5:54:e7:5e:3a:ea:de:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c0f57093d800de75f32a1eea554e75e3aeadeec/; sid:902201245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"94:42:bb:9e:31:81:5f:e7:8e:f8:9a:45:61:75:82:c3:50:22:eb:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9442bb9e31815fe78ef89a45617582c35022eb13/; sid:902201246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d8:b1:2e:83:59:5f:43:99:6c:83:1d:7c:00:0b:f4:cb:9b:a9:e5:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8b12e83595f43996c831d7c000bf4cb9ba9e51a/; sid:902201247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"2f:c9:af:d5:d4:fb:22:ea:31:25:84:24:c2:44:4a:f7:c7:a0:11:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2fc9afd5d4fb22ea31258424c2444af7c7a01139/; sid:902201248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e3:bd:aa:15:f6:c6:31:39:c2:8e:57:fa:5a:32:89:19:0d:ac:0a:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3bdaa15f6c63139c28e57fa5a3289190dac0a12/; sid:902201249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d9:ea:8c:49:ad:85:60:e1:91:e2:42:de:5e:bd:49:b0:d6:c0:c1:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9ea8c49ad8560e191e242de5ebd49b0d6c0c180/; sid:902201250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:fc:02:72:94:23:5c:86:25:cd:1a:ca:79:48:32:8c:1e:85:32:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2fc027294235c8625cd1aca7948328c1e85325c/; sid:902201251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f8:90:d6:bc:87:90:a2:9f:91:3c:b4:b6:a9:30:37:0c:38:08:9a:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f890d6bc8790a29f913cb4b6a930370c38089a25/; sid:902201252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8b:35:6c:2a:7c:08:57:04:c5:99:59:ba:06:db:d0:17:1f:74:fb:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b356c2a7c085704c59959ba06dbd0171f74fbd5/; sid:902201253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"27:24:0e:97:4a:bb:90:57:0d:76:3a:d5:31:76:8d:35:54:5a:36:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27240e974abb90570d763ad531768d35545a36fd/; sid:902201254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"99:3d:a5:48:6c:11:06:2f:3b:3a:1f:19:36:fa:24:16:51:3d:8c:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/993da5486c11062f3b3a1f1936fa2416513d8c4a/; sid:902201255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"87:86:45:d2:ae:90:20:67:e8:a8:09:60:60:e9:d2:75:93:cd:a7:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/878645d2ae902067e8a8096060e9d27593cda7c4/; sid:902201256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"15:84:6b:fb:b4:3e:5b:57:6d:d3:f3:f6:27:5c:eb:73:1d:99:26:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15846bfbb43e5b576dd3f3f6275ceb731d9926bc/; sid:902201257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2f:fd:d8:8a:84:9a:80:1c:96:a4:65:70:44:7f:7a:6b:9c:56:23:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ffdd88a849a801c96a46570447f7a6b9c562346/; sid:902201258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5c:b2:5a:c5:4c:e0:40:e1:24:c4:52:3d:ca:fc:c2:68:64:aa:92:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5cb25ac54ce040e124c4523dcafcc26864aa9277/; sid:902201259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"7f:cd:2c:56:08:47:7d:34:c2:a3:9e:0a:74:3a:20:52:dc:de:94:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7fcd2c5608477d34c2a39e0a743a2052dcde94d1/; sid:902201260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"24:67:d1:8c:4d:1a:74:9b:0e:0c:03:17:7b:22:59:66:00:0a:ce:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2467d18c4d1a749b0e0c03177b225966000aced9/; sid:902201261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"de:64:20:f6:91:74:9b:27:5d:ee:88:46:9a:08:82:09:35:9c:ef:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de6420f691749b275dee88469a088209359cef29/; sid:902201262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"29:73:49:4a:8c:67:7e:0e:7b:23:7b:8e:1a:92:fd:73:db:3f:93:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2973494a8c677e0e7b237b8e1a92fd73db3f9394/; sid:902201263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"22:99:80:d6:20:53:47:0e:aa:cd:87:3e:c6:c5:03:ba:54:4e:03:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/229980d62053470eaacd873ec6c503ba544e03a5/; sid:902201264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f3:a3:b0:16:11:12:b3:41:fb:e6:b3:e0:f7:85:ec:cd:76:c3:5e:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3a3b0161112b341fbe6b3e0f785eccd76c35e19/; sid:902201265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d7:9b:48:61:80:8a:f8:f3:a9:af:8b:35:a8:9d:0d:47:24:55:bd:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d79b4861808af8f3a9af8b35a89d0d472455bd41/; sid:902201266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"19:8b:e3:e1:19:89:34:fe:ec:57:d1:10:ff:36:cf:79:05:dc:de:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/198be3e1198934feec57d110ff36cf7905dcde8b/; sid:902201267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"96:fc:9c:af:a6:7f:a6:61:6c:88:17:60:fc:ab:36:d2:27:be:bd:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96fc9cafa67fa6616c881760fcab36d227bebd2c/; sid:902201268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shylock C&C)"; tls.fingerprint:"b1:1e:5d:b4:da:0a:1e:b4:19:ec:3d:14:44:3b:10:61:6d:aa:02:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b11e5db4da0a1eb419ec3d14443b10616daa0233/; sid:902201269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"4e:6a:4b:49:76:81:b4:c0:9e:2b:f4:4c:65:6f:a4:b8:c3:76:aa:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e6a4b497681b4c09e2bf44c656fa4b8c376aa37/; sid:902201270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:8f:e7:6f:ee:e3:44:16:52:5f:8b:e5:d5:0f:aa:5d:58:5b:13:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a8fe76feee34416525f8be5d50faa5d585b13cf/; sid:902201271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:da:69:17:83:c1:66:f7:50:bb:bf:34:0d:63:71:69:a9:e8:d6:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ada691783c166f750bbbf340d637169a9e8d6f9/; sid:902201272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"46:ff:ef:69:7f:40:21:09:36:60:58:6d:bd:fc:00:87:a0:48:95:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46ffef697f4021093660586dbdfc0087a0489571/; sid:902201273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5d:88:2b:e7:32:98:26:77:ba:3e:57:e9:dc:95:ae:77:d0:39:ab:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d882be732982677ba3e57e9dc95ae77d039abcc/; sid:902201274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ab:d3:4c:09:da:5f:04:3d:82:11:2f:9e:b2:86:79:2e:47:43:ed:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abd34c09da5f043d82112f9eb286792e4743ed39/; sid:902201275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d4:a6:63:6b:43:f8:96:af:c5:03:eb:97:6a:66:2d:23:7e:06:fa:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4a6636b43f896afc503eb976a662d237e06fa9e/; sid:902201276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"95:61:05:c5:cb:1e:4a:33:94:6d:29:97:d9:f7:e4:07:ae:13:df:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/956105c5cb1e4a33946d2997d9f7e407ae13dfa0/; sid:902201277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6d:32:5b:fa:a6:b6:e1:9b:ca:22:8d:73:bb:0a:d4:41:61:9f:d1:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d325bfaa6b6e19bca228d73bb0ad441619fd1a0/; sid:902201278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"4a:48:de:cf:eb:6a:4a:ea:44:10:a7:7a:d3:08:f1:b0:10:8c:ea:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a48decfeb6a4aea4410a77ad308f1b0108ceaa5/; sid:902201279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"08:6f:65:08:9d:7e:24:63:aa:60:ab:71:93:4f:e0:4c:4c:9d:7c:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/086f65089d7e2463aa60ab71934fe04c4c9d7cc6/; sid:902201280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"44:7f:91:67:6e:92:66:5a:a0:4b:08:cc:12:29:ca:65:d0:54:47:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/447f91676e92665aa04b08cc1229ca65d0544744/; sid:902201281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"76:f3:a4:6e:e4:ef:a9:be:c5:ea:a1:44:0f:ee:7c:b7:4c:24:fd:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76f3a46ee4efa9bec5eaa1440fee7cb74c24fd25/; sid:902201282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"43:b2:09:1b:b1:cc:23:b0:0e:1c:b2:32:d6:8f:a3:03:8a:a1:07:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43b2091bb1cc23b00e1cb232d68fa3038aa10792/; sid:902201283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"4d:b1:ba:4e:f3:ca:53:dd:88:df:a0:94:20:a0:76:91:2b:d5:b9:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4db1ba4ef3ca53dd88dfa09420a076912bd5b956/; sid:902201284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"c4:2d:2a:84:cb:f7:9b:6c:09:1f:01:e3:38:e5:14:11:2c:2b:fa:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c42d2a84cbf79b6c091f01e338e514112c2bfa0b/; sid:902201285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f9:5b:24:25:00:03:78:4f:2a:95:97:fc:8e:82:ad:d3:ed:25:cf:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f95b24250003784f2a9597fc8e82add3ed25cf2e/; sid:902201286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"c4:cc:25:a2:88:92:56:b8:ec:a1:6d:4c:34:42:17:5d:c1:84:cd:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4cc25a2889256b8eca16d4c3442175dc184cd43/; sid:902201287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e3:32:d7:32:74:34:ac:d5:68:1a:de:b8:24:2d:f3:f9:e2:82:9b:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e332d7327434acd5681adeb8242df3f9e2829bbf/; sid:902201288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f1:01:a8:c2:df:f8:93:62:78:7a:05:38:1d:96:d1:30:eb:c0:22:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f101a8c2dff89362787a05381d96d130ebc02242/; sid:902201289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"20:f9:b3:06:c1:84:0a:ec:ba:b9:17:e3:4d:6c:dc:a1:d7:78:73:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20f9b306c1840aecbab917e34d6cdca1d778730f/; sid:902201290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"68:18:c8:a5:16:8e:b2:0f:0c:39:7d:2e:71:7f:53:ae:06:5a:bd:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6818c8a5168eb20f0c397d2e717f53ae065abd38/; sid:902201291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"22:99:18:d6:5d:7b:b2:18:6e:cf:b9:e8:6a:25:c4:65:5a:a9:1b:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/229918d65d7bb2186ecfb9e86a25c4655aa91bda/; sid:902201292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d2:18:6c:23:5f:70:b7:fe:fb:cf:c4:d9:db:83:f3:72:48:0d:57:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2186c235f70b7fefbcfc4d9db83f372480d57b7/; sid:902201293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"db:ca:34:41:a2:04:7f:58:f2:f4:f2:49:30:16:a1:cb:97:b7:3e:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbca3441a2047f58f2f4f2493016a1cb97b73e6c/; sid:902201294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f9:aa:3c:a3:b2:ab:fc:70:8b:53:50:1d:4f:98:6b:64:25:7b:e1:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9aa3ca3b2abfc708b53501d4f986b64257be1e2/; sid:902201295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3a:a5:03:9f:af:5c:c5:fe:6d:47:02:3c:6f:01:9b:23:f8:80:31:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3aa5039faf5cc5fe6d47023c6f019b23f880311b/; sid:902201296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"29:6e:ba:e2:d8:57:7f:07:86:17:ad:01:d6:aa:a4:c0:dc:b9:a5:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/296ebae2d8577f078617ad01d6aaa4c0dcb9a55a/; sid:902201297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4b:d1:0c:59:4b:1f:75:b6:af:86:e9:93:83:fe:07:7e:4b:14:d2:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4bd10c594b1f75b6af86e99383fe077e4b14d296/; sid:902201298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:dd:2a:78:3d:f0:77:06:8f:b0:6b:81:9f:fb:1e:0a:42:e9:98:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77dd2a783df077068fb06b819ffb1e0a42e9988e/; sid:902201299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"aa:4d:98:0d:9e:2b:3c:e6:d6:b1:b6:36:f6:1e:78:e5:9e:1d:20:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa4d980d9e2b3ce6d6b1b636f61e78e59e1d205d/; sid:902201300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"cd:3b:43:da:61:4f:64:31:9b:ba:b8:71:b5:e9:ba:da:c2:65:f9:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd3b43da614f64319bbab871b5e9badac265f9a6/; sid:902201301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b7:46:92:1e:21:4a:79:b7:a3:70:64:8a:4b:47:d7:5a:82:f1:a2:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b746921e214a79b7a370648a4b47d75a82f1a24c/; sid:902201302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"55:0c:e6:33:bb:6d:c4:d5:72:f1:d5:2b:91:80:12:c2:66:fd:d7:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/550ce633bb6dc4d572f1d52b918012c266fdd718/; sid:902201303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4e:9f:67:44:a0:2c:56:13:de:d8:27:bf:cd:91:e5:a1:77:58:18:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e9f6744a02c5613ded827bfcd91e5a1775818e5/; sid:902201304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c1:ce:35:ab:00:51:71:c2:46:ed:ed:e1:d3:d0:6a:1b:e0:25:4e:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1ce35ab005171c246edede1d3d06a1be0254ee1/; sid:902201305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b0:20:18:45:52:13:7b:fe:20:69:b1:bc:64:32:43:5a:a5:23:68:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b020184552137bfe2069b1bc6432435aa523687f/; sid:902201306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"aa:42:73:3a:1a:af:65:d4:f7:73:25:fd:2b:2d:09:04:df:04:61:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa42733a1aaf65d4f77325fd2b2d0904df0461d2/; sid:902201307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"76:2e:04:c8:cb:4d:0f:4c:ac:c8:22:02:8e:7a:84:73:c2:7f:1f:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/762e04c8cb4d0f4cacc822028e7a8473c27f1f50/; sid:902201308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:ba:8f:3e:18:63:b3:95:ec:75:2a:6f:55:ac:61:08:4a:3b:09:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6ba8f3e1863b395ec752a6f55ac61084a3b09e7/; sid:902201309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a2:45:97:12:4a:58:4a:d4:5c:7e:d8:55:62:fe:9a:40:af:00:8d:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a24597124a584ad45c7ed85562fe9a40af008dd0/; sid:902201310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dc:f0:f5:d0:59:d5:55:44:14:f1:dc:1a:80:9d:e7:8e:70:18:02:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dcf0f5d059d5554414f1dc1a809de78e7018024a/; sid:902201311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"73:74:3f:8e:80:db:8d:d4:20:9e:a9:d0:ce:c7:1e:43:58:48:58:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73743f8e80db8dd4209ea9d0cec71e43584858e5/; sid:902201312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d0:34:02:17:c2:96:82:45:ee:46:d0:99:77:94:b7:09:12:f2:c5:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0340217c2968245ee46d0997794b70912f2c51a/; sid:902201313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"35:77:58:7d:f9:2f:9c:5f:df:df:74:92:af:f3:1b:4a:58:9a:f0:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3577587df92f9c5fdfdf7492aff31b4a589af02c/; sid:902201314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a2:ca:09:f4:83:94:af:e0:e7:8a:23:b5:b4:cf:c8:9a:b7:38:46:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2ca09f48394afe0e78a23b5b4cfc89ab738460c/; sid:902201315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"69:fd:f0:ee:a2:40:52:98:66:78:d0:e8:49:de:27:92:05:b1:be:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69fdf0eea24052986678d0e849de279205b1beb6/; sid:902201316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"99:d7:6b:c2:ab:d3:34:b3:83:16:7e:df:35:dc:e1:1f:22:41:aa:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99d76bc2abd334b383167edf35dce11f2241aae4/; sid:902201317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a2:75:76:84:61:b0:ac:e4:a3:5e:3a:5f:93:10:43:76:83:c0:08:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a275768461b0ace4a35e3a5f9310437683c0087b/; sid:902201318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f7:27:dc:37:c0:a7:d9:e3:87:d0:5f:85:34:01:70:46:e7:2e:be:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f727dc37c0a7d9e387d05f8534017046e72ebe72/; sid:902201319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e6:eb:19:b9:6e:1c:dd:3a:5f:aa:f1:db:ca:3b:cb:c6:ba:57:3e:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6eb19b96e1cdd3a5faaf1dbca3bcbc6ba573e34/; sid:902201320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b3:6c:ff:6d:8f:c6:2b:06:a5:45:e6:98:50:57:32:c1:e7:04:45:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b36cff6d8fc62b06a545e698505732c1e70445bc/; sid:902201321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a5:74:e4:f9:9b:fc:08:aa:3b:d3:2f:0e:b7:71:43:95:2a:77:0a:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a574e4f99bfc08aa3bd32f0eb77143952a770ab9/; sid:902201322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"23:7c:75:e1:50:31:a9:ee:64:26:d9:36:c1:f0:76:41:fa:8b:fe:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/237c75e15031a9ee6426d936c1f07641fa8bfe83/; sid:902201323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"28:48:8d:78:8e:a4:78:3b:04:bf:ec:c2:47:ad:54:40:23:f8:1e:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28488d788ea4783b04bfecc247ad544023f81e84/; sid:902201324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"8b:97:ff:88:64:d4:9f:70:29:57:ba:87:b4:56:45:2e:44:27:85:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b97ff8864d49f702957ba87b456452e44278556/; sid:902201325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8d:f0:d5:16:5b:66:59:15:97:e7:ac:68:89:30:91:32:a0:6b:1a:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8df0d5165b66591597e7ac6889309132a06b1a21/; sid:902201326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"07:39:aa:cd:13:14:0b:b3:a1:41:da:80:57:8f:4e:46:ec:f3:16:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0739aacd13140bb3a141da80578f4e46ecf31689/; sid:902201327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ca:5e:b0:93:0d:ac:1a:7b:b0:d2:05:8c:eb:b3:13:3b:d0:11:02:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca5eb0930dac1a7bb0d2058cebb3133bd0110244/; sid:902201328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"08:18:62:7a:01:ed:9e:09:5e:77:9d:0b:1a:26:fc:df:b2:6b:a5:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0818627a01ed9e095e779d0b1a26fcdfb26ba56d/; sid:902201329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"43:84:dd:02:68:c5:b7:a6:0b:ae:8a:51:64:f7:37:e3:11:b1:bd:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4384dd0268c5b7a60bae8a5164f737e311b1bddb/; sid:902201330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"32:fa:c3:7a:39:3d:6f:dc:d2:a2:f1:b9:78:91:7b:71:30:70:3f:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32fac37a393d6fdcd2a2f1b978917b7130703f59/; sid:902201331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1e:65:53:ad:8b:b9:84:de:0f:a0:68:e4:d4:2c:03:74:2a:43:29:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e6553ad8bb984de0fa068e4d42c03742a4329c7/; sid:902201332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"2c:dd:a5:39:04:71:2f:a2:fd:15:c3:48:26:cd:05:f2:7c:94:f9:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2cdda53904712fa2fd15c34826cd05f27c94f967/; sid:902201333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"31:16:2c:d4:5c:41:ab:8e:b5:e7:e3:63:08:08:bd:1e:4e:24:25:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31162cd45c41ab8eb5e7e3630808bd1e4e2425ee/; sid:902201334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"92:4c:a1:d6:8c:e0:8d:3c:b4:e5:dc:fd:8a:9b:13:80:8d:57:bc:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/924ca1d68ce08d3cb4e5dcfd8a9b13808d57bcaf/; sid:902201335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"03:3c:fe:41:ee:16:7a:a3:1b:8a:f8:98:b0:33:f6:bf:ec:5c:c9:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/033cfe41ee167aa31b8af898b033f6bfec5cc9d2/; sid:902201336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7b:de:44:76:d1:8e:87:83:7c:15:08:cf:57:af:f9:42:9f:17:b7:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7bde4476d18e87837c1508cf57aff9429f17b7b0/; sid:902201337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"56:95:62:9c:53:90:72:e3:33:95:ea:2c:b3:81:c9:7e:db:1c:cf:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5695629c539072e33395ea2cb381c97edb1ccf7a/; sid:902201338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"06:1e:5f:80:c1:a8:66:a3:b3:88:74:ff:84:78:f6:bb:ec:99:c9:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/061e5f80c1a866a3b38874ff8478f6bbec99c9a6/; sid:902201339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"be:50:d6:86:13:53:bf:62:7a:02:82:5e:6d:b1:19:55:ba:a6:23:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be50d6861353bf627a02825e6db11955baa62398/; sid:902201340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"66:fb:92:5c:f7:8d:e7:1c:e1:85:1e:4b:69:c7:c0:7b:3d:6d:9a:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66fb925cf78de71ce1851e4b69c7c07b3d6d9a48/; sid:902201341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ba:0b:4e:be:6f:07:d2:f3:4f:98:d2:c6:02:18:8a:9d:1c:d8:a7:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba0b4ebe6f07d2f34f98d2c602188a9d1cd8a709/; sid:902201342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"64:b9:6d:98:11:b9:f9:ae:73:5c:5f:78:75:8d:9a:7b:37:80:b9:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64b96d9811b9f9ae735c5f78758d9a7b3780b989/; sid:902201343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5c:04:8b:96:c2:22:ca:b6:20:63:a7:37:13:8d:f0:49:e7:08:42:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c048b96c222cab62063a737138df049e70842ef/; sid:902201344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1c:ee:c6:bd:f4:d5:87:38:3d:8c:66:ff:60:6f:84:d8:bf:51:90:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ceec6bdf4d587383d8c66ff606f84d8bf5190f9/; sid:902201345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d4:d7:9d:24:88:10:61:99:fa:0f:89:cf:9f:4d:eb:fe:32:d7:c8:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4d79d2488106199fa0f89cf9f4debfe32d7c81b/; sid:902201346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"29:73:53:4e:d6:89:21:f2:32:42:b0:35:83:e1:ff:ad:e1:f2:03:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2973534ed68921f23242b03583e1ffade1f2039f/; sid:902201347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f1:30:00:e5:23:67:db:c2:82:19:02:5e:c5:e0:55:c3:35:0a:49:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f13000e52367dbc28219025ec5e055c3350a4961/; sid:902201348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bf:d9:a5:b9:cc:08:ab:5d:bf:5a:5d:7a:6b:64:aa:23:5f:ba:51:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfd9a5b9cc08ab5dbf5a5d7a6b64aa235fba51f9/; sid:902201349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"da:c8:43:9f:e1:00:09:8d:b0:4e:96:26:a1:77:4b:30:63:94:ce:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dac8439fe100098db04e9626a1774b306394cec6/; sid:902201350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"45:f8:08:17:d0:11:66:4f:23:3d:b3:35:49:40:e0:80:12:88:6d:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45f80817d011664f233db3354940e08012886d17/; sid:902201351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"96:a2:d4:41:b2:3a:8c:26:34:8f:4f:68:c2:b2:6b:f4:9d:59:e9:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96a2d441b23a8c26348f4f68c2b26bf49d59e94f/; sid:902201352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"03:a0:ac:10:93:3f:bf:84:4a:72:28:08:39:69:b1:a0:dc:ba:d7:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03a0ac10933fbf844a7228083969b1a0dcbad740/; sid:902201353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c1:b1:77:74:c1:6c:d6:17:9a:6c:49:d1:f5:b6:f1:7a:2b:08:e3:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1b17774c16cd6179a6c49d1f5b6f17a2b08e3ed/; sid:902201354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"bc:3e:59:0d:11:8d:fb:46:90:99:9a:47:33:e5:bf:f5:34:51:d1:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc3e590d118dfb4690999a4733e5bff53451d123/; sid:902201355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"90:21:32:c3:2d:01:e0:ee:d9:20:7a:ad:ff:a4:01:7b:46:9a:d9:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/902132c32d01e0eed9207aadffa4017b469ad9e8/; sid:902201356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"41:29:5a:7e:73:ea:49:c1:25:41:96:b2:f2:a7:bf:4e:94:59:60:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41295a7e73ea49c1254196b2f2a7bf4e9459600e/; sid:902201357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b8:22:cb:45:a2:e4:e8:42:2a:84:5f:d9:5f:c9:9d:5b:12:b7:b8:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b822cb45a2e4e8422a845fd95fc99d5b12b7b87c/; sid:902201358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"06:d2:ca:ce:ee:c3:ce:bf:40:18:9a:27:f7:90:69:bc:da:28:ea:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06d2caceeec3cebf40189a27f79069bcda28ea2b/; sid:902201359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8a:00:e9:7c:2e:6a:ef:c6:1e:b3:c0:59:b6:1c:e2:64:4d:31:de:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a00e97c2e6aefc61eb3c059b61ce2644d31de58/; sid:902201360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"67:09:e7:52:fd:6e:05:bc:d4:44:a8:4f:46:94:c7:d3:08:9e:97:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6709e752fd6e05bcd444a84f4694c7d3089e97f3/; sid:902201361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4a:7b:de:af:42:84:06:ba:ba:73:d7:25:17:1b:a6:aa:07:07:92:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a7bdeaf428406baba73d725171ba6aa070792d8/; sid:902201362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5e:0b:97:df:7b:a7:96:31:01:0d:c6:bd:10:59:b8:fb:fb:65:1e:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e0b97df7ba79631010dc6bd1059b8fbfb651ed1/; sid:902201363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"44:d2:18:a8:76:02:f6:5f:9e:00:21:a1:ad:1e:95:18:9b:e8:aa:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44d218a87602f65f9e0021a1ad1e95189be8aaaf/; sid:902201364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ab:63:1d:10:a2:95:27:79:5c:17:1a:da:34:a3:a7:31:07:eb:cf:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab631d10a29527795c171ada34a3a73107ebcfbd/; sid:902201365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f4:ba:5e:19:1d:9e:31:29:02:c7:b4:9d:08:5c:b1:1f:a1:6a:96:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4ba5e191d9e312902c7b49d085cb11fa16a961f/; sid:902201366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"20:42:59:23:8e:df:44:37:22:a5:94:d3:bb:06:b6:4a:71:f0:20:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/204259238edf443722a594d3bb06b64a71f0207c/; sid:902201367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ce:6c:46:61:f7:04:3d:bf:0f:9a:f5:b8:b5:ff:0a:8e:dd:74:35:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce6c4661f7043dbf0f9af5b8b5ff0a8edd743555/; sid:902201368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"53:c8:88:1e:8e:a0:0a:a1:27:0e:23:32:2b:40:3f:86:57:e0:28:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53c8881e8ea00aa1270e23322b403f8657e028dc/; sid:902201369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"23:ef:58:39:e1:41:48:d0:75:4b:27:a3:74:cf:fc:83:2f:5a:e4:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23ef5839e14148d0754b27a374cffc832f5ae473/; sid:902201370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"87:4f:42:08:c8:eb:91:d8:a2:f5:d2:f1:55:e9:41:38:d9:69:b2:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/874f4208c8eb91d8a2f5d2f155e94138d969b2f6/; sid:902201371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:a5:23:f9:52:3f:bf:d9:8f:eb:3e:d0:62:b5:0f:05:8f:8b:df:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37a523f9523fbfd98feb3ed062b50f058f8bdff2/; sid:902201372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0b:6d:45:67:07:c8:d5:75:da:52:3f:b8:2a:11:9f:a9:4b:1d:d6:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b6d456707c8d575da523fb82a119fa94b1dd64e/; sid:902201373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f1:f2:5b:dc:25:e6:24:7a:9a:53:04:8c:73:9a:cd:a6:0d:75:06:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1f25bdc25e6247a9a53048c739acda60d750653/; sid:902201374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8b:00:d3:78:7a:5b:c6:59:9d:6c:de:f4:54:4f:2c:cd:ad:d1:2d:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b00d3787a5bc6599d6cdef4544f2ccdadd12dc2/; sid:902201375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1c:ac:ed:b7:c2:51:5f:12:d8:23:3e:37:c6:78:a7:22:55:52:e7:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cacedb7c2515f12d8233e37c678a7225552e7b0/; sid:902201376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"44:de:8f:4b:d7:8b:b4:ff:83:37:02:86:de:5e:4c:0d:ef:fb:81:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44de8f4bd78bb4ff83370286de5e4c0deffb8195/; sid:902201377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"04:08:4d:04:ae:e0:7d:52:d6:a8:36:78:94:fe:f3:24:0f:c4:9e:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/04084d04aee07d52d6a8367894fef3240fc49e63/; sid:902201378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"21:2c:93:da:89:61:b8:8f:a9:35:58:2c:58:36:ba:d8:06:3d:96:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/212c93da8961b88fa935582c5836bad8063d9624/; sid:902201379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6f:22:7b:05:e3:2d:37:c2:d5:9d:46:5d:d1:8c:70:79:5c:0a:b3:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f227b05e32d37c2d59d465dd18c70795c0ab356/; sid:902201380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"46:33:e1:0a:a7:63:b9:f9:60:f6:9c:ed:c6:3d:6a:b1:8b:3f:23:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4633e10aa763b9f960f69cedc63d6ab18b3f2380/; sid:902201381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"17:dd:98:22:d9:3b:d0:1d:91:e9:9a:42:a3:02:70:a3:05:17:e8:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17dd9822d93bd01d91e99a42a30270a30517e82d/; sid:902201382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"6c:0d:0d:b6:d2:d3:1a:b9:b6:e2:7b:00:76:9c:fb:b9:e5:2a:48:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c0d0db6d2d31ab9b6e27b00769cfbb9e52a484e/; sid:902201383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e1:cd:4a:73:06:fb:0f:5e:ad:f6:ca:a7:11:62:55:94:23:ea:45:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1cd4a7306fb0f5eadf6caa71162559423ea45fe/; sid:902201384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"9a:0d:73:d7:dd:55:8c:d3:de:78:53:58:6d:4a:d0:6c:21:80:35:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a0d73d7dd558cd3de7853586d4ad06c21803500/; sid:902201385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"3f:7e:87:75:19:d5:ff:64:52:0c:d2:96:09:5e:a0:9a:bb:09:0f:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f7e877519d5ff64520cd296095ea09abb090f45/; sid:902201386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"2a:ea:63:09:58:d5:38:71:e9:b2:04:30:f8:7f:55:5b:c5:4c:76:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2aea630958d53871e9b20430f87f555bc54c763e/; sid:902201387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"50:e7:63:a9:40:d0:95:71:0e:09:c0:7e:db:0f:12:69:24:26:a0:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50e763a940d095710e09c07edb0f12692426a0c6/; sid:902201388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7e:46:0f:1c:30:c6:84:34:2f:b8:f9:6e:45:47:f6:7b:1d:3a:ee:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e460f1c30c684342fb8f96e4547f67b1d3aee9e/; sid:902201389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"f5:fd:20:8c:44:a7:40:33:67:bc:23:15:4b:7d:82:9e:11:fa:47:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5fd208c44a7403367bc23154b7d829e11fa47de/; sid:902201390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c8:c7:68:be:d2:57:32:85:25:7e:b4:09:27:9c:f3:d7:39:3a:8a:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8c768bed2573285257eb409279cf3d7393a8a51/; sid:902201391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:50:cb:64:7f:6b:d0:c0:cf:71:2c:55:f1:a6:6f:af:1e:3c:c6:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e250cb647f6bd0c0cf712c55f1a66faf1e3cc630/; sid:902201392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1a:f0:89:69:77:20:70:47:01:5f:85:b6:a3:63:53:62:d0:2b:81:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1af0896977207047015f85b6a3635362d02b8146/; sid:902201393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"11:10:07:c2:ca:c6:24:10:61:07:5c:68:34:a7:9e:bd:1a:e5:a4:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/111007c2cac6241061075c6834a79ebd1ae5a4cb/; sid:902201394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ce:8c:bf:ff:a1:97:75:40:07:ef:65:7a:51:a2:f4:03:9f:ac:5f:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce8cbfffa197754007ef657a51a2f4039fac5f03/; sid:902201395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"6b:71:30:22:9d:fb:db:cf:38:e5:72:51:53:a9:cd:96:f0:03:2a:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b7130229dfbdbcf38e5725153a9cd96f0032ae2/; sid:902201396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"26:dd:0e:9d:98:67:93:4f:75:b2:5e:25:dd:02:88:19:95:b4:be:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26dd0e9d9867934f75b25e25dd02881995b4be42/; sid:902201397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"98:29:3f:f5:b0:05:d9:f9:a7:39:9f:e4:16:72:d1:21:70:92:70:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98293ff5b005d9f9a7399fe41672d121709270bb/; sid:902201398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f4:b6:20:23:25:10:3d:6b:2d:ad:f0:b8:0f:03:0c:05:b5:93:60:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4b6202325103d6b2dadf0b80f030c05b5936052/; sid:902201399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"15:76:1e:8a:78:18:9f:6c:05:0d:07:1a:16:4a:3f:42:6a:e1:74:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15761e8a78189f6c050d071a164a3f426ae174c3/; sid:902201400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"07:49:c4:8b:dd:1c:ba:96:dd:5b:4d:8b:de:b8:95:e5:4c:db:cf:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0749c48bdd1cba96dd5b4d8bdeb895e54cdbcf7f/; sid:902201401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"11:a8:f9:1e:9c:ed:99:fa:01:a5:f9:f3:e7:69:ae:d3:b9:96:50:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11a8f91e9ced99fa01a5f9f3e769aed3b99650f8/; sid:902201402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"00:94:5e:df:41:cc:fa:28:99:df:d4:1d:71:b8:42:75:65:31:38:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00945edf41ccfa2899dfd41d71b8427565313820/; sid:902201403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"12:b5:fc:f9:1f:d8:b5:c8:9a:74:b7:b6:91:ac:90:a3:66:fe:5a:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12b5fcf91fd8b5c89a74b7b691ac90a366fe5aca/; sid:902201404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"da:be:87:24:55:89:72:9e:d8:81:f4:d1:5d:42:ec:09:f0:fc:ae:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dabe87245589729ed881f4d15d42ec09f0fcae6c/; sid:902201405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c4:8e:de:ba:9a:63:b1:31:46:16:49:d2:0f:e6:5a:78:4a:5a:3f:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c48edeba9a63b131461649d20fe65a784a5a3fad/; sid:902201406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4b:dd:42:de:62:85:6a:64:31:5d:2d:c6:12:b3:ce:87:94:f9:08:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4bdd42de62856a64315d2dc612b3ce8794f90895/; sid:902201407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"bb:56:0c:df:03:50:e8:41:8a:6f:60:74:2e:5c:8a:18:ff:0f:80:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb560cdf0350e8418a6f60742e5c8a18ff0f8040/; sid:902201408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c0:9d:8b:14:f1:92:fc:4e:c9:1c:e9:4a:ff:7c:1d:52:f8:1f:a5:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c09d8b14f192fc4ec91ce94aff7c1d52f81fa555/; sid:902201409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0e:46:fd:94:50:41:13:bc:42:f1:02:66:72:23:9a:ab:82:49:96:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e46fd94504113bc42f1026672239aab8249962c/; sid:902201410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c1:19:d0:8b:51:35:fe:42:1d:5d:56:2b:84:24:3a:bb:13:91:1e:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c119d08b5135fe421d5d562b84243abb13911efb/; sid:902201411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ec:a6:d4:7e:51:1e:72:ae:f8:13:0d:3b:0d:0c:78:ce:a0:aa:2d:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eca6d47e511e72aef8130d3b0d0c78cea0aa2d30/; sid:902201412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"21:07:c1:e3:60:90:a5:46:ee:56:c4:d1:a8:42:e5:e9:c6:0c:e2:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2107c1e36090a546ee56c4d1a842e5e9c60ce221/; sid:902201413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"61:8f:fa:46:fe:59:2b:df:61:fe:f3:ac:d7:d0:4a:a6:eb:c4:d4:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/618ffa46fe592bdf61fef3acd7d04aa6ebc4d4f3/; sid:902201414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c4:77:55:a7:e2:88:27:93:d7:ab:d6:f7:f0:57:c5:b5:71:69:fb:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c47755a7e2882793d7abd6f7f057c5b57169fbc5/; sid:902201415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c8:64:63:3b:d7:c4:32:ff:8a:b8:7b:5c:b1:a3:b3:3c:a8:62:99:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c864633bd7c432ff8ab87b5cb1a3b33ca8629926/; sid:902201416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b1:b6:14:1d:df:f2:24:6b:c2:b6:53:bc:f6:ee:86:2c:e3:b3:09:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1b6141ddff2246bc2b653bcf6ee862ce3b309f6/; sid:902201417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b8:b9:20:9d:ad:7e:b5:9d:bf:9a:b6:c2:2a:77:b6:20:07:c6:8a:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8b9209dad7eb59dbf9ab6c22a77b62007c68ac5/; sid:902201418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"50:1c:82:25:e8:7b:6f:b8:58:df:2e:05:93:75:09:dd:33:a3:4b:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/501c8225e87b6fb858df2e05937509dd33a34b58/; sid:902201419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RockLoader C&C)"; tls.fingerprint:"ff:c3:bf:9b:72:df:3d:f1:0e:22:61:f5:70:ed:99:74:51:5e:1e:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ffc3bf9b72df3df10e2261f570ed9974515e1e2b/; sid:902201420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"ac:99:29:98:8c:ab:80:0a:65:3b:01:12:ba:31:6c:47:25:d1:9f:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac9929988cab800a653b0112ba316c4725d19fc3/; sid:902201421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"91:c9:4e:e2:98:fc:bd:a3:2e:ed:9c:67:59:97:92:04:a1:63:7c:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91c94ee298fcbda32eed9c6759979204a1637cbc/; sid:902201422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:9e:4d:1c:20:7a:26:c4:c0:bd:4c:75:83:ae:b6:22:a9:c2:c1:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce9e4d1c207a26c4c0bd4c7583aeb622a9c2c1e9/; sid:902201423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6b:bd:37:a0:3c:68:85:6c:cf:a1:d0:44:52:69:a4:30:14:32:d9:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bbd37a03c68856ccfa1d0445269a4301432d9ee/; sid:902201424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"11:62:b1:e7:e4:c9:16:6f:0e:74:be:ad:5b:e1:4c:1f:8d:68:ca:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1162b1e7e4c9166f0e74bead5be14c1f8d68ca62/; sid:902201425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"18:86:4b:d0:12:31:a8:3c:ab:6a:6c:ea:2e:d3:76:9b:55:3d:5c:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18864bd01231a83cab6a6cea2ed3769b553d5ccf/; sid:902201426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0c:45:ce:8c:56:fc:c4:00:b7:98:22:23:45:c2:4b:5d:38:60:21:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c45ce8c56fcc400b798222345c24b5d386021f4/; sid:902201427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7d:0a:fe:78:52:11:80:19:f1:a2:1b:ba:51:2e:8d:88:aa:95:a5:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d0afe7852118019f1a21bba512e8d88aa95a506/; sid:902201428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dd:eb:9c:78:d4:3d:90:9c:3b:c3:19:6b:80:7b:1d:5f:21:cf:d0:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddeb9c78d43d909c3bc3196b807b1d5f21cfd060/; sid:902201429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"2b:52:fb:88:1d:57:95:90:6e:07:ed:e2:73:e4:45:2e:7f:35:57:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b52fb881d5795906e07ede273e4452e7f355755/; sid:902201430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"67:75:a9:ca:ff:ab:72:56:b5:cb:30:fe:5d:a9:78:3c:18:b1:07:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6775a9caffab7256b5cb30fe5da9783c18b107bb/; sid:902201431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"09:55:d4:14:ef:66:a2:51:c4:9f:8a:f6:95:9d:0a:44:1f:c8:cc:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0955d414ef66a251c49f8af6959d0a441fc8cc65/; sid:902201432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"72:2b:94:4f:b5:12:34:9b:7f:72:00:25:9b:9d:49:1e:bc:f6:76:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/722b944fb512349b7f7200259b9d491ebcf6768e/; sid:902201433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"dd:92:ad:90:f3:90:3d:6a:03:fc:98:d5:22:e1:2a:16:c5:ac:ba:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd92ad90f3903d6a03fc98d522e12a16c5acbafc/; sid:902201434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"62:9e:d4:9f:00:e6:5e:13:28:56:1e:52:32:f5:68:29:00:53:48:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/629ed49f00e65e1328561e5232f568290053485b/; sid:902201435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1a:45:0a:f1:e4:2f:98:a2:83:22:16:40:1b:cb:17:bb:73:ac:1d:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a450af1e42f98a2832216401bcb17bb73ac1d32/; sid:902201436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (H1N1 C&C)"; tls.fingerprint:"3a:71:6a:c2:45:91:76:11:da:c7:f5:7a:d3:93:a8:19:57:e0:f3:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a716ac245917611dac7f57ad393a81957e0f386/; sid:902201437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b2:ab:ff:c7:53:d5:55:76:e1:9f:22:37:80:7e:69:1e:2a:ba:f3:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2abffc753d55576e19f2237807e691e2abaf3af/; sid:902201438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"ee:90:55:2b:ae:63:b3:f8:c8:74:bb:66:a9:6e:1f:7b:b1:e0:a5:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee90552bae63b3f8c874bb66a96e1f7bb1e0a595/; sid:902201439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"79:5a:e7:76:68:04:58:0e:e7:d3:db:01:ce:24:a1:78:df:9e:de:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/795ae7766804580ee7d3db01ce24a178df9ede23/; sid:902201440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"62:e9:30:b1:3d:24:0f:e4:ca:ef:56:1c:90:d4:88:9e:9b:25:11:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62e930b13d240fe4caef561c90d4889e9b25119b/; sid:902201441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b0:82:c7:f2:3c:49:39:1c:03:3d:05:37:4c:ad:e3:44:e6:d0:a0:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b082c7f23c49391c033d05374cade344e6d0a095/; sid:902201442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"78:24:e5:3f:1e:c2:c9:e8:89:6e:24:69:51:9a:c8:60:15:34:50:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7824e53f1ec2c9e8896e2469519ac860153450de/; sid:902201443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"53:f3:53:bf:17:fb:83:80:9c:7a:36:69:ae:72:b0:8f:27:58:55:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53f353bf17fb83809c7a3669ae72b08f275855df/; sid:902201444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ce:7c:5b:4a:26:07:c4:8a:1e:34:28:ce:45:58:2a:ba:1d:a2:18:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce7c5b4a2607c48a1e3428ce45582aba1da21812/; sid:902201445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e8:14:a1:ca:9c:80:d9:63:bf:43:e9:8f:68:33:af:ea:a8:73:81:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e814a1ca9c80d963bf43e98f6833afeaa8738108/; sid:902201446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e8:6a:7d:ef:d8:37:17:d2:29:b2:8f:26:3c:cb:74:30:0e:ff:6b:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e86a7defd83717d229b28f263ccb74300eff6b9a/; sid:902201447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d5:64:e3:c1:f3:cb:f2:56:d9:76:bd:8c:07:bb:22:40:09:c3:9a:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d564e3c1f3cbf256d976bd8c07bb224009c39a0a/; sid:902201448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"86:fd:7e:1c:08:0b:d4:d1:50:7c:6f:25:94:c7:be:62:df:08:44:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86fd7e1c080bd4d1507c6f2594c7be62df0844e9/; sid:902201449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"62:10:1d:5a:29:89:91:9f:19:09:2e:b6:b7:3d:1a:39:ce:1c:00:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62101d5a2989919f19092eb6b73d1a39ce1c00d9/; sid:902201450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c9:d8:13:17:9c:e2:af:bc:ff:6f:73:48:87:c4:ff:6b:e0:33:5e:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9d813179ce2afbcff6f734887c4ff6be0335e0a/; sid:902201451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"69:dc:a2:80:43:55:56:41:43:f2:1c:eb:cd:42:8b:5c:ca:d0:83:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69dca2804355564143f21cebcd428b5ccad08311/; sid:902201452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ab:a2:0d:f9:de:f8:ee:a6:7e:9b:d4:51:3e:3b:4e:aa:84:d7:47:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aba20df9def8eea67e9bd4513e3b4eaa84d7470d/; sid:902201453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"42:c3:4e:c2:cf:08:4d:f0:75:31:12:9e:22:75:04:68:59:85:e7:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42c34ec2cf084df07531129e227504685985e766/; sid:902201454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ee:c7:bf:78:cf:94:a4:f7:f7:5c:64:bc:ec:4a:2c:4d:cd:26:0e:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eec7bf78cf94a4f7f75c64bcec4a2c4dcd260eab/; sid:902201455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"fd:8e:06:77:99:1e:ef:52:02:bf:55:56:61:af:ae:70:ab:7e:ea:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd8e0677991eef5202bf555661afae70ab7eea47/; sid:902201456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ed:b8:8d:d3:be:67:4a:9c:f4:85:0f:4e:40:32:56:81:b6:aa:c8:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edb88dd3be674a9cf4850f4e40325681b6aac8d3/; sid:902201457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"50:c1:e8:61:d0:2c:a2:35:05:17:4e:f7:c0:74:a8:63:6c:fa:5f:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50c1e861d02ca23505174ef7c074a8636cfa5f90/; sid:902201458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"19:39:a1:55:90:6f:e3:47:6a:9d:43:e1:59:0e:d6:8a:bb:ba:8a:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1939a155906fe3476a9d43e1590ed68abbba8abb/; sid:902201459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7d:cf:44:72:48:99:4c:c8:0d:de:b4:c5:96:a5:3f:be:16:f7:39:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dcf447248994cc80ddeb4c596a53fbe16f739ef/; sid:902201460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f4:38:7c:38:ff:9e:46:df:e3:48:07:28:fc:50:26:c6:1e:48:78:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4387c38ff9e46dfe3480728fc5026c61e4878ed/; sid:902201461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"48:0f:10:01:35:82:88:47:30:85:a5:4b:5d:11:24:6f:9e:d4:b1:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/480f1001358288473085a54b5d11246f9ed4b188/; sid:902201462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"77:63:84:c4:9c:c8:93:13:9b:68:0f:a9:2d:a8:2a:11:d7:54:a2:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/776384c49cc893139b680fa92da82a11d754a25f/; sid:902201463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"8d:fb:92:83:89:c4:b4:08:89:b1:ad:eb:50:6c:a6:d6:2a:e3:42:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dfb928389c4b40889b1adeb506ca6d62ae3422e/; sid:902201464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"66:a1:a0:37:e8:29:68:05:1b:63:ec:f0:22:1f:e6:42:c8:23:10:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66a1a037e82968051b63ecf0221fe642c8231029/; sid:902201465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f0:6c:b2:a9:49:fe:48:93:17:77:00:d0:f7:b7:da:ea:a7:e1:03:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f06cb2a949fe4893177700d0f7b7daeaa7e10317/; sid:902201466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d1:fa:32:b4:13:e9:27:12:08:22:53:f5:ed:c4:f5:79:90:06:e2:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1fa32b413e92712082253f5edc4f5799006e294/; sid:902201467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"9b:e4:ab:3c:d5:8a:13:2b:65:2e:c3:9f:c5:0e:41:f2:cc:93:a4:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9be4ab3cd58a132b652ec39fc50e41f2cc93a44b/; sid:902201468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"be:77:9d:c4:95:e7:c1:6a:61:c5:bd:3b:3d:ae:f5:d6:f4:84:bd:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be779dc495e7c16a61c5bd3b3daef5d6f484bd02/; sid:902201469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b4:4b:59:4d:09:b3:82:5a:c4:4b:5f:24:33:43:c9:bf:b7:6c:fe:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b44b594d09b3825ac44b5f243343c9bfb76cfec7/; sid:902201470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"2c:54:2e:32:c6:cb:a4:b4:99:d1:42:f9:57:51:97:06:ac:53:3a:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c542e32c6cba4b499d142f957519706ac533a1f/; sid:902201471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"96:63:b6:79:9b:a2:0d:68:73:4c:c9:9a:a8:3d:6b:bb:05:06:f0:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9663b6799ba20d68734cc99aa83d6bbb0506f064/; sid:902201472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"54:d4:b6:c4:8e:d2:07:e2:a4:11:e0:d8:04:08:8d:9a:e0:00:c8:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54d4b6c48ed207e2a411e0d804088d9ae000c85c/; sid:902201473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8c:91:ea:76:23:94:e0:94:aa:ec:33:3a:b5:0b:ee:0d:d2:4e:11:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c91ea762394e094aaec333ab50bee0dd24e1102/; sid:902201474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bf:58:38:a9:93:4b:99:55:61:ac:b7:89:3a:70:12:75:40:42:4c:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf5838a9934b995561acb7893a70127540424ca4/; sid:902201475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"3b:4e:f6:5e:f0:b5:af:89:ec:98:53:ae:ad:53:05:1f:6d:ff:5c:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b4ef65ef0b5af89ec9853aead53051f6dff5c0a/; sid:902201476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a0:1f:76:da:b7:4e:1e:a9:52:91:24:05:96:88:7d:42:b1:81:64:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a01f76dab74e1ea95291240596887d42b18164f4/; sid:902201477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"fb:c5:51:bf:c0:6f:94:f9:46:0e:ab:40:21:37:68:5b:56:5f:39:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fbc551bfc06f94f9460eab402137685b565f3985/; sid:902201478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"25:1b:e2:d8:16:49:44:66:bb:6a:23:bc:3d:f9:bc:73:bd:ec:ea:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/251be2d816494466bb6a23bc3df9bc73bdeceab0/; sid:902201479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5c:b0:f8:39:0c:9a:07:a8:a1:a9:7d:88:ad:49:35:f9:d3:5d:92:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5cb0f8390c9a07a8a1a97d88ad4935f9d35d92e7/; sid:902201480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"93:53:26:06:c0:c0:1c:e7:94:f9:c7:25:fe:63:a1:c9:bb:1c:9a:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93532606c0c01ce794f9c725fe63a1c9bb1c9a7c/; sid:902201481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"67:2f:29:f8:cf:cd:b9:49:4e:f2:c6:43:d6:20:8c:19:b6:8e:95:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/672f29f8cfcdb9494ef2c643d6208c19b68e953f/; sid:902201482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"94:75:a7:c4:d1:9d:9d:ac:68:ce:09:77:a9:ec:46:23:c7:c3:95:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9475a7c4d19d9dac68ce0977a9ec4623c7c395b7/; sid:902201483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ec:2c:fd:44:3b:d4:67:69:cf:f7:81:38:a9:5f:88:4f:32:72:63:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec2cfd443bd46769cff78138a95f884f32726387/; sid:902201484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"25:fd:0b:a7:66:0d:05:52:47:45:d6:dc:ad:0c:bd:7d:8b:bc:b1:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25fd0ba7660d05524745d6dcad0cbd7d8bbcb169/; sid:902201485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"81:bf:49:7b:56:15:bd:45:57:b8:70:b5:21:3b:a0:18:e6:11:3d:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81bf497b5615bd4557b870b5213ba018e6113d48/; sid:902201486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"74:27:91:20:25:6b:c0:96:1b:a2:7a:cd:52:d0:41:f4:16:4e:86:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/74279120256bc0961ba27acd52d041f4164e863f/; sid:902201487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5b:03:85:98:fb:63:ca:7c:93:5f:a8:ac:7b:7a:b7:1f:de:89:bd:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b038598fb63ca7c935fa8ac7b7ab71fde89bd6b/; sid:902201488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6a:ec:a8:f9:e1:02:ca:cc:4d:f5:2b:a7:54:00:47:0d:ce:d6:f6:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6aeca8f9e102cacc4df52ba75400470dced6f690/; sid:902201489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d1:fa:73:cc:db:4b:36:11:37:09:ad:ff:3c:8e:e8:0c:bc:f6:e2:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1fa73ccdb4b36113709adff3c8ee80cbcf6e2ce/; sid:902201490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"06:83:50:6f:22:15:1f:54:45:fa:08:0f:32:25:91:90:de:d1:ab:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0683506f22151f5445fa080f32259190ded1ab42/; sid:902201491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"54:06:85:89:04:53:84:51:5a:45:84:88:3c:7d:39:38:53:54:c8:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54068589045384515a4584883c7d39385354c8de/; sid:902201492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"dd:be:a7:ab:02:af:e4:4d:5b:fc:1d:be:f0:90:f2:6c:8b:01:e8:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddbea7ab02afe44d5bfc1dbef090f26c8b01e823/; sid:902201493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"90:3d:fd:be:81:a8:01:6d:5f:c4:05:e1:e7:6f:22:9d:de:e5:04:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/903dfdbe81a8016d5fc405e1e76f229ddee5045c/; sid:902201494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5e:89:e6:07:8c:be:b2:21:ae:f7:36:e7:49:0c:03:1c:74:88:18:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e89e6078cbeb221aef736e7490c031c748818f6/; sid:902201495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"15:5f:9a:76:e7:6f:f2:29:3a:3a:28:3f:23:24:48:d3:71:7c:90:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/155f9a76e76ff2293a3a283f232448d3717c9097/; sid:902201496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3c:ad:c4:99:ea:df:d2:37:f6:2d:17:47:bc:ce:fb:78:a8:9e:f2:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cadc499eadfd237f62d1747bccefb78a89ef295/; sid:902201497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d3:28:2b:a8:32:45:f7:df:f4:c0:f8:eb:25:7f:2c:f7:8e:f4:03:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3282ba83245f7dff4c0f8eb257f2cf78ef40360/; sid:902201498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e9:27:61:0a:7a:36:e0:e2:20:e6:ce:54:a1:f4:68:53:c5:d4:4b:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e927610a7a36e0e220e6ce54a1f46853c5d44bbe/; sid:902201499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1b:3f:55:9b:b1:04:50:a5:8b:6d:6b:94:25:08:81:be:c3:db:1b:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b3f559bb10450a58b6d6b94250881bec3db1bb4/; sid:902201500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"76:c7:c0:90:dc:32:3f:56:e2:c0:31:11:ca:92:ae:67:ef:a5:8d:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76c7c090dc323f56e2c03111ca92ae67efa58db0/; sid:902201501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"09:c5:02:c2:e9:67:fe:f1:b1:81:50:f6:0e:20:c0:41:c4:84:ef:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09c502c2e967fef1b18150f60e20c041c484ef62/; sid:902201502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b1:d5:1e:8c:09:5d:01:ef:20:c7:6b:7f:4c:a7:68:43:1e:a0:46:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1d51e8c095d01ef20c76b7f4ca768431ea04628/; sid:902201503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"35:a2:b2:d7:84:b0:e1:26:1a:12:cd:3f:61:9f:55:d8:59:36:76:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35a2b2d784b0e1261a12cd3f619f55d85936763d/; sid:902201504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c7:16:75:67:38:aa:fa:01:29:43:1e:69:f6:73:ab:ca:2b:14:09:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c716756738aafa0129431e69f673abca2b140975/; sid:902201505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Downloader.Pony C&C)"; tls.fingerprint:"e2:79:81:1f:74:ac:19:2d:ed:19:52:2e:b8:cd:5b:88:ba:fd:47:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e279811f74ac192ded19522eb8cd5b88bafd47cc/; sid:902201506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"cf:ab:4c:e6:f2:25:9d:74:e8:aa:41:e3:0e:c7:e1:ce:98:3f:9a:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfab4ce6f2259d74e8aa41e30ec7e1ce983f9a17/; sid:902201507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"03:99:b4:d2:13:2a:02:7f:5e:69:a9:9e:2f:d5:29:fc:e1:9a:42:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0399b4d2132a027f5e69a99e2fd529fce19a42ab/; sid:902201508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"42:ea:2a:4d:e6:56:40:10:0d:72:23:e9:75:2d:07:83:cf:56:ad:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42ea2a4de65640100d7223e9752d0783cf56ad58/; sid:902201509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3c:ee:08:dc:89:08:8d:a5:ca:35:f8:cf:12:29:ea:42:a6:78:f2:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cee08dc89088da5ca35f8cf1229ea42a678f2c5/; sid:902201510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"98:6f:0d:81:63:60:16:3f:03:eb:b8:dd:37:24:9b:69:9e:65:cc:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/986f0d816360163f03ebb8dd37249b699e65cc24/; sid:902201511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"49:4f:05:60:e1:20:b7:5b:10:7d:dc:3a:22:17:58:cc:15:2a:83:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/494f0560e120b75b107ddc3a221758cc152a8385/; sid:902201512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4b:9c:1b:73:66:16:2a:65:f2:0f:cf:ae:74:04:32:6a:dc:5a:99:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b9c1b7366162a65f20fcfae7404326adc5a9960/; sid:902201513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"73:d8:ec:1f:29:19:5e:f2:d9:e0:b6:18:e7:2f:3c:80:c0:ac:6b:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73d8ec1f29195ef2d9e0b618e72f3c80c0ac6ba7/; sid:902201514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1a:e2:81:e3:2a:78:6a:cf:8a:fd:28:c2:70:e6:a5:0c:8a:29:02:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ae281e32a786acf8afd28c270e6a50c8a290233/; sid:902201515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"08:17:e0:e3:aa:88:56:9f:70:c4:a7:9d:a4:e1:da:cc:6c:03:40:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0817e0e3aa88569f70c4a79da4e1dacc6c034058/; sid:902201516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cf:b8:6f:7a:5e:dc:30:cb:ce:ef:cf:57:2d:89:12:e1:8e:eb:c5:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfb86f7a5edc30cbceefcf572d8912e18eebc583/; sid:902201517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cd:08:b5:57:1b:d2:d5:cb:da:b9:7f:00:e5:ee:8d:64:c6:d5:d6:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd08b5571bd2d5cbdab97f00e5ee8d64c6d5d6c4/; sid:902201518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e9:ff:e9:4c:89:41:1b:cb:c5:8f:3a:8a:3b:63:68:f0:24:36:73:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9ffe94c89411bcbc58f3a8a3b6368f024367302/; sid:902201519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6d:ba:b1:c9:41:d5:74:e3:78:17:5d:78:87:a3:3a:76:2a:32:7e:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6dbab1c941d574e378175d7887a33a762a327e42/; sid:902201520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"12:d0:c4:77:0b:7c:dd:7a:9b:3a:32:82:8b:61:bb:bc:80:c9:62:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12d0c4770b7cdd7a9b3a32828b61bbbc80c962e4/; sid:902201521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"f9:f3:22:5b:7b:9e:a4:ac:04:42:89:ff:cc:8a:33:ee:3b:df:a6:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9f3225b7b9ea4ac044289ffcc8a33ee3bdfa6ef/; sid:902201522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"88:37:c6:82:2f:45:d9:b9:9c:eb:58:2f:5d:98:c8:27:89:47:7e:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8837c6822f45d9b99ceb582f5d98c82789477ea4/; sid:902201523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"bf:cf:9c:b6:e2:67:b0:60:37:03:9b:5a:a7:cd:c4:03:bb:92:fa:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfcf9cb6e267b06037039b5aa7cdc403bb92fac2/; sid:902201524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4a:b3:d7:5c:4d:15:a7:75:68:6b:19:21:a3:82:59:d9:ea:e6:46:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ab3d75c4d15a775686b1921a38259d9eae64620/; sid:902201525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a1:fb:81:ab:f5:e0:45:3e:6f:b1:29:b5:e2:58:3b:17:1b:fd:e4:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1fb81abf5e0453e6fb129b5e2583b171bfde416/; sid:902201526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fa:6c:d2:47:8a:9a:31:8c:2f:f8:3d:f1:32:b7:5b:4b:e7:2d:ab:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa6cd2478a9a318c2ff83df132b75b4be72dab28/; sid:902201527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"55:00:8f:ce:90:54:e4:7b:5b:14:61:b7:66:c2:44:3b:b2:73:c4:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55008fce9054e47b5b1461b766c2443bb273c4b1/; sid:902201528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fa:d4:0c:e0:ba:6f:e3:31:bb:b7:ae:fc:aa:d2:69:d8:bc:86:5c:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fad40ce0ba6fe331bbb7aefcaad269d8bc865cb2/; sid:902201529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8e:29:49:47:d3:57:fd:2b:76:09:7e:db:2f:30:b2:eb:0e:61:87:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e294947d357fd2b76097edb2f30b2eb0e618717/; sid:902201530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"63:22:a9:e1:7b:a0:0b:8a:be:ae:60:dd:f2:f0:d9:3b:7a:b5:cd:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6322a9e17ba00b8abeae60ddf2f0d93b7ab5cd94/; sid:902201531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f2:3f:07:fb:0d:e5:72:9e:79:b2:9b:4c:20:5d:39:2b:45:dc:98:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f23f07fb0de5729e79b29b4c205d392b45dc98a9/; sid:902201532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"07:57:2d:4e:9d:91:6d:35:9a:7e:a5:bc:03:6a:09:26:cd:cb:b1:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07572d4e9d916d359a7ea5bc036a0926cdcbb128/; sid:902201533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b0:9b:ca:1e:01:bf:3b:f5:5b:b4:54:71:f8:35:d2:bb:8b:8d:ad:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b09bca1e01bf3bf55bb45471f835d2bb8b8dadf9/; sid:902201534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6f:7b:dd:d7:24:32:66:8d:16:d4:29:50:45:98:e8:88:98:65:f5:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f7bddd72432668d16d429504598e8889865f50e/; sid:902201535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"45:69:14:03:1e:5d:57:88:d6:ad:41:b7:21:1b:7a:01:c0:4d:7c:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/456914031e5d5788d6ad41b7211b7a01c04d7cae/; sid:902201536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"7f:fd:7b:c9:90:c3:eb:78:49:ef:9c:46:35:d8:c5:a8:fb:16:a7:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ffd7bc990c3eb7849ef9c4635d8c5a8fb16a7bf/; sid:902201537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"56:d7:27:1a:71:d6:73:a7:6b:43:f2:a9:8f:c9:10:c2:fe:11:7f:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56d7271a71d673a76b43f2a98fc910c2fe117f24/; sid:902201538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e8:99:57:33:f6:ea:a1:22:02:df:81:20:6d:0d:d4:69:e7:9d:94:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8995733f6eaa12202df81206d0dd469e79d94c7/; sid:902201539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d1:f7:3d:cc:44:11:72:80:50:d3:fc:4a:22:24:26:3b:af:ff:fc:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1f73dcc4411728050d3fc4a2224263baffffcdd/; sid:902201540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e9:75:be:d4:20:61:b5:8e:f7:6d:d4:4c:d6:9c:8e:82:b0:39:d7:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e975bed42061b58ef76dd44cd69c8e82b039d730/; sid:902201541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Hancitor C&C)"; tls.fingerprint:"a3:05:27:ca:8a:de:21:87:1e:72:98:d5:b3:2e:75:0b:9e:58:d7:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a30527ca8ade21871e7298d5b32e750b9e58d79d/; sid:902201542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"db:97:cb:b7:25:58:88:68:ac:8a:90:36:e0:96:aa:4f:01:17:a9:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db97cbb725588868ac8a9036e096aa4f0117a99b/; sid:902201543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"92:b2:68:6b:8f:00:7b:93:77:2b:fd:de:74:bd:cb:d8:2d:46:43:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92b2686b8f007b93772bfdde74bdcbd82d4643cc/; sid:902201544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"72:3a:d7:c1:18:e3:22:c5:dd:0f:71:84:d2:7b:79:5f:0a:9b:20:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/723ad7c118e322c5dd0f7184d27b795f0a9b20cf/; sid:902201545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d3:40:fc:07:78:47:ac:74:6c:f8:66:41:2b:a9:ed:ef:5f:10:85:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d340fc077847ac746cf866412ba9edef5f1085c7/; sid:902201546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ba:42:1e:58:62:4e:ff:e4:5f:55:78:79:7e:82:e5:e8:b0:40:65:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba421e58624effe45f5578797e82e5e8b0406585/; sid:902201547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"91:55:e4:cd:a1:6d:df:06:54:c0:e8:3d:a8:2a:3e:aa:ff:da:99:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9155e4cda16ddf0654c0e83da82a3eaaffda9962/; sid:902201548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4d:8d:c8:00:54:35:6a:31:55:48:66:9b:9f:9e:94:16:de:c0:42:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d8dc80054356a315548669b9f9e9416dec042ba/; sid:902201549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"25:03:30:b5:39:ae:6c:71:2f:9e:7d:07:f9:51:93:e5:90:c0:8b:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/250330b539ae6c712f9e7d07f95193e590c08bc2/; sid:902201550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"f3:75:7b:64:d9:e4:31:2e:6b:04:4c:b2:0e:e1:75:07:ca:89:23:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3757b64d9e4312e6b044cb20ee17507ca8923d3/; sid:902201551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6d:5f:9b:fb:1b:76:8c:3f:da:90:46:6d:96:bb:15:51:df:d9:ee:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d5f9bfb1b768c3fda90466d96bb1551dfd9ee0b/; sid:902201552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"2b:29:68:f0:4b:b6:55:6e:c2:91:b8:44:3c:23:04:75:4c:9a:d7:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b2968f04bb6556ec291b8443c2304754c9ad7f1/; sid:902201553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"a5:cc:5f:0f:b6:3d:b7:ef:4f:8c:99:cf:49:28:75:3c:ea:90:29:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5cc5f0fb63db7ef4f8c99cf4928753cea90295c/; sid:902201554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"5b:ca:53:43:b1:de:a0:09:6e:d7:b2:07:fc:d3:d3:83:1e:a6:d1:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5bca5343b1dea0096ed7b207fcd3d3831ea6d130/; sid:902201555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a5:49:80:fc:f6:de:b0:53:77:d0:94:d2:ff:07:11:2d:7e:c1:05:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a54980fcf6deb05377d094d2ff07112d7ec105cc/; sid:902201556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cf:9a:b3:62:35:0c:23:5b:b2:90:25:0f:9a:62:33:ac:12:72:9a:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf9ab362350c235bb290250f9a6233ac12729ab2/; sid:902201557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"fd:51:bc:1d:19:8d:9f:42:f9:8b:4e:22:bc:a8:9a:6e:41:be:27:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd51bc1d198d9f42f98b4e22bca89a6e41be27c8/; sid:902201558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"f8:cf:b4:79:0c:d5:b2:71:05:ee:c5:6d:e9:dc:2e:2b:5f:4d:c8:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8cfb4790cd5b27105eec56de9dc2e2b5f4dc846/; sid:902201559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ca:9e:2e:b0:7d:8f:75:6a:97:74:1f:12:94:11:de:93:9f:1c:67:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca9e2eb07d8f756a97741f129411de939f1c67e1/; sid:902201560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"ca:e1:54:2c:5d:83:cd:78:16:3d:00:96:91:68:08:03:25:d4:ac:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cae1542c5d83cd78163d00969168080325d4ac4f/; sid:902201561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0f:20:6c:9a:95:22:ca:50:c6:df:64:0e:3f:7d:be:bf:aa:b8:17:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f206c9a9522ca50c6df640e3f7dbebfaab817fc/; sid:902201562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"1d:68:f8:64:01:bb:75:01:7c:01:a9:a5:53:ff:f3:37:c2:a7:37:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d68f86401bb75017c01a9a553fff337c2a737c6/; sid:902201563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"1c:8b:d9:5b:67:ad:70:ab:dd:e9:f7:37:87:fc:15:f0:88:1e:a3:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c8bd95b67ad70abdde9f73787fc15f0881ea33f/; sid:902201564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RockLoader C&C)"; tls.fingerprint:"7e:75:cd:f9:22:b9:a2:4f:86:da:31:58:1a:e4:c6:2d:c1:bd:25:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e75cdf922b9a24f86da31581ae4c62dc1bd25b0/; sid:902201565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6f:40:b3:08:16:49:1b:23:5e:ff:b3:02:97:af:50:78:95:7d:b7:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f40b30816491b235effb30297af5078957db75e/; sid:902201566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b1:a1:f7:38:f7:e4:c3:6d:e3:9c:4f:46:22:b5:e8:b4:d1:58:62:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1a1f738f7e4c36de39c4f4622b5e8b4d15862e7/; sid:902201567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"eb:52:85:89:e1:b4:23:05:c6:78:0a:05:96:09:b8:9b:90:79:b7:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb528589e1b42305c6780a059609b89b9079b7f7/; sid:902201568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"af:50:d0:af:aa:f5:c0:bf:5a:6b:04:6d:93:83:9a:d4:02:56:40:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af50d0afaaf5c0bf5a6b046d93839ad402564005/; sid:902201569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"e1:d3:8d:99:d7:b3:d1:9d:d3:c4:0e:8d:a7:ec:d4:d8:b8:5b:67:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1d38d99d7b3d19dd3c40e8da7ecd4d8b85b675e/; sid:902201570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ec:ef:03:ad:9f:e7:b8:81:42:52:6b:ca:b5:29:78:13:6f:95:db:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecef03ad9fe7b88142526bcab52978136f95db1d/; sid:902201571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6b:67:10:99:7c:bb:00:db:5b:50:bb:76:15:e7:6d:54:ff:36:d3:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b6710997cbb00db5b50bb7615e76d54ff36d3f7/; sid:902201572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"89:1f:bb:78:d4:2e:3e:b6:93:a9:ca:7c:cf:50:28:fd:25:ca:f8:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/891fbb78d42e3eb693a9ca7ccf5028fd25caf8a7/; sid:902201573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"61:ea:f7:39:f5:a9:ce:3b:3e:fb:76:f3:b6:2e:50:78:dd:0d:b1:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61eaf739f5a9ce3b3efb76f3b62e5078dd0db193/; sid:902201574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c6:5e:76:a5:54:7c:16:41:7f:36:a2:f9:12:7b:19:6e:cd:86:a8:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c65e76a5547c16417f36a2f9127b196ecd86a8ac/; sid:902201575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a2:55:60:55:34:34:23:ad:37:59:8d:a0:9e:9a:7b:f4:52:25:51:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2556055343423ad37598da09e9a7bf452255140/; sid:902201576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c7:f6:c0:2c:88:08:f6:e4:9b:4f:d1:f4:b0:fc:08:ed:e6:1e:5d:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c7f6c02c8808f6e49b4fd1f4b0fc08ede61e5ded/; sid:902201577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2e:79:6e:28:e2:aa:dd:7f:65:7c:db:c8:53:22:6f:f2:f8:49:80:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e796e28e2aadd7f657cdbc853226ff2f84980e4/; sid:902201578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8a:50:ad:95:29:98:4d:f8:94:b8:59:1e:7e:19:3f:ce:30:eb:9f:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a50ad9529984df894b8591e7e193fce30eb9fa8/; sid:902201579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cc:f9:26:3d:e3:eb:09:b9:08:c7:91:ba:b1:0a:c1:f7:38:c0:d9:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ccf9263de3eb09b908c791bab10ac1f738c0d9e8/; sid:902201580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e5:06:91:f1:1e:bf:3d:91:60:a8:20:d7:c9:05:e2:b0:0f:6c:2d:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e50691f11ebf3d9160a820d7c905e2b00f6c2d9c/; sid:902201581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c0:5d:8b:e1:bb:8d:b7:3d:62:5e:77:e8:de:0c:d6:25:4a:8f:0d:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c05d8be1bb8db73d625e77e8de0cd6254a8f0d75/; sid:902201582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8d:bb:ad:65:31:d9:d3:01:b8:ae:64:09:7e:5f:9c:8c:a2:c9:01:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dbbad6531d9d301b8ae64097e5f9c8ca2c901ef/; sid:902201583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"48:6e:3f:b2:77:a2:5b:9f:4c:b6:a2:f1:09:a0:b5:17:f8:15:19:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/486e3fb277a25b9f4cb6a2f109a0b517f815193f/; sid:902201584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d4:bb:3b:06:b5:00:67:cc:f5:b9:22:ea:a6:7c:f5:fe:0e:6c:c9:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4bb3b06b50067ccf5b922eaa67cf5fe0e6cc9ff/; sid:902201585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"29:48:9e:12:a9:07:4a:70:02:43:50:cb:d9:d0:d5:94:45:f9:a6:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29489e12a9074a70024350cbd9d0d59445f9a655/; sid:902201586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1a:17:f1:01:f6:5e:46:19:de:08:a8:e4:03:d1:29:74:df:94:eb:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a17f101f65e4619de08a8e403d12974df94ebfa/; sid:902201587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6b:a0:28:8a:54:a4:ac:dc:e0:01:e9:e3:d2:a6:bb:69:ed:c5:05:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ba0288a54a4acdce001e9e3d2a6bb69edc50532/; sid:902201588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"87:61:5b:b0:1f:c6:fa:61:88:1b:f4:33:38:6a:49:e0:17:8c:91:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87615bb01fc6fa61881bf433386a49e0178c91d4/; sid:902201589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1d:83:93:b9:fd:9a:a0:b4:c7:7e:aa:bd:53:cb:34:1d:b1:1b:a4:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d8393b9fd9aa0b4c77eaabd53cb341db11ba41e/; sid:902201590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"2e:00:b1:6d:b0:9e:78:00:72:48:d5:43:83:b9:7e:a9:ef:3b:54:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e00b16db09e78007248d54383b97ea9ef3b54a4/; sid:902201591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7d:2e:e4:2f:4f:0a:70:86:3a:3c:8d:04:59:99:52:4b:d2:2f:62:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d2ee42f4f0a70863a3c8d045999524bd22f62bc/; sid:902201592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"33:c3:d1:f2:64:76:24:ca:dd:a3:f0:f9:86:08:41:08:bb:2a:94:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33c3d1f2647624cadda3f0f986084108bb2a941b/; sid:902201593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"89:be:3a:84:0c:2d:18:96:e4:4f:15:14:82:e5:2e:93:2f:d0:2b:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89be3a840c2d1896e44f151482e52e932fd02b9f/; sid:902201594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"8b:31:91:e6:a7:4e:86:db:88:65:a5:95:ab:65:ac:3d:0f:82:5e:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b3191e6a74e86db8865a595ab65ac3d0f825e10/; sid:902201595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5a:5d:28:91:8c:c1:44:bf:b4:a3:1f:5c:92:60:e3:d4:0d:6b:81:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a5d28918cc144bfb4a31f5c9260e3d40d6b811d/; sid:902201596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"29:91:b5:87:99:4b:cf:fa:56:95:21:43:45:bd:8c:82:45:d7:78:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2991b587994bcffa5695214345bd8c8245d7786c/; sid:902201597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"02:1c:92:b4:d4:6d:bc:31:58:9b:3d:b9:77:35:db:8b:f5:1a:d6:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/021c92b4d46dbc31589b3db97735db8bf51ad65a/; sid:902201598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"cf:b1:71:e9:03:18:6d:96:9d:c2:87:50:bb:f7:77:c4:ee:48:61:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfb171e903186d969dc28750bbf777c4ee4861f6/; sid:902201599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e5:5c:47:6b:3b:8a:bd:15:67:49:1a:a9:39:13:41:0a:9b:b9:be:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e55c476b3b8abd1567491aa93913410a9bb9be62/; sid:902201600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ee:53:9b:1e:90:a8:db:4d:00:79:3b:ef:1f:1d:c5:7e:5a:ba:97:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee539b1e90a8db4d00793bef1f1dc57e5aba9706/; sid:902201601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a2:d8:2b:dd:7d:c3:ab:6a:3d:48:19:89:53:cb:13:1d:ab:87:17:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2d82bdd7dc3ab6a3d48198953cb131dab8717a0/; sid:902201602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"bb:53:aa:5a:c3:ec:91:52:2b:a6:fa:32:b6:d1:9e:0d:16:63:0c:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb53aa5ac3ec91522ba6fa32b6d19e0d16630c8a/; sid:902201603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e5:8f:32:e9:10:1b:92:8f:a9:8a:b0:f7:0c:d9:b5:84:68:13:b5:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e58f32e9101b928fa98ab0f70cd9b5846813b523/; sid:902201604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9a:6f:a1:bd:e6:ba:d7:5c:55:17:81:97:b8:12:3c:c4:ed:65:8f:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a6fa1bde6bad75c55178197b8123cc4ed658f50/; sid:902201605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d9:dd:7d:1e:38:16:83:06:95:bc:3e:53:2f:35:ea:b2:64:ec:e7:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9dd7d1e3816830695bc3e532f35eab264ece7a8/; sid:902201606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"46:ed:d8:d4:49:51:65:0a:5b:e5:ae:a5:fe:d3:91:4c:df:5a:3a:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46edd8d44951650a5be5aea5fed3914cdf5a3ad0/; sid:902201607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4d:47:e2:a1:9f:d9:01:92:dc:3b:2d:17:89:a0:60:37:2b:c5:cd:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d47e2a19fd90192dc3b2d1789a060372bc5cd48/; sid:902201608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"75:16:f7:0c:b9:a1:d4:f2:f3:a5:71:56:77:1c:70:7d:04:5c:f1:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7516f70cb9a1d4f2f3a57156771c707d045cf143/; sid:902201609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"27:bb:8d:2c:44:6d:fc:fe:e4:65:40:79:ef:8f:00:b0:af:db:c3:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27bb8d2c446dfcfee4654079ef8f00b0afdbc333/; sid:902201610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c2:20:d2:04:95:40:32:25:aa:ba:cb:66:05:87:e2:55:51:83:9e:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c220d20495403225aabacb660587e25551839eef/; sid:902201611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"55:2d:23:48:f1:01:37:4d:b7:d9:a3:24:9f:4f:d9:a3:7f:52:70:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/552d2348f101374db7d9a3249f4fd9a37f5270cf/; sid:902201612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"55:00:44:83:a0:ff:8a:ce:b9:e1:c6:5d:f4:07:61:d7:45:76:63:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55004483a0ff8aceb9e1c65df40761d7457663ad/; sid:902201613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"de:80:19:40:6c:b5:0a:7c:53:82:ed:8c:86:cb:46:8b:06:ee:6e:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de8019406cb50a7c5382ed8c86cb468b06ee6e24/; sid:902201614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4c:f1:34:33:ad:87:84:ca:e0:53:fe:51:a3:86:43:a8:b5:dc:2b:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cf13433ad8784cae053fe51a38643a8b5dc2b3e/; sid:902201615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"dc:be:92:0e:3d:0c:ba:40:be:80:fb:a5:e2:3a:6b:4f:9a:70:6d:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dcbe920e3d0cba40be80fba5e23a6b4f9a706dd4/; sid:902201616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"4b:a1:e8:85:5b:47:ce:16:19:e2:ba:ef:19:db:ce:1d:f5:b3:eb:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ba1e8855b47ce1619e2baef19dbce1df5b3eb2c/; sid:902201617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2e:16:74:f9:28:4d:da:60:a0:b4:83:54:a1:55:17:94:c6:53:b8:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e1674f9284dda60a0b48354a1551794c653b8a8/; sid:902201618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Sinkhole)"; tls.fingerprint:"e0:3e:33:56:29:b8:82:f1:f0:3f:09:11:23:51:1e:aa:3f:c2:d6:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e03e335629b882f1f03f091123511eaa3fc2d6b1/; sid:902201619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"57:2e:fc:1d:71:cb:6a:49:11:c1:43:93:f1:82:58:57:79:3a:18:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/572efc1d71cb6a4911c14393f1825857793a1869/; sid:902201620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"5f:cb:5b:41:8f:77:9a:54:2b:71:48:f2:dd:ea:21:14:95:78:77:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fcb5b418f779a542b7148f2ddea211495787733/; sid:902201621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"2a:5d:84:0b:a9:92:28:08:2b:f7:0a:a8:ae:41:6f:fd:4f:86:80:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a5d840ba99228082bf70aa8ae416ffd4f868051/; sid:902201622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"6e:03:78:b9:8e:8b:b4:ea:8e:dc:15:4f:2c:82:94:28:70:4a:98:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6e0378b98e8bb4ea8edc154f2c829428704a9839/; sid:902201623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"9d:86:3f:cb:32:7a:d4:41:18:41:ee:07:13:29:3e:a4:a5:2a:df:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d863fcb327ad4411841ee0713293ea4a52adf95/; sid:902201624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b6:c3:0a:7e:59:97:39:80:14:cb:b4:1d:0c:5e:ca:44:52:55:54:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c30a7e5997398014cbb41d0c5eca4452555490/; sid:902201625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:c4:e1:ee:51:64:ca:3e:d0:18:42:d5:91:e3:9d:c2:64:4e:c0:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06c4e1ee5164ca3ed01842d591e39dc2644ec026/; sid:902201626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c4:cb:7f:0d:4f:65:8f:71:c3:b1:32:f2:73:06:59:da:60:da:ae:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4cb7f0d4f658f71c3b132f2730659da60daaeac/; sid:902201627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"77:3b:b1:21:21:46:96:29:41:01:a7:33:18:fe:30:bf:c3:2c:2d:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/773bb121214696294101a73318fe30bfc32c2dcf/; sid:902201628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0d:ec:05:bb:54:8c:b8:41:2f:83:b4:25:fd:08:22:06:b2:8f:87:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dec05bb548cb8412f83b425fd082206b28f87b5/; sid:902201629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d9:ee:1e:bc:5d:05:64:7e:9e:57:c9:80:5a:2d:c8:56:5c:5c:60:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9ee1ebc5d05647e9e57c9805a2dc8565c5c60f6/; sid:902201630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"18:a1:05:f3:f6:2e:52:e2:47:14:49:3e:38:2b:00:b9:30:70:07:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18a105f3f62e52e24714493e382b00b93070077b/; sid:902201631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"3c:9b:b4:44:80:fa:d3:57:7c:51:6b:21:86:9f:78:4b:10:43:bd:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c9bb44480fad3577c516b21869f784b1043bd21/; sid:902201632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"8f:2b:e1:bb:91:3b:54:a1:68:c0:39:4a:ff:c6:74:27:2e:da:9e:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f2be1bb913b54a168c0394affc674272eda9eeb/; sid:902201633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"82:c0:a9:7f:05:88:93:a7:7f:8a:2a:27:bb:75:b5:fb:7a:d2:30:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82c0a97f058893a77f8a2a27bb75b5fb7ad230ac/; sid:902201634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c7:01:fa:6c:fe:bc:57:7a:6c:20:f7:74:5c:85:a9:93:85:07:b8:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c701fa6cfebc577a6c20f7745c85a9938507b8a3/; sid:902201635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"b6:05:c6:66:e1:9d:5d:bc:06:f5:73:a4:1f:35:94:d1:c9:31:fa:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b605c666e19d5dbc06f573a41f3594d1c931faf1/; sid:902201636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Shifu C&C)"; tls.fingerprint:"f7:78:c5:7a:70:3a:49:c5:a5:5f:a1:ad:06:81:00:67:c4:03:fa:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f778c57a703a49c5a55fa1ad06810067c403fae9/; sid:902201637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"37:32:ab:da:e5:df:b0:59:d9:20:b5:1a:4f:99:f6:54:41:1c:a6:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3732abdae5dfb059d920b51a4f99f654411ca6f7/; sid:902201638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1e:5e:a2:74:98:84:d3:aa:c8:05:97:9e:ad:d0:e4:5f:98:48:a9:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e5ea2749884d3aac805979eadd0e45f9848a95b/; sid:902201639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"80:9e:cc:b2:e4:16:b8:27:d4:52:d5:37:93:ec:bf:8c:28:e3:28:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/809eccb2e416b827d452d53793ecbf8c28e32884/; sid:902201640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c3:06:f5:67:cd:3d:eb:0d:8c:f4:93:f1:b3:e1:47:b9:1f:2e:be:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c306f567cd3deb0d8cf493f1b3e147b91f2ebef3/; sid:902201641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:ef:17:d3:c7:a1:1a:e0:5e:f7:8b:9b:4b:42:df:a1:3b:69:92:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38ef17d3c7a11ae05ef78b9b4b42dfa13b6992b2/; sid:902201642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2a:a1:c1:bf:cc:8d:4b:6a:04:f2:0f:80:a8:9b:64:19:ea:cf:c5:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2aa1c1bfcc8d4b6a04f20f80a89b6419eacfc50a/; sid:902201643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ca:de:0e:d9:c0:b0:9a:24:16:94:f9:3e:e5:1b:6f:ac:bc:67:12:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cade0ed9c0b09a241694f93ee51b6facbc671230/; sid:902201644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware C&C)"; tls.fingerprint:"b0:23:8c:54:7a:90:5b:fa:11:9c:4e:8b:ac:ca:ea:cf:36:49:1f:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0238c547a905bfa119c4e8baccaeacf36491ff6/; sid:902201645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"6f:bc:ae:7b:3f:fa:53:de:f5:21:95:e1:87:36:4a:dc:a0:03:07:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fbcae7b3ffa53def52195e187364adca0030719/; sid:902201646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"3c:cc:af:27:6c:8f:31:45:2a:9a:44:c8:d2:ae:ea:64:9a:92:b6:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cccaf276c8f31452a9a44c8d2aeea649a92b675/; sid:902201647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"f4:d0:e0:cf:53:2a:f4:5c:50:2f:64:d1:84:71:ad:76:18:9f:4a:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4d0e0cf532af45c502f64d18471ad76189f4a33/; sid:902201648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3c:87:5d:a1:4a:71:bc:66:0b:b7:c9:0d:b7:9a:aa:69:c7:6f:d0:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c875da14a71bc660bb7c90db79aaa69c76fd0e0/; sid:902201649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"63:c6:b8:54:da:a6:b2:ae:7f:35:5d:24:03:f6:e1:28:40:4e:9a:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63c6b854daa6b2ae7f355d2403f6e128404e9a58/; sid:902201650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"65:38:fb:5f:1e:71:24:85:d2:56:04:0c:21:94:6c:35:d5:1e:62:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6538fb5f1e712485d256040c21946c35d51e6244/; sid:902201651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:50:84:1f:19:de:dd:73:4b:53:0d:e2:18:57:b9:9d:fe:9d:f0:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3250841f19dedd734b530de21857b99dfe9df057/; sid:902201652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"0c:f7:10:e3:3d:3e:4a:57:2d:cb:a9:76:3d:92:e6:5b:5d:9c:af:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0cf710e33d3e4a572dcba9763d92e65b5d9caf57/; sid:902201653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2d:ee:94:1d:f3:dd:2f:65:48:1f:f4:61:8d:cd:15:2f:98:6a:fa:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2dee941df3dd2f65481ff4618dcd152f986afab6/; sid:902201654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5d:47:e1:02:ad:3a:c8:ff:59:10:aa:41:1c:a5:52:04:82:b4:f0:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d47e102ad3ac8ff5910aa411ca5520482b4f05f/; sid:902201655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"37:3a:97:ff:16:73:02:9d:1d:af:67:25:37:07:dd:89:d6:1f:2f:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/373a97ff1673029d1daf67253707dd89d61f2f13/; sid:902201656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"7c:1c:df:ad:43:21:63:48:0d:48:3d:76:63:11:78:61:e7:ee:84:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c1cdfad432163480d483d7663117861e7ee84ad/; sid:902201657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"6d:5f:3c:c2:2e:17:cd:61:cf:7c:08:22:4d:37:40:cc:34:dd:a8:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d5f3cc22e17cd61cf7c08224d3740cc34dda8a1/; sid:902201658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"0c:1a:ab:eb:94:f4:35:80:ef:47:b5:b4:3d:94:24:db:1f:f4:66:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c1aabeb94f43580ef47b5b43d9424db1ff4661d/; sid:902201659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"3e:06:09:e8:75:69:3c:68:a0:7a:da:48:b6:8c:8e:d4:a7:ca:96:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e0609e875693c68a07ada48b68c8ed4a7ca96ef/; sid:902201660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZeuS C&C)"; tls.fingerprint:"0f:a9:4b:03:19:b7:95:2e:80:9e:2f:a0:84:d3:6a:9e:bc:42:8a:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0fa94b0319b7952e809e2fa084d36a9ebc428add/; sid:902201661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"69:d6:9d:6d:ee:c4:ef:a2:c8:ea:37:69:8d:15:70:b6:a0:3c:ce:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69d69d6deec4efa2c8ea37698d1570b6a03cce0a/; sid:902201662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"92:75:d5:27:40:c0:b0:1c:e9:52:32:3d:0f:53:68:d7:8a:74:ff:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9275d52740c0b01ce952323d0f5368d78a74ffbf/; sid:902201663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"98:a6:d6:8d:80:04:05:d0:33:92:10:24:b3:7d:54:51:0c:72:c4:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98a6d68d800405d033921024b37d54510c72c4ce/; sid:902201664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"19:8c:4b:58:52:d2:1b:42:5a:cb:05:da:a5:90:d4:09:f3:a5:4a:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/198c4b5852d21b425acb05daa590d409f3a54a65/; sid:902201665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8a:18:9e:f3:c9:49:c3:8b:a2:38:10:3e:ff:f4:e1:7a:39:b9:c3:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a189ef3c949c38ba238103efff4e17a39b9c3df/; sid:902201666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"98:4b:3c:4e:f8:3e:14:ed:69:ff:2f:6a:44:63:03:12:71:e6:5a:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/984b3c4ef83e14ed69ff2f6a4463031271e65a86/; sid:902201667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"2c:8e:d1:0a:08:7b:d1:80:96:46:48:2b:07:43:5b:82:29:79:93:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c8ed10a087bd1809646482b07435b82297993f0/; sid:902201668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"fd:02:8d:cb:df:0d:f6:9d:70:1f:ca:55:8b:b3:0a:88:48:ad:4f:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd028dcbdf0df69d701fca558bb30a8848ad4f3e/; sid:902201669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b4:a7:3b:85:43:89:db:e3:5e:ca:2c:c2:a1:ea:7f:63:34:8a:7a:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4a73b854389dbe35eca2cc2a1ea7f63348a7a67/; sid:902201670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"51:76:d7:ea:82:0b:96:f7:66:b2:3c:17:c3:66:ac:4d:95:0e:37:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5176d7ea820b96f766b23c17c366ac4d950e37c1/; sid:902201671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"b7:fb:60:58:e5:fc:1d:f0:8a:13:b6:f2:ac:8b:0e:da:4c:a1:a2:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7fb6058e5fc1df08a13b6f2ac8b0eda4ca1a2db/; sid:902201672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"37:f7:d3:a0:f5:ac:ac:31:69:e6:df:b0:f0:f9:25:f9:5f:ed:4b:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37f7d3a0f5acac3169e6dfb0f0f925f95fed4be6/; sid:902201673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Sofacy C&C)"; tls.fingerprint:"5b:e5:6e:06:60:a0:01:a1:2c:8e:f2:50:ff:86:36:9c:50:ca:73:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5be56e0660a001a12c8ef250ff86369c50ca73a8/; sid:902201674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6e:48:d8:f5:76:b1:37:a6:b3:22:88:28:37:0d:77:b2:1e:f8:8a:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6e48d8f576b137a6b3228828370d77b21ef88adc/; sid:902201675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c4:1f:27:7c:64:95:b2:99:ae:1b:d0:28:a0:a5:7f:c1:7b:60:42:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c41f277c6495b299ae1bd028a0a57fc17b6042de/; sid:902201676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"25:d2:22:2b:e7:21:91:de:03:cc:da:98:c1:3b:1b:b7:a6:cf:28:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25d2222be72191de03ccda98c13b1bb7a6cf2810/; sid:902201677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"be:fc:88:84:8e:20:3f:dc:46:5c:0f:ca:03:c3:f6:e4:0e:e4:30:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/befc88848e203fdc465c0fca03c3f6e40ee4305c/; sid:902201678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:dc:61:76:05:65:a7:05:62:59:28:33:b6:76:7e:05:c3:80:1d:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38dc61760565a70562592833b6767e05c3801d95/; sid:902201679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"91:ca:40:0a:83:6a:85:a3:95:a3:d5:25:ee:96:3c:46:19:ad:4d:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91ca400a836a85a395a3d525ee963c4619ad4dcb/; sid:902201680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"e2:8d:d9:91:4a:5a:18:e5:c0:83:db:f8:29:1f:01:8f:ab:a0:9f:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e28dd9914a5a18e5c083dbf8291f018faba09fc0/; sid:902201681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"3b:a9:31:86:86:32:7d:79:38:34:f1:65:96:4b:bd:6e:35:4a:a7:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ba9318686327d793834f165964bbd6e354aa74d/; sid:902201682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"14:2e:f2:14:dc:ac:d7:83:83:d8:6f:20:a9:91:e5:39:a6:2c:90:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/142ef214dcacd78383d86f20a991e539a62c90ca/; sid:902201683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"49:64:a6:d2:e8:76:a5:ad:c3:76:9d:92:98:f5:c0:77:14:09:1c:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4964a6d2e876a5adc3769d9298f5c07714091cf1/; sid:902201684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8b:c2:66:f7:bb:f4:24:48:e8:7c:bf:f1:56:7a:65:e6:08:47:df:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bc266f7bbf42448e87cbff1567a65e60847df34/; sid:902201685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"90:1f:02:c2:5e:05:08:88:41:49:ce:a2:77:71:70:28:da:2f:a6:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/901f02c25e0508884149cea277717028da2fa6ce/; sid:902201686; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2b:bf:93:89:f2:b6:25:b4:6d:74:77:55:c9:e1:f0:c3:31:fa:37:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bbf9389f2b625b46d747755c9e1f0c331fa377c/; sid:902201687; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"28:59:46:b1:5d:55:b9:7c:25:ee:cf:fa:22:bc:2e:42:47:ab:40:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/285946b15d55b97c25eecffa22bc2e4247ab405d/; sid:902201688; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6a:c0:57:18:a0:ab:32:b0:c5:df:21:9a:df:81:0a:c4:cf:c7:70:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ac05718a0ab32b0c5df219adf810ac4cfc77083/; sid:902201689; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:f4:c2:03:81:01:23:11:56:b0:59:3f:e2:0a:40:e3:13:27:5a:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cef4c2038101231156b0593fe20a40e313275a07/; sid:902201690; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"97:14:2a:b7:ff:13:0a:3d:fc:8c:b5:7d:e1:a1:f2:a0:15:93:c4:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97142ab7ff130a3dfc8cb57de1a1f2a01593c42b/; sid:902201691; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"4e:0c:78:38:5e:ab:da:e8:ec:84:32:9f:ee:83:8d:44:6c:2b:ea:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e0c78385eabdae8ec84329fee838d446c2bea08/; sid:902201692; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"36:4b:89:17:a3:e1:af:ca:07:96:d0:2d:43:84:fd:57:41:cd:95:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/364b8917a3e1afca0796d02d4384fd5741cd9593/; sid:902201693; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"1f:0e:dd:ff:31:74:fe:3e:bc:fa:4c:62:5f:e9:f6:19:a5:8e:28:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f0eddff3174fe3ebcfa4c625fe9f619a58e282e/; sid:902201694; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"fc:7f:30:ca:d7:f6:06:e5:21:20:16:a3:58:cf:1d:ce:d3:f7:9c:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc7f30cad7f606e5212016a358cf1dced3f79c5e/; sid:902201695; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"23:5b:67:3c:f7:50:b7:5b:97:1b:45:c8:67:f1:f6:aa:23:c5:84:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/235b673cf750b75b971b45c867f1f6aa23c584ac/; sid:902201696; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"60:60:70:e1:72:11:79:ad:fc:c7:d2:a9:ca:96:b8:ac:d6:f0:20:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/606070e1721179adfcc7d2a9ca96b8acd6f02049/; sid:902201697; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"7f:9b:36:d5:67:8b:a5:c7:eb:1a:1a:c4:f1:ff:59:e1:00:46:a6:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f9b36d5678ba5c7eb1a1ac4f1ff59e10046a674/; sid:902201698; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Tuhkit C&C)"; tls.fingerprint:"0c:6d:37:21:e9:b4:ba:3b:ba:c4:61:7b:34:f0:f0:ff:75:f8:8e:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c6d3721e9b4ba3bbac4617b34f0f0ff75f88e72/; sid:902201699; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:c2:3a:77:81:77:2d:9f:9d:f9:5d:ae:22:cf:3a:a2:d1:82:0a:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3c23a7781772d9f9df95dae22cf3aa2d1820aab/; sid:902201700; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d2:12:e2:65:14:30:19:23:dd:7e:cb:b5:6e:eb:8f:a5:c5:27:74:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d212e26514301923dd7ecbb56eeb8fa5c5277478/; sid:902201701; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b6:04:c8:21:ae:0f:81:ab:9b:0e:9f:c4:31:8d:b5:e0:92:20:20:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b604c821ae0f81ab9b0e9fc4318db5e09220204e/; sid:902201702; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"8b:14:04:4f:38:67:41:50:ab:70:e8:74:4f:1d:cd:03:9a:9c:40:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b14044f38674150ab70e8744f1dcd039a9c4098/; sid:902201703; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Flokibot C&C)"; tls.fingerprint:"a8:0f:80:72:47:22:cd:77:4b:80:38:8f:4b:85:3e:c5:d4:27:0e:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a80f80724722cd774b80388f4b853ec5d4270ef3/; sid:902201704; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2d:e8:c1:99:00:14:0c:e5:ee:9e:82:44:7d:00:8e:69:cb:dc:8f:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2de8c19900140ce5ee9e82447d008e69cbdc8f8e/; sid:902201705; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"93:0b:e3:26:b1:33:5b:0c:e8:3f:0b:2d:60:39:10:09:c9:d4:46:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/930be326b1335b0ce83f0b2d60391009c9d44684/; sid:902201706; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"c1:3f:38:a3:85:f2:37:97:8e:77:93:ae:92:8b:45:ba:e5:c9:3d:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c13f38a385f237978e7793ae928b45bae5c93d58/; sid:902201707; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"d2:07:43:87:b1:d9:75:fe:52:55:f5:28:5e:1c:75:4d:95:09:5a:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2074387b1d975fe5255f5285e1c754d95095a24/; sid:902201708; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"91:e0:5e:f0:66:3b:df:d9:69:3a:5c:68:73:5a:4b:7b:e1:3c:94:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91e05ef0663bdfd9693a5c68735a4b7be13c941e/; sid:902201709; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"1e:ef:63:b9:1a:fa:ad:d5:a5:10:cf:b6:7d:3d:1e:a3:3a:f1:8c:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1eef63b91afaadd5a510cfb67d3d1ea33af18c49/; sid:902201710; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:1c:66:be:0e:b4:5d:10:62:7f:af:8d:c3:86:83:00:c3:07:93:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/371c66be0eb45d10627faf8dc3868300c30793ed/; sid:902201711; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"c3:d4:ae:f8:80:95:19:b1:40:77:ad:b7:0f:7b:52:0b:85:33:d5:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3d4aef8809519b14077adb70f7b520b8533d569/; sid:902201712; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Flokibot C&C)"; tls.fingerprint:"b7:a4:74:3e:88:56:75:b9:ac:54:f7:3b:42:17:ef:60:da:84:f7:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7a4743e885675b9ac54f73b4217ef60da84f73a/; sid:902201713; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"d1:25:06:37:88:10:7c:42:75:be:9f:ad:e6:97:bf:03:1f:31:90:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d125063788107c4275be9fade697bf031f3190ee/; sid:902201714; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c8:bf:c4:45:d1:33:d9:c3:a6:e4:60:6f:10:5e:0d:d8:b1:99:48:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8bfc445d133d9c3a6e4606f105e0dd8b19948a3/; sid:902201715; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"26:f2:61:5d:18:e3:90:0b:1a:72:b4:1e:a5:5b:8c:20:ef:7b:da:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26f2615d18e3900b1a72b41ea55b8c20ef7bda66/; sid:902201716; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"bf:1d:af:81:ab:7b:c7:a1:53:ce:ef:91:1c:09:5e:dc:3f:ba:fc:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf1daf81ab7bc7a153ceef911c095edc3fbafc99/; sid:902201717; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:31:c7:07:fe:04:2f:ff:0d:cb:55:3e:af:27:03:9f:1c:dd:b7:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce31c707fe042fff0dcb553eaf27039f1cddb7e6/; sid:902201718; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3b:76:3c:d8:d1:96:1e:a9:85:d5:bb:88:4a:ef:f6:6e:51:e6:2a:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b763cd8d1961ea985d5bb884aeff66e51e62a40/; sid:902201719; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"53:81:ad:cf:3c:17:b7:f8:62:28:1a:5a:08:92:06:92:e5:0c:45:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5381adcf3c17b7f862281a5a08920692e50c45f4/; sid:902201720; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"a8:a1:19:83:27:02:69:1a:b0:a7:b0:fc:6a:42:42:7a:a2:97:d7:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8a119832702691ab0a7b0fc6a42427aa297d748/; sid:902201721; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"15:92:d6:bd:7a:96:77:d4:b6:b3:30:68:e5:3f:ad:ea:15:f8:c7:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1592d6bd7a9677d4b6b33068e53fadea15f8c793/; sid:902201722; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"12:10:c3:32:4a:06:74:48:d4:7a:d1:98:08:4d:7a:04:b1:5f:bb:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1210c3324a067448d47ad198084d7a04b15fbb39/; sid:902201723; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c6:11:65:5c:84:ac:07:49:bd:81:05:ea:3d:ec:1f:4c:df:14:8f:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c611655c84ac0749bd8105ea3dec1f4cdf148fb5/; sid:902201724; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c4:d6:08:de:17:a8:57:69:ed:a8:b3:ae:b3:ad:ea:6a:58:f2:11:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4d608de17a85769eda8b3aeb3adea6a58f21107/; sid:902201725; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"7c:fe:27:5c:ea:e4:24:5c:73:e0:87:63:12:4d:17:cc:aa:19:bf:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7cfe275ceae4245c73e08763124d17ccaa19bf44/; sid:902201726; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"37:f5:ca:ec:69:16:96:5a:7f:9c:2a:4d:26:22:33:4a:e5:f1:4c:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37f5caec6916965a7f9c2a4d2622334ae5f14c3a/; sid:902201727; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:a7:dc:38:b9:0f:71:8d:3b:34:ea:0f:c6:be:c3:9c:8f:2f:7a:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3a7dc38b90f718d3b34ea0fc6bec39c8f2f7a8c/; sid:902201728; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:5c:84:f8:db:f9:df:c1:92:38:38:13:70:1b:f1:ca:f8:27:fd:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/435c84f8dbf9dfc192383813701bf1caf827fdbf/; sid:902201729; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"92:42:3f:82:4a:66:6d:95:b1:2e:63:a5:6e:fd:e3:cc:c1:ae:7f:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92423f824a666d95b12e63a56efde3ccc1ae7fc7/; sid:902201730; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"31:53:36:e7:51:3e:ba:5b:06:73:64:95:ca:bc:cc:e9:4c:58:f8:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/315336e7513eba5b06736495cabccce94c58f8d0/; sid:902201731; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"83:17:a8:5e:af:39:ec:5a:6f:03:80:a3:b9:74:4b:8e:3f:f3:ab:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8317a85eaf39ec5a6f0380a3b9744b8e3ff3abe6/; sid:902201732; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"04:bb:ff:19:be:2e:b0:8c:b7:0d:02:f1:3c:0a:36:0c:71:6a:81:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/04bbff19be2eb08cb70d02f13c0a360c716a8196/; sid:902201733; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"37:83:0c:93:5a:7d:ba:47:51:3e:24:b5:79:2b:de:cb:fa:df:2a:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37830c935a7dba47513e24b5792bdecbfadf2a73/; sid:902201734; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"1d:99:bb:47:24:51:4e:2a:87:f5:dd:de:8c:81:a8:03:c5:04:ac:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d99bb4724514e2a87f5ddde8c81a803c504accf/; sid:902201735; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"e1:8d:a4:f1:48:05:8c:77:70:37:01:92:fc:f0:c9:e1:81:00:c7:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e18da4f148058c7770370192fcf0c9e18100c79e/; sid:902201736; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"0f:07:3d:24:a6:76:37:f4:27:e7:4b:2f:a1:ff:5b:bc:42:c4:c1:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f073d24a67637f427e74b2fa1ff5bbc42c4c157/; sid:902201737; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"5d:40:6e:44:b8:90:d6:85:5c:44:fa:e3:88:bc:a3:bd:82:8a:c7:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d406e44b890d6855c44fae388bca3bd828ac7ff/; sid:902201738; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c3:e1:7e:de:e4:98:6c:b6:3b:be:d8:57:20:c9:4e:0f:a2:84:10:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3e17edee4986cb63bbed85720c94e0fa2841011/; sid:902201739; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"42:73:d1:03:c5:fe:c2:ed:e6:f9:ca:d0:92:a8:34:17:a4:3f:e7:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4273d103c5fec2ede6f9cad092a83417a43fe741/; sid:902201740; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"f4:57:07:8a:ca:7b:2b:93:6f:2a:91:87:0c:77:29:ae:d6:13:fb:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f457078aca7b2b936f2a91870c7729aed613fb80/; sid:902201741; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"06:52:9c:2f:d2:41:d9:05:ab:19:df:a0:fa:75:8d:51:95:0e:3c:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06529c2fd241d905ab19dfa0fa758d51950e3c35/; sid:902201742; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"69:9a:e2:9f:d3:0a:77:23:a6:96:57:8b:4b:8f:fe:08:9e:ad:8e:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/699ae29fd30a7723a696578b4b8ffe089ead8e9b/; sid:902201743; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0a:c6:ec:94:53:c6:87:b1:83:69:7c:cc:b8:41:55:d1:46:99:c5:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ac6ec9453c687b183697cccb84155d14699c513/; sid:902201744; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"34:6f:f7:29:94:50:45:49:d5:3f:73:37:34:dc:5d:f3:88:17:18:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/346ff72994504549d53f733734dc5df3881718a0/; sid:902201745; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"68:de:c5:1d:9d:27:fd:d6:ef:c5:7b:b5:58:1b:54:24:3f:b6:0a:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68dec51d9d27fdd6efc57bb5581b54243fb60aeb/; sid:902201746; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"82:a3:4d:b6:eb:6f:1f:a2:d6:38:3f:f0:d2:67:5f:09:6b:a6:bc:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82a34db6eb6f1fa2d6383ff0d2675f096ba6bc1b/; sid:902201747; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ce:c3:a8:ff:a8:61:ca:55:6f:cc:59:04:72:ac:b8:c8:04:65:b0:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cec3a8ffa861ca556fcc590472acb8c80465b0f5/; sid:902201748; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:29:5c:b4:4d:4d:41:53:75:26:f8:c6:eb:ca:ca:e1:eb:d4:3d:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15295cb44d4d41537526f8c6ebcacae1ebd43d4b/; sid:902201749; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"dc:44:1e:d1:e1:33:5b:90:45:1c:cd:04:6b:83:73:e7:3a:fc:b0:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc441ed1e1335b90451ccd046b8373e73afcb097/; sid:902201750; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8e:ef:8e:5d:51:19:d2:3d:25:92:64:48:5f:ce:70:6d:f2:41:1e:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8eef8e5d5119d23d259264485fce706df2411e52/; sid:902201751; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"4f:fa:b6:86:3c:c3:7f:a2:bd:b1:b6:44:96:ad:ec:45:61:07:04:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ffab6863cc37fa2bdb1b64496adec4561070472/; sid:902201752; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"03:a9:c8:bd:3e:09:2e:f8:73:1d:b9:8e:c0:fa:3e:b6:df:83:8b:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03a9c8bd3e092ef8731db98ec0fa3eb6df838b08/; sid:902201753; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"07:99:fa:be:78:85:88:13:7e:90:f0:82:8d:06:b5:34:32:69:ab:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0799fabe788588137e90f0828d06b5343269abe4/; sid:902201754; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b5:ad:8c:78:3c:57:ef:bd:67:64:91:a5:d2:d7:a8:63:16:3d:9e:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5ad8c783c57efbd676491a5d2d7a863163d9e14/; sid:902201755; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"06:07:2c:50:f1:31:ca:75:79:9c:b5:57:26:b2:89:ce:35:c0:d0:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06072c50f131ca75799cb55726b289ce35c0d048/; sid:902201756; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bf:d5:80:57:41:97:75:1e:f6:39:21:b5:9c:9a:7c:af:f1:43:06:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfd580574197751ef63921b59c9a7caff14306c5/; sid:902201757; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d4:96:42:2a:79:34:df:51:3c:16:83:84:4c:8a:68:69:e6:46:2f:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d496422a7934df513c1683844c8a6869e6462f6f/; sid:902201758; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"10:71:d0:60:d0:c1:25:7a:33:fb:fd:9b:83:de:c0:ab:30:43:6e:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1071d060d0c1257a33fbfd9b83dec0ab30436e04/; sid:902201759; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vawtrak C&C)"; tls.fingerprint:"d4:f3:ef:1b:ef:3d:14:0a:d9:1e:83:c1:8a:af:28:ad:3a:c8:79:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4f3ef1bef3d140ad91e83c18aaf28ad3ac87980/; sid:902201760; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"62:bd:b4:04:03:8f:4d:32:a7:51:99:d7:ac:01:d0:91:bb:e4:46:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62bdb404038f4d32a75199d7ac01d091bbe446e2/; sid:902201761; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9c:31:42:02:20:91:7a:09:fa:3f:26:ce:82:6c:83:da:3d:c3:d4:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c31420220917a09fa3f26ce826c83da3dc3d409/; sid:902201762; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c5:03:6f:5e:25:b1:9c:8d:37:6e:17:52:83:50:0b:bc:e4:a4:d1:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5036f5e25b19c8d376e175283500bbce4a4d19a/; sid:902201763; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a8:2d:d2:58:54:4a:cf:0a:10:92:96:49:34:21:26:23:97:74:1d:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a82dd258544acf0a109296493421262397741db7/; sid:902201764; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1d:05:c6:fe:f1:4d:26:71:d7:59:a0:5b:49:64:64:b8:31:c6:50:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d05c6fef14d2671d759a05b496464b831c650e8/; sid:902201765; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"7b:72:31:6f:e4:a9:06:9c:8b:4f:97:3d:bb:28:68:f1:b9:e9:fa:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b72316fe4a9069c8b4f973dbb2868f1b9e9fa63/; sid:902201766; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:d5:0b:e8:83:1f:4a:2a:e9:31:dd:31:56:a8:cd:8e:12:17:bd:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38d50be8831f4a2ae931dd3156a8cd8e1217bd53/; sid:902201767; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3d:b0:61:1a:bf:b1:9d:1b:fe:5e:28:35:ba:d8:85:4a:50:e9:28:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3db0611abfb19d1bfe5e2835bad8854a50e928b0/; sid:902201768; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"eb:98:f0:0e:43:e7:a1:32:e5:3f:5a:2d:03:20:8d:47:58:e4:0b:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb98f00e43e7a132e53f5a2d03208d4758e40b56/; sid:902201769; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"52:70:99:bd:97:e1:c8:e8:77:09:13:78:06:6e:91:8b:15:63:ef:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/527099bd97e1c8e877091378066e918b1563ef8d/; sid:902201770; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:0f:88:7a:4a:f0:19:4e:b5:81:d5:60:80:a3:ba:bf:bc:1d:12:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/450f887a4af0194eb581d56080a3babfbc1d12b4/; sid:902201771; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"81:c6:eb:5c:91:7e:43:01:cc:81:84:0c:74:93:8e:92:07:bc:ce:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81c6eb5c917e4301cc81840c74938e9207bccee6/; sid:902201772; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:0e:4f:80:38:bf:48:3a:f1:74:9e:7e:bc:5a:21:7a:4b:bd:43:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d0e4f8038bf483af1749e7ebc5a217a4bbd43e0/; sid:902201773; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2d:2b:f3:24:d7:f3:52:d9:e6:d4:9b:b0:d9:6e:05:19:6d:f7:93:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d2bf324d7f352d9e6d49bb0d96e05196df793cc/; sid:902201774; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"ec:21:cd:3a:9b:2d:4a:0a:5d:c6:d1:8c:71:4b:f4:ea:b9:22:13:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec21cd3a9b2d4a0a5dc6d18c714bf4eab92213d2/; sid:902201775; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"21:a1:c4:b9:7d:84:ec:d3:eb:69:50:c1:b9:f0:31:35:71:9e:5d:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21a1c4b97d84ecd3eb6950c1b9f03135719e5dc0/; sid:902201776; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"57:60:00:86:f4:46:f8:93:b9:98:52:b7:e1:95:2c:f8:97:9f:fd:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57600086f446f893b99852b7e1952cf8979ffd4b/; sid:902201777; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"79:6a:99:bc:9f:7d:b3:1a:cd:d4:8b:5a:76:1f:70:b3:b2:17:0b:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/796a99bc9f7db31acdd48b5a761f70b3b2170bf9/; sid:902201778; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"db:24:81:4f:76:47:f9:15:71:9b:06:c4:bc:d7:d9:63:82:2f:d5:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db24814f7647f915719b06c4bcd7d963822fd507/; sid:902201779; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"89:f7:0f:43:f5:d8:1a:48:f4:8a:cd:5c:de:c9:d3:7f:d8:a0:4b:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89f70f43f5d81a48f48acd5cdec9d37fd8a04bba/; sid:902201780; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"cf:7a:4a:22:21:b0:3e:c1:e6:04:96:22:3b:8c:85:ce:32:ab:ed:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf7a4a2221b03ec1e60496223b8c85ce32abede6/; sid:902201781; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b4:a9:29:48:18:89:8d:84:95:aa:53:9f:07:9d:7a:78:80:01:07:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4a9294818898d8495aa539f079d7a78800107fa/; sid:902201782; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"df:f9:91:d6:d9:b0:c9:47:27:2b:b3:d7:80:0b:41:77:be:49:2f:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dff991d6d9b0c947272bb3d7800b4177be492f91/; sid:902201783; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"43:85:58:04:f0:a4:2b:76:ed:90:57:b8:20:92:80:f7:56:f5:36:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43855804f0a42b76ed9057b8209280f756f536ee/; sid:902201784; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a9:7b:76:16:d3:cf:e7:fe:c8:4f:27:0d:15:cd:d1:49:d3:0e:cd:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a97b7616d3cfe7fec84f270d15cdd149d30ecdc6/; sid:902201785; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6f:4b:b2:5c:c3:6d:1c:bd:f5:35:d0:6f:4b:3e:d4:e4:5b:ab:bd:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f4bb25cc36d1cbdf535d06f4b3ed4e45babbdd4/; sid:902201786; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7a:03:a2:d9:f0:cf:40:5c:d3:ec:2b:1a:10:e2:6a:a1:b6:36:57:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a03a2d9f0cf405cd3ec2b1a10e26aa1b63657b1/; sid:902201787; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"45:35:bf:9a:e7:e7:86:d7:7e:e4:82:d7:4b:9a:22:cb:e0:99:be:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4535bf9ae7e786d77ee482d74b9a22cbe099be2e/; sid:902201788; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrrentLocker C&C)"; tls.fingerprint:"1b:43:bb:82:f2:fe:80:e5:ce:f4:de:6e:4b:31:7f:ff:51:ba:83:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b43bb82f2fe80e5cef4de6e4b317fff51ba83b7/; sid:902201789; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b3:8a:86:55:ec:b5:69:de:29:43:4a:e8:c7:b1:87:c9:3b:84:b6:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b38a8655ecb569de29434ae8c7b187c93b84b606/; sid:902201790; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9e:93:5b:1f:30:af:15:da:28:0d:e0:99:ec:72:58:97:8b:69:c7:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e935b1f30af15da280de099ec7258978b69c756/; sid:902201791; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d9:23:2a:ef:f9:e8:23:a4:d8:c3:dc:77:67:4a:6b:dd:88:ed:6e:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9232aeff9e823a4d8c3dc77674a6bdd88ed6e9b/; sid:902201792; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"74:8e:31:8f:08:23:28:d0:5e:1a:e6:8b:88:e5:13:9f:fa:73:4b:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/748e318f082328d05e1ae68b88e5139ffa734b5a/; sid:902201793; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"db:f0:33:7b:21:43:6f:b6:2e:6e:79:e8:88:bd:d9:0f:26:68:b3:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbf0337b21436fb62e6e79e888bdd90f2668b31f/; sid:902201794; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d8:eb:24:f9:08:48:87:2f:db:ec:a3:9d:b3:4b:e1:00:4f:1b:03:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8eb24f90848872fdbeca39db34be1004f1b030d/; sid:902201795; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"2b:00:84:c8:89:c0:17:a7:07:4a:09:b5:bb:6e:58:e4:d7:50:dd:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b0084c889c017a7074a09b5bb6e58e4d750dde7/; sid:902201796; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"66:9f:16:d4:38:46:94:2f:01:1f:d1:52:56:2f:db:1f:62:f3:ff:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/669f16d43846942f011fd152562fdb1f62f3ffb8/; sid:902201797; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"1b:1e:ed:d1:9f:9f:11:33:7e:ba:e2:8a:03:c4:a9:d6:60:ee:b3:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b1eedd19f9f11337ebae28a03c4a9d660eeb3a8/; sid:902201798; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"9b:a5:9e:04:a7:c8:be:3d:94:02:5d:53:19:16:0d:9c:f0:16:a8:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ba59e04a7c8be3d94025d5319160d9cf016a843/; sid:902201799; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4e:1c:98:bd:26:40:f3:ac:8e:1c:9a:b2:0c:b8:35:bd:33:b7:9d:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e1c98bd2640f3ac8e1c9ab20cb835bd33b79da1/; sid:902201800; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7e:17:89:fa:7e:4d:34:69:80:c1:15:7e:ea:cc:0d:49:2d:d5:be:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e1789fa7e4d346980c1157eeacc0d492dd5bea4/; sid:902201801; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"cd:48:bd:25:00:3a:23:33:87:c6:a3:99:1d:94:74:da:d3:64:ca:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd48bd25003a233387c6a3991d9474dad364ca9a/; sid:902201802; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"1f:20:93:d3:3c:6a:aa:0f:1e:93:65:99:1f:37:cc:27:62:3e:2c:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f2093d33c6aaa0f1e9365991f37cc27623e2cf7/; sid:902201803; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3b:a9:d8:29:ac:97:f9:29:db:1a:55:90:d0:1f:29:03:06:7e:0b:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ba9d829ac97f929db1a5590d01f2903067e0bb5/; sid:902201804; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1d:1b:4f:67:f0:70:df:5c:ae:8f:39:55:39:78:f0:ad:b3:ab:d0:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d1b4f67f070df5cae8f39553978f0adb3abd0c0/; sid:902201805; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"bc:2a:55:d2:bc:b8:c1:f7:ae:75:58:01:d8:b0:70:90:34:14:4e:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc2a55d2bcb8c1f7ae755801d8b0709034144ece/; sid:902201806; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6c:e3:74:01:40:12:8c:f5:50:0b:56:e1:b5:02:0b:c2:2d:e6:47:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ce3740140128cf5500b56e1b5020bc22de647a1/; sid:902201807; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"7c:03:62:46:3c:c2:bb:dd:16:b9:d2:e2:46:f0:e4:48:9b:1f:c3:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c0362463cc2bbdd16b9d2e246f0e4489b1fc3b7/; sid:902201808; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:a5:8a:8a:db:fc:e0:80:7e:8e:1e:be:8f:54:31:97:98:ec:17:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5da58a8adbfce0807e8e1ebe8f54319798ec174e/; sid:902201809; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"34:6e:1b:a0:00:e1:a9:1f:b5:a1:db:b9:7f:fe:aa:1d:de:41:2c:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/346e1ba000e1a91fb5a1dbb97ffeaa1dde412c5f/; sid:902201810; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"aa:1e:69:d1:3f:c1:90:b5:91:7e:f6:9f:a1:ab:f3:86:3f:21:15:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa1e69d13fc190b5917ef69fa1abf3863f2115aa/; sid:902201811; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"46:bd:7b:b0:ee:db:1b:0e:05:52:30:ee:b7:6e:d1:df:db:41:da:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46bd7bb0eedb1b0e055230eeb76ed1dfdb41dafc/; sid:902201812; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"cc:09:f3:54:23:a1:c1:08:c9:92:85:4f:ab:1f:b7:7f:44:75:57:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc09f35423a1c108c992854fab1fb77f44755782/; sid:902201813; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"21:26:96:55:07:eb:de:32:5e:1b:c4:2c:a1:4d:3d:1f:68:1b:96:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2126965507ebde325e1bc42ca14d3d1f681b96eb/; sid:902201814; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ba:6c:97:97:22:1f:84:1e:9f:48:8b:cc:2e:d0:80:59:39:70:91:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba6c9797221f841e9f488bcc2ed08059397091bf/; sid:902201815; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"66:e8:7d:1e:55:9f:4c:28:c4:5c:ef:85:2f:74:d1:37:21:2a:0e:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66e87d1e559f4c28c45cef852f74d137212a0e6f/; sid:902201816; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"b0:93:d2:ee:30:4e:e3:f3:aa:7b:3e:ac:7a:84:8f:ce:0e:4b:90:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b093d2ee304ee3f3aa7b3eac7a848fce0e4b9095/; sid:902201817; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"93:5c:76:42:6a:91:f4:bc:38:a0:f8:76:b5:3b:0b:c2:7a:57:ba:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/935c76426a91f4bc38a0f876b53b0bc27a57ba83/; sid:902201818; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"ab:f5:ce:4f:1c:12:52:57:60:01:59:68:18:25:15:2a:8a:e8:7e:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abf5ce4f1c125257600159681825152a8ae87e1b/; sid:902201819; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"88:87:30:fb:84:c1:1d:d0:ae:ff:49:99:10:4b:47:79:a8:f6:de:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/888730fb84c11dd0aeff4999104b4779a8f6deb0/; sid:902201820; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"41:a1:80:cf:b9:e2:ec:1b:70:9d:2f:e8:c6:2d:cf:5a:7e:8c:91:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41a180cfb9e2ec1b709d2fe8c62dcf5a7e8c911e/; sid:902201821; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"51:22:63:41:62:40:f6:64:f5:b6:c8:e7:65:49:8c:0f:fd:45:72:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/512263416240f664f5b6c8e765498c0ffd45729e/; sid:902201822; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"53:ba:46:ad:70:66:2e:1d:3e:eb:ce:45:4c:d4:06:25:12:f7:17:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53ba46ad70662e1d3eebce454cd4062512f717c8/; sid:902201823; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1f:ca:c1:c0:39:dd:9d:d5:8a:4b:93:3c:aa:03:4a:7a:91:39:17:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fcac1c039dd9dd58a4b933caa034a7a91391700/; sid:902201824; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ff:10:a4:06:af:a6:97:ce:b6:0c:a2:ac:74:3e:bb:92:8d:5e:dd:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff10a406afa697ceb60ca2ac743ebb928d5eddf7/; sid:902201825; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a9:f9:2a:27:81:22:c9:2d:17:ae:ed:fc:e5:2c:7f:57:d4:cc:95:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9f92a278122c92d17aeedfce52c7f57d4cc95b7/; sid:902201826; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a7:6d:bf:aa:e1:46:43:7a:13:66:b5:a3:2d:59:95:94:8e:63:00:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a76dbfaae146437a1366b5a32d5995948e6300d1/; sid:902201827; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"be:69:17:86:56:4d:72:46:b3:ba:95:63:e8:e9:62:06:41:c3:63:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be691786564d7246b3ba9563e8e9620641c363c4/; sid:902201828; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"73:2b:c4:31:d9:d4:22:40:1c:18:53:70:f4:81:cc:2c:eb:9d:83:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/732bc431d9d422401c185370f481cc2ceb9d8326/; sid:902201829; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"62:db:4d:ed:d0:8c:62:9e:af:d8:dd:93:bf:4b:37:7a:61:f4:6c:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62db4dedd08c629eafd8dd93bf4b377a61f46c8e/; sid:902201830; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"43:9b:32:93:4a:b5:96:dd:ce:f4:7a:b1:3b:bc:d5:1a:1b:26:98:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/439b32934ab596ddcef47ab13bbcd51a1b269896/; sid:902201831; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e6:d8:37:21:4a:81:81:76:71:1a:61:64:6b:db:39:aa:02:32:86:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6d837214a818176711a61646bdb39aa02328644/; sid:902201832; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5a:4e:01:e0:ce:a5:83:94:c6:4b:ce:65:a7:e3:ef:28:53:14:65:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a4e01e0cea58394c64bce65a7e3ef28531465d1/; sid:902201833; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"df:a5:4f:6e:30:78:09:8e:4c:d6:e3:20:30:37:98:f2:7a:64:00:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfa54f6e3078098e4cd6e320303798f27a640096/; sid:902201834; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"37:4c:24:ce:ee:92:08:a1:88:1b:73:36:7a:d2:41:46:ec:8c:23:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/374c24ceee9208a1881b73367ad24146ec8c23bb/; sid:902201835; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"02:32:2f:13:4d:1c:4d:43:e7:f9:05:cc:bb:25:43:1b:a9:7e:0c:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02322f134d1c4d43e7f905ccbb25431ba97e0cb8/; sid:902201836; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"85:1a:e0:21:34:4b:31:ea:a0:81:50:b7:fa:a1:5a:57:fc:b1:55:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/851ae021344b31eaa08150b7faa15a57fcb155c3/; sid:902201837; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"34:76:6e:3b:5a:53:ea:03:9d:0d:7b:f6:44:69:45:14:03:4c:26:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34766e3b5a53ea039d0d7bf644694514034c26aa/; sid:902201838; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a1:e6:cc:33:a4:a9:57:f2:f2:21:02:98:38:88:60:16:4d:c0:84:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1e6cc33a4a957f2f2210298388860164dc08404/; sid:902201839; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"af:01:a8:59:ba:00:dc:ed:9e:a6:1a:e5:37:bf:b4:cb:5d:3d:eb:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af01a859ba00dced9ea61ae537bfb4cb5d3deb0a/; sid:902201840; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d9:59:2d:62:46:c3:2f:60:09:68:91:f0:66:65:3c:87:d6:14:19:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9592d6246c32f60096891f066653c87d614199c/; sid:902201841; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1e:91:be:5b:b2:22:34:bd:19:ce:a3:d2:ec:8b:7f:f1:c1:9c:be:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e91be5bb22234bd19cea3d2ec8b7ff1c19cbe37/; sid:902201842; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"00:09:a6:6e:ab:25:c8:1f:94:0e:1c:83:24:d8:48:28:6d:91:e0:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0009a66eab25c81f940e1c8324d848286d91e015/; sid:902201843; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"10:1b:0f:5b:4f:4e:33:6a:2e:9c:c8:2b:8e:00:d3:97:f4:93:9e:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/101b0f5b4f4e336a2e9cc82b8e00d397f4939e6b/; sid:902201844; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ff:ff:89:55:e7:62:ca:a2:7b:97:a2:2e:2c:6f:e6:d0:53:a8:f1:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ffff8955e762caa27b97a22e2c6fe6d053a8f19a/; sid:902201845; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"41:32:66:2a:da:64:a2:9d:65:00:55:78:c9:de:1c:6e:05:d6:23:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4132662ada64a29d65005578c9de1c6e05d62378/; sid:902201846; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d2:a5:1b:61:a3:22:77:df:a6:1d:49:4d:c2:06:54:67:5f:ee:f4:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2a51b61a32277dfa61d494dc20654675feef47f/; sid:902201847; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"20:7a:20:9e:4b:7a:56:51:40:5a:f7:80:ed:c2:40:6e:b0:bf:b6:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/207a209e4b7a5651405af780edc2406eb0bfb658/; sid:902201848; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4c:27:cd:56:4b:05:48:61:19:e4:7e:c2:99:f4:76:c0:f9:f0:db:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c27cd564b05486119e47ec299f476c0f9f0dbfd/; sid:902201849; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"47:77:bf:5f:0d:e5:7f:cf:a0:b0:e1:8a:72:8a:86:95:7b:99:86:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4777bf5f0de57fcfa0b0e18a728a86957b99863c/; sid:902201850; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"75:84:b6:d8:52:87:12:da:45:bd:cf:94:e1:60:fc:d8:94:a5:9b:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7584b6d8528712da45bdcf94e160fcd894a59b7b/; sid:902201851; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"11:e6:83:57:b3:e0:88:a3:70:8f:1b:64:cf:8d:a3:01:74:88:b3:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11e68357b3e088a3708f1b64cf8da3017488b379/; sid:902201852; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"cd:25:6e:fa:c6:80:9f:14:bb:84:c3:90:a8:98:19:c0:82:2c:24:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd256efac6809f14bb84c390a89819c0822c24a2/; sid:902201853; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"53:ea:66:43:ef:eb:0f:3f:88:ac:de:34:59:d9:5d:95:15:d8:d6:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53ea6643efeb0f3f88acde3459d95d9515d8d6f8/; sid:902201854; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ca:17:e7:0b:72:90:44:5d:04:9d:9f:53:89:76:e4:fa:d8:f8:72:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca17e70b7290445d049d9f538976e4fad8f872a0/; sid:902201855; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"5d:23:1b:d1:88:44:18:09:ea:b3:4d:25:e0:90:4f:0c:31:e8:24:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d231bd188441809eab34d25e0904f0c31e82452/; sid:902201856; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"ed:76:6b:75:7f:be:f9:bf:96:5d:f3:eb:98:12:3e:bf:a1:7e:ee:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed766b757fbef9bf965df3eb98123ebfa17eee87/; sid:902201857; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"db:41:09:56:af:c9:7c:c5:3d:e0:70:27:8c:24:43:93:80:b4:59:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db410956afc97cc53de070278c24439380b4596f/; sid:902201858; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"de:d2:72:f3:06:f9:a8:14:7d:00:b7:b5:d3:75:44:f6:3f:70:bb:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ded272f306f9a8147d00b7b5d37544f63f70bb35/; sid:902201859; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"fa:58:74:13:07:70:57:99:bc:d1:e9:3b:09:85:80:ac:fe:91:44:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa58741307705799bcd1e93b098580acfe9144dc/; sid:902201860; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"31:71:0a:be:62:15:f9:93:8e:43:eb:9a:43:52:29:9d:f0:06:a5:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31710abe6215f9938e43eb9a4352299df006a59d/; sid:902201861; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"df:af:2a:46:c7:26:8b:57:5c:b1:72:84:e1:28:aa:02:79:52:76:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfaf2a46c7268b575cb17284e128aa02795276e5/; sid:902201862; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"34:65:fc:30:7c:14:39:a0:1c:f6:56:2b:7d:0f:4c:25:ae:e4:9e:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3465fc307c1439a01cf6562b7d0f4c25aee49eb5/; sid:902201863; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"00:b0:19:58:89:06:8d:b8:4f:76:33:92:dc:18:06:f9:20:ad:03:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00b0195889068db84f763392dc1806f920ad030e/; sid:902201864; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"9c:ab:35:a0:e7:19:70:6d:ad:7f:7f:c2:85:c9:31:f1:79:8c:21:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cab35a0e719706dad7f7fc285c931f1798c212d/; sid:902201865; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"cf:bb:86:65:d5:2d:17:bf:98:17:67:10:7e:43:90:5e:bd:e5:d7:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfbb8665d52d17bf981767107e43905ebde5d785/; sid:902201866; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"28:16:27:8e:8b:be:cf:9d:a5:d2:f4:87:7b:67:49:d4:3b:19:6c:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2816278e8bbecf9da5d2f4877b6749d43b196c95/; sid:902201867; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"87:1b:fc:42:26:10:b9:48:61:c1:7b:01:ba:14:b1:1e:67:20:ae:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/871bfc422610b94861c17b01ba14b11e6720aed9/; sid:902201868; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ca:7e:77:93:8c:b8:ca:7c:09:fa:52:41:37:d5:04:2d:6f:83:e2:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca7e77938cb8ca7c09fa524137d5042d6f83e21a/; sid:902201869; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"07:61:63:e0:fd:77:49:3e:b9:bd:25:22:60:c6:29:b5:35:80:68:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/076163e0fd77493eb9bd252260c629b5358068ec/; sid:902201870; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Nexuslogger C&C)"; tls.fingerprint:"25:95:00:49:3b:3d:96:26:86:64:4a:9a:05:29:b1:c1:a0:60:cb:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/259500493b3d962686644a9a0529b1c1a060cbcc/; sid:902201871; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"56:2e:7f:2f:7b:3d:59:13:a6:ca:64:f2:58:54:d1:31:e5:6c:4f:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/562e7f2f7b3d5913a6ca64f25854d131e56c4ff7/; sid:902201872; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"72:a5:63:44:4b:6c:f3:3f:b6:e0:22:a0:1b:87:66:56:e1:ed:ee:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72a563444b6cf33fb6e022a01b876656e1edee40/; sid:902201873; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"00:45:eb:6e:50:c1:cc:da:72:f9:4b:56:2e:e1:7b:e7:5c:c2:06:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0045eb6e50c1ccda72f94b562ee17be75cc20673/; sid:902201874; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"42:90:40:19:16:56:3b:1a:e8:f3:9f:08:ee:ae:09:1b:ea:58:e2:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4290401916563b1ae8f39f08eeae091bea58e22b/; sid:902201875; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"1c:47:e7:5c:24:31:e7:2d:54:44:f1:1f:c9:37:84:e7:57:e1:5e:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c47e75c2431e72d5444f11fc93784e757e15e96/; sid:902201876; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"e2:70:46:6a:42:c2:e8:8a:72:c4:ba:41:3b:57:56:8e:f3:b8:eb:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e270466a42c2e88a72c4ba413b57568ef3b8eb92/; sid:902201877; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"51:f8:1c:38:66:68:5c:c2:fd:3d:82:c4:6d:7e:9d:0a:80:59:f0:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51f81c3866685cc2fd3d82c46d7e9d0a8059f06e/; sid:902201878; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ca:31:e1:cf:30:44:1b:a1:22:73:44:51:f7:44:c9:67:15:1e:52:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca31e1cf30441ba122734451f744c967151e523b/; sid:902201879; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a2:e2:d3:0e:55:e3:44:30:68:e6:eb:cf:80:70:71:76:68:64:53:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2e2d30e55e3443068e6ebcf807071766864530c/; sid:902201880; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d6:40:42:0a:23:80:27:0f:2b:84:5f:e2:4a:a5:a7:cf:f6:e2:35:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d640420a2380270f2b845fe24aa5a7cff6e235ad/; sid:902201881; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"12:ef:34:a0:47:2d:1d:50:22:8b:dc:bd:10:89:c7:28:f6:80:0d:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12ef34a0472d1d50228bdcbd1089c728f6800d9e/; sid:902201882; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"01:ad:b6:51:7f:e8:bf:0a:e1:6f:15:f8:1a:f2:43:7d:ed:2c:e3:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01adb6517fe8bf0ae16f15f81af2437ded2ce344/; sid:902201883; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f0:af:95:05:c7:af:2b:bf:df:1d:12:ae:fb:b7:a7:93:22:05:71:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0af9505c7af2bbfdf1d12aefbb7a7932205715f/; sid:902201884; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6f:df:54:29:fa:84:c5:58:5d:ed:4f:d9:a1:7f:d3:7e:95:71:1b:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fdf5429fa84c5585ded4fd9a17fd37e95711b4b/; sid:902201885; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"25:d0:ed:69:8d:99:4e:a8:d9:b9:11:0e:30:0c:1e:1f:92:59:be:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25d0ed698d994ea8d9b9110e300c1e1f9259be12/; sid:902201886; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"bc:6a:c5:d0:0e:99:18:d6:df:8a:74:e8:04:26:e0:fc:c6:73:28:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc6ac5d00e9918d6df8a74e80426e0fcc67328c6/; sid:902201887; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"cc:2a:6d:c9:ac:f4:3d:86:a2:1e:8b:f4:1f:f8:95:27:8b:e3:ae:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc2a6dc9acf43d86a21e8bf41ff895278be3aedc/; sid:902201888; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"78:35:91:ef:d6:23:cf:4d:c9:83:8d:30:8b:f5:31:79:12:75:6e:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/783591efd623cf4dc9838d308bf5317912756e72/; sid:902201889; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0c:1f:dd:7c:00:86:b6:35:0a:39:68:51:62:62:a1:a9:59:a2:ec:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c1fdd7c0086b6350a3968516262a1a959a2ec54/; sid:902201890; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0f:6f:1a:ba:7e:fd:8c:2a:4a:aa:42:97:af:4c:06:1f:d1:c0:d5:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f6f1aba7efd8c2a4aaa4297af4c061fd1c0d5fd/; sid:902201891; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"17:e9:58:d3:00:3b:c9:07:32:46:bd:49:86:6c:35:58:70:a6:08:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17e958d3003bc9073246bd49866c355870a60830/; sid:902201892; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"86:71:4f:5c:1b:87:67:8d:50:20:f8:de:86:9c:d9:16:d2:89:e3:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86714f5c1b87678d5020f8de869cd916d289e342/; sid:902201893; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"95:c5:f2:03:35:4b:2d:79:fc:26:ff:27:ad:4b:e3:0a:8d:77:e3:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95c5f203354b2d79fc26ff27ad4be30a8d77e3b0/; sid:902201894; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b8:8e:f6:bc:d4:65:35:e4:58:18:90:c6:54:4c:ed:2a:54:e8:c9:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b88ef6bcd46535e4581890c6544ced2a54e8c954/; sid:902201895; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"92:aa:18:f0:49:98:20:1d:53:cc:a6:a4:b1:ee:19:06:8e:95:6b:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92aa18f04998201d53cca6a4b1ee19068e956ba2/; sid:902201896; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"66:05:0b:13:89:f3:e0:22:99:40:a5:c4:9a:51:0f:83:5a:63:6c:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66050b1389f3e0229940a5c49a510f835a636cf0/; sid:902201897; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"96:71:57:9d:3f:10:5a:86:85:de:1a:e4:93:42:66:a6:95:b7:62:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9671579d3f105a8685de1ae4934266a695b7628f/; sid:902201898; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b1:bc:81:f0:ac:31:58:27:e3:a2:60:d1:8b:d1:51:f4:48:da:f7:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1bc81f0ac315827e3a260d18bd151f448daf710/; sid:902201899; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"be:f3:d6:8f:b9:62:f1:b6:68:e5:3a:d7:fa:c6:28:2e:2e:b0:60:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bef3d68fb962f1b668e53ad7fac6282e2eb0601c/; sid:902201900; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d3:fe:24:a0:f7:6a:0d:21:e7:a3:e4:19:28:ca:b7:be:18:57:5e:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3fe24a0f76a0d21e7a3e41928cab7be18575e53/; sid:902201901; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"09:9f:ad:79:46:60:b5:cc:f6:bf:89:78:2e:0c:b5:43:34:25:47:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/099fad794660b5ccf6bf89782e0cb543342547f1/; sid:902201902; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"45:34:bd:e6:bc:86:c0:a8:68:ec:74:56:6c:4c:be:16:e7:58:16:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4534bde6bc86c0a868ec74566c4cbe16e7581670/; sid:902201903; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6d:9a:2a:0e:9a:93:e2:8f:61:6d:f8:a5:8e:8c:6f:28:04:ce:89:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d9a2a0e9a93e28f616df8a58e8c6f2804ce8917/; sid:902201904; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"02:49:b9:53:aa:54:4b:b6:66:21:39:3f:23:c6:bc:33:b1:8c:fc:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0249b953aa544bb66621393f23c6bc33b18cfc1a/; sid:902201905; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f4:b1:7c:b0:f1:6e:e8:7d:af:9d:0f:f5:d8:1f:c7:b8:f0:ec:6c:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4b17cb0f16ee87daf9d0ff5d81fc7b8f0ec6cc2/; sid:902201906; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f6:53:9a:f4:03:9b:ea:25:bf:d1:b3:f6:78:47:fe:c8:e8:5a:3e:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6539af4039bea25bfd1b3f67847fec8e85a3e29/; sid:902201907; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:b0:4b:6f:8a:49:40:39:5b:36:70:ed:69:56:bf:3d:35:b5:8a:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2b04b6f8a4940395b3670ed6956bf3d35b58a11/; sid:902201908; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a1:49:71:d2:d9:bc:0c:b5:4e:11:4d:3c:34:e6:fe:34:88:73:61:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a14971d2d9bc0cb54e114d3c34e6fe348873613a/; sid:902201909; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4f:49:88:b7:db:26:30:64:1b:56:27:90:b0:fb:c9:69:3f:4c:f7:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f4988b7db2630641b562790b0fbc9693f4cf7ae/; sid:902201910; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"62:30:08:22:fe:df:08:22:23:71:5f:41:02:ea:40:ff:90:11:d5:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62300822fedf082223715f4102ea40ff9011d52a/; sid:902201911; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6b:1e:e9:ad:97:72:9a:d1:38:58:fa:ae:63:78:ae:63:55:4d:a7:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b1ee9ad97729ad13858faae6378ae63554da7ff/; sid:902201912; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"57:b7:84:9a:53:f7:2b:06:da:11:bf:ac:40:87:9b:07:83:aa:4f:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57b7849a53f72b06da11bfac40879b0783aa4ff5/; sid:902201913; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ed:f8:ab:0a:1c:4c:29:de:e0:95:81:fc:87:85:38:72:78:22:73:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edf8ab0a1c4c29dee09581fc8785387278227377/; sid:902201914; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"11:c0:28:08:a8:5d:24:5a:e7:9c:15:0f:57:e6:aa:8b:cf:43:a3:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11c02808a85d245ae79c150f57e6aa8bcf43a328/; sid:902201915; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"03:5d:18:7b:fe:97:58:1d:22:9f:eb:da:2a:8a:1c:b2:92:ed:64:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/035d187bfe97581d229febda2a8a1cb292ed64da/; sid:902201916; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"af:49:0a:39:38:ed:f5:30:c7:70:aa:a9:46:8c:6c:59:a1:b5:0c:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af490a3938edf530c770aaa9468c6c59a1b50cc1/; sid:902201917; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"84:94:f0:c0:94:c2:4a:1f:d2:c1:12:26:89:60:19:b0:97:fe:bc:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8494f0c094c24a1fd2c11226896019b097febccf/; sid:902201918; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"12:dd:4c:2c:c3:23:7e:d0:04:09:82:77:b0:0d:43:32:c7:cc:07:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12dd4c2cc3237ed004098277b00d4332c7cc07f3/; sid:902201919; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"14:4b:04:7f:c5:2f:3d:2e:66:28:33:8e:54:82:cd:e2:9a:1c:eb:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/144b047fc52f3d2e6628338e5482cde29a1ceb3d/; sid:902201920; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"48:fd:38:08:98:71:b8:7f:2e:6b:1c:4a:57:93:ce:67:ec:5e:81:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48fd38089871b87f2e6b1c4a5793ce67ec5e818e/; sid:902201921; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1c:68:db:74:33:35:41:7a:e9:84:65:5b:32:6d:8b:a3:bb:1e:7b:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c68db743335417ae984655b326d8ba3bb1e7b16/; sid:902201922; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6e:ae:fc:28:4c:6c:bd:c8:0d:92:a0:30:5b:ea:ec:a7:26:dd:93:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6eaefc284c6cbdc80d92a0305beaeca726dd9377/; sid:902201923; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"17:87:4b:a0:64:a5:a5:a8:4d:90:93:e3:21:cd:0a:cb:da:2f:af:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17874ba064a5a5a84d9093e321cd0acbda2faf7c/; sid:902201924; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4a:07:04:97:08:1d:fa:f8:9f:32:4f:48:96:a9:1e:db:9c:42:5c:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a070497081dfaf89f324f4896a91edb9c425c0c/; sid:902201925; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b4:a8:b5:5e:d5:00:a0:8f:3c:83:c2:f4:70:8a:ea:66:a5:d5:21:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4a8b55ed500a08f3c83c2f4708aea66a5d521dc/; sid:902201926; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:77:0c:be:6b:23:2f:7e:28:1c:48:05:a5:76:00:fe:d3:c9:ea:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1770cbe6b232f7e281c4805a57600fed3c9ea02/; sid:902201927; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:98:bd:ab:a9:51:57:b5:c5:76:6f:20:ac:2d:c0:d9:6b:91:4a:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4598bdaba95157b5c5766f20ac2dc0d96b914a56/; sid:902201928; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4f:a9:9c:8b:c1:7b:90:c2:e3:61:20:c3:4f:12:ed:a4:74:77:d7:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4fa99c8bc17b90c2e36120c34f12eda47477d7ff/; sid:902201929; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"07:60:b7:06:96:97:6b:36:ee:cc:0a:67:1b:7f:f7:10:b8:19:fe:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0760b70696976b36eecc0a671b7ff710b819fea7/; sid:902201930; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"00:9f:d7:0b:9f:42:a2:b3:70:c8:5a:60:a7:7b:2f:cd:7a:7c:0b:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/009fd70b9f42a2b370c85a60a77b2fcd7a7c0ba7/; sid:902201931; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"db:59:b9:5d:87:49:a7:79:b9:0e:e7:d3:b9:3c:d7:b4:b1:66:6b:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db59b95d8749a779b90ee7d3b93cd7b4b1666bfe/; sid:902201932; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ba:7c:40:be:7d:c0:68:2a:66:8d:16:31:58:5e:f2:88:a6:24:7d:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba7c40be7dc0682a668d1631585ef288a6247d4e/; sid:902201933; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a6:cb:f1:d8:6d:bc:3c:09:48:3c:fd:3d:28:34:00:8b:05:a0:3f:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6cbf1d86dbc3c09483cfd3d2834008b05a03fd9/; sid:902201934; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"50:ea:19:98:63:00:e1:f3:13:d7:81:12:8f:6f:dd:8b:8f:ef:57:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50ea19986300e1f313d781128f6fdd8b8fef57c8/; sid:902201935; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ad:72:3f:df:00:4b:0c:35:f3:cc:37:a8:b0:5b:ee:79:c1:24:ab:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad723fdf004b0c35f3cc37a8b05bee79c124ab54/; sid:902201936; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a3:02:02:f4:2c:88:49:7e:50:8e:87:f6:9d:18:da:e1:56:c6:9b:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a30202f42c88497e508e87f69d18dae156c69b27/; sid:902201937; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"95:37:5f:69:c1:da:e0:bd:3b:35:a1:91:ac:67:d1:c5:8f:f3:9a:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95375f69c1dae0bd3b35a191ac67d1c58ff39ac6/; sid:902201938; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"17:e4:cc:52:40:26:2f:73:f6:c1:ae:27:21:72:4e:d0:f5:47:a5:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17e4cc5240262f73f6c1ae2721724ed0f547a59c/; sid:902201939; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"62:c3:0b:50:ec:e6:ce:29:03:1d:5b:1f:38:66:b1:5f:bd:65:6a:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62c30b50ece6ce29031d5b1f3866b15fbd656a6b/; sid:902201940; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"22:da:4d:7c:a0:81:b1:10:b6:c2:a1:83:a3:20:59:67:33:7e:9e:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22da4d7ca081b110b6c2a183a3205967337e9e86/; sid:902201941; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"19:a4:d2:66:64:45:94:c1:a7:d5:f2:5e:79:49:02:fb:05:29:27:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19a4d266644594c1a7d5f25e794902fb05292723/; sid:902201942; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b5:37:02:cc:09:cf:8a:18:62:18:33:37:95:7f:87:15:c3:8c:b7:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b53702cc09cf8a1862183337957f8715c38cb733/; sid:902201943; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ce:83:65:cf:f9:9b:43:09:66:6a:66:1a:f5:95:50:be:8c:a0:7f:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce8365cff99b4309666a661af59550be8ca07f8a/; sid:902201944; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"1b:82:37:30:66:3d:26:e7:23:ff:e3:08:c1:9e:7c:68:70:2a:57:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b823730663d26e723ffe308c19e7c68702a5724/; sid:902201945; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"37:f2:11:b8:02:4c:72:06:e4:01:50:dc:a9:38:f5:c8:38:a6:29:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37f211b8024c7206e40150dca938f5c838a629a3/; sid:902201946; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0c:84:12:99:8e:79:a3:3f:88:1f:85:cc:a8:3c:6b:37:51:1f:cc:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c8412998e79a33f881f85cca83c6b37511fcc23/; sid:902201947; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"be:eb:2a:73:ea:8a:82:94:57:e8:8e:ce:92:e5:6a:b6:ba:e2:51:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/beeb2a73ea8a829457e88ece92e56ab6bae25199/; sid:902201948; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"f4:05:f9:49:fd:09:35:ca:b1:66:08:44:97:43:3f:66:e0:a1:93:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f405f949fd0935cab166084497433f66e0a19318/; sid:902201949; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"ca:a4:74:67:05:d7:82:3a:39:b0:ff:a7:07:ee:6d:ec:2a:f4:d3:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/caa4746705d7823a39b0ffa707ee6dec2af4d3d5/; sid:902201950; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c1:ec:4f:82:e7:f1:98:c4:fd:d4:00:9d:68:06:64:4d:01:f2:f8:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1ec4f82e7f198c4fdd4009d6806644d01f2f810/; sid:902201951; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d7:a1:9b:9e:da:fb:2f:bb:7d:40:4f:c7:9c:0c:cd:ef:5a:12:79:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7a19b9edafb2fbb7d404fc79c0ccdef5a1279c1/; sid:902201952; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"60:a3:27:75:01:a9:2e:68:e7:b7:03:31:98:5a:38:36:67:9e:72:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60a3277501a92e68e7b70331985a3836679e72df/; sid:902201953; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"b9:ae:e8:cc:c7:a3:f5:28:09:91:db:ef:66:28:bb:b1:af:9e:85:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9aee8ccc7a3f5280991dbef6628bbb1af9e857a/; sid:902201954; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"55:83:32:67:b8:62:bb:54:33:10:a6:56:10:48:4c:a0:ab:62:e6:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55833267b862bb543310a65610484ca0ab62e666/; sid:902201955; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"54:b0:ac:0b:bc:4d:2e:7e:af:81:fc:8e:a2:ef:c2:2d:86:ce:c6:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54b0ac0bbc4d2e7eaf81fc8ea2efc22d86cec64f/; sid:902201956; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"f3:89:a4:bc:ed:c2:3e:de:90:05:61:91:54:8f:5f:ac:03:bd:2b:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f389a4bcedc23ede90056191548f5fac03bd2b18/; sid:902201957; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"27:97:59:7a:7b:c6:b3:b4:5f:9e:5e:c6:de:47:10:53:71:26:fc:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2797597a7bc6b3b45f9e5ec6de4710537126fc03/; sid:902201958; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"bd:2a:7a:d9:37:83:9a:60:8c:56:60:6b:ef:85:e4:3a:cd:09:4e:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd2a7ad937839a608c56606bef85e43acd094e4e/; sid:902201959; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"65:f1:c7:95:61:9f:25:89:cc:4f:22:8a:59:0d:01:e4:8d:db:2e:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65f1c795619f2589cc4f228a590d01e48ddb2e88/; sid:902201960; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"25:c4:0c:a8:3f:45:f3:2a:bf:ad:18:ca:50:a7:ac:14:d4:b0:2a:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25c40ca83f45f32abfad18ca50a7ac14d4b02af8/; sid:902201961; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"bf:7a:de:50:fd:ef:af:43:e6:99:4f:8b:45:65:ab:19:92:da:08:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf7ade50fdefaf43e6994f8b4565ab1992da086d/; sid:902201962; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"7e:8e:41:1b:64:6d:5e:d8:37:3d:5c:86:7f:23:a4:a4:05:aa:72:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e8e411b646d5ed8373d5c867f23a4a405aa7238/; sid:902201963; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"44:68:ce:d9:56:de:cf:14:39:e9:e4:53:13:62:d1:a3:94:fa:e8:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4468ced956decf1439e9e4531362d1a394fae8fb/; sid:902201964; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"f2:66:29:99:5e:1c:de:46:3b:8e:3d:b3:de:0c:d8:1b:33:4d:03:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f26629995e1cde463b8e3db3de0cd81b334d03e4/; sid:902201965; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"a5:d3:8f:17:fb:fb:1a:e0:b9:29:bd:1d:7d:3b:d9:ae:2d:16:6c:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5d38f17fbfb1ae0b929bd1d7d3bd9ae2d166c28/; sid:902201966; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"20:09:d3:92:b9:dc:fa:e2:cc:cd:84:2c:9f:da:d5:6b:64:73:7b:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2009d392b9dcfae2cccd842c9fdad56b64737b80/; sid:902201967; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"c9:74:f1:b0:2b:43:17:63:7a:ad:55:c6:ce:33:e1:b8:de:25:20:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c974f1b02b4317637aad55c6ce33e1b8de2520c5/; sid:902201968; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"97:de:75:8a:7c:3c:86:1c:32:f1:59:f3:9d:08:ab:d0:49:9d:93:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97de758a7c3c861c32f159f39d08abd0499d9383/; sid:902201969; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"46:37:13:30:70:06:11:77:3c:8f:df:04:d6:0a:84:b0:0b:0a:a5:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46371330700611773c8fdf04d60a84b00b0aa5fb/; sid:902201970; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d4:ad:3a:76:55:2e:f6:2f:ac:1b:cb:c0:ae:e1:c6:f1:f0:85:13:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4ad3a76552ef62fac1bcbc0aee1c6f1f085137a/; sid:902201971; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5e:21:63:42:42:a7:53:44:d3:ac:3e:a4:bf:0a:c6:6e:ae:04:f6:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e21634242a75344d3ac3ea4bf0ac66eae04f627/; sid:902201972; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"57:b7:a7:71:46:f4:0c:f0:14:6f:b7:5f:ab:34:8e:e2:8d:d3:c3:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57b7a77146f40cf0146fb75fab348ee28dd3c3be/; sid:902201973; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"3c:b3:8f:ea:d3:63:d5:48:0a:2a:23:d2:6b:26:9e:d4:34:fa:07:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cb38fead363d5480a2a23d26b269ed434fa078f/; sid:902201974; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"33:27:ed:64:60:b6:71:41:b8:ce:5e:ea:30:7d:d8:6d:8b:ab:62:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3327ed6460b67141b8ce5eea307dd86d8bab626c/; sid:902201975; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"76:be:20:15:18:6a:03:af:bf:39:80:6c:e7:19:84:2f:93:39:e2:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76be2015186a03afbf39806ce719842f9339e2ea/; sid:902201976; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"61:3c:96:82:e9:87:17:7b:ee:34:a4:40:0d:5b:08:b7:8b:42:a5:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/613c9682e987177bee34a4400d5b08b78b42a5b5/; sid:902201977; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3d:f4:48:e1:4c:99:f7:a2:5d:86:72:4d:d8:3d:be:6c:d1:36:b4:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3df448e14c99f7a25d86724dd83dbe6cd136b42e/; sid:902201978; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"74:39:d5:01:75:77:95:b6:f9:0f:56:af:10:c9:bc:5d:c7:db:94:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7439d501757795b6f90f56af10c9bc5dc7db94c0/; sid:902201979; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:00:f2:9c:44:34:c0:ef:3e:70:cf:7d:63:ea:ef:69:bf:75:7f:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4500f29c4434c0ef3e70cf7d63eaef69bf757fb2/; sid:902201980; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2b:b3:62:e2:91:3b:9e:2c:0e:db:cb:db:dd:aa:f2:33:12:33:a9:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bb362e2913b9e2c0edbcbdbddaaf2331233a991/; sid:902201981; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"87:ca:c3:d8:c1:6c:e0:72:8e:86:bf:9e:69:59:6f:fd:ca:f9:db:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87cac3d8c16ce0728e86bf9e69596ffdcaf9db8f/; sid:902201982; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"76:1a:a0:2e:86:54:2b:d5:dd:13:ab:b8:3b:59:5a:f2:36:a7:38:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/761aa02e86542bd5dd13abb83b595af236a738a9/; sid:902201983; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"53:3a:4d:57:8c:89:48:a5:38:25:ca:52:e3:70:5f:2f:26:9b:58:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/533a4d578c8948a53825ca52e3705f2f269b588a/; sid:902201984; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"91:1a:66:48:e7:3b:89:1a:58:89:04:e1:fa:f8:c8:90:1d:e9:f0:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/911a6648e73b891a588904e1faf8c8901de9f08d/; sid:902201985; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"83:0f:59:68:57:11:41:04:95:b9:76:fb:c6:ae:a3:88:bd:7b:82:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/830f59685711410495b976fbc6aea388bd7b8213/; sid:902201986; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1b:66:5c:e2:1b:59:2d:d2:bc:c9:95:18:88:db:c0:f1:9f:5b:ed:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b665ce21b592dd2bcc9951888dbc0f19f5bede3/; sid:902201987; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ac:1d:f3:9c:13:e4:78:3f:37:de:77:4c:0b:df:8b:f1:ed:9a:3f:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac1df39c13e4783f37de774c0bdf8bf1ed9a3f8e/; sid:902201988; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"19:db:b5:56:06:74:86:a7:89:84:78:51:a7:93:ef:ba:00:d4:c4:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19dbb556067486a789847851a793efba00d4c4b8/; sid:902201989; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"d9:85:3b:64:22:06:cd:48:97:d6:9f:78:c6:4b:27:42:43:82:3e:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9853b642206cd4897d69f78c64b274243823e83/; sid:902201990; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e6:c3:6a:e1:c5:84:a3:a5:f0:e0:ac:ae:9c:c8:8f:fd:e9:db:c9:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6c36ae1c584a3a5f0e0acae9cc88ffde9dbc9aa/; sid:902201991; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"8a:da:65:cf:9b:dd:81:60:41:5b:02:8d:c4:fb:15:28:8b:8e:56:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ada65cf9bdd8160415b028dc4fb15288b8e5677/; sid:902201992; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c1:9c:48:ca:9b:bd:9d:98:c3:1d:30:f8:31:9e:a2:b8:f4:95:fa:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c19c48ca9bbd9d98c31d30f8319ea2b8f495fada/; sid:902201993; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"6f:e5:15:9d:cd:44:21:48:ba:16:26:97:0d:46:39:5f:60:a3:38:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fe5159dcd442148ba1626970d46395f60a3381c/; sid:902201994; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"77:c1:91:2e:2a:4f:80:68:49:03:44:16:fb:aa:bb:af:c1:46:22:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77c1912e2a4f806849034416fbaabbafc14622df/; sid:902201995; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ef:ed:79:af:32:bf:cb:56:2d:93:95:63:a5:df:85:ed:fe:41:8b:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efed79af32bfcb562d939563a5df85edfe418b5c/; sid:902201996; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"7f:51:72:b4:ca:fe:33:05:60:d8:85:2c:11:6c:01:04:05:d9:bb:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f5172b4cafe330560d8852c116c010405d9bb82/; sid:902201997; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"60:ed:f4:25:3a:2b:81:cc:f0:d6:9c:ac:6f:e1:ec:b1:bc:3b:66:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60edf4253a2b81ccf0d69cac6fe1ecb1bc3b667d/; sid:902201998; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1b:1d:f7:07:8d:71:80:53:31:20:37:cc:fe:1f:86:7d:cc:59:3e:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b1df7078d718053312037ccfe1f867dcc593ec5/; sid:902201999; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a5:d7:00:a9:8f:78:95:42:01:84:34:86:f3:34:fd:75:71:8f:91:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5d700a98f78954201843486f334fd75718f91ed/; sid:902202000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4a:26:8f:ea:4c:de:0b:bc:cb:a9:42:90:02:a1:e4:fc:63:8e:58:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a268fea4cde0bbccba9429002a1e4fc638e58b8/; sid:902202001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"70:50:66:39:1f:2b:7f:8c:c3:50:46:7b:b3:37:64:8c:c1:76:82:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/705066391f2b7f8cc350467bb337648cc1768256/; sid:902202002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AKBuilder C&C)"; tls.fingerprint:"6e:ce:5e:ce:41:92:68:3d:2d:84:e2:5b:0b:a7:e0:4f:9c:b7:eb:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ece5ece4192683d2d84e25b0ba7e04f9cb7eb7c/; sid:902202003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"75:20:f2:3b:99:d6:fe:a6:3f:0c:1b:ae:e0:c8:3d:b0:35:a1:dd:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7520f23b99d6fea63f0c1baee0c83db035a1ddd1/; sid:902202004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"58:70:6c:c0:c8:da:4d:ae:3b:6b:a6:80:88:20:be:33:3e:41:86:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58706cc0c8da4dae3b6ba6808820be333e41862e/; sid:902202005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a3:a8:da:e5:3a:7f:e1:56:ef:e5:05:25:3f:4c:c8:f0:0f:d2:27:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3a8dae53a7fe156efe505253f4cc8f00fd22732/; sid:902202006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9d:2a:25:5f:77:02:90:2d:f8:f1:df:9a:89:e4:b5:5c:ae:5b:da:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d2a255f7702902df8f1df9a89e4b55cae5bda58/; sid:902202007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"68:e3:7d:a0:89:22:44:80:41:11:9e:43:2c:2a:30:57:99:2c:58:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68e37da08922448041119e432c2a3057992c586e/; sid:902202008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c8:54:ce:95:58:79:ab:d2:78:69:5a:a3:72:3a:a5:b8:b3:6f:0e:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c854ce955879abd278695aa3723aa5b8b36f0e59/; sid:902202009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"0a:14:dd:97:f0:1d:b2:e1:c2:f7:c7:51:08:be:46:df:32:11:df:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a14dd97f01db2e1c2f7c75108be46df3211df45/; sid:902202010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"97:ef:89:ff:cd:19:d6:bf:00:03:2f:20:bf:a2:d3:c2:a1:40:7d:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97ef89ffcd19d6bf00032f20bfa2d3c2a1407ddb/; sid:902202011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Chthonic C&C)"; tls.fingerprint:"d0:68:91:73:fe:15:4f:ce:3a:6b:ff:92:64:83:9c:f6:c5:b9:17:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0689173fe154fce3a6bff9264839cf6c5b91742/; sid:902202012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ce:52:98:b9:c6:a5:d2:19:7c:0c:24:af:2f:f9:fd:0e:71:17:90:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce5298b9c6a5d2197c0c24af2ff9fd0e711790de/; sid:902202013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5c:49:8b:ef:f2:d6:50:7d:0d:05:1a:15:f0:8b:55:16:60:24:76:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c498beff2d6507d0d051a15f08b5516602476ae/; sid:902202014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"73:74:b2:80:9b:ba:52:95:4d:c6:1b:4b:cf:e7:00:52:41:e2:c6:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7374b2809bba52954dc61b4bcfe7005241e2c653/; sid:902202015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2b:0a:76:17:8c:be:81:a7:c1:76:27:fd:36:15:da:09:0c:74:78:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b0a76178cbe81a7c17627fd3615da090c747892/; sid:902202016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"52:16:0f:04:33:ec:ad:d7:86:69:56:7f:b0:ea:3e:6d:be:58:62:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52160f0433ecadd78669567fb0ea3e6dbe586261/; sid:902202017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TorrentLocker C&C)"; tls.fingerprint:"12:b4:b8:c8:1b:a4:77:31:a8:1f:dc:ad:11:1a:0f:38:ad:5b:09:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12b4b8c81ba47731a81fdcad111a0f38ad5b09e6/; sid:902202018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Neutrino C&C)"; tls.fingerprint:"17:f0:1f:88:9f:10:bc:21:b6:6f:d8:76:9b:c4:16:34:51:49:4b:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17f01f889f10bc21b66fd8769bc4163451494b4b/; sid:902202019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"cf:31:d2:f8:e4:19:d7:65:17:b0:bc:6c:3e:ad:1f:24:6b:95:0a:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf31d2f8e419d76517b0bc6c3ead1f246b950a42/; sid:902202020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"da:5e:5d:bf:5a:86:3b:6d:29:23:eb:fd:ce:4a:28:0d:8b:df:03:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da5e5dbf5a863b6d2923ebfdce4a280d8bdf0374/; sid:902202021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cf:38:65:6e:14:9d:da:84:cf:cb:94:f3:b3:50:34:e4:18:ba:7f:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf38656e149dda84cfcb94f3b35034e418ba7fe6/; sid:902202022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f2:d6:16:c7:a3:cc:bb:99:38:6e:f6:1e:4d:43:56:8c:8b:9b:7f:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2d616c7a3ccbb99386ef61e4d43568c8b9b7f2b/; sid:902202023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DiamondFox C&C)"; tls.fingerprint:"ea:17:68:5c:b3:c6:b4:d2:25:a0:d1:ce:21:3a:2f:6c:2c:fd:e8:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea17685cb3c6b4d225a0d1ce213a2f6c2cfde824/; sid:902202024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"dc:39:c2:60:7c:2c:b0:ad:74:65:fd:6b:8f:99:d2:37:a4:a0:8a:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc39c2607c2cb0ad7465fd6b8f99d237a4a08a71/; sid:902202025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"47:51:d4:a2:bb:7e:4c:ae:6d:51:f7:43:c7:3c:2d:5f:92:53:0b:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4751d4a2bb7e4cae6d51f743c73c2d5f92530be5/; sid:902202026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"91:69:29:ef:b6:27:85:6e:86:6d:f6:32:1b:7e:9a:a8:16:7a:53:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/916929efb627856e866df6321b7e9aa8167a53ad/; sid:902202027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"b4:9c:d7:3e:2b:de:b2:d1:2f:e8:b0:8f:d5:e1:8d:77:fe:89:c3:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b49cd73e2bdeb2d12fe8b08fd5e18d77fe89c37e/; sid:902202028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"ed:c8:9e:34:63:30:02:83:05:25:53:7c:cc:2f:cf:65:ab:2f:43:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edc89e34633002830525537ccc2fcf65ab2f43dd/; sid:902202029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"31:bf:c8:fe:a6:c3:99:e6:9e:7e:ce:77:19:99:af:1e:23:f7:44:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31bfc8fea6c399e69e7ece771999af1e23f74445/; sid:902202030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Nexuslogger C&C)"; tls.fingerprint:"a6:51:18:56:07:80:ca:37:f8:68:75:b6:8b:d7:f2:80:15:2a:8f:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a65118560780ca37f86875b68bd7f280152a8f7c/; sid:902202031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"6a:13:52:f9:9b:9a:48:d5:38:16:9c:ac:bf:57:ac:e3:27:16:84:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a1352f99b9a48d538169cacbf57ace327168499/; sid:902202032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"3c:f3:94:36:9b:c8:24:5b:1e:eb:00:e6:b5:ee:74:52:8d:0f:e0:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cf394369bc8245b1eeb00e6b5ee74528d0fe01f/; sid:902202033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"67:d4:57:d4:91:af:d8:0a:81:de:88:53:70:31:7b:0b:84:1d:68:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67d457d491afd80a81de885370317b0b841d68c8/; sid:902202034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"89:f0:1f:d3:65:51:67:34:2d:71:eb:de:e5:15:2a:11:84:9e:0c:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89f01fd3655167342d71ebdee5152a11849e0caa/; sid:902202035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"9b:a1:f6:31:ca:af:b3:33:f3:c8:fa:f8:27:19:a7:26:42:95:59:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ba1f631caafb333f3c8faf82719a72642955927/; sid:902202036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"16:ba:5b:21:4b:47:f1:53:61:21:d4:39:38:10:ad:4f:6e:7a:2b:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16ba5b214b47f1536121d4393810ad4f6e7a2b7c/; sid:902202037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"01:f6:b2:93:e6:61:6b:ad:21:c2:ec:f8:08:df:51:ea:b4:17:34:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01f6b293e6616bad21c2ecf808df51eab4173471/; sid:902202038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Nexuslogger C&C)"; tls.fingerprint:"e8:cc:06:a8:b1:90:72:66:0d:b7:22:29:be:2c:80:b4:83:36:85:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8cc06a8b19072660db72229be2c80b48336852e/; sid:902202039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f9:b6:53:1c:4b:8f:43:a8:a6:85:66:db:27:ea:f9:b4:b1:42:87:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9b6531c4b8f43a8a68566db27eaf9b4b142871b/; sid:902202040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"22:aa:5a:ef:e5:69:e7:17:6e:e1:df:b1:66:db:45:fa:b4:cc:7b:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22aa5aefe569e7176ee1dfb166db45fab4cc7b35/; sid:902202041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"17:10:fe:0b:2e:03:54:bb:0c:8a:96:c4:fe:bd:42:46:22:26:be:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1710fe0b2e0354bb0c8a96c4febd42462226be5a/; sid:902202042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"32:b2:81:05:c1:e7:51:fb:41:6d:78:75:1c:f3:61:25:d6:43:34:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32b28105c1e751fb416d78751cf36125d6433422/; sid:902202043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"92:55:dc:0f:98:91:31:1a:fe:8b:33:65:91:2b:83:65:3e:87:74:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9255dc0f9891311afe8b3365912b83653e877452/; sid:902202044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"57:40:21:bf:d9:fb:dc:88:b6:3c:e9:13:83:63:0a:83:e8:46:4a:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/574021bfd9fbdc88b63ce91383630a83e8464a89/; sid:902202045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d7:a8:e8:28:12:82:bb:30:fc:d8:b1:80:f9:a7:0b:01:7d:40:7d:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7a8e8281282bb30fcd8b180f9a70b017d407df5/; sid:902202046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4a:54:5f:cd:b6:5b:43:3b:8b:0b:d6:18:6b:d9:b3:71:f1:4f:1a:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a545fcdb65b433b8b0bd6186bd9b371f14f1ad8/; sid:902202047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b4:d5:45:68:21:8b:36:49:fe:0b:50:ea:e6:ca:0e:0b:41:0e:1a:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4d54568218b3649fe0b50eae6ca0e0b410e1a81/; sid:902202048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"40:48:18:7e:49:4e:0a:98:64:0d:84:20:98:62:71:51:8e:24:2f:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4048187e494e0a98640d8420986271518e242ff8/; sid:902202049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"19:3a:05:c5:32:5d:1c:c0:cb:f4:8e:87:f6:1e:95:e7:21:58:8b:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/193a05c5325d1cc0cbf48e87f61e95e721588bcc/; sid:902202050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"3a:e6:f6:0d:a1:6b:99:c5:80:7f:e9:3e:47:29:ad:7c:2f:4f:fa:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ae6f60da16b99c5807fe93e4729ad7c2f4ffab3/; sid:902202051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ce:30:fa:24:a8:f2:e2:69:64:97:43:64:16:63:61:31:58:b6:3a:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce30fa24a8f2e269649743641663613158b63aa6/; sid:902202052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"fc:d3:3d:87:46:b4:51:11:d0:e3:bd:b0:c4:0b:36:55:4d:91:06:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcd33d8746b45111d0e3bdb0c40b36554d910603/; sid:902202053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"34:f0:60:57:ee:a1:ba:0e:cd:07:34:fb:78:90:e5:b5:4b:3f:89:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34f06057eea1ba0ecd0734fb7890e5b54b3f89dc/; sid:902202054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"fb:0c:d7:3b:25:89:ef:a2:bc:1c:7b:32:02:ae:c0:7b:36:77:62:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb0cd73b2589efa2bc1c7b3202aec07b36776207/; sid:902202055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"22:f5:4e:90:fa:b6:d8:ee:7f:6d:09:38:49:46:73:77:51:90:0c:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22f54e90fab6d8ee7f6d09384946737751900c4d/; sid:902202056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"e0:04:28:f7:1b:20:23:86:aa:c4:31:cc:90:06:8e:92:04:f3:d5:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e00428f71b202386aac431cc90068e9204f3d586/; sid:902202057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"9c:29:b1:8c:09:1c:31:71:a8:72:74:b0:d9:5e:d7:98:24:61:79:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c29b18c091c3171a87274b0d95ed798246179c4/; sid:902202058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"83:15:a2:dc:68:8a:96:cb:70:25:e0:69:32:9c:cd:5a:0a:6a:c4:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8315a2dc688a96cb7025e069329ccd5a0a6ac4d1/; sid:902202059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"66:5d:62:ba:17:47:7c:9c:a3:93:bf:a8:08:f4:e5:58:50:9f:98:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/665d62ba17477c9ca393bfa808f4e558509f9876/; sid:902202060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f3:e8:5e:c8:d7:b2:0e:45:b9:cc:64:91:be:f0:98:df:78:bb:17:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3e85ec8d7b20e45b9cc6491bef098df78bb17cf/; sid:902202061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ec:3f:c0:68:bc:44:18:a6:3e:24:06:bc:b8:67:4a:af:11:40:8b:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec3fc068bc4418a63e2406bcb8674aaf11408b50/; sid:902202062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"14:e5:63:51:9a:67:e0:07:73:3e:e6:87:a2:37:c6:86:a2:a6:2c:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14e563519a67e007733ee687a237c686a2a62c2f/; sid:902202063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b8:f9:10:c7:f8:ce:9a:7c:e3:91:8a:24:38:af:dd:be:01:3b:e8:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8f910c7f8ce9a7ce3918a2438afddbe013be80e/; sid:902202064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Zloader C&C)"; tls.fingerprint:"d8:27:5a:0d:7a:e3:27:68:79:7e:c2:cc:f1:c0:fc:2f:f5:98:a1:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8275a0d7ae32768797ec2ccf1c0fc2ff598a1ae/; sid:902202065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ca:7d:35:ea:0a:3e:63:56:40:07:f8:00:3e:e1:13:a2:d6:1d:b6:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca7d35ea0a3e63564007f8003ee113a2d61db61d/; sid:902202066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"02:4c:bd:cb:0f:37:95:ef:6d:7e:f2:49:af:3b:34:73:da:6a:47:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/024cbdcb0f3795ef6d7ef249af3b3473da6a4790/; sid:902202067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"26:e1:30:af:6c:10:9c:b7:ed:1d:41:11:11:9c:83:e8:35:7e:8f:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26e130af6c109cb7ed1d4111119c83e8357e8f9c/; sid:902202068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"61:45:cb:40:6e:2f:cd:03:a2:e6:d1:13:ef:ae:6c:a2:c3:88:eb:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6145cb406e2fcd03a2e6d113efae6ca2c388eb8b/; sid:902202069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"93:08:54:97:ea:75:11:d4:75:94:d0:04:14:2d:13:b6:9f:2e:48:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93085497ea7511d47594d004142d13b69f2e4847/; sid:902202070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"0b:fd:e5:36:68:bf:3b:68:63:86:d9:48:77:bb:f7:f2:48:b3:53:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bfde53668bf3b686386d94877bbf7f248b3530e/; sid:902202071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"af:ce:eb:97:ab:ea:d6:b3:50:73:c4:1a:10:20:06:af:91:3e:66:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/afceeb97abead6b35073c41a102006af913e66b7/; sid:902202072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f3:3d:f7:12:50:2b:b0:ce:4b:10:d8:d0:84:6a:26:7d:fc:6b:fc:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f33df712502bb0ce4b10d8d0846a267dfc6bfc68/; sid:902202073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"24:2e:ed:6d:11:b9:c0:7e:c9:10:3b:63:75:85:95:b8:c2:1a:ff:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/242eed6d11b9c07ec9103b63758595b8c21affd3/; sid:902202074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"17:db:88:74:48:8b:8a:df:06:b3:00:50:75:06:c4:bd:e0:48:bf:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17db8874488b8adf06b300507506c4bde048bfe2/; sid:902202075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ca:a3:0a:d0:8b:fe:bf:e9:6b:b8:66:22:ac:a4:32:01:ba:53:9d:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/caa30ad08bfebfe96bb86622aca43201ba539de1/; sid:902202076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6e:ef:f6:fc:73:ac:46:76:03:56:29:69:c3:f2:44:ed:dc:6a:95:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6eeff6fc73ac467603562969c3f244eddc6a9500/; sid:902202077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"3e:0a:89:f4:59:60:32:4c:92:55:a3:9d:4a:96:12:be:5a:90:27:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e0a89f45960324c9255a39d4a9612be5a90270a/; sid:902202078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"81:b0:b0:66:89:87:30:5b:07:73:5c:57:9d:de:92:e0:93:fe:96:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81b0b0668987305b07735c579dde92e093fe9659/; sid:902202079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1f:a2:ee:1c:77:52:37:8d:e3:66:1c:2d:aa:6c:17:54:74:9b:b3:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fa2ee1c7752378de3661c2daa6c1754749bb313/; sid:902202080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"e2:f2:18:54:fa:46:f4:70:10:c1:e4:38:fc:89:33:56:64:4e:f1:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2f21854fa46f47010c1e438fc893356644ef1e2/; sid:902202081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"45:8d:77:bf:ca:ad:1b:e4:f7:fd:a9:23:a9:4c:16:df:8f:70:01:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/458d77bfcaad1be4f7fda923a94c16df8f700166/; sid:902202082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"88:ab:c3:45:00:41:ac:f6:80:b5:d7:b0:06:b9:e6:16:90:d8:34:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88abc3450041acf680b5d7b006b9e61690d834bf/; sid:902202083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (JBifrost C&C)"; tls.fingerprint:"7a:99:8d:76:53:10:87:29:3b:25:0f:12:48:b2:a1:66:6e:d9:b2:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a998d76531087293b250f1248b2a1666ed9b2c5/; sid:902202084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"cf:29:b6:fd:ff:e3:31:5e:8b:60:b6:5d:5e:20:da:ec:c2:a0:70:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf29b6fdffe3315e8b60b65d5e20daecc2a070a4/; sid:902202085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Qadars C&C)"; tls.fingerprint:"7c:5e:e0:9b:5e:3a:16:11:b0:78:7c:a5:08:fd:88:a2:c2:18:59:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c5ee09b5e3a1611b0787ca508fd88a2c21859c0/; sid:902202086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"54:10:84:4f:fd:3e:3f:c6:5f:1c:a3:b7:90:4f:f2:14:81:92:86:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5410844ffd3e3fc65f1ca3b7904ff2148192867f/; sid:902202087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"cf:2b:01:49:38:c3:6b:30:f7:d5:77:08:00:3e:d5:e6:7a:ae:f0:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf2b014938c36b30f7d57708003ed5e67aaef0e4/; sid:902202088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f7:dc:34:b2:bc:79:65:8c:ed:26:b3:4c:ed:f9:70:3d:38:4c:ae:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7dc34b2bc79658ced26b34cedf9703d384caee5/; sid:902202089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"74:da:05:6d:eb:7d:d9:a0:ce:fb:80:23:61:4d:54:2b:79:f4:1d:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/74da056deb7dd9a0cefb8023614d542b79f41d01/; sid:902202090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"89:14:35:7c:ce:21:cb:dc:b4:91:c9:eb:2d:d9:bf:c1:64:ec:55:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8914357cce21cbdcb491c9eb2dd9bfc164ec55d8/; sid:902202091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"85:a0:9b:fc:48:68:95:2e:02:28:a3:8d:bf:2c:4a:45:c1:9b:4a:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85a09bfc4868952e0228a38dbf2c4a45c19b4a70/; sid:902202092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8d:b2:f4:77:38:4f:fb:a0:08:b7:7d:54:ea:bf:4d:ab:24:65:46:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8db2f477384ffba008b77d54eabf4dab246546b9/; sid:902202093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (JBifrost C&C)"; tls.fingerprint:"1a:b8:06:97:79:2c:1f:c2:aa:cf:51:3a:69:b4:38:53:67:69:67:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ab80697792c1fc2aacf513a69b43853676967d7/; sid:902202094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"11:a1:60:3f:74:9e:f5:d4:d4:60:63:4a:d3:ae:6f:c5:7d:44:f5:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11a1603f749ef5d4d460634ad3ae6fc57d44f5ea/; sid:902202095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ac:f6:72:eb:31:d0:4d:f6:11:cb:94:0b:f6:77:64:ad:73:64:1d:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acf672eb31d04df611cb940bf67764ad73641d22/; sid:902202096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ab:28:a0:84:e8:89:75:4e:bb:f7:c7:29:e2:f4:ca:85:3e:0e:6b:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab28a084e889754ebbf7c729e2f4ca853e0e6bda/; sid:902202097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"79:e2:34:30:44:65:ff:5c:76:74:22:34:24:a1:85:a7:0b:c4:52:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79e234304465ff5c7674223424a185a70bc4528a/; sid:902202098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"66:b3:40:1e:21:f8:77:cc:3c:c2:cd:d8:1d:be:f5:67:ba:ea:72:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66b3401e21f877cc3cc2cdd81dbef567baea72e0/; sid:902202099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ee:7b:36:e2:e4:54:b4:ea:28:aa:c4:3a:f0:a4:62:11:98:82:3f:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee7b36e2e454b4ea28aac43af0a4621198823fb9/; sid:902202100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"a5:dc:76:6d:11:83:7f:cf:6e:23:b2:81:a5:c9:c1:02:69:92:59:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5dc766d11837fcf6e23b281a5c9c102699259e2/; sid:902202101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"cf:5f:9a:81:4a:7f:14:a8:69:25:13:45:8a:98:c0:86:26:db:31:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf5f9a814a7f14a8692513458a98c08626db3134/; sid:902202102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"2b:60:bf:5e:1f:05:a4:c8:44:dd:39:35:71:d2:95:9e:56:eb:6c:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b60bf5e1f05a4c844dd393571d2959e56eb6cac/; sid:902202103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e4:68:83:4d:83:5d:8e:69:d3:f0:04:da:97:0f:be:bd:af:9c:0f:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e468834d835d8e69d3f004da970fbebdaf9c0f5e/; sid:902202104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"18:d7:78:87:05:5d:be:89:81:28:24:98:74:56:06:df:24:56:fe:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18d77887055dbe8981282498745606df2456fed1/; sid:902202105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"1e:e1:67:be:7e:c2:15:47:4f:00:57:f2:cd:7b:cb:f6:67:c5:48:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ee167be7ec215474f0057f2cd7bcbf667c548e3/; sid:902202106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c9:25:3e:41:0b:5e:e3:a3:3d:7e:1c:0e:85:4b:1a:ee:a4:2d:f7:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9253e410b5ee3a33d7e1c0e854b1aeea42df7fe/; sid:902202107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c9:a6:34:5f:69:10:3f:14:a9:c4:0c:bf:cf:94:80:bd:1c:7a:05:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9a6345f69103f14a9c40cbfcf9480bd1c7a05b5/; sid:902202108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"18:0d:c5:df:76:80:cc:83:e7:6d:62:18:d8:63:6e:04:81:9b:75:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/180dc5df7680cc83e76d6218d8636e04819b75f2/; sid:902202109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"64:f5:70:05:eb:ce:85:29:d1:56:c4:65:eb:19:44:f6:3d:22:87:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64f57005ebce8529d156c465eb1944f63d228711/; sid:902202110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"20:42:da:83:87:78:90:fc:69:a5:85:1a:9c:a6:6e:23:4f:fd:74:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2042da83877890fc69a5851a9ca66e234ffd7412/; sid:902202111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"bf:77:fa:07:43:ff:57:04:6b:a6:ca:f9:7d:a5:a4:b3:d2:ef:11:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf77fa0743ff57046ba6caf97da5a4b3d2ef1112/; sid:902202112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"75:c2:c8:03:9f:6a:a0:ac:d8:ae:b6:f1:0d:43:77:52:f1:ad:e6:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75c2c8039f6aa0acd8aeb6f10d437752f1ade615/; sid:902202113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5b:ea:fc:e0:06:a6:c5:57:14:4e:dd:6a:39:9b:cd:fd:af:42:b1:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5beafce006a6c557144edd6a399bcdfdaf42b1f6/; sid:902202114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"89:df:93:9f:76:db:fc:4c:38:14:72:47:5f:58:04:2c:56:48:1e:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89df939f76dbfc4c381472475f58042c56481e19/; sid:902202115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"d6:3b:bb:18:43:18:4a:04:8f:df:1f:86:ae:54:ae:31:92:cc:8d:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d63bbb1843184a048fdf1f86ae54ae3192cc8d99/; sid:902202116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"b8:05:e6:a3:5e:d0:f5:fd:06:42:ea:84:08:2b:84:bf:90:36:ed:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b805e6a35ed0f5fd0642ea84082b84bf9036ede5/; sid:902202117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"9f:e4:69:5a:08:76:39:ec:e0:02:f5:12:e1:18:ff:18:83:18:6a:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9fe4695a087639ece002f512e118ff1883186ae7/; sid:902202118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (JBifrost C&C)"; tls.fingerprint:"79:25:d9:21:38:30:67:b6:07:17:f7:41:04:02:ae:ef:3b:a7:90:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7925d921383067b60717f7410402aeef3ba7903e/; sid:902202119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"6e:1e:10:6a:f3:82:0b:4f:98:4e:7e:c8:af:d7:64:39:a3:99:b1:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6e1e106af3820b4f984e7ec8afd76439a399b1f3/; sid:902202120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"19:33:1a:e7:a5:d4:57:bc:36:2c:88:27:97:93:6e:79:8c:35:bf:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19331ae7a5d457bc362c882797936e798c35bf51/; sid:902202121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"c5:38:f6:66:92:80:c6:84:96:11:71:a7:60:4f:31:82:57:db:e7:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c538f6669280c684961171a7604f318257dbe789/; sid:902202122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"44:1b:76:61:e2:b2:01:e4:14:98:0a:51:80:d1:5a:c7:1c:bc:50:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/441b7661e2b201e414980a5180d15ac71cbc50dc/; sid:902202123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"13:73:e2:0d:48:3e:f2:c2:b3:fe:92:85:ad:34:9b:ca:9f:1b:e2:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1373e20d483ef2c2b3fe9285ad349bca9f1be2d6/; sid:902202124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7e:1e:d8:8e:eb:98:d5:23:42:2b:bb:f2:2f:0a:7d:cf:a7:90:de:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e1ed88eeb98d523422bbbf22f0a7dcfa790ded4/; sid:902202125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b6:ea:f9:c4:d0:5b:77:64:87:0d:b1:ed:76:e7:fa:64:8f:ce:28:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6eaf9c4d05b7764870db1ed76e7fa648fce28bd/; sid:902202126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"68:6c:67:07:7f:27:a8:b0:19:20:db:38:ee:01:6f:4b:49:2a:c0:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/686c67077f27a8b01920db38ee016f4b492ac0a3/; sid:902202127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"fd:3f:b9:5b:ed:57:fc:03:61:58:d5:c6:ec:3c:25:fb:33:03:56:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd3fb95bed57fc036158d5c6ec3c25fb33035650/; sid:902202128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c8:ee:ba:31:45:17:38:18:4e:f8:09:39:aa:8f:0b:12:bb:90:f7:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8eeba31451738184ef80939aa8f0b12bb90f784/; sid:902202129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"46:f1:6d:f3:09:11:fc:3f:3a:ef:08:8d:20:6a:87:32:36:c8:70:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46f16df30911fc3f3aef088d206a873236c870ea/; sid:902202130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"38:ba:a2:94:04:5f:bf:a1:19:4b:a5:68:10:f8:a1:f2:9d:43:92:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38baa294045fbfa1194ba56810f8a1f29d439268/; sid:902202131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"10:a7:49:78:fd:77:9e:57:3f:20:82:90:28:86:ba:bf:d4:aa:6c:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10a74978fd779e573f2082902886babfd4aa6c36/; sid:902202132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"79:aa:b5:0a:24:66:47:98:dc:5f:ab:9e:48:fa:9f:93:63:03:d3:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79aab50a24664798dc5fab9e48fa9f936303d3cf/; sid:902202133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"2f:73:84:8a:07:6c:43:e3:61:cf:f2:fd:3f:4b:af:e9:87:14:43:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f73848a076c43e361cff2fd3f4bafe9871443e2/; sid:902202134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c3:0b:f6:8a:ff:79:89:8c:b1:9e:e7:44:df:b0:07:95:14:48:27:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c30bf68aff79898cb19ee744dfb0079514482782/; sid:902202135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"21:5a:08:86:f1:b3:d5:fb:66:3a:19:c1:f2:10:17:48:65:84:d0:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/215a0886f1b3d5fb663a19c1f21017486584d034/; sid:902202136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"57:5a:cb:10:56:e6:e6:89:8c:3f:06:3d:48:04:c6:d7:e9:d6:19:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/575acb1056e6e6898c3f063d4804c6d7e9d619e4/; sid:902202137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9a:c2:22:95:66:c6:58:62:bb:ec:96:ad:6a:48:f4:27:66:2e:33:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ac2229566c65862bbec96ad6a48f427662e3315/; sid:902202138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"02:5b:7c:07:b2:77:e9:29:64:79:91:80:e0:8c:79:d9:30:ee:83:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/025b7c07b277e92964799180e08c79d930ee833a/; sid:902202139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"3f:c4:62:a5:29:a2:35:62:63:aa:c7:2a:bd:1b:51:75:97:b7:5d:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3fc462a529a2356263aac72abd1b517597b75d7c/; sid:902202140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"28:6e:90:60:9d:cc:a5:8a:00:fc:e4:ee:cf:b0:68:bd:46:82:f1:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/286e90609dcca58a00fce4eecfb068bd4682f1cc/; sid:902202141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"7c:55:88:f7:2d:85:9a:2b:37:ad:72:f0:72:32:74:a0:fe:49:ec:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c5588f72d859a2b37ad72f0723274a0fe49ec2a/; sid:902202142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"da:9b:7e:ee:e8:1a:b8:a7:5e:21:cb:60:f3:90:c2:fa:aa:0f:1a:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da9b7eeee81ab8a75e21cb60f390c2faaa0f1a09/; sid:902202143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7d:2e:9e:8b:18:eb:3e:32:ea:4c:19:73:78:7c:b6:34:05:c2:f7:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d2e9e8b18eb3e32ea4c1973787cb63405c2f77a/; sid:902202144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c4:0c:61:c5:ea:7b:ce:a5:12:39:59:22:24:42:8d:5a:e7:2d:6b:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c40c61c5ea7bcea51239592224428d5ae72d6b8c/; sid:902202145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"45:1e:a6:1c:dc:99:5a:9c:ef:aa:82:1c:49:0e:42:7c:3a:e2:14:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/451ea61cdc995a9cefaa821c490e427c3ae214c5/; sid:902202146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"5d:a0:36:f6:ae:0a:02:52:ca:f4:26:1c:6f:ce:95:99:e9:70:71:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5da036f6ae0a0252caf4261c6fce9599e97071b7/; sid:902202147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"fa:50:4d:7e:a1:66:b6:27:d8:38:38:be:08:b8:08:ea:c9:38:1d:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa504d7ea166b627d83838be08b808eac9381dc6/; sid:902202148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"14:46:8f:27:7d:ff:9e:73:fc:e6:84:e8:bb:35:04:56:ff:61:5f:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14468f277dff9e73fce684e8bb350456ff615f0b/; sid:902202149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d5:d9:e5:2e:28:9a:14:87:c0:4a:99:ea:ba:7f:8f:4a:89:16:ae:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5d9e52e289a1487c04a99eaba7f8f4a8916ae2b/; sid:902202150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"91:8f:16:c0:92:ce:9f:9b:31:7c:a5:22:f5:0e:fe:06:3c:0d:a1:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/918f16c092ce9f9b317ca522f50efe063c0da17a/; sid:902202151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"a6:68:71:1d:f4:20:10:83:53:85:14:57:22:bb:42:16:35:fb:5b:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a668711df42010835385145722bb421635fb5bec/; sid:902202152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"28:86:41:33:d3:c5:33:1f:22:82:d8:66:e3:d5:ff:0c:18:2b:1b:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28864133d3c5331f2282d866e3d5ff0c182b1bad/; sid:902202153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3f:44:ba:28:bd:f0:3c:75:f1:68:fa:bc:4f:d5:50:7a:1e:4c:84:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f44ba28bdf03c75f168fabc4fd5507a1e4c84c2/; sid:902202154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d6:43:57:62:3c:6f:1c:a7:86:1e:78:ed:0b:42:ba:dc:b3:c9:d9:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d64357623c6f1ca7861e78ed0b42badcb3c9d9ba/; sid:902202155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ac:ee:60:a2:70:36:f5:15:07:cc:39:23:e4:67:b0:53:6f:f8:a0:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acee60a27036f51507cc3923e467b0536ff8a068/; sid:902202156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"73:b3:88:58:7e:7c:4e:ac:f9:3e:9b:72:fb:89:6f:d9:c1:5e:e4:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73b388587e7c4eacf93e9b72fb896fd9c15ee490/; sid:902202157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7d:91:4e:ee:0d:ea:cb:f6:b4:ea:df:f9:3e:ed:da:6a:54:0a:48:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d914eee0deacbf6b4eadff93eedda6a540a4806/; sid:902202158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5e:26:4c:b4:fc:21:6d:cd:df:a6:fe:06:c9:0d:8a:dd:74:27:e1:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e264cb4fc216dcddfa6fe06c90d8add7427e13d/; sid:902202159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"2a:cf:28:c2:20:0b:63:68:05:49:39:6a:73:29:21:ca:97:76:8c:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2acf28c2200b63680549396a732921ca97768c21/; sid:902202160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"30:3f:a0:84:8c:1a:98:ba:90:b3:c0:74:02:ca:2a:98:5c:4b:89:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/303fa0848c1a98ba90b3c07402ca2a985c4b89d1/; sid:902202161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"31:6d:cc:56:27:b8:bf:d6:06:57:40:fc:34:e8:86:a7:a1:b1:df:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/316dcc5627b8bfd6065740fc34e886a7a1b1df6b/; sid:902202162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a9:8f:9d:28:6b:45:b3:9f:30:7b:71:cf:43:a2:5d:0f:75:29:ab:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a98f9d286b45b39f307b71cf43a25d0f7529abb8/; sid:902202163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ae:7c:42:e5:84:3f:1b:2e:f1:f7:36:3d:27:df:1a:b0:f7:b0:11:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae7c42e5843f1b2ef1f7363d27df1ab0f7b01111/; sid:902202164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ae:62:5f:32:fa:ec:a9:99:5d:20:19:c0:67:b0:ca:8c:e6:fc:01:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae625f32faeca9995d2019c067b0ca8ce6fc014b/; sid:902202165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"0d:ea:64:6c:b3:3f:b2:85:b1:2d:a4:34:1c:5f:8b:4c:f4:5a:51:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dea646cb33fb285b12da4341c5f8b4cf45a51fd/; sid:902202166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ac:7f:51:af:5e:0c:f0:ea:0a:59:b7:e9:6d:43:f4:1e:6f:c5:f6:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac7f51af5e0cf0ea0a59b7e96d43f41e6fc5f60c/; sid:902202167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5c:b2:4e:0c:ca:a1:31:fb:5d:44:d9:61:9f:e2:ad:3c:91:03:b8:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5cb24e0ccaa131fb5d44d9619fe2ad3c9103b8f5/; sid:902202168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"03:20:01:68:3d:d0:42:92:ee:9f:88:96:d3:ce:4b:5a:64:be:af:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/032001683dd04292ee9f8896d3ce4b5a64beafb3/; sid:902202169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"05:a0:30:09:3a:51:41:f5:3b:37:eb:66:84:fa:75:75:be:e0:df:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05a030093a5141f53b37eb6684fa7575bee0dfab/; sid:902202170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"fd:a0:59:b2:81:8c:be:1f:7f:03:4f:17:65:ed:3e:6a:d0:e9:2b:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fda059b2818cbe1f7f034f1765ed3e6ad0e92bbf/; sid:902202171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"b3:d3:72:97:ce:0f:b5:d6:b9:5f:a2:0d:b1:1d:c2:40:8b:4b:73:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b3d37297ce0fb5d6b95fa20db11dc2408b4b7377/; sid:902202172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f6:54:1a:42:47:de:1d:10:26:53:3a:3a:9b:94:2a:dd:e5:46:92:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6541a4247de1d1026533a3a9b942adde5469233/; sid:902202173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b9:bd:55:34:c2:74:a6:70:49:a4:fd:5d:0d:95:d8:28:40:91:60:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9bd5534c274a67049a4fd5d0d95d82840916044/; sid:902202174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ac:ac:86:d2:92:b5:3c:83:87:61:25:80:8f:63:a0:a1:b1:ab:72:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acac86d292b53c83876125808f63a0a1b1ab7257/; sid:902202175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"11:a6:13:0c:1c:d6:c9:4b:43:ec:7d:9e:41:02:61:d0:90:a9:a0:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11a6130c1cd6c94b43ec7d9e410261d090a9a0c8/; sid:902202176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"f3:71:10:e5:1b:ac:1e:b7:2c:f4:6d:d3:09:bf:85:35:e7:6a:da:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f37110e51bac1eb72cf46dd309bf8535e76ada28/; sid:902202177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"0a:60:a6:1a:bc:5b:97:be:e9:2a:fb:73:26:2a:37:b9:32:35:f1:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a60a61abc5b97bee92afb73262a37b93235f147/; sid:902202178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f4:ef:63:00:b5:cd:5f:96:53:c5:37:d5:0d:39:f0:d6:e1:66:a4:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4ef6300b5cd5f9653c537d50d39f0d6e166a493/; sid:902202179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"90:06:60:70:8e:65:8a:29:42:57:34:06:79:af:da:71:49:2e:90:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/900660708e658a294257340679afda71492e90ce/; sid:902202180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"3c:d7:c8:87:08:d5:b0:3c:5f:6a:46:96:9b:70:67:5b:7c:8e:08:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cd7c88708d5b03c5f6a46969b70675b7c8e089b/; sid:902202181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"03:0b:47:a3:ca:4c:a0:41:de:ab:48:46:b3:a5:89:a5:d4:01:57:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/030b47a3ca4ca041deab4846b3a589a5d40157db/; sid:902202182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"99:40:ac:e3:d2:fb:71:d9:ee:07:fb:a8:81:f5:b7:e1:ef:b5:88:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9940ace3d2fb71d9ee07fba881f5b7e1efb58830/; sid:902202183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"66:d0:0f:b9:dd:dd:f5:50:1c:e7:20:fe:9a:c4:91:f7:48:53:98:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66d00fb9ddddf5501ce720fe9ac491f748539886/; sid:902202184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"32:e3:a5:5c:af:2d:8b:e8:87:e5:7f:a9:89:6f:0b:74:98:c8:c5:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32e3a55caf2d8be887e57fa9896f0b7498c8c5b3/; sid:902202185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3d:31:4a:f3:95:55:97:24:45:6b:60:1f:e7:75:ce:6e:b9:13:72:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d314af395559724456b601fe775ce6eb9137212/; sid:902202186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"20:7c:6e:0b:8d:94:71:ec:2e:3d:52:0f:a5:01:11:39:22:4d:00:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/207c6e0b8d9471ec2e3d520fa5011139224d009d/; sid:902202187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"bc:cd:88:ae:63:c3:96:58:e7:a5:a3:fc:35:11:dc:7b:ee:29:38:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bccd88ae63c39658e7a5a3fc3511dc7bee2938c9/; sid:902202188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b5:fb:3b:5d:ed:e3:80:b1:40:8c:ec:eb:2f:86:bf:96:dd:3d:1d:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5fb3b5dede380b1408ceceb2f86bf96dd3d1d52/; sid:902202189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a9:49:d4:6c:29:a8:7d:82:5e:d5:c2:52:0d:67:9b:3f:df:02:14:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a949d46c29a87d825ed5c2520d679b3fdf0214c4/; sid:902202190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"d5:23:80:91:8a:07:32:2c:50:f1:bf:a2:b4:3a:f3:bb:54:cb:33:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d52380918a07322c50f1bfa2b43af3bb54cb33db/; sid:902202191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"25:21:02:a8:db:bf:30:c6:eb:05:7c:df:5c:76:a9:7e:e5:74:a9:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/252102a8dbbf30c6eb057cdf5c76a97ee574a999/; sid:902202192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"97:be:a2:f2:4d:92:08:a3:14:ef:bb:88:6a:c0:79:1b:d0:00:b6:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97bea2f24d9208a314efbb886ac0791bd000b608/; sid:902202193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c0:fd:b6:f6:f8:69:ec:69:22:de:63:9c:58:6b:6c:ea:95:dc:9e:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0fdb6f6f869ec6922de639c586b6cea95dc9edb/; sid:902202194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"83:05:cb:9f:39:63:8d:ad:87:bb:c1:bf:b8:4f:8d:e1:63:0e:2b:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8305cb9f39638dad87bbc1bfb84f8de1630e2b32/; sid:902202195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"25:13:f1:d9:b8:4f:88:d6:46:f4:85:39:1c:d7:22:f3:23:29:5c:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2513f1d9b84f88d646f485391cd722f323295c93/; sid:902202196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"65:4d:4f:33:b1:fb:15:02:0e:de:87:0d:e6:d3:d7:d4:38:ea:25:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/654d4f33b1fb15020ede870de6d3d7d438ea2506/; sid:902202197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"b2:3d:e8:95:08:4a:da:8f:64:8f:af:ea:cf:c5:1b:2b:3f:ab:59:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b23de895084ada8f648fafeacfc51b2b3fab592b/; sid:902202198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"94:43:34:58:d4:ad:93:00:f1:ee:8d:3f:e9:00:7c:a1:1b:5e:20:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94433458d4ad9300f1ee8d3fe9007ca11b5e20cd/; sid:902202199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"2f:6e:ce:78:97:cf:e2:06:74:90:a2:7d:0a:01:55:21:2e:7c:94:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f6ece7897cfe2067490a27d0a0155212e7c94fc/; sid:902202200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"aa:23:78:53:43:96:5f:2e:0c:82:31:fa:57:64:ea:15:82:2e:93:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa23785343965f2e0c8231fa5764ea15822e9376/; sid:902202201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"8d:88:67:de:05:fb:e3:a5:9d:49:a9:19:e8:f4:9f:09:62:8c:c0:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d8867de05fbe3a59d49a919e8f49f09628cc0a5/; sid:902202202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"e3:07:da:6d:d8:4b:a9:21:de:22:18:1e:13:bf:8f:d4:01:e3:54:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e307da6dd84ba921de22181e13bf8fd401e354d7/; sid:902202203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"4c:ee:86:a4:a3:df:fe:67:ff:90:dc:30:e4:dd:76:92:fb:a2:d1:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cee86a4a3dffe67ff90dc30e4dd7692fba2d1dd/; sid:902202204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"fc:9f:19:19:30:f0:f5:eb:e7:fc:88:8d:f9:59:33:8d:57:45:5a:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc9f191930f0f5ebe7fc888df959338d57455a1d/; sid:902202205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5b:00:23:7b:d2:09:bf:77:8c:a8:dd:46:7d:d6:44:d0:2e:fc:a5:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b00237bd209bf778ca8dd467dd644d02efca5aa/; sid:902202206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2b:ed:ff:8e:51:9f:e4:0b:33:77:d7:a2:85:46:21:f0:38:e1:60:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bedff8e519fe40b3377d7a2854621f038e16093/; sid:902202207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ff:21:8c:49:25:14:12:42:8f:0b:d1:2d:d4:18:c7:60:6f:51:07:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff218c49251412428f0bd12dd418c7606f5107fe/; sid:902202208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6e:dd:06:f7:1b:b8:68:a3:e7:21:f6:60:39:05:c1:45:ab:97:79:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6edd06f71bb868a3e721f6603905c145ab97790c/; sid:902202209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"2e:97:74:5a:a3:04:af:85:b4:7e:ea:3d:f6:fa:84:e0:15:c4:e1:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e97745aa304af85b47eea3df6fa84e015c4e160/; sid:902202210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"0b:e8:6a:6f:0a:79:c0:f3:a3:20:34:c2:1c:7d:cf:a1:59:ad:5d:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0be86a6f0a79c0f3a32034c21c7dcfa159ad5d45/; sid:902202211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"7d:3a:d8:cc:c7:48:e0:a3:40:d5:c5:9a:86:de:52:50:6e:57:7a:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d3ad8ccc748e0a340d5c59a86de52506e577a40/; sid:902202212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"a8:00:e5:b1:86:ed:5c:21:02:b7:97:65:a4:d3:24:55:b4:f3:65:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a800e5b186ed5c2102b79765a4d32455b4f3658e/; sid:902202213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"60:a7:81:30:c2:0e:36:bf:18:9a:8a:0b:46:51:28:9f:aa:cd:64:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60a78130c20e36bf189a8a0b4651289faacd646b/; sid:902202214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"2b:08:3b:95:2d:9a:7a:22:d1:15:78:cd:d6:ad:37:a4:96:ea:2a:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b083b952d9a7a22d11578cdd6ad37a496ea2a06/; sid:902202215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"eb:fd:61:5c:3c:e5:d9:87:49:b6:4a:7c:f6:76:fb:a0:00:0d:57:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebfd615c3ce5d98749b64a7cf676fba0000d572c/; sid:902202216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"43:8f:8a:f4:14:25:5d:74:91:1a:c7:18:34:77:a4:23:98:96:90:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/438f8af414255d74911ac7183477a42398969010/; sid:902202217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"3a:b4:d6:e9:7e:c2:6d:1a:b1:94:f4:4f:19:68:ec:cd:35:fc:66:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ab4d6e97ec26d1ab194f44f1968eccd35fc66ae/; sid:902202218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"b8:82:8d:aa:fe:02:24:d6:de:45:7e:d1:a5:26:a3:80:0a:ce:57:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8828daafe0224d6de457ed1a526a3800ace57ab/; sid:902202219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"cd:b5:48:ca:de:0a:fb:9d:70:da:a7:fa:c4:3a:51:fd:23:04:85:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cdb548cade0afb9d70daa7fac43a51fd23048540/; sid:902202220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"de:ec:a2:35:54:54:61:30:16:3a:a4:eb:0b:71:80:93:a1:6f:b1:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/deeca23554546130163aa4eb0b718093a16fb13a/; sid:902202221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"dd:b4:ab:26:04:42:73:f7:c6:1e:90:bd:a2:ac:c0:c7:84:0f:1f:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddb4ab26044273f7c61e90bda2acc0c7840f1f79/; sid:902202222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"c2:da:79:a6:fe:70:3c:e9:6c:e6:3f:64:46:f8:9e:29:9f:99:84:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c2da79a6fe703ce96ce63f6446f89e299f998494/; sid:902202223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"12:45:6b:42:c1:9d:9b:11:6a:e5:77:6f:74:48:95:1f:c2:ca:1b:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12456b42c19d9b116ae5776f7448951fc2ca1baa/; sid:902202224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c7:7c:c4:9c:34:2e:46:3c:d6:48:9c:76:5f:ca:ef:0b:22:77:3f:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c77cc49c342e463cd6489c765fcaef0b22773f96/; sid:902202225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"36:49:e6:5d:15:47:27:db:2f:70:e6:a8:45:73:b1:01:f9:de:bb:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3649e65d154727db2f70e6a84573b101f9debb7e/; sid:902202226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"18:3e:70:3a:4e:55:99:a2:2a:a0:d5:63:ee:d4:9e:0d:47:b7:64:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/183e703a4e5599a22aa0d563eed49e0d47b7640f/; sid:902202227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"8c:82:e0:b1:f1:63:bb:f4:71:7d:f8:f7:fd:69:83:00:aa:21:9c:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c82e0b1f163bbf4717df8f7fd698300aa219c07/; sid:902202228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"00:c2:e0:37:5f:9b:44:ba:19:15:9a:88:2a:24:3d:f3:20:47:5a:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00c2e0375f9b44ba19159a882a243df320475a60/; sid:902202229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"3e:40:b5:8f:2c:7a:fa:5c:10:aa:bf:58:fa:64:c6:d1:5d:fa:e2:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e40b58f2c7afa5c10aabf58fa64c6d15dfae2a8/; sid:902202230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"3d:aa:7c:bc:b2:16:c8:3a:04:1a:89:b3:2d:96:7a:8e:20:f9:47:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3daa7cbcb216c83a041a89b32d967a8e20f9479d/; sid:902202231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"dd:a8:ad:6d:9d:7c:84:76:a5:ad:d6:bc:37:a3:ea:b1:f5:e4:6c:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dda8ad6d9d7c8476a5add6bc37a3eab1f5e46c9c/; sid:902202232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"5d:89:88:a9:f4:06:b0:77:f2:bf:4c:be:db:cc:dc:07:34:54:53:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d8988a9f406b077f2bf4cbedbccdc07345453d6/; sid:902202233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a4:98:70:5d:59:fd:fb:e6:6f:67:fb:47:9b:42:e9:0e:fc:cc:f9:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a498705d59fdfbe66f67fb479b42e90efcccf9d7/; sid:902202234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"2a:21:fd:57:c3:aa:86:5a:c9:cf:a6:fe:6a:08:43:d0:07:2a:a1:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a21fd57c3aa865ac9cfa6fe6a0843d0072aa18b/; sid:902202235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"89:90:75:9b:cb:b9:ed:72:cc:b0:16:07:4e:89:f8:cf:d7:68:f6:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8990759bcbb9ed72ccb016074e89f8cfd768f62a/; sid:902202236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"90:65:1b:6c:ee:66:22:95:34:5a:e9:1d:8e:c5:07:02:fa:bc:ae:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90651b6cee662295345ae91d8ec50702fabcaee3/; sid:902202237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"aa:3c:5a:4d:93:06:67:db:cb:38:a5:02:db:7a:25:09:a8:aa:95:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa3c5a4d930667dbcb38a502db7a2509a8aa95da/; sid:902202238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"3a:57:b9:f0:8a:00:8f:b3:8b:0a:63:db:33:b8:43:32:7c:c8:87:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a57b9f08a008fb38b0a63db33b843327cc88775/; sid:902202239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0e:1f:2e:f3:c4:59:c7:4c:6d:8e:76:eb:bf:bf:54:c3:c6:93:54:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e1f2ef3c459c74c6d8e76ebbfbf54c3c69354de/; sid:902202240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"77:48:70:24:0b:62:a8:95:61:2d:50:05:d6:9b:c3:91:4f:99:02:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/774870240b62a895612d5005d69bc3914f9902d1/; sid:902202241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c7:5e:cf:9e:cc:51:be:d8:68:45:0f:a6:d0:0b:c6:61:35:80:0c:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c75ecf9ecc51bed868450fa6d00bc66135800c9d/; sid:902202242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"75:7e:c4:39:a7:69:e6:9a:74:b1:21:1e:6a:e5:79:28:d7:ea:f3:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/757ec439a769e69a74b1211e6ae57928d7eaf351/; sid:902202243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"8c:ea:e1:72:60:75:a4:d1:69:07:64:fd:72:ed:55:b6:7a:5b:df:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ceae1726075a4d1690764fd72ed55b67a5bdf84/; sid:902202244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b6:2f:a5:a0:a6:c3:85:b3:88:f9:1f:08:e1:75:9f:2f:a3:52:95:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b62fa5a0a6c385b388f91f08e1759f2fa35295c5/; sid:902202245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ea:5e:48:94:6d:37:e5:d0:c4:56:bc:68:b0:90:61:67:16:f2:71:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea5e48946d37e5d0c456bc68b090616716f27145/; sid:902202246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"3b:37:25:dd:24:b8:bc:46:8c:e3:8b:ca:b7:69:21:00:b5:85:50:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b3725dd24b8bc468ce38bcab7692100b5855077/; sid:902202247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"19:df:51:91:5f:bd:54:62:26:fb:ad:59:81:b3:b6:79:98:82:44:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19df51915fbd546226fbad5981b3b67998824486/; sid:902202248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5f:70:ec:dd:48:a4:9c:35:69:b5:cf:51:b1:78:ef:9d:be:42:82:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f70ecdd48a49c3569b5cf51b178ef9dbe4282d0/; sid:902202249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7a:cd:43:e7:e4:60:07:f4:93:a8:c0:f7:d9:8d:4a:51:60:46:38:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7acd43e7e46007f493a8c0f7d98d4a51604638de/; sid:902202250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"52:db:5a:ab:62:99:a4:fb:57:f3:69:83:bc:fd:e6:79:3a:bd:56:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52db5aab6299a4fb57f36983bcfde6793abd5687/; sid:902202251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"97:f8:b6:68:7a:b0:3d:2e:f5:b3:ea:9d:24:95:e2:8a:bf:2f:e9:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97f8b6687ab03d2ef5b3ea9d2495e28abf2fe9d8/; sid:902202252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5c:2d:86:ce:d0:61:c6:7f:f0:72:e2:9c:bc:67:44:75:da:20:e4:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c2d86ced061c67ff072e29cbc674475da20e486/; sid:902202253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"64:45:58:13:ff:85:64:4f:57:2f:f2:70:13:af:d5:bc:f9:cf:d1:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64455813ff85644f572ff27013afd5bcf9cfd116/; sid:902202254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7d:0f:8a:9e:44:be:f4:e3:cd:20:4c:16:9e:a1:6f:9c:36:02:c7:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d0f8a9e44bef4e3cd204c169ea16f9c3602c710/; sid:902202255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"7b:78:42:50:8e:74:b0:a6:c2:b8:4f:71:18:ee:4e:a7:3d:0d:d1:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b7842508e74b0a6c2b84f7118ee4ea73d0dd12a/; sid:902202256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"18:4b:3b:c4:da:e2:04:ae:dc:16:b4:82:a7:a5:da:42:1f:ae:fa:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/184b3bc4dae204aedc16b482a7a5da421faefa31/; sid:902202257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"7a:5d:fe:85:e0:8a:d5:1b:28:aa:62:82:74:02:7d:f3:67:19:9f:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a5dfe85e08ad51b28aa628274027df367199fd4/; sid:902202258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"fa:b9:d1:5d:8f:2e:ad:bb:8f:75:bc:ce:15:2e:1c:c7:d7:3e:d8:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fab9d15d8f2eadbb8f75bcce152e1cc7d73ed8da/; sid:902202259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Downloader.AuotIT.ZLIB C&C)"; tls.fingerprint:"6c:b5:27:f1:c6:b5:a6:cf:41:eb:34:d3:41:36:a5:44:5e:57:df:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cb527f1c6b5a6cf41eb34d34136a5445e57df40/; sid:902202260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Downloader.AuotIT.ZLIB C&C)"; tls.fingerprint:"03:e6:bd:14:e1:00:d4:1b:68:d6:c4:0e:45:bb:f7:1f:f7:3c:62:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03e6bd14e100d41b68d6c40e45bbf71ff73c6274/; sid:902202261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (LockPOS C&C)"; tls.fingerprint:"dc:81:8e:71:e0:55:8b:0b:a3:62:57:71:c8:04:56:d9:32:d4:5b:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc818e71e0558b0ba3625771c80456d932d45b0e/; sid:902202262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"28:e2:71:dc:3d:86:eb:53:0e:78:d6:c0:5d:a2:30:3a:49:16:98:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28e271dc3d86eb530e78d6c05da2303a491698ca/; sid:902202263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"da:ad:d8:8d:8e:e8:a1:e2:71:9b:df:5d:38:6c:74:4f:93:eb:c0:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/daadd88d8ee8a1e2719bdf5d386c744f93ebc025/; sid:902202264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"20:7a:31:fb:22:bd:e2:b2:36:d3:6b:d4:64:76:22:06:4e:fc:dd:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/207a31fb22bde2b236d36bd4647622064efcdd6a/; sid:902202265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"80:20:18:d0:95:0e:da:31:a3:04:f4:2c:25:e7:74:3a:a3:9a:2a:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/802018d0950eda31a304f42c25e7743aa39a2ab5/; sid:902202266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"31:d2:d9:13:ea:30:5d:df:a3:c2:75:18:4f:3d:13:86:27:a0:c8:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31d2d913ea305ddfa3c275184f3d138627a0c86e/; sid:902202267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"9d:00:d6:2b:06:a9:7c:1e:43:97:50:ed:2c:5d:44:c3:03:68:32:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d00d62b06a97c1e439750ed2c5d44c303683202/; sid:902202268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"51:9a:f4:00:67:c7:19:74:9b:86:26:47:9f:ac:81:c1:4e:24:8b:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/519af40067c719749b8626479fac81c14e248b48/; sid:902202269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"af:c8:d1:19:ca:d2:f1:17:7e:1c:51:24:81:53:cb:26:a3:67:cd:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/afc8d119cad2f1177e1c51248153cb26a367cdbf/; sid:902202270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c8:a2:37:c9:07:b3:3e:e1:e3:43:1c:45:d3:ab:dd:76:f9:6f:8e:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8a237c907b33ee1e3431c45d3abdd76f96f8e43/; sid:902202271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"fc:f5:7e:83:1a:5f:e8:34:b0:cd:25:40:d1:c1:9a:f7:1b:af:21:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcf57e831a5fe834b0cd2540d1c19af71baf21a1/; sid:902202272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"60:2c:5d:ba:d0:7f:d4:c9:82:5a:2d:fc:16:04:46:49:7c:39:6b:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/602c5dbad07fd4c9825a2dfc160446497c396bbd/; sid:902202273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"0c:d0:5b:b4:3a:7b:af:3f:5c:07:76:0b:f6:d1:7c:cc:9d:e0:bb:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0cd05bb43a7baf3f5c07760bf6d17ccc9de0bb19/; sid:902202274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c8:80:92:cf:53:2a:46:b3:c9:fa:bd:ff:63:61:f8:a3:38:b7:d2:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c88092cf532a46b3c9fabdff6361f8a338b7d292/; sid:902202275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"70:2d:01:5c:52:0f:d5:b7:6e:e7:ed:49:b3:8f:88:92:37:2a:c5:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/702d015c520fd5b76ee7ed49b38f8892372ac54f/; sid:902202276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"a4:8f:cb:66:3d:e8:db:ba:dc:d1:7b:8f:83:6e:2c:5d:4e:d3:b3:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a48fcb663de8dbbadcd17b8f836e2c5d4ed3b330/; sid:902202277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ec:18:e0:40:6f:3e:af:a3:ee:d3:ca:ff:61:f5:9e:2e:5c:e2:6f:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec18e0406f3eafa3eed3caff61f59e2e5ce26fff/; sid:902202278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d0:f1:70:91:24:4f:89:2e:a2:7a:ac:d3:d6:4a:dc:b9:82:28:32:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0f17091244f892ea27aacd3d64adcb9822832b4/; sid:902202279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"9b:58:5b:40:14:ef:6c:c5:ea:bc:23:5f:63:b8:1a:01:b6:a7:d0:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b585b4014ef6cc5eabc235f63b81a01b6a7d091/; sid:902202280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ac:e9:4d:19:d9:d7:8c:91:5d:9e:e0:80:bf:60:cd:41:ac:8d:b9:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ace94d19d9d78c915d9ee080bf60cd41ac8db91a/; sid:902202281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d1:97:58:7b:bc:14:5b:81:eb:2e:ac:5b:06:7f:02:7f:3d:17:d0:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d197587bbc145b81eb2eac5b067f027f3d17d0c3/; sid:902202282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"eb:d9:95:19:da:72:87:3a:e0:3f:92:10:99:6f:49:af:6b:16:9f:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebd99519da72873ae03f9210996f49af6b169fa0/; sid:902202283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"7e:2f:eb:5c:7e:af:88:0e:85:87:b3:49:d3:de:e9:4a:77:65:0d:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e2feb5c7eaf880e8587b349d3dee94a77650dd4/; sid:902202284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"22:c5:ec:e6:63:9c:9c:ed:35:d6:a2:d4:5d:7d:c1:8f:9d:4f:52:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22c5ece6639c9ced35d6a2d45d7dc18f9d4f5256/; sid:902202285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"58:ae:ab:46:c6:cd:fe:c4:66:7f:68:3e:d1:5b:84:d5:41:51:38:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58aeab46c6cdfec4667f683ed15b84d541513857/; sid:902202286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"cb:06:cd:0c:dd:50:db:37:64:7e:44:4a:9a:09:2f:fc:3a:29:8e:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb06cd0cdd50db37647e444a9a092ffc3a298e95/; sid:902202287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"d0:35:1b:59:fd:d6:e8:2b:26:07:80:f2:b6:0c:15:6e:25:30:3f:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0351b59fdd6e82b260780f2b60c156e25303fa4/; sid:902202288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6a:d7:1b:16:3c:fc:3a:a1:cf:0c:fd:78:6d:87:fd:1b:19:8d:a3:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ad71b163cfc3aa1cf0cfd786d87fd1b198da3ba/; sid:902202289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d2:e3:57:14:1d:f5:39:27:5a:b0:47:e7:d7:a6:7f:f8:60:cf:21:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2e357141df539275ab047e7d7a67ff860cf2168/; sid:902202290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Cobalt C&C)"; tls.fingerprint:"85:14:71:ad:80:3a:2d:58:30:2c:e4:e7:09:1b:84:45:64:43:62:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/851471ad803a2d58302ce4e7091b84456443626e/; sid:902202291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"64:7c:00:a1:f7:27:bb:2f:1c:97:55:3d:4f:4b:a4:b5:18:42:ec:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/647c00a1f727bb2f1c97553d4f4ba4b51842ec74/; sid:902202292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"a8:27:af:b8:a4:f4:6d:06:63:7a:ac:05:6e:a3:91:3f:bc:ab:d8:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a827afb8a4f46d06637aac056ea3913fbcabd8bc/; sid:902202293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"d5:56:70:35:30:c7:b2:fa:bb:80:22:a7:77:fb:ff:fd:fc:95:b1:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d556703530c7b2fabb8022a777fbfffdfc95b16c/; sid:902202294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e2:49:94:e2:fb:a3:df:ef:bf:f7:6e:35:ea:37:b9:b8:83:bf:10:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e24994e2fba3dfefbff76e35ea37b9b883bf1034/; sid:902202295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"32:e2:ff:19:c0:9a:bb:cd:b5:64:94:25:ad:67:39:e9:1c:94:69:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32e2ff19c09abbcdb5649425ad6739e91c946923/; sid:902202296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"3c:f1:90:53:ae:2a:f4:c1:c3:87:45:d8:42:33:ea:f9:65:d9:31:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cf19053ae2af4c1c38745d84233eaf965d93187/; sid:902202297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Cobalt C&C)"; tls.fingerprint:"c6:e4:22:fd:5f:59:9e:ce:5d:0e:d6:51:12:00:5b:f2:18:92:ca:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6e422fd5f599ece5d0ed65112005bf21892ca16/; sid:902202298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"52:5d:2e:f8:df:f4:e7:21:19:ce:cb:76:47:48:28:5c:53:f2:13:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/525d2ef8dff4e72119cecb764748285c53f21327/; sid:902202299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"61:c6:d4:d5:ef:7a:ef:36:27:58:97:d6:63:5b:b7:a5:8a:3e:5b:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61c6d4d5ef7aef36275897d6635bb7a58a3e5b11/; sid:902202300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"aa:aa:54:9e:6e:6c:d5:23:3a:22:8b:4c:bb:72:06:a7:59:da:f4:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aaaa549e6e6cd5233a228b4cbb7206a759daf4cb/; sid:902202301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"aa:6a:2c:1d:61:be:29:34:08:a1:bd:aa:f3:da:51:da:49:c5:42:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa6a2c1d61be293408a1bdaaf3da51da49c542e1/; sid:902202302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Cobalt C&C)"; tls.fingerprint:"39:47:d0:e9:fd:01:c4:85:ed:0b:61:66:2b:8f:69:93:fc:c4:26:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3947d0e9fd01c485ed0b61662b8f6993fcc4267c/; sid:902202303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"4e:38:b2:76:fb:2d:3a:de:de:ee:50:ed:3a:a0:c0:d8:65:89:e2:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e38b276fb2d3adedeee50ed3aa0c0d86589e24c/; sid:902202304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"31:84:0e:a2:8e:21:e9:9c:1e:5c:8d:48:3b:20:da:aa:07:78:bb:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31840ea28e21e99c1e5c8d483b20daaa0778bb76/; sid:902202305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"4d:86:1b:8a:86:50:e3:e6:f1:45:e4:7d:a8:ea:2d:cc:7b:d4:38:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d861b8a8650e3e6f145e47da8ea2dcc7bd43883/; sid:902202306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6f:08:c9:6d:d7:cf:c5:da:1b:89:aa:9b:76:2a:91:3c:ea:f1:72:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f08c96dd7cfc5da1b89aa9b762a913ceaf17252/; sid:902202307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"55:ab:bf:41:5e:48:51:92:b1:bb:1f:df:7e:d1:21:2d:c9:86:c3:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55abbf415e485192b1bb1fdf7ed1212dc986c351/; sid:902202308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"54:6d:66:a7:23:cf:6c:45:86:cf:04:13:f1:69:59:7c:35:86:39:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/546d66a723cf6c4586cf0413f169597c3586394f/; sid:902202309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"74:3e:be:f6:94:16:d4:29:93:76:37:b2:1b:b6:2e:39:32:71:50:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/743ebef69416d429937637b21bb62e393271500d/; sid:902202310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"4c:8d:70:ec:7e:fb:4b:38:06:ef:1e:86:49:dc:9f:47:38:a2:7c:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c8d70ec7efb4b3806ef1e8649dc9f4738a27c98/; sid:902202311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"e9:fb:f9:ce:3a:3e:ea:7b:a2:bd:ad:ba:b1:63:cf:f2:14:8d:c9:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9fbf9ce3a3eea7ba2bdadbab163cff2148dc9e7/; sid:902202312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"01:be:74:65:68:57:6d:7a:ec:ee:c8:ee:6d:07:49:f1:26:0c:d6:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01be746568576d7aeceec8ee6d0749f1260cd686/; sid:902202313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"1a:b8:0a:1e:be:ce:5e:ad:35:b6:8e:2c:19:eb:ce:ef:6e:43:18:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ab80a1ebece5ead35b68e2c19ebceef6e431888/; sid:902202314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f6:2a:9d:0d:ba:6d:39:84:67:f3:7a:e8:e2:72:d6:c2:69:d7:eb:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f62a9d0dba6d398467f37ae8e272d6c269d7eb5d/; sid:902202315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"00:39:61:d4:a2:37:13:54:b2:33:80:86:97:cd:ad:4d:66:07:92:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/003961d4a2371354b233808697cdad4d660792a9/; sid:902202316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"88:65:fb:17:f0:50:fc:ea:17:4f:4b:cc:68:b9:b5:33:9e:b6:98:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8865fb17f050fcea174f4bcc68b9b5339eb698d3/; sid:902202317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"86:fe:3f:99:8c:40:05:17:67:e9:54:27:66:12:9e:83:33:65:24:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86fe3f998c40051767e9542766129e833365241f/; sid:902202318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"05:6d:df:72:0a:ab:43:45:0b:83:17:87:52:72:6e:82:76:1f:e3:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/056ddf720aab43450b83178752726e82761fe316/; sid:902202319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuantLoader C&C)"; tls.fingerprint:"a7:1f:89:9a:de:ab:0b:88:22:2b:81:66:c3:a6:53:6d:20:2a:2d:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a71f899adeab0b88222b8166c3a6536d202a2d02/; sid:902202320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuantLoader C&C)"; tls.fingerprint:"c1:2e:c7:ea:70:46:33:70:31:ee:6a:17:77:f7:9d:ba:21:98:de:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c12ec7ea7046337031ee6a1777f79dba2198def6/; sid:902202321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"8d:e9:dd:b6:34:ef:d8:33:ad:59:c3:55:9a:13:56:79:91:e5:05:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8de9ddb634efd833ad59c3559a13567991e50537/; sid:902202322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"79:22:7e:b9:43:4e:ac:83:89:a5:f9:0e:01:92:be:72:4c:aa:93:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79227eb9434eac8389a5f90e0192be724caa93dd/; sid:902202323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Trickbot C&C)"; tls.fingerprint:"b7:8f:93:23:15:e7:35:74:78:de:18:c1:d6:f0:9b:25:46:ec:3a:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b78f932315e7357478de18c1d6f09b2546ec3a1c/; sid:902202324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Trickbot C&C)"; tls.fingerprint:"d1:3b:d2:30:b6:96:f6:c3:bb:65:b5:a0:f1:99:fd:5c:58:79:2c:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d13bd230b696f6c3bb65b5a0f199fd5c58792c21/; sid:902202325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"9e:61:f8:d9:2b:30:38:85:d9:cb:6f:27:8d:0d:44:3e:11:ad:8c:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e61f8d92b303885d9cb6f278d0d443e11ad8ca7/; sid:902202326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c0:4a:0f:b7:bc:2f:61:fd:ce:c6:d2:ec:e8:fd:d1:13:48:3a:32:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c04a0fb7bc2f61fdcec6d2ece8fdd113483a323a/; sid:902202327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bd:83:72:81:6e:fa:5a:4e:ac:bd:26:a1:25:04:6f:08:86:c8:3f:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd8372816efa5a4eacbd26a125046f0886c83f35/; sid:902202328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"0a:82:03:9c:bc:71:8b:67:3e:0b:0c:34:1d:4a:96:01:d9:e8:59:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a82039cbc718b673e0b0c341d4a9601d9e859a1/; sid:902202329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"cf:fb:49:20:8d:80:e6:51:99:2f:22:66:5a:06:e8:fc:f9:85:ab:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cffb49208d80e651992f22665a06e8fcf985ab82/; sid:902202330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"0a:af:e0:6c:86:f4:d2:02:80:47:85:05:37:19:f7:59:5d:a5:14:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0aafe06c86f4d202804785053719f7595da514b9/; sid:902202331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Corebot C&C)"; tls.fingerprint:"be:0b:4d:fe:e0:a2:05:15:a3:0d:e2:5b:22:d1:65:a4:3d:fb:c0:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be0b4dfee0a20515a30de25b22d165a43dfbc07c/; sid:902202332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"be:bb:7c:da:06:10:e6:20:4f:29:41:c3:79:23:3a:c1:22:aa:b9:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bebb7cda0610e6204f2941c379233ac122aab973/; sid:902202333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"12:f3:ea:9d:65:4d:ee:a6:79:ad:ba:bd:27:62:1b:fc:d2:bb:aa:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12f3ea9d654deea679adbabd27621bfcd2bbaa33/; sid:902202334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"48:6a:af:c0:05:8f:f1:5e:08:0c:ed:c5:49:d0:f6:0d:64:fb:91:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/486aafc0058ff15e080cedc549d0f60d64fb91c1/; sid:902202335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ac:c7:46:d6:17:42:cb:bd:58:3f:a5:1d:78:ab:af:53:7c:fe:00:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acc746d61742cbbd583fa51d78abaf537cfe0047/; sid:902202336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c8:e6:7f:61:65:a5:63:14:8e:d0:16:93:a8:66:d2:ea:e1:29:0d:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8e67f6165a563148ed01693a866d2eae1290d7b/; sid:902202337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"93:e1:0a:63:a8:4e:81:e0:b4:6d:39:fe:3c:8a:26:c5:a9:c9:db:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93e10a63a84e81e0b46d39fe3c8a26c5a9c9db53/; sid:902202338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"1f:ba:b9:e8:de:c5:23:3a:fb:48:0e:a9:e3:ac:e7:be:c1:dc:98:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fbab9e8dec5233afb480ea9e3ace7bec1dc98bf/; sid:902202339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b5:cd:58:78:a1:45:3a:a7:da:65:47:88:76:b3:be:a9:dd:f6:d4:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5cd5878a1453aa7da65478876b3bea9ddf6d479/; sid:902202340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e1:38:df:e9:37:25:44:81:ad:5c:47:b0:7d:c8:9c:b2:c4:7b:12:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e138dfe937254481ad5c47b07dc89cb2c47b12f3/; sid:902202341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"24:bb:be:14:7a:1a:29:41:f7:0a:4f:6e:60:ea:87:76:0f:d0:6f:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24bbbe147a1a2941f70a4f6e60ea87760fd06f06/; sid:902202342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"25:1a:9d:f4:15:e2:a8:1e:93:97:94:53:ef:1a:88:74:f7:5d:70:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/251a9df415e2a81e93979453ef1a8874f75d70fc/; sid:902202343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"ee:4d:64:11:bc:8a:56:61:07:56:ec:f6:c8:22:17:df:c9:60:85:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee4d6411bc8a56610756ecf6c82217dfc9608528/; sid:902202344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"10:10:97:81:26:8c:e3:d9:43:1e:0a:8d:08:86:b9:44:00:bf:ce:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10109781268ce3d9431e0a8d0886b94400bfced3/; sid:902202345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4f:67:8d:31:85:86:38:1a:77:22:e5:fd:88:14:5e:91:e7:b3:0d:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f678d318586381a7722e5fd88145e91e7b30d2c/; sid:902202346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"43:fb:e0:db:76:3d:3d:6e:37:09:ac:8a:7b:46:69:e4:b3:d8:e5:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43fbe0db763d3d6e3709ac8a7b4669e4b3d8e5ee/; sid:902202347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"16:55:05:c9:54:ef:9c:18:2b:5d:ba:eb:98:83:4b:3d:50:25:bb:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/165505c954ef9c182b5dbaeb98834b3d5025bb31/; sid:902202348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"65:c0:c1:06:19:ca:af:5d:fa:ba:e0:46:9f:28:4e:9d:df:b2:92:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65c0c10619caaf5dfabae0469f284e9ddfb292fb/; sid:902202349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"86:af:39:2e:9b:42:ec:50:e2:87:f6:42:9e:f7:48:4c:48:bb:bd:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86af392e9b42ec50e287f6429ef7484c48bbbd95/; sid:902202350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"33:d6:73:5d:d1:05:c2:d0:d9:00:df:60:3c:16:bb:69:a3:9b:6f:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33d6735dd105c2d0d900df603c16bb69a39b6f5a/; sid:902202351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d0:bf:5d:40:33:79:d6:b9:50:8c:7f:0f:84:dd:3a:58:ed:6a:bc:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0bf5d403379d6b9508c7f0f84dd3a58ed6abc53/; sid:902202352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"63:b9:85:50:d1:cd:85:24:9c:85:6d:04:b2:eb:27:ec:8a:81:b6:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63b98550d1cd85249c856d04b2eb27ec8a81b6c9/; sid:902202353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"47:bb:5d:ec:74:45:47:f6:2c:c6:78:b0:ac:89:73:3c:de:51:40:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47bb5dec744547f62cc678b0ac89733cde514039/; sid:902202354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"66:61:ba:a6:0d:1a:12:48:be:57:6b:0c:f4:03:5d:f7:72:24:38:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6661baa60d1a1248be576b0cf4035df772243860/; sid:902202355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"07:72:c4:c6:a3:b4:89:71:4e:d5:17:5a:93:05:bb:7c:c0:86:fb:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0772c4c6a3b489714ed5175a9305bb7cc086fb17/; sid:902202356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d4:2b:50:12:18:0b:45:54:2b:4c:80:d9:bf:11:5c:d1:ce:c9:9c:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d42b5012180b45542b4c80d9bf115cd1cec99c67/; sid:902202357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedId C&C)"; tls.fingerprint:"aa:38:75:b3:f9:cb:de:32:f2:e1:a5:9c:72:f4:48:1b:d2:a6:a1:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa3875b3f9cbde32f2e1a59c72f4481bd2a6a180/; sid:902202358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedId C&C)"; tls.fingerprint:"77:f0:b3:ef:2a:93:9f:80:1d:c7:e7:61:e0:72:e7:1b:34:13:b1:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77f0b3ef2a939f801dc7e761e072e71b3413b1c1/; sid:902202359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"5e:82:63:19:ab:ea:f2:0f:0d:90:e9:75:5d:5a:c4:a6:2e:64:93:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e826319abeaf20f0d90e9755d5ac4a62e64931a/; sid:902202360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"46:aa:93:0d:14:4e:a3:27:ee:d4:c3:3c:44:02:23:3d:52:0c:4f:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46aa930d144ea327eed4c33c4402233d520c4f8b/; sid:902202361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"fb:d2:d6:bf:48:f2:f5:14:51:ce:b4:69:24:d2:e5:13:76:7e:82:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fbd2d6bf48f2f51451ceb46924d2e513767e8215/; sid:902202362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"4a:d2:77:c5:b7:fd:e7:cc:ab:01:4a:65:59:b7:b1:cf:ee:c0:21:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ad277c5b7fde7ccab014a6559b7b1cfeec0218f/; sid:902202363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"c4:7a:93:41:57:2d:05:9d:64:27:d2:4d:f9:65:26:7a:01:2b:d9:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c47a9341572d059d6427d24df965267a012bd9b7/; sid:902202364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"f9:67:1b:15:d5:b4:21:72:93:46:95:b6:14:9a:6f:1c:6b:04:85:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9671b15d5b42172934695b6149a6f1c6b0485bc/; sid:902202365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"18:59:ed:5a:a3:f7:22:08:90:cc:94:e8:3d:19:bb:3d:14:60:59:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1859ed5aa3f7220890cc94e83d19bb3d146059ae/; sid:902202366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"24:20:0d:6b:e5:dc:2b:91:cd:a6:e2:fe:cb:bd:ed:bb:d5:1b:8f:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24200d6be5dc2b91cda6e2fecbbdedbbd51b8f9c/; sid:902202367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"55:44:35:b1:c4:ab:1f:24:1a:08:a7:a0:8a:18:8a:05:d3:7f:5a:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/554435b1c4ab1f241a08a7a08a188a05d37f5a74/; sid:902202368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"27:a5:ba:d4:21:fb:64:b9:06:ba:07:9b:ad:dd:0e:5c:6e:b7:93:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27a5bad421fb64b906ba079baddd0e5c6eb7936f/; sid:902202369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"03:84:d2:35:e6:a7:36:d1:cb:56:7a:ea:36:0f:fd:dc:52:78:69:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0384d235e6a736d1cb567aea360ffddc5278698b/; sid:902202370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Trickbot C&C)"; tls.fingerprint:"29:64:69:69:f6:8f:41:6d:b8:ae:8c:a4:13:d4:d2:90:0a:e5:e8:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29646969f68f416db8ae8ca413d4d2900ae5e814/; sid:902202371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"6f:b3:f5:e9:05:9a:30:d7:a6:ba:44:64:a3:7d:b3:9b:ba:69:e7:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fb3f5e9059a30d7a6ba4464a37db39bba69e716/; sid:902202372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Trickbot C&C)"; tls.fingerprint:"c8:4c:e8:c4:4b:b6:59:ed:a3:11:4a:0c:e7:b5:f5:4c:7d:86:8c:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c84ce8c44bb659eda3114a0ce7b5f54c7d868cff/; sid:902202373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"49:02:c7:e0:f2:7f:35:a0:bd:cf:1d:c3:4c:db:d0:dd:90:c4:04:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4902c7e0f27f35a0bdcf1dc34cdbd0dd90c404f9/; sid:902202374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"51:fa:6c:81:07:cd:e5:59:76:a0:35:99:2e:49:0e:6f:10:0a:1c:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51fa6c8107cde55976a035992e490e6f100a1ca1/; sid:902202375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"d6:1b:eb:58:b1:66:2e:64:99:b6:2a:0d:f3:93:95:5b:9f:e4:6f:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d61beb58b1662e6499b62a0df393955b9fe46ffb/; sid:902202376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"e5:2c:7f:68:ec:01:54:34:f4:21:cc:0b:4e:40:ec:93:98:16:54:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e52c7f68ec015434f421cc0b4e40ec9398165412/; sid:902202377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"aa:67:d3:da:a2:2f:c2:55:6b:1e:81:77:fb:ac:bb:b2:4f:66:85:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa67d3daa22fc2556b1e8177fbacbbb24f668577/; sid:902202378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"6c:94:e4:fd:43:e4:fc:66:1b:f2:b2:f6:3e:1c:61:40:22:6c:e3:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c94e4fd43e4fc661bf2b2f63e1c6140226ce37a/; sid:902202379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"8c:8b:00:25:bb:8a:ca:f1:ed:25:b7:df:b2:f8:22:2d:61:53:b4:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c8b0025bb8acaf1ed25b7dfb2f8222d6153b4d8/; sid:902202380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"90:8a:df:d0:55:32:c9:fa:42:0e:1e:0f:4f:39:bb:6a:69:b5:29:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/908adfd05532c9fa420e1e0f4f39bb6a69b529ec/; sid:902202381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"38:37:e4:30:19:24:fd:86:7b:24:1b:02:d1:27:3f:31:48:77:3b:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3837e4301924fd867b241b02d1273f3148773b83/; sid:902202382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"78:fe:7c:56:1c:43:52:bb:9c:16:1c:12:a0:29:38:b1:c4:2e:70:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78fe7c561c4352bb9c161c12a02938b1c42e70cc/; sid:902202383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"20:ff:ea:17:d3:4c:83:2f:7e:77:3a:6a:03:7c:fc:59:00:21:1a:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20ffea17d34c832f7e773a6a037cfc5900211a2a/; sid:902202384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Neutrino C&C)"; tls.fingerprint:"e1:a5:8a:14:6e:22:9c:c3:0d:47:75:9a:18:d6:da:6b:e3:b8:b7:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1a58a146e229cc30d47759a18d6da6be3b8b70c/; sid:902202385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (JBifrost C&C)"; tls.fingerprint:"bb:07:bd:6f:83:9f:23:6b:8e:dd:49:5e:1a:36:1f:3f:5f:70:2e:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb07bd6f839f236b8edd495e1a361f3f5f702e71/; sid:902202386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"e0:1b:1d:77:1b:ac:35:16:7c:79:e1:38:91:25:54:a1:60:57:7f:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e01b1d771bac35167c79e138912554a160577f3f/; sid:902202387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"64:8a:ad:16:9c:99:e9:97:7e:f9:5b:f2:20:10:10:f8:88:80:82:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/648aad169c99e9977ef95bf2201010f888808222/; sid:902202388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"91:b5:68:ea:95:2c:bf:4a:d6:55:cc:32:15:90:fc:65:cd:ff:9d:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91b568ea952cbf4ad655cc321590fc65cdff9de6/; sid:902202389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"03:2f:69:7e:5a:17:20:f5:59:97:29:09:ee:cc:1e:7a:1b:ff:67:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/032f697e5a1720f559972909eecc1e7a1bff67be/; sid:902202390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"50:ef:77:4f:2d:86:65:9b:55:e2:41:1f:37:90:19:9c:e3:fa:3c:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50ef774f2d86659b55e2411f3790199ce3fa3c5e/; sid:902202391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"4d:8e:93:19:ba:4b:8d:20:5d:c7:c0:8d:28:0e:f0:0f:46:08:98:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d8e9319ba4b8d205dc7c08d280ef00f460898cf/; sid:902202392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"24:eb:69:f3:d1:b9:4e:49:6b:15:19:54:33:64:0e:d6:99:1b:c0:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24eb69f3d1b94e496b15195433640ed6991bc05a/; sid:902202393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"dc:45:c4:5a:c1:bd:2c:fd:21:63:ec:61:da:70:00:59:9c:d4:5a:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc45c45ac1bd2cfd2163ec61da7000599cd45aaf/; sid:902202394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"cd:a6:eb:fe:ea:00:3d:d9:0d:79:ab:6b:34:1e:ed:25:69:43:9c:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cda6ebfeea003dd90d79ab6b341eed2569439c2d/; sid:902202395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (JBifrost C&C)"; tls.fingerprint:"bb:d4:38:0b:ab:66:8d:9a:7f:92:59:b4:4f:fc:5c:93:b9:91:e9:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbd4380bab668d9a7f9259b44ffc5c93b991e99e/; sid:902202396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"33:60:d8:59:0e:75:19:d9:b0:e1:ef:17:89:09:0b:9d:67:df:33:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3360d8590e7519d9b0e1ef1789090b9d67df3344/; sid:902202397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"df:ca:93:b2:4b:40:8e:a6:ea:5f:93:7f:c3:1a:60:2a:66:b7:22:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfca93b24b408ea6ea5f937fc31a602a66b722d1/; sid:902202398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"81:b6:20:37:f9:d5:3a:ee:b0:6a:9b:39:41:1c:a9:a3:0e:8c:62:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81b62037f9d53aeeb06a9b39411ca9a30e8c6216/; sid:902202399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"8d:fc:45:5a:31:9f:2a:f4:ed:17:f3:7e:19:e7:cc:f0:05:34:11:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dfc455a319f2af4ed17f37e19e7ccf0053411d9/; sid:902202400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"7c:58:c7:ec:9e:cd:0e:5e:6f:02:2b:d7:2a:f4:15:aa:4f:52:ad:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c58c7ec9ecd0e5e6f022bd72af415aa4f52ad10/; sid:902202401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"06:cb:f1:2a:81:aa:63:04:57:d2:68:36:c6:2a:c0:bb:aa:77:f3:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06cbf12a81aa630457d26836c62ac0bbaa77f3f9/; sid:902202402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"27:3b:0f:ab:7e:fd:e3:65:25:63:2e:74:98:9b:3e:a5:38:3f:3e:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/273b0fab7efde36525632e74989b3ea5383f3e05/; sid:902202403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e9:8b:d7:5c:f7:e9:92:84:7d:d1:64:39:7a:62:df:aa:c0:36:d1:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e98bd75cf7e992847dd164397a62dfaac036d14b/; sid:902202404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"1f:1d:4a:59:b9:d7:20:d6:9d:df:cd:65:b9:0d:51:e5:23:66:a2:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f1d4a59b9d720d69ddfcd65b90d51e52366a2e3/; sid:902202405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1e:85:b5:59:a3:c5:2d:45:c4:b6:82:82:d1:0b:21:bb:a3:a8:78:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e85b559a3c52d45c4b68282d10b21bba3a878a5/; sid:902202406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7b:21:cf:dd:cf:88:de:4c:38:32:a0:7d:0a:0f:22:b2:32:ce:25:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b21cfddcf88de4c3832a07d0a0f22b232ce251b/; sid:902202407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fc:ab:10:cf:56:45:9c:8c:25:7f:54:39:d0:11:51:45:9d:e7:93:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcab10cf56459c8c257f5439d01151459de79363/; sid:902202408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a2:db:2b:8e:32:11:10:60:8d:a4:d7:fb:ce:45:98:8f:f8:ea:a0:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2db2b8e321110608da4d7fbce45988ff8eaa048/; sid:902202409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"0e:d2:66:20:06:05:c8:61:f8:ee:04:23:9e:92:12:87:d0:b2:0a:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ed266200605c861f8ee04239e921287d0b20a21/; sid:902202410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"4a:05:57:91:3a:4b:6e:5a:8e:69:74:5b:41:14:9e:5b:16:f8:96:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a0557913a4b6e5a8e69745b41149e5b16f8964f/; sid:902202411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"26:00:35:eb:97:20:d8:79:95:1b:e4:10:59:15:df:63:29:c9:c0:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/260035eb9720d879951be4105915df6329c9c0e3/; sid:902202412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"a0:79:a1:69:44:67:fe:94:e6:ee:e9:5b:0e:ad:9b:65:2b:69:f7:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a079a1694467fe94e6eee95b0ead9b652b69f774/; sid:902202413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"e0:d9:03:bb:dd:c6:42:e5:f7:82:0b:22:d8:6e:ae:9e:15:a7:b2:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0d903bbddc642e5f7820b22d86eae9e15a7b2f8/; sid:902202414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Quakbot C&C)"; tls.fingerprint:"6c:fe:bb:47:09:8a:bd:1b:3e:1e:cd:cc:14:e2:94:a3:36:84:88:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cfebb47098abd1b3e1ecdcc14e294a3368488fa/; sid:902202415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"e9:76:1a:a8:44:2c:5a:77:d2:d3:67:cb:6b:4c:5b:0d:b9:7c:da:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9761aa8442c5a77d2d367cb6b4c5b0db97cda64/; sid:902202416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"87:9c:44:5c:7a:5b:31:9e:e0:4e:3a:1d:1e:34:24:f4:6b:15:06:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/879c445c7a5b319ee04e3a1d1e3424f46b15064e/; sid:902202417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"7b:e5:9f:8f:08:11:aa:bc:b7:3c:9f:1c:7d:f3:b3:e6:6f:96:4c:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7be59f8f0811aabcb73c9f1c7df3b3e66f964ca0/; sid:902202418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Godzilla C&C)"; tls.fingerprint:"91:1b:fb:c7:6d:3c:05:6b:8f:61:ae:ce:04:2f:ef:cc:d2:be:07:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/911bfbc76d3c056b8f61aece042fefccd2be0741/; sid:902202419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"d3:70:34:3a:1c:20:c3:09:ff:59:86:01:a1:06:ec:9b:38:5c:55:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d370343a1c20c309ff598601a106ec9b385c55c2/; sid:902202420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"90:27:03:c5:69:f3:a5:b5:51:67:00:c8:3d:2a:a1:83:7d:26:92:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/902703c569f3a5b5516700c83d2aa1837d2692d5/; sid:902202421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"8a:9a:ab:e3:cb:98:60:8e:65:d1:0c:9c:f0:b4:c5:3a:f9:a8:fb:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a9aabe3cb98608e65d10c9cf0b4c53af9a8fb6f/; sid:902202422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AgentTesla C&C)"; tls.fingerprint:"f6:da:c3:39:e1:6f:90:b8:4d:91:58:8e:7f:58:1f:35:f2:0d:e2:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6dac339e16f90b84d91588e7f581f35f20de2a7/; sid:902202423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"0e:ca:9e:f8:35:6e:ce:1b:e7:32:d9:f6:fc:01:a8:e5:37:af:26:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0eca9ef8356ece1be732d9f6fc01a8e537af2611/; sid:902202424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"1e:7a:0c:90:03:f3:32:a7:01:0f:ec:12:7f:79:dc:28:3e:be:c6:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e7a0c9003f332a7010fec127f79dc283ebec65c/; sid:902202425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedId C&C)"; tls.fingerprint:"81:6c:8e:ed:c2:63:2d:e8:a8:8b:77:7e:28:f9:1a:4f:3f:7e:89:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/816c8eedc2632de8a88b777e28f91a4f3f7e8936/; sid:902202426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"01:a4:58:bd:2d:46:b4:38:3b:11:46:9f:1c:8e:4f:33:67:53:ec:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01a458bd2d46b4383b11469f1c8e4f336753ec4d/; sid:902202427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"56:1a:72:26:7a:de:93:d2:7c:59:ba:c1:7e:08:ea:41:13:21:54:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/561a72267ade93d27c59bac17e08ea411321548b/; sid:902202428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"41:5d:67:5f:e2:87:39:b2:63:dd:69:d7:b3:c3:88:13:84:df:b3:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/415d675fe28739b263dd69d7b3c3881384dfb381/; sid:902202429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b9:15:72:36:5a:7e:b7:1c:32:4f:67:dc:08:ac:0f:96:b0:a1:0b:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b91572365a7eb71c324f67dc08ac0f96b0a10bf2/; sid:902202430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"27:4e:6b:65:83:4c:29:ac:9c:f7:60:e4:35:d2:74:4e:cb:f2:57:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/274e6b65834c29ac9cf760e435d2744ecbf25736/; sid:902202431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"32:fd:c0:8f:0e:5b:bd:94:d9:48:72:3f:5b:d1:86:ff:ab:96:38:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32fdc08f0e5bbd94d948723f5bd186ffab9638ee/; sid:902202432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"11:a3:71:40:0d:c9:e6:e3:1b:f5:10:c0:8f:d2:bf:b4:d2:26:f0:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11a371400dc9e6e31bf510c08fd2bfb4d226f056/; sid:902202433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"c3:09:eb:88:fe:d4:9b:93:25:54:88:52:79:b9:aa:05:71:9c:cd:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c309eb88fed49b932554885279b9aa05719ccd61/; sid:902202434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"ef:88:a8:2e:c4:d8:53:ed:f8:49:28:a5:ba:cc:a4:ea:c8:4c:b5:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef88a82ec4d853edf84928a5bacca4eac84cb5dc/; sid:902202435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f3:36:0e:03:9f:06:9d:0a:5c:4d:b8:e8:48:bd:bf:1a:8b:ff:46:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3360e039f069d0a5c4db8e848bdbf1a8bff461a/; sid:902202436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"de:d1:f2:77:d9:be:c1:f6:e6:ba:23:79:4c:5a:5a:80:b3:9a:ee:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ded1f277d9bec1f6e6ba23794c5a5a80b39aeee4/; sid:902202437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"b6:f8:4c:4c:e2:41:3e:59:d9:d7:a8:95:b9:34:3f:64:81:98:90:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6f84c4ce2413e59d9d7a895b9343f64819890d5/; sid:902202438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Neutrino C&C)"; tls.fingerprint:"67:88:d7:dc:2b:81:8c:98:8e:07:d8:91:13:9b:96:3c:39:61:5d:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6788d7dc2b818c988e07d891139b963c39615d8a/; sid:902202439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3f:03:cd:3f:d3:66:ad:cd:3c:6c:db:f8:35:ae:72:e2:72:c5:c9:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f03cd3fd366adcd3c6cdbf835ae72e272c5c904/; sid:902202440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"cb:66:0b:8e:58:fa:3e:8b:85:f7:a4:75:f3:7f:b3:7a:3e:07:2e:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb660b8e58fa3e8b85f7a475f37fb37a3e072e4f/; sid:902202441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"34:61:60:fd:d3:6f:63:56:2b:60:e3:ed:39:d1:fd:65:b3:e5:d2:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/346160fdd36f63562b60e3ed39d1fd65b3e5d282/; sid:902202442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3a:1f:60:e1:65:0f:c9:29:79:c6:22:64:8f:be:e1:5e:ce:6c:7a:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a1f60e1650fc92979c622648fbee15ece6c7a69/; sid:902202443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"32:17:fa:d9:7e:f7:9c:5f:fd:02:24:62:9b:ef:a8:df:5e:7f:92:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3217fad97ef79c5ffd0224629befa8df5e7f92ff/; sid:902202444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RevCodeRAT C&C)"; tls.fingerprint:"df:e1:a7:f8:a0:02:88:bd:50:13:61:e4:72:18:7b:9f:71:4b:ea:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfe1a7f8a00288bd501361e472187b9f714bea21/; sid:902202445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"e4:04:61:15:78:42:7b:91:9c:fe:99:56:0c:cd:55:f9:b0:af:a4:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e404611578427b919cfe99560ccd55f9b0afa4ad/; sid:902202446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"59:2b:c7:2a:43:de:df:22:2c:7d:44:35:e0:2d:ad:0d:8a:8a:2a:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/592bc72a43dedf222c7d4435e02dad0d8a8a2a55/; sid:902202447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"d3:32:98:d1:fe:3d:43:ec:c0:87:c2:88:3f:ba:8a:6c:c1:24:c4:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d33298d1fe3d43ecc087c2883fba8a6cc124c42e/; sid:902202448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"90:cb:e1:c1:78:89:25:72:f2:42:79:45:c2:80:c8:89:b3:7a:82:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90cbe1c178892572f2427945c280c889b37a82bd/; sid:902202449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"9b:97:45:ca:28:5a:39:0d:ed:ed:ca:e5:53:df:50:8b:3b:45:01:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b9745ca285a390dededcae553df508b3b450127/; sid:902202450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"05:b2:3a:86:fe:8e:9c:0a:5f:68:ff:7a:72:ee:3c:65:ce:6d:d6:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05b23a86fe8e9c0a5f68ff7a72ee3c65ce6dd61f/; sid:902202451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ea:e7:19:ff:45:92:30:73:22:3a:8f:fe:06:5b:b7:33:b2:f0:f6:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eae719ff45923073223a8ffe065bb733b2f0f6b6/; sid:902202452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"81:7c:e4:c9:b0:36:bc:5f:76:e2:7b:fe:5f:02:fd:dc:b6:bb:8a:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/817ce4c9b036bc5f76e27bfe5f02fddcb6bb8a80/; sid:902202453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"26:30:75:8f:20:6f:a9:48:92:ff:bd:10:94:0c:86:a8:86:ac:18:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2630758f206fa94892ffbd10940c86a886ac1814/; sid:902202454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PlugX C&C)"; tls.fingerprint:"16:0b:26:68:d6:72:06:c1:a6:ed:b3:b6:04:8d:77:b6:be:2b:ec:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/160b2668d67206c1a6edb3b6048d77b6be2becc7/; sid:902202455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cf:ba:3a:23:0f:38:b1:ce:2c:0f:6c:84:85:4f:b1:f1:db:e7:4d:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfba3a230f38b1ce2c0f6c84854fb1f1dbe74d46/; sid:902202456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"a1:db:30:fa:02:97:55:10:06:48:c0:05:58:eb:32:74:c4:c9:8b:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1db30fa029755100648c00558eb3274c4c98b1d/; sid:902202457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"de:d6:8c:5f:77:07:c1:8a:9c:cc:37:a1:21:27:d0:6a:95:e9:e9:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ded68c5f7707c18a9ccc37a12127d06a95e9e97e/; sid:902202458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"19:3e:5a:e8:78:e2:a7:1f:4f:cc:60:f4:21:68:bc:63:d1:9d:1f:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/193e5ae878e2a71f4fcc60f42168bc63d19d1fb5/; sid:902202459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f5:63:9b:20:d1:35:17:44:5e:5d:fb:6c:01:d1:f2:4d:f6:16:b0:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5639b20d13517445e5dfb6c01d1f24df616b034/; sid:902202460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"98:c9:7e:bc:f9:a1:6f:60:41:36:30:7b:cf:25:1f:9e:00:75:5d:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98c97ebcf9a16f604136307bcf251f9e00755d99/; sid:902202461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"46:4b:cd:ed:25:95:72:2c:00:c2:44:70:98:06:b6:4b:95:fd:52:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/464bcded2595722c00c244709806b64b95fd52cc/; sid:902202462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"de:d0:f2:f4:52:cf:44:8b:64:ac:9e:47:5c:3e:62:1e:dd:7a:7f:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ded0f2f452cf448b64ac9e475c3e621edd7a7f87/; sid:902202463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"38:83:e2:f7:30:57:40:57:d5:cd:f9:1e:ae:56:2b:9c:56:e5:b5:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3883e2f730574057d5cdf91eae562b9c56e5b50d/; sid:902202464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2c:34:71:27:a7:33:33:09:51:af:90:bd:39:1d:4c:b2:5c:f6:86:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c347127a733330951af90bd391d4cb25cf68620/; sid:902202465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5b:66:b1:0a:ec:a3:0b:93:d2:c7:76:c9:2b:3b:cb:02:d6:d3:6a:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b66b10aeca30b93d2c776c92b3bcb02d6d36ae5/; sid:902202466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7e:55:fb:87:67:15:0f:56:55:cd:0a:b8:53:c4:6c:cd:83:e0:e2:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e55fb8767150f5655cd0ab853c46ccd83e0e26c/; sid:902202467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"b1:5b:34:ca:a4:71:58:b1:7b:5d:64:fc:ce:46:21:19:35:5c:db:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b15b34caa47158b17b5d64fcce462119355cdb16/; sid:902202468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5c:95:5d:b9:6e:be:42:de:ea:35:db:89:92:ca:f9:43:e2:a3:3d:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c955db96ebe42deea35db8992caf943e2a33db1/; sid:902202469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ac:d5:3a:9a:fe:1e:cc:f4:13:14:05:19:93:5d:ab:f7:52:b4:43:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acd53a9afe1eccf413140519935dabf752b4434b/; sid:902202470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ac:2d:7d:26:06:2d:68:bc:48:87:0c:fe:1a:fb:c1:dd:42:a2:43:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac2d7d26062d68bc48870cfe1afbc1dd42a24341/; sid:902202471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedId C&C)"; tls.fingerprint:"d6:41:2d:b5:0d:f6:62:b5:af:43:a2:a2:0d:fe:58:e0:0c:ab:09:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6412db50df662b5af43a2a20dfe58e00cab0996/; sid:902202472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"a2:39:ed:1a:80:53:2b:74:1f:b9:e0:94:cd:51:b0:5c:ea:9b:6f:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a239ed1a80532b741fb9e094cd51b05cea9b6ffa/; sid:902202473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a9:03:28:dc:8d:f0:80:df:60:1e:67:3f:30:59:a7:03:c0:c4:06:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a90328dc8df080df601e673f3059a703c0c40684/; sid:902202474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d0:5e:2e:91:f5:75:61:10:6c:b0:83:83:e6:99:6e:a7:2a:d9:a0:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d05e2e91f57561106cb08383e6996ea72ad9a035/; sid:902202475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f5:79:9d:92:0d:c1:e4:34:b0:87:33:d3:79:d8:b2:85:9a:00:ca:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5799d920dc1e434b08733d379d8b2859a00ca24/; sid:902202476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f7:9b:be:93:2d:59:f4:c5:03:a5:33:8d:bc:3a:24:de:a7:c2:f6:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f79bbe932d59f4c503a5338dbc3a24dea7c2f6ea/; sid:902202477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CoinMiner C&C)"; tls.fingerprint:"84:ec:9d:5d:57:9c:aa:09:83:fe:30:91:7e:09:aa:35:5a:f9:fe:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84ec9d5d579caa0983fe30917e09aa355af9fe3c/; sid:902202478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"82:80:52:63:69:cf:bb:46:ed:5d:87:99:f6:51:b0:e6:9a:73:09:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8280526369cfbb46ed5d8799f651b0e69a73099f/; sid:902202479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f0:f6:30:28:24:cd:73:b2:c8:b6:dd:8e:0c:d3:25:a3:ef:08:24:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0f6302824cd73b2c8b6dd8e0cd325a3ef082409/; sid:902202480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"42:75:c1:28:8b:76:98:3c:d6:ec:48:b4:79:08:99:2f:13:41:63:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4275c1288b76983cd6ec48b47908992f13416354/; sid:902202481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"10:b9:1a:45:3a:e6:c3:dc:71:df:8d:44:85:fa:48:92:99:b9:85:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10b91a453ae6c3dc71df8d4485fa489299b9859f/; sid:902202482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"f3:50:26:cf:90:e2:b7:6b:8b:74:d9:45:bf:19:1f:cc:02:c3:bd:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f35026cf90e2b76b8b74d945bf191fcc02c3bdc5/; sid:902202483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fc:72:a8:a7:b4:67:b2:76:32:4d:92:31:c9:e4:5f:c3:10:0c:0c:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc72a8a7b467b276324d9231c9e45fc3100c0cdc/; sid:902202484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8c:c8:47:8b:20:f1:70:1f:8d:58:41:05:59:da:00:57:78:2f:22:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8cc8478b20f1701f8d58410559da0057782f2258/; sid:902202485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"45:5d:8e:38:4d:21:4c:17:d3:45:22:41:3a:98:dc:00:23:52:b7:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/455d8e384d214c17d34522413a98dc002352b78e/; sid:902202486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"60:11:78:22:72:80:3e:d6:c3:0a:3e:91:56:c8:a7:18:c9:9c:39:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6011782272803ed6c30a3e9156c8a718c99c3974/; sid:902202487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4e:f2:cc:e6:ed:ae:cb:12:65:22:59:cd:f9:81:5b:65:6d:1d:a2:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ef2cce6edaecb12652259cdf9815b656d1da27a/; sid:902202488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d9:37:f9:49:68:e0:cd:d1:b7:df:10:99:e6:1f:86:75:24:a1:ad:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d937f94968e0cdd1b7df1099e61f867524a1ad81/; sid:902202489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a5:85:fb:98:c1:71:bd:5e:2c:91:fb:b5:a3:23:64:df:6e:13:6f:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a585fb98c171bd5e2c91fbb5a32364df6e136f1f/; sid:902202490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5b:42:11:d7:1b:ea:47:b6:5f:dc:d5:26:b1:7a:6e:f3:2a:f6:5c:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b4211d71bea47b65fdcd526b17a6ef32af65c5d/; sid:902202491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"60:a3:76:7e:f8:b6:80:c7:86:71:95:63:83:69:b0:51:ce:b5:45:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60a3767ef8b680c7867195638369b051ceb545d7/; sid:902202492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ba:66:b8:10:3d:8f:a5:c3:0e:b6:46:49:bd:24:cf:cb:08:93:bf:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba66b8103d8fa5c30eb64649bd24cfcb0893bf37/; sid:902202493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"34:ad:00:df:ba:a6:1d:0f:03:7a:8c:32:d9:2d:f7:7e:d6:38:38:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34ad00dfbaa61d0f037a8c32d92df77ed63838ec/; sid:902202494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ec:ed:fc:67:4b:72:45:69:c0:1c:4d:a4:53:6f:d7:f8:ed:60:65:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecedfc674b724569c01c4da4536fd7f8ed60650f/; sid:902202495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"9b:c0:71:9a:6b:45:02:7c:6b:18:c3:c6:a9:22:84:c6:36:51:0a:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bc0719a6b45027c6b18c3c6a92284c636510a65/; sid:902202496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PandaZeuS C&C)"; tls.fingerprint:"e8:a1:74:bd:78:96:e9:7d:ca:77:ec:a0:e5:eb:1c:ab:6d:68:08:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8a174bd7896e97dca77eca0e5eb1cab6d680894/; sid:902202497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"14:f2:a0:8a:c3:07:c0:02:5f:39:47:c4:5e:e1:28:42:28:f9:78:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14f2a08ac307c0025f3947c45ee1284228f97842/; sid:902202498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8b:2f:81:38:1d:66:32:72:76:4b:f9:29:aa:d9:b8:00:b2:56:1a:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b2f81381d663272764bf929aad9b800b2561a22/; sid:902202499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"3e:26:b4:46:41:70:a1:59:49:7c:79:98:16:85:24:dd:e5:65:a2:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e26b4464170a159497c7998168524dde565a2f1/; sid:902202500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e9:5a:33:88:c2:a7:96:fb:e0:5e:c1:1e:1f:f5:bc:b4:b6:72:60:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e95a3388c2a796fbe05ec11e1ff5bcb4b67260f5/; sid:902202501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"67:46:07:2c:2f:7c:05:77:e4:05:56:2e:3e:21:72:c9:d3:00:37:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6746072c2f7c0577e405562e3e2172c9d300370d/; sid:902202502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"01:b8:a3:89:9b:ae:90:fb:4c:4e:05:96:d5:48:00:34:07:d6:5b:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01b8a3899bae90fb4c4e0596d548003407d65b53/; sid:902202503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"66:f6:92:63:1b:d7:c5:82:5c:69:fe:94:1a:68:47:b9:96:8f:d7:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66f692631bd7c5825c69fe941a6847b9968fd72f/; sid:902202504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5d:8e:26:00:0d:2c:35:f4:07:e9:aa:be:58:aa:00:c6:7f:c3:0b:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d8e26000d2c35f407e9aabe58aa00c67fc30b8b/; sid:902202505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5d:6e:fa:1e:8d:d9:d2:d9:67:8a:16:b9:cb:c9:81:47:3b:11:96:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d6efa1e8dd9d2d9678a16b9cbc981473b1196ed/; sid:902202506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"5b:38:cd:65:8f:78:a0:20:10:ba:1e:e6:ef:d5:2b:97:80:92:09:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b38cd658f78a02010ba1ee6efd52b97809209c3/; sid:902202507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"64:c8:42:14:79:42:b6:e7:a7:fb:09:d9:02:76:66:96:ad:07:de:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64c842147942b6e7a7fb09d902766696ad07de89/; sid:902202508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b7:81:c5:2d:5b:3a:56:6d:d0:65:91:81:ff:3d:14:84:8c:04:45:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b781c52d5b3a566dd0659181ff3d14848c0445be/; sid:902202509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e3:43:fe:e3:ad:bf:70:e5:34:37:07:d2:9b:f3:45:56:bd:0d:3f:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e343fee3adbf70e5343707d29bf34556bd0d3f27/; sid:902202510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c5:26:33:61:ea:09:64:98:cf:9d:c6:3b:8a:96:7c:9e:26:92:47:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5263361ea096498cf9dc63b8a967c9e2692470b/; sid:902202511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"73:c3:4b:94:98:93:4f:5f:78:1a:46:87:ba:c2:90:17:f6:c9:5f:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73c34b9498934f5f781a4687bac29017f6c95fac/; sid:902202512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"58:f8:fa:bc:ac:cf:b7:7c:a5:48:15:d1:c8:13:02:3f:c8:70:17:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58f8fabcaccfb77ca54815d1c813023fc870172d/; sid:902202513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b9:57:c8:02:5a:ac:4e:da:cc:8f:3a:9b:3b:cd:9b:2c:30:97:78:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b957c8025aac4edacc8f3a9b3bcd9b2c30977805/; sid:902202514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"90:7c:73:ee:89:0f:4f:b7:89:b2:0d:17:e4:35:2d:eb:f1:b0:f8:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/907c73ee890f4fb789b20d17e4352debf1b0f8f9/; sid:902202515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c1:7c:2b:b7:38:62:7e:81:9e:93:39:f5:7e:8b:98:96:7e:09:f3:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c17c2bb738627e819e9339f57e8b98967e09f3cb/; sid:902202516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f4:eb:3c:7d:e0:3b:77:76:8b:a3:0a:b3:54:4c:87:90:e5:46:51:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4eb3c7de03b77768ba30ab3544c8790e546514f/; sid:902202517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"38:8d:99:59:2d:32:b7:60:7e:5c:cb:ff:f6:08:78:d1:4e:c2:16:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/388d99592d32b7607e5ccbfff60878d14ec2163f/; sid:902202518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"98:68:fd:c9:a9:dd:14:97:ce:4f:ad:ad:7c:8d:44:14:07:e0:af:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9868fdc9a9dd1497ce4fadad7c8d441407e0afee/; sid:902202519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"eb:65:5b:ef:01:a9:70:ec:00:ff:5b:3b:bf:ae:ae:96:b8:02:7a:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb655bef01a970ec00ff5b3bbfaeae96b8027a06/; sid:902202520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"9c:0a:86:3f:8f:c3:ed:a4:57:18:ba:00:5e:11:ad:68:91:b7:56:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c0a863f8fc3eda45718ba005e11ad6891b75631/; sid:902202521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"05:94:6f:5e:76:64:d0:84:30:55:00:3b:e6:aa:63:5d:6c:69:24:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05946f5e7664d0843055003be6aa635d6c69243b/; sid:902202522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a5:58:47:bc:3a:b9:21:01:a7:05:0d:07:e9:d0:42:a2:27:2a:fd:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a55847bc3ab92101a7050d07e9d042a2272afd77/; sid:902202523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"60:4c:15:52:88:60:f0:f9:de:f6:a5:ac:e4:19:10:5f:13:3a:88:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/604c15528860f0f9def6a5ace419105f133a886c/; sid:902202524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b0:5d:8b:ff:3c:d8:60:c0:05:fe:98:da:c3:b3:8e:c1:4f:46:bd:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b05d8bff3cd860c005fe98dac3b38ec14f46bd7b/; sid:902202525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fb:26:15:62:4b:31:ec:99:8f:5a:70:6d:e5:f8:73:90:57:be:eb:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb2615624b31ec998f5a706de5f8739057beebc9/; sid:902202526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1e:91:b3:70:24:81:31:94:61:27:bc:a8:dc:21:32:2a:d1:00:06:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e91b370248131946127bca8dc21322ad1000653/; sid:902202527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d2:24:e5:be:bb:cb:3a:b7:20:6d:70:30:e1:51:58:ac:1e:f8:8f:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d224e5bebbcb3ab7206d7030e15158ac1ef88f7c/; sid:902202528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b6:2a:f5:2f:f5:63:89:ee:60:d2:30:6a:ab:f4:ff:d1:f0:58:d2:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b62af52ff56389ee60d2306aabf4ffd1f058d2dc/; sid:902202529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"26:80:88:84:50:c9:f7:9c:f7:d3:c6:ea:9f:2e:4a:f9:8f:96:cf:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2680888450c9f79cf7d3c6ea9f2e4af98f96cfef/; sid:902202530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ab:4e:c2:61:cf:ea:45:9e:21:70:97:db:b9:fc:f6:19:63:ff:89:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab4ec261cfea459e217097dbb9fcf61963ff890e/; sid:902202531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ad:b1:c8:6b:00:ed:2a:d3:8e:00:42:8d:8f:34:8d:53:d5:f8:59:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/adb1c86b00ed2ad38e00428d8f348d53d5f85967/; sid:902202532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"77:45:7b:9d:c2:45:ec:9c:ff:b2:e3:38:83:b3:bf:df:37:3d:fe:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77457b9dc245ec9cffb2e33883b3bfdf373dfeca/; sid:902202533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex malware distribution)"; tls.fingerprint:"3b:db:2f:4b:21:9c:b0:8d:bf:ba:e4:dc:08:81:a1:62:37:e7:ad:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bdb2f4b219cb08dbfbae4dc0881a16237e7ad68/; sid:902202534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"0f:3f:71:70:20:b1:32:bd:e9:6c:9d:00:17:3a:7a:53:dd:68:ea:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f3f717020b132bde96c9d00173a7a53dd68ead9/; sid:902202535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"ec:e2:71:9a:4d:35:7e:7e:a7:00:24:f6:51:af:8d:9c:ce:43:25:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ece2719a4d357e7ea70024f651af8d9cce43256b/; sid:902202536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"76:69:10:3e:a0:a2:e9:00:17:9e:52:20:a1:3b:f3:41:54:38:b6:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7669103ea0a2e900179e5220a13bf3415438b665/; sid:902202537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"27:1e:87:98:5f:3d:6b:e3:9e:94:a1:25:e1:76:6d:99:6f:3f:1e:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/271e87985f3d6be39e94a125e1766d996f3f1e6c/; sid:902202538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ff:5d:86:92:50:a5:c8:c0:8e:dc:fe:83:25:c1:a1:0e:28:3e:cb:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff5d869250a5c8c08edcfe8325c1a10e283ecb1f/; sid:902202539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c8:92:27:62:73:a6:2a:cb:df:f9:f6:ce:68:85:d0:9f:4f:95:c9:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c892276273a62acbdff9f6ce6885d09f4f95c944/; sid:902202540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d3:dd:70:6d:4d:c2:5e:e6:3a:55:02:b0:7f:d2:06:32:14:a9:46:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3dd706d4dc25ee63a5502b07fd2063214a94651/; sid:902202541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"21:bc:5c:b3:66:1d:43:36:66:b0:b9:68:44:30:61:56:1b:82:18:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21bc5cb3661d433666b0b968443061561b8218f8/; sid:902202542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"41:12:fd:7e:6a:5f:6d:49:90:ef:99:d3:10:c1:e2:03:15:23:be:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4112fd7e6a5f6d4990ef99d310c1e2031523be38/; sid:902202543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7b:97:6d:83:a1:8a:cd:d0:a0:bc:6d:74:c7:c6:1e:95:63:aa:4f:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b976d83a18acdd0a0bc6d74c7c61e9563aa4f48/; sid:902202544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"88:88:a7:cd:6c:9a:e6:56:a4:af:d2:1a:5e:37:8f:6a:0d:d4:69:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8888a7cd6c9ae656a4afd21a5e378f6a0dd469e6/; sid:902202545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0f:54:d8:f7:eb:72:3b:69:0d:8d:5b:61:61:01:36:fa:68:40:d2:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f54d8f7eb723b690d8d5b61610136fa6840d2e1/; sid:902202546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"cb:fb:79:de:f9:bb:d7:6d:3e:06:eb:11:c1:33:d7:a7:4f:93:b7:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cbfb79def9bbd76d3e06eb11c133d7a74f93b707/; sid:902202547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"54:e1:3b:d7:35:01:76:81:7c:2a:0c:58:99:67:ea:7e:00:19:93:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54e13bd7350176817c2a0c589967ea7e00199357/; sid:902202548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3e:d3:f4:04:47:b4:17:04:ea:25:41:b2:bb:86:84:8c:33:2b:14:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ed3f40447b41704ea2541b2bb86848c332b14c3/; sid:902202549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"4e:06:3c:d8:a4:03:64:1d:03:79:29:a5:2e:ba:fa:47:d4:7f:8a:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e063cd8a403641d037929a52ebafa47d47f8afa/; sid:902202550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a2:17:93:16:1e:08:cc:ed:10:5d:bd:0d:5f:63:cf:22:af:13:22:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a21793161e08cced105dbd0d5f63cf22af13224d/; sid:902202551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"9e:1c:95:c3:70:b0:d1:e1:0c:47:b1:ae:29:22:b7:e8:2f:e4:b0:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e1c95c370b0d1e10c47b1ae2922b7e82fe4b0f1/; sid:902202552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"d2:9d:61:cb:52:57:a8:51:da:02:60:8f:45:30:a9:44:ad:ae:e0:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d29d61cb5257a851da02608f4530a944adaee071/; sid:902202553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e9:1c:16:05:80:18:94:94:6c:0e:e4:06:51:cf:98:48:84:f5:4c:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e91c1605801894946c0ee40651cf984884f54cb9/; sid:902202554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f1:4f:1a:83:ed:dc:df:14:66:8e:6f:09:42:6f:c2:72:d7:1d:c3:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f14f1a83eddcdf14668e6f09426fc272d71dc371/; sid:902202555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6e:bc:65:b3:26:99:9b:45:34:3b:63:6b:7d:22:ef:c0:85:f7:c6:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ebc65b326999b45343b636b7d22efc085f7c674/; sid:902202556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"d1:01:78:9b:a0:68:fc:74:5a:db:51:a3:20:ef:01:63:23:6a:a9:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d101789ba068fc745adb51a320ef0163236aa9f7/; sid:902202557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"15:e1:bd:e4:90:62:db:f2:d8:e2:1f:01:cb:f4:23:1e:af:f8:b2:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15e1bde49062dbf2d8e21f01cbf4231eaff8b2dd/; sid:902202558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"85:64:cd:4e:73:70:2c:53:4b:d9:d6:9f:13:32:82:64:44:9e:93:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8564cd4e73702c534bd9d69f13328264449e9380/; sid:902202559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"4a:51:71:cf:80:f8:d9:95:0b:e3:2f:e3:dd:22:0a:92:a3:11:6f:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a5171cf80f8d9950be32fe3dd220a92a3116fa6/; sid:902202560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"f2:9e:95:3d:d2:78:98:18:77:ae:7b:53:68:ca:a5:37:85:6a:e9:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f29e953dd278981877ae7b5368caa537856ae9f4/; sid:902202561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"bd:b7:4e:c2:21:c2:c4:50:52:d1:c7:b1:3a:b9:21:85:7b:29:c4:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdb74ec221c2c45052d1c7b13ab921857b29c4e6/; sid:902202562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2c:f8:0f:a7:8c:7a:b8:03:1d:80:1a:8a:f3:29:c4:8c:99:bf:79:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2cf80fa78c7ab8031d801a8af329c48c99bf79f5/; sid:902202563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"58:60:c1:fb:dc:9c:99:14:c3:98:63:90:44:0f:24:45:90:97:d3:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5860c1fbdc9c9914c3986390440f24459097d33e/; sid:902202564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"19:fc:51:f0:a4:18:1e:61:0b:61:87:a5:22:a1:5a:ef:7b:56:ed:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19fc51f0a4181e610b6187a522a15aef7b56ed33/; sid:902202565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4f:f3:6a:9b:0d:db:2a:ea:da:45:e3:a9:38:47:a3:38:52:88:68:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ff36a9b0ddb2aeada45e3a93847a33852886853/; sid:902202566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ec:d6:ec:44:a3:0b:04:7d:6e:75:40:12:02:b2:20:a7:64:8b:d4:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecd6ec44a30b047d6e75401202b220a7648bd4cc/; sid:902202567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Meterpreter C&C)"; tls.fingerprint:"04:3d:1a:11:a0:6d:7a:60:65:01:65:9a:34:ca:e9:41:50:84:6e:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/043d1a11a06d7a606501659a34cae94150846e9d/; sid:902202568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"08:c1:91:86:c8:80:6b:0b:81:6b:ef:14:da:8e:b1:67:47:b5:5b:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08c19186c8806b0b816bef14da8eb16747b55b5a/; sid:902202569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"fc:80:21:84:e7:d0:85:d0:36:50:a9:d6:a8:80:b2:c8:96:66:d0:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc802184e7d085d03650a9d6a880b2c89666d017/; sid:902202570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"03:1d:54:84:27:25:0e:43:9a:67:b7:93:04:3d:f2:d5:a2:19:16:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/031d548427250e439a67b793043df2d5a21916ac/; sid:902202571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"28:21:83:e6:4c:46:48:41:ed:c4:24:16:3e:36:45:6a:48:92:13:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/282183e64c464841edc424163e36456a489213fe/; sid:902202572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"89:ff:12:a2:15:18:7f:e8:e9:00:5c:0c:e2:fe:0b:a4:14:16:3d:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89ff12a215187fe8e9005c0ce2fe0ba414163d45/; sid:902202573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"c1:d7:91:2b:6a:17:6b:02:a9:c7:de:1e:94:a5:ea:36:79:4e:7b:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1d7912b6a176b02a9c7de1e94a5ea36794e7b20/; sid:902202574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e8:f3:af:d3:a0:34:36:21:8f:ff:3d:c0:a0:d7:a6:71:c8:23:13:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8f3afd3a03436218fff3dc0a0d7a671c8231353/; sid:902202575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"61:86:ae:b9:1b:ad:fe:e6:1d:97:0d:59:64:69:70:7d:fa:b7:53:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6186aeb91badfee61d970d596469707dfab75392/; sid:902202576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"95:67:8e:05:29:47:3b:f8:b2:97:01:0a:c0:8e:9f:59:75:df:b8:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95678e0529473bf8b297010ac08e9f5975dfb873/; sid:902202577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"6b:b0:fa:cc:3a:17:02:36:63:4a:92:b6:2f:c6:e6:77:05:da:3f:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bb0facc3a170236634a92b62fc6e67705da3fbf/; sid:902202578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"8c:b6:48:6f:88:e6:f2:29:a4:55:0c:98:cb:9b:4d:a7:cd:47:5b:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8cb6486f88e6f229a4550c98cb9b4da7cd475b5a/; sid:902202579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"37:83:44:80:35:25:c8:2d:3e:13:4d:cd:22:22:cf:2c:fa:b0:c3:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/378344803525c82d3e134dcd2222cf2cfab0c338/; sid:902202580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e7:ec:c9:43:ad:1c:50:e4:16:f7:e7:d0:ec:25:d5:9d:28:24:98:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7ecc943ad1c50e416f7e7d0ec25d59d282498ba/; sid:902202581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"45:b6:c8:ce:24:f4:3e:f7:6a:0d:6c:17:2a:05:c0:ca:dc:a2:37:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45b6c8ce24f43ef76a0d6c172a05c0cadca23767/; sid:902202582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ba:30:74:27:81:6d:18:40:43:38:bc:c8:c9:80:2c:77:6f:de:ec:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba307427816d18404338bcc8c9802c776fdeec95/; sid:902202583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"24:27:26:51:5b:55:01:f1:df:9e:2d:bd:8b:3b:df:4c:e2:fe:d3:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/242726515b5501f1df9e2dbd8b3bdf4ce2fed3a9/; sid:902202584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c7:a8:be:1f:b4:71:f0:a1:ed:85:72:a1:0d:21:18:01:c3:32:7a:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c7a8be1fb471f0a1ed8572a10d211801c3327add/; sid:902202585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"23:e7:90:82:bb:21:e2:0d:ea:f5:38:63:da:64:59:ad:f0:4c:0f:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23e79082bb21e20deaf53863da6459adf04c0f33/; sid:902202586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"6c:bd:84:b6:93:54:72:bc:4b:10:18:92:fc:5c:cd:77:ce:29:64:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cbd84b6935472bc4b101892fc5ccd77ce2964a6/; sid:902202587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d3:6a:68:52:ee:bf:98:6c:2d:6f:79:6f:ab:28:09:7b:db:81:60:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d36a6852eebf986c2d6f796fab28097bdb8160c4/; sid:902202588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ff:05:d5:0d:6b:2e:f0:30:d6:2a:be:5a:c2:a4:50:d2:7c:28:00:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff05d50d6b2ef030d62abe5ac2a450d27c28004b/; sid:902202589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4c:fa:ad:ec:5c:b5:e4:ac:6f:d7:54:21:a6:ac:cb:7a:5f:e9:09:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cfaadec5cb5e4ac6fd75421a6accb7a5fe909e1/; sid:902202590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Loki C&C)"; tls.fingerprint:"d7:79:c7:3c:af:d2:c0:12:b1:34:b3:c0:39:de:24:86:5b:c7:82:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d779c73cafd2c012b134b3c039de24865bc78288/; sid:902202591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8c:76:ad:34:07:40:75:f4:dc:9a:7a:1c:29:32:93:73:9b:2c:fd:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c76ad34074075f4dc9a7a1c293293739b2cfdc0/; sid:902202592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NetWire C&C)"; tls.fingerprint:"97:74:32:d5:a8:46:a3:d8:69:a6:be:e2:f7:c1:5d:51:9a:e9:d9:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/977432d5a846a3d869a6bee2f7c15d519ae9d9a0/; sid:902202593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7c:53:95:5e:d3:31:be:72:8c:dd:a7:19:8a:8f:19:10:51:45:72:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c53955ed331be728cdda7198a8f191051457266/; sid:902202594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e7:f8:d9:44:f4:a6:ee:9e:7b:d9:ae:6f:e3:7e:2a:79:c9:f7:a9:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7f8d944f4a6ee9e7bd9ae6fe37e2a79c9f7a91c/; sid:902202595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"9a:5c:d3:e9:90:9d:74:35:84:95:7b:c9:c8:8b:34:d9:3e:d7:87:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a5cd3e9909d743584957bc9c88b34d93ed78761/; sid:902202596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"98:82:dd:65:37:6a:4b:6e:93:5e:4d:b3:6b:5e:f6:0e:a1:35:16:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9882dd65376a4b6e935e4db36b5ef60ea135164b/; sid:902202597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"a2:67:72:cc:0b:66:ca:18:9d:36:a0:76:16:60:7f:74:51:e3:51:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a26772cc0b66ca189d36a07616607f7451e35125/; sid:902202598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d0:2b:de:77:9e:85:3c:84:61:7f:ac:74:0b:cd:47:65:9a:f2:f3:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d02bde779e853c84617fac740bcd47659af2f375/; sid:902202599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b2:dc:f0:be:ee:69:18:13:65:a7:da:7a:d4:92:1b:cf:f9:64:61:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2dcf0beee69181365a7da7ad4921bcff96461ec/; sid:902202600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"5f:83:c8:d6:40:c1:72:cd:f7:5f:72:3c:3d:2e:5c:ae:95:5b:e8:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f83c8d640c172cdf75f723c3d2e5cae955be89a/; sid:902202601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"93:ba:dc:9f:18:a7:08:52:a7:a5:c0:46:41:f5:a0:2a:d5:31:69:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93badc9f18a70852a7a5c04641f5a02ad53169c8/; sid:902202602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"91:a4:7b:29:99:12:f1:20:4f:db:e2:97:4e:27:26:2b:f8:9a:0a:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91a47b299912f1204fdbe2974e27262bf89a0a06/; sid:902202603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5c:19:cc:1f:79:f6:8f:54:2a:5f:31:34:9b:48:79:83:10:c9:f1:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c19cc1f79f68f542a5f31349b48798310c9f1e4/; sid:902202604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f1:0c:6f:69:a0:25:24:54:79:2f:c3:cb:cd:d7:f0:e7:ba:b3:bb:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f10c6f69a0252454792fc3cbcdd7f0e7bab3bb2b/; sid:902202605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b8:e3:ed:1b:b5:9b:ac:1a:0d:18:72:5e:75:1a:7b:43:b4:62:df:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8e3ed1bb59bac1a0d18725e751a7b43b462df59/; sid:902202606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"fd:3a:17:32:fc:5b:27:2d:16:7a:5d:40:1e:bb:86:ce:6d:4a:bd:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd3a1732fc5b272d167a5d401ebb86ce6d4abd48/; sid:902202607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a2:31:e4:7b:96:ad:21:0c:1f:d5:00:ac:54:33:82:d0:e5:f0:78:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a231e47b96ad210c1fd500ac543382d0e5f07871/; sid:902202608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"86:61:4a:67:6d:06:9e:27:da:e4:eb:6e:e6:db:1d:98:36:97:ea:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86614a676d069e27dae4eb6ee6db1d983697ea48/; sid:902202609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware distribution)"; tls.fingerprint:"fc:06:d5:03:eb:38:49:a3:06:7f:32:d7:6e:e2:24:cb:83:df:91:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc06d503eb3849a3067f32d76ee224cb83df91e8/; sid:902202610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"be:b3:57:74:f7:d6:29:41:67:ee:03:a9:15:e7:9c:3b:b9:5e:0a:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/beb35774f7d6294167ee03a915e79c3bb95e0acd/; sid:902202611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c2:7b:5b:b9:72:3e:34:77:48:8d:60:4b:c3:90:6f:9d:78:f2:d7:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c27b5bb9723e3477488d604bc3906f9d78f2d701/; sid:902202612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"88:1a:ce:0d:30:fd:b1:ca:08:78:96:47:bb:55:fc:40:bc:2e:fc:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/881ace0d30fdb1ca08789647bb55fc40bc2efc13/; sid:902202613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Zebrocy C&C)"; tls.fingerprint:"30:73:67:5b:92:c8:e2:42:fa:f3:64:e3:fa:a5:7b:60:11:b7:71:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3073675b92c8e242faf364e3faa57b6011b77184/; sid:902202614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"89:38:a6:d4:96:33:4e:1d:cf:7c:e0:2f:8e:3d:c9:e5:59:06:90:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8938a6d496334e1dcf7ce02f8e3dc9e5590690aa/; sid:902202615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"91:6b:a4:8c:05:fc:16:b7:39:d6:dc:cf:b5:1d:2f:0c:57:68:df:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/916ba48c05fc16b739d6dccfb51d2f0c5768df20/; sid:902202616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c4:c7:85:ae:a2:c1:df:aa:b8:44:c4:4f:22:a7:1e:9c:65:29:6e:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4c785aea2c1dfaab844c44f22a71e9c65296e79/; sid:902202617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"54:90:61:5e:13:fd:a2:92:cc:46:b5:c5:0a:63:9c:da:c2:6d:c0:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5490615e13fda292cc46b5c50a639cdac26dc07a/; sid:902202618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"fb:65:e6:17:6c:22:52:71:01:f6:5e:12:38:84:dc:55:b3:aa:85:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb65e6176c22527101f65e123884dc55b3aa8593/; sid:902202619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"4a:3a:4e:20:c5:20:7e:f8:34:e7:fe:f6:fb:f8:9f:e0:59:69:d2:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a3a4e20c5207ef834e7fef6fbf89fe05969d2a2/; sid:902202620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PredatorStealer C&C)"; tls.fingerprint:"ec:5d:a2:14:56:fb:52:c5:83:f4:2c:ad:d3:d1:01:2f:4a:10:ac:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec5da21456fb52c583f42cadd3d1012f4a10ac42/; sid:902202621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ef:a8:c5:eb:a6:b4:d0:a7:4f:aa:9b:a8:35:b2:4b:be:3b:01:bd:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efa8c5eba6b4d0a74faa9ba835b24bbe3b01bd99/; sid:902202622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b0:e5:93:55:af:6b:fb:e6:69:74:f1:c0:d3:8a:93:a3:51:97:46:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0e59355af6bfbe66974f1c0d38a93a351974679/; sid:902202623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"11:06:c3:95:fd:9f:92:81:63:2b:71:2b:b3:4e:ff:dc:b9:01:63:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1106c395fd9f9281632b712bb34effdcb9016378/; sid:902202624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ba:3c:94:3a:48:61:54:ca:de:ca:7e:14:e0:de:11:e9:e4:81:9f:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba3c943a486154cadeca7e14e0de11e9e4819f27/; sid:902202625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"db:9f:d1:a3:56:c0:dd:0b:df:8c:3e:19:e1:d4:da:5d:73:42:88:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db9fd1a356c0dd0bdf8c3e19e1d4da5d7342883e/; sid:902202626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"bb:02:79:1f:e1:b4:4c:69:e3:8d:2b:c7:b8:24:74:9c:57:ae:bb:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb02791fe1b44c69e38d2bc7b824749c57aebb13/; sid:902202627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"59:62:9a:72:df:fb:81:c2:05:42:98:39:76:74:20:00:59:e4:a9:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59629a72dffb81c2054298397674200059e4a910/; sid:902202628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"db:c2:69:e4:38:ec:2e:d7:59:2d:40:d4:35:7e:c0:a4:ed:09:20:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbc269e438ec2ed7592d40d4357ec0a4ed0920ec/; sid:902202629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"04:7d:cf:71:ad:69:0d:3a:d4:93:23:3a:24:cd:ab:d0:59:93:f0:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/047dcf71ad690d3ad493233a24cdabd05993f04e/; sid:902202630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"4c:f3:59:be:1c:88:49:b7:85:c3:3e:4f:da:f1:3f:48:22:8b:8d:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cf359be1c8849b785c33e4fdaf13f48228b8def/; sid:902202631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"5b:ed:e8:36:fa:11:62:bf:19:a1:ba:2d:f9:7d:ae:8c:2c:bd:6d:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5bede836fa1162bf19a1ba2df97dae8c2cbd6dce/; sid:902202632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"ef:b9:eb:a1:4b:82:10:a2:7a:72:d7:da:45:50:ad:44:45:dc:50:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efb9eba14b8210a27a72d7da4550ad4445dc5024/; sid:902202633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d1:ac:88:71:c0:11:5e:68:60:1f:1f:93:db:a8:21:d2:dd:09:33:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1ac8871c0115e68601f1f93dba821d2dd0933f3/; sid:902202634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c3:6a:68:7d:6a:5d:d2:92:62:74:4a:15:2a:cb:4d:07:32:03:f3:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c36a687d6a5dd29262744a152acb4d073203f389/; sid:902202635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"32:db:2f:1d:8b:39:a3:12:6d:e2:30:93:65:9d:cb:90:17:92:37:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32db2f1d8b39a3126de23093659dcb90179237b0/; sid:902202636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"a5:6a:f2:33:b0:c4:57:d0:bc:dc:a5:a5:ac:08:4b:67:d7:38:e3:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a56af233b0c457d0bcdca5a5ac084b67d738e3ff/; sid:902202637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"92:d8:8c:fe:0b:ed:5b:10:a2:a1:e8:db:a3:6c:af:e8:e8:fb:45:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92d88cfe0bed5b10a2a1e8dba36cafe8e8fb45f5/; sid:902202638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"9f:91:0c:6a:b3:00:a3:67:e9:7f:54:08:28:a6:ea:e9:74:aa:45:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f910c6ab300a367e97f540828a6eae974aa4515/; sid:902202639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"44:fc:f5:1b:2f:b5:5e:fe:33:66:ef:27:77:a4:95:91:77:b9:c2:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44fcf51b2fb55efe3366ef2777a4959177b9c2be/; sid:902202640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"38:a0:cf:1a:72:4c:49:8a:e9:bd:64:c0:77:a6:0c:42:32:ff:ea:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38a0cf1a724c498ae9bd64c077a60c4232ffeab3/; sid:902202641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"95:fe:aa:57:4c:70:86:6e:1b:20:30:d3:1b:0b:b4:48:ce:c3:5c:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95feaa574c70866e1b2030d31b0bb448cec35c8a/; sid:902202642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"c0:a4:84:25:90:f5:06:b2:bd:e4:26:60:68:08:76:db:f1:07:3b:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0a4842590f506b2bde42660680876dbf1073b17/; sid:902202643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"01:4e:ab:17:84:6f:60:7b:15:64:21:ba:4a:b4:2d:8e:2d:72:47:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/014eab17846f607b156421ba4ab42d8e2d7247b4/; sid:902202644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"75:8c:14:71:e8:76:41:84:e4:ec:43:44:41:9c:68:8d:5b:7f:52:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/758c1471e8764184e4ec4344419c688d5b7f52af/; sid:902202645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"85:0c:e5:44:ab:68:87:5c:bc:35:10:de:80:50:a3:78:78:ad:6e:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/850ce544ab68875cbc3510de8050a37878ad6ee4/; sid:902202646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"9c:26:b4:f3:b3:7e:81:17:f9:71:35:96:b9:c1:25:96:28:ea:1d:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c26b4f3b37e8117f9713596b9c1259628ea1dee/; sid:902202647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"82:64:b3:52:0a:1d:92:7a:3b:b5:af:19:f6:6b:b8:97:a8:d8:85:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8264b3520a1d927a3bb5af19f66bb897a8d885fd/; sid:902202648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"e0:2d:cd:bd:af:bd:c8:36:dc:b3:5f:d1:c6:1f:f7:db:f6:88:68:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e02dcdbdafbdc836dcb35fd1c61ff7dbf6886865/; sid:902202649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4a:d2:2d:ac:e3:7d:1c:e4:45:4e:a0:d0:2d:eb:d5:8e:f4:3d:66:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ad22dace37d1ce4454ea0d02debd58ef43d660b/; sid:902202650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"10:b3:56:0d:b0:c7:74:46:be:f4:87:ec:e9:c5:d2:6c:f6:e8:d0:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10b3560db0c77446bef487ece9c5d26cf6e8d0e9/; sid:902202651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"69:96:0a:ca:ec:a0:35:28:47:d8:87:94:bd:31:7e:7a:a0:e3:8a:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69960acaeca0352847d88794bd317e7aa0e38a7e/; sid:902202652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f6:6e:2e:8a:a5:83:8d:39:1c:49:0f:70:f2:3a:6b:34:48:83:23:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f66e2e8aa5838d391c490f70f23a6b34488323a8/; sid:902202653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"45:00:3a:24:f2:3f:d0:76:d3:ba:50:e9:aa:1f:69:af:ad:f1:8c:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45003a24f23fd076d3ba50e9aa1f69afadf18cd1/; sid:902202654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"36:67:f5:99:b3:5d:29:fd:08:3a:87:8e:3a:77:6b:6e:b6:66:f5:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3667f599b35d29fd083a878e3a776b6eb666f58e/; sid:902202655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"38:e1:c4:8d:fe:29:df:43:54:7c:c3:c1:d0:36:ae:bb:c9:e1:d3:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38e1c48dfe29df43547cc3c1d036aebbc9e1d3bb/; sid:902202656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b6:44:bd:c6:b7:40:6d:08:e8:39:b9:8b:97:e1:cc:30:9a:00:e6:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b644bdc6b7406d08e839b98b97e1cc309a00e60c/; sid:902202657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8c:6e:e9:c3:f5:cb:e0:5a:7c:ab:dd:47:4a:89:bf:c2:dc:ce:4e:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c6ee9c3f5cbe05a7cabdd474a89bfc2dcce4e17/; sid:902202658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f7:7e:84:d1:0f:f0:b2:93:b6:c7:07:b9:bb:79:bb:0a:cf:88:07:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f77e84d10ff0b293b6c707b9bb79bb0acf8807a6/; sid:902202659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"20:d6:6b:71:74:9f:52:09:2f:b9:e2:af:ea:a2:b9:cc:e8:a5:75:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20d66b71749f52092fb9e2afeaa2b9cce8a57520/; sid:902202660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8a:dc:ad:74:16:7f:5b:27:d4:7a:4f:62:9d:11:aa:18:77:10:fd:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8adcad74167f5b27d47a4f629d11aa187710fd41/; sid:902202661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"71:12:c5:02:62:5c:ec:0a:02:11:71:4f:8d:5c:29:72:86:89:63:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7112c502625cec0a0211714f8d5c2972868963d4/; sid:902202662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2f:b8:c4:60:29:4b:26:de:7e:a3:c7:64:7c:52:68:84:12:58:11:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2fb8c460294b26de7ea3c7647c5268841258113e/; sid:902202663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gootkit C&C)"; tls.fingerprint:"34:4d:47:f3:40:f5:35:f5:30:1e:6d:7a:6d:07:cf:05:be:1e:f7:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/344d47f340f535f5301e6d7a6d07cf05be1ef7d4/; sid:902202664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"dd:b5:9d:8c:c9:36:88:bb:f4:92:5c:7d:27:46:2b:70:e5:32:25:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddb59d8cc93688bbf4925c7d27462b70e53225cb/; sid:902202665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d8:58:31:5e:4c:36:dd:7d:51:c9:84:01:fc:90:33:e3:71:41:14:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d858315e4c36dd7d51c98401fc9033e3714114d9/; sid:902202666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ba:87:5b:e4:74:a8:c9:c3:2d:e8:b1:e4:4c:36:36:7c:ac:ba:5c:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba875be474a8c9c32de8b1e44c36367cacba5ca9/; sid:902202667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e2:e6:13:2d:87:11:90:32:83:d2:db:76:4e:25:9b:d5:81:b5:26:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2e6132d8711903283d2db764e259bd581b526ee/; sid:902202668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"79:72:b9:a8:96:45:d7:69:6e:d0:54:2a:8b:94:4f:dc:24:f4:7f:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7972b9a89645d7696ed0542a8b944fdc24f47fb2/; sid:902202669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ae:1a:40:00:be:2c:83:51:16:1a:f7:21:c8:a8:29:7a:a3:18:fa:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae1a4000be2c8351161af721c8a8297aa318fa82/; sid:902202670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f5:19:18:bb:c3:2a:6d:be:2b:3c:4f:34:64:b2:47:43:5a:2f:06:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f51918bbc32a6dbe2b3c4f3464b247435a2f064b/; sid:902202671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"af:74:24:d7:b3:88:bd:98:13:45:e5:55:a6:75:f1:56:87:5b:52:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af7424d7b388bd981345e555a675f156875b52ec/; sid:902202672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"50:9d:f0:2a:70:22:bb:5d:a8:5f:cf:55:6b:ac:68:9d:66:4d:6d:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/509df02a7022bb5da85fcf556bac689d664d6d4c/; sid:902202673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a5:5a:87:24:50:41:04:e5:b7:9a:d8:35:df:80:df:94:89:37:2f:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a55a8724504104e5b79ad835df80df9489372fd8/; sid:902202674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"53:6c:7f:a5:5b:b4:20:78:b3:19:b5:19:7e:6a:eb:f9:ce:f3:db:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/536c7fa55bb42078b319b5197e6aebf9cef3db72/; sid:902202675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"5e:46:91:b5:67:c8:ab:03:31:6c:7f:58:3c:d8:0a:13:3c:e4:91:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e4691b567c8ab03316c7f583cd80a133ce4917e/; sid:902202676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"13:4e:5e:e1:f8:d4:c3:52:4b:f0:c7:0d:61:48:b6:25:12:a7:b8:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/134e5ee1f8d4c3524bf0c70d6148b62512a7b81b/; sid:902202677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"60:a7:b1:0e:07:04:65:b9:59:eb:18:a9:e8:10:0f:dd:c6:20:2f:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60a7b10e070465b959eb18a9e8100fddc6202f34/; sid:902202678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f2:43:f6:f5:87:b9:36:a6:aa:b9:95:1a:1e:0b:97:ad:aa:5c:2d:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f243f6f587b936a6aab9951a1e0b97adaa5c2d9c/; sid:902202679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e1:b2:0d:36:a9:ea:dd:5d:88:49:3e:4c:eb:fd:0a:ea:a6:b2:7d:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1b20d36a9eadd5d88493e4cebfd0aeaa6b27ddc/; sid:902202680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6c:08:88:5c:2a:ba:f9:ad:f0:84:0d:a1:cb:e7:c9:de:be:73:6b:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c08885c2abaf9adf0840da1cbe7c9debe736b2e/; sid:902202681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f9:96:f8:7d:90:52:a7:b6:44:2b:ae:48:8d:df:15:16:7c:dd:0a:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f996f87d9052a7b6442bae488ddf15167cdd0a56/; sid:902202682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"70:d4:19:af:c7:42:e4:56:b4:42:ca:fd:24:d7:03:b7:c7:ae:01:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70d419afc742e456b442cafd24d703b7c7ae0193/; sid:902202683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c9:2a:c9:79:7c:30:f7:88:cd:4b:28:0e:d5:e0:cf:74:e9:30:60:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c92ac9797c30f788cd4b280ed5e0cf74e930603a/; sid:902202684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e5:72:f2:a6:cf:c4:38:59:4a:f7:12:ea:06:3d:97:b3:a5:e0:43:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e572f2a6cfc438594af712ea063d97b3a5e0435e/; sid:902202685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"00:8d:33:ce:2e:5d:35:83:d8:eb:b1:15:f7:2b:25:09:75:75:70:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/008d33ce2e5d3583d8ebb115f72b250975757018/; sid:902202686; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"cf:3b:ee:45:f8:78:27:fa:2c:5d:db:c5:09:87:ac:6a:5e:5a:ba:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf3bee45f87827fa2c5ddbc50987ac6a5e5aba6c/; sid:902202687; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7d:c5:16:b0:43:6d:c0:be:82:96:dc:b6:75:cb:96:a8:19:fe:0f:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dc516b0436dc0be8296dcb675cb96a819fe0f68/; sid:902202688; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"3a:9c:06:6e:76:bd:13:f2:e4:c6:08:59:d7:b4:d9:ff:6e:66:6c:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a9c066e76bd13f2e4c60859d7b4d9ff6e666cf0/; sid:902202689; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"60:26:0a:f7:e0:1f:04:1e:44:c5:c7:b9:10:67:26:7e:90:b4:8f:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60260af7e01f041e44c5c7b91067267e90b48f7a/; sid:902202690; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6c:39:73:dc:d6:84:e1:b4:eb:41:d9:c5:b6:ca:c5:62:fa:87:c6:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c3973dcd684e1b4eb41d9c5b6cac562fa87c67a/; sid:902202691; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"65:45:00:6a:b4:1b:38:bb:c2:18:11:70:92:71:73:bd:ee:ab:b5:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6545006ab41b38bbc2181170927173bdeeabb5bc/; sid:902202692; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"f6:58:38:a9:8e:2b:13:fe:1e:67:64:8d:8d:db:f9:11:ba:e2:32:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f65838a98e2b13fe1e67648d8ddbf911bae2329b/; sid:902202693; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"13:52:05:db:70:a8:08:7c:c8:55:74:69:24:a6:27:56:47:bd:1c:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/135205db70a8087cc855746924a6275647bd1c3d/; sid:902202694; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5f:51:04:9f:3f:47:b4:ec:35:50:31:c0:8e:4d:ae:b1:ff:40:b5:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f51049f3f47b4ec355031c08e4daeb1ff40b52a/; sid:902202695; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"fc:67:ab:8e:0f:63:5f:00:d8:ea:55:6f:d9:8c:0f:56:13:05:7b:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc67ab8e0f635f00d8ea556fd98c0f5613057b56/; sid:902202696; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"04:63:a5:f0:2f:7e:ed:1a:79:7a:1b:0f:f0:8a:0b:62:63:9e:7b:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0463a5f02f7eed1a797a1b0ff08a0b62639e7be0/; sid:902202697; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"91:15:ed:8c:d0:e1:90:b5:62:9a:ca:39:96:b8:64:01:51:55:a3:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9115ed8cd0e190b5629aca3996b864015155a333/; sid:902202698; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"fa:04:ad:17:15:28:f9:b7:16:68:7c:29:12:a2:25:7b:37:bd:4e:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa04ad171528f9b716687c2912a2257b37bd4eb5/; sid:902202699; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"de:28:1b:03:31:35:23:90:c2:97:7e:d3:9e:4c:62:47:2d:2d:ab:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de281b0331352390c2977ed39e4c62472d2dabe4/; sid:902202700; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"fe:15:30:7f:cf:a1:98:58:bb:54:96:1a:8e:19:3f:1f:3f:5b:cf:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe15307fcfa19858bb54961a8e193f1f3f5bcf44/; sid:902202701; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"80:c8:32:7f:b0:22:63:78:d1:00:9e:74:9c:5e:91:21:df:9a:75:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80c8327fb0226378d1009e749c5e9121df9a7524/; sid:902202702; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"91:6c:be:db:7b:91:1a:80:ca:de:f2:fb:a8:ef:65:e1:75:00:50:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/916cbedb7b911a80cadef2fba8ef65e17500503f/; sid:902202703; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"15:e7:39:1b:57:d7:d6:10:aa:60:83:6d:d8:db:bb:af:57:b0:78:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15e7391b57d7d610aa60836dd8dbbbaf57b07882/; sid:902202704; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6a:39:a5:3b:51:79:6f:0a:32:d5:5d:1e:fd:55:00:10:f3:11:e8:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a39a53b51796f0a32d55d1efd550010f311e8ef/; sid:902202705; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8c:24:b6:03:dc:1d:57:da:f5:7c:53:d1:c2:9c:8a:d2:94:2f:7b:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c24b603dc1d57daf57c53d1c29c8ad2942f7b7c/; sid:902202706; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"16:04:65:7c:34:62:7b:d6:9a:e1:f8:85:bf:4a:88:70:c7:89:cd:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1604657c34627bd69ae1f885bf4a8870c789cddf/; sid:902202707; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"18:de:fc:22:07:2e:af:19:4b:f7:22:36:2e:22:2b:e2:19:45:9e:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18defc22072eaf194bf722362e222be219459e20/; sid:902202708; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1c:c9:67:9b:0f:86:57:5f:b5:84:b2:c2:a3:c2:c3:51:97:08:33:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cc9679b0f86575fb584b2c2a3c2c3519708333f/; sid:902202709; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"16:e0:6a:88:db:b1:0c:75:07:77:80:d4:ba:ed:6d:0b:27:33:f9:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16e06a88dbb10c75077780d4baed6d0b2733f985/; sid:902202710; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6e:f4:fa:e0:9e:f3:a3:fc:81:e2:1d:a6:f4:7a:8c:b9:b2:99:6a:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ef4fae09ef3a3fc81e21da6f47a8cb9b2996af4/; sid:902202711; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0d:bd:1e:ea:34:54:61:fc:7d:0a:fe:92:e4:d8:49:0b:00:47:9a:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dbd1eea345461fc7d0afe92e4d8490b00479afa/; sid:902202712; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"dd:ae:0c:37:e8:3a:8f:1d:9b:a9:a9:28:52:98:59:17:43:59:0e:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddae0c37e83a8f1d9ba9a9285298591743590ed5/; sid:902202713; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"55:d7:2e:3e:7c:44:50:b2:f1:35:6d:ce:d3:be:70:6c:b4:88:64:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55d72e3e7c4450b2f1356dced3be706cb48864d0/; sid:902202714; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d3:a8:15:2a:00:f4:25:dc:cd:75:35:ff:cf:df:4c:cd:33:da:c2:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3a8152a00f425dccd7535ffcfdf4ccd33dac2f8/; sid:902202715; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"08:70:50:6a:75:dd:2e:4a:92:0f:df:39:f5:b3:de:16:49:93:df:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0870506a75dd2e4a920fdf39f5b3de164993df1f/; sid:902202716; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"33:6c:3c:cd:a3:69:bf:0c:6e:49:86:22:e4:3d:9a:6f:2e:9c:f7:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/336c3ccda369bf0c6e498622e43d9a6f2e9cf76f/; sid:902202717; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"10:ec:90:3d:02:7a:1f:35:26:8d:d5:3a:f5:be:5f:d2:c7:e3:89:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10ec903d027a1f35268dd53af5be5fd2c7e3892a/; sid:902202718; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"87:5a:1c:f4:a0:d5:d6:4b:87:dd:47:36:c8:ec:b4:a2:d4:01:d1:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/875a1cf4a0d5d64b87dd4736c8ecb4a2d401d13e/; sid:902202719; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"ba:5a:62:49:7e:fa:9a:50:9c:2e:b8:df:28:c9:16:15:c9:af:d1:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba5a62497efa9a509c2eb8df28c91615c9afd1d1/; sid:902202720; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"00:22:a1:82:1c:4c:ae:59:ac:39:18:e4:dc:be:7c:5c:29:bc:bb:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0022a1821c4cae59ac3918e4dcbe7c5c29bcbbc6/; sid:902202721; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"38:2e:2f:e1:ca:91:b4:26:82:7a:12:7d:93:ae:ef:8c:05:35:e9:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/382e2fe1ca91b426827a127d93aeef8c0535e95f/; sid:902202722; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d4:ef:49:24:4a:3e:94:bd:e7:a6:ef:69:e7:c7:09:5c:d3:94:45:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4ef49244a3e94bde7a6ef69e7c7095cd3944500/; sid:902202723; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"15:b4:cb:de:c2:d2:ec:1b:2a:44:88:39:fe:73:d6:c2:d5:b3:e0:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15b4cbdec2d2ec1b2a448839fe73d6c2d5b3e0ff/; sid:902202724; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a6:10:c8:03:df:57:0d:50:57:4c:00:46:83:a7:15:7b:bd:d7:1d:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a610c803df570d50574c004683a7157bbdd71dfa/; sid:902202725; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c8:72:6c:6d:97:d5:d4:ae:c5:b9:18:a7:42:06:21:72:b6:8c:bc:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8726c6d97d5d4aec5b918a742062172b68cbc3a/; sid:902202726; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"39:1a:54:c4:1d:8d:ac:78:9a:87:49:be:a9:6d:81:fe:81:53:44:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/391a54c41d8dac789a8749bea96d81fe8153448f/; sid:902202727; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"dd:09:66:fb:66:cc:22:78:3d:1a:fc:06:e6:dc:8c:42:6a:cc:a9:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd0966fb66cc22783d1afc06e6dc8c426acca926/; sid:902202728; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:8d:6f:8e:46:9e:73:ce:ae:4d:be:da:4c:f1:77:43:e3:c6:5f:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/798d6f8e469e73ceae4dbeda4cf17743e3c65f3a/; sid:902202729; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"6b:5b:77:98:f8:bb:ad:bd:6d:34:94:12:9e:48:1e:f9:fa:d8:a7:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b5b7798f8bbadbd6d3494129e481ef9fad8a7ac/; sid:902202730; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"dc:13:06:d5:d7:e2:4d:24:af:3c:a8:a8:7e:2b:26:f8:be:2d:ea:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc1306d5d7e24d24af3ca8a87e2b26f8be2dea45/; sid:902202731; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b5:8a:b8:7f:55:4b:5c:99:aa:a0:48:d5:6a:03:0f:28:c4:39:77:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b58ab87f554b5c99aaa048d56a030f28c43977a4/; sid:902202732; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot C&C)"; tls.fingerprint:"9a:03:4b:35:0f:51:73:22:a9:f8:e9:0d:57:74:51:91:08:c4:f2:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a034b350f517322a9f8e90d5774519108c4f299/; sid:902202733; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"5f:63:6d:33:60:70:0e:95:6a:2c:58:b6:dc:45:b7:a9:a7:48:4f:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f636d3360700e956a2c58b6dc45b7a9a7484f6b/; sid:902202734; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e3:4f:0a:7d:95:99:2d:75:4c:78:ba:d7:d3:07:c7:eb:01:29:0a:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e34f0a7d95992d754c78bad7d307c7eb01290a05/; sid:902202735; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1f:1b:5b:22:78:5b:41:89:05:04:7f:62:dc:39:2f:65:7b:49:76:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f1b5b22785b418905047f62dc392f657b49761f/; sid:902202736; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:0f:98:67:3b:09:56:f8:65:2b:ab:02:20:a0:10:f8:3d:38:1f:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/230f98673b0956f8652bab0220a010f83d381f4c/; sid:902202737; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"0a:d3:c3:52:ff:ec:da:a0:a1:4c:55:66:39:14:6e:49:7d:1b:97:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ad3c352ffecdaa0a14c556639146e497d1b971b/; sid:902202738; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0d:f1:b6:e7:51:4f:b4:e7:28:14:4d:9b:2a:bf:68:42:38:b1:00:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0df1b6e7514fb4e728144d9b2abf684238b1000b/; sid:902202739; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"18:88:d4:25:28:55:80:2d:9b:79:8b:13:0d:4f:65:6d:89:ac:ed:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1888d4252855802d9b798b130d4f656d89aced55/; sid:902202740; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"98:22:95:60:c6:34:9e:a0:54:d6:71:9f:53:19:a0:a2:53:88:b0:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98229560c6349ea054d6719f5319a0a25388b08b/; sid:902202741; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cd:47:a9:1b:ba:81:a0:f0:1b:99:20:70:ce:b7:00:1b:5a:90:df:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd47a91bba81a0f01b992070ceb7001b5a90dfb0/; sid:902202742; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3c:39:2d:20:e3:15:77:1d:27:65:56:c7:da:37:07:f0:81:70:1f:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c392d20e315771d276556c7da3707f081701f78/; sid:902202743; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"76:08:87:d6:5b:34:07:46:37:f0:2f:96:0a:b3:b3:a5:9a:37:9b:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/760887d65b34074637f02f960ab3b3a59a379b5d/; sid:902202744; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"81:8c:d9:27:c3:d5:2c:8b:57:6f:9d:aa:2f:96:5a:60:da:c3:be:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/818cd927c3d52c8b576f9daa2f965a60dac3be23/; sid:902202745; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8b:63:50:10:58:e8:c9:c2:53:ed:23:d1:85:c9:09:31:6b:6d:e0:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b63501058e8c9c253ed23d185c909316b6de0e7/; sid:902202746; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bc:f8:55:79:6d:e0:18:a6:31:76:d6:92:0f:b0:b6:c7:08:36:31:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcf855796de018a63176d6920fb0b6c708363100/; sid:902202747; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1f:19:e7:fa:82:ed:ce:b0:df:f1:22:b0:ff:43:b8:0e:73:6a:2a:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f19e7fa82edceb0dff122b0ff43b80e736a2ad2/; sid:902202748; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"39:79:fd:e3:b5:02:5f:8b:33:1e:e9:0a:99:8b:de:f8:fb:74:1c:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3979fde3b5025f8b331ee90a998bdef8fb741c6d/; sid:902202749; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"db:f3:22:88:7f:f4:ae:75:f6:bb:51:f9:29:4a:50:71:99:9a:41:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbf322887ff4ae75f6bb51f9294a5071999a412a/; sid:902202750; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4b:a4:3c:2c:74:6a:17:d8:42:9a:99:78:27:fd:89:7a:43:64:e2:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ba43c2c746a17d8429a997827fd897a4364e2d6/; sid:902202751; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f8:7d:2a:ff:41:48:f9:8f:01:44:60:ab:70:9c:77:58:7e:a1:e4:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f87d2aff4148f98f014460ab709c77587ea1e430/; sid:902202752; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5e:21:f8:04:85:6b:3d:64:d2:1d:5f:af:d5:c0:44:03:fe:c9:43:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e21f804856b3d64d21d5fafd5c04403fec943c8/; sid:902202753; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5e:39:1e:5b:c7:89:03:88:1e:e1:23:e4:4a:22:4d:29:48:04:4e:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e391e5bc78903881ee123e44a224d2948044eb7/; sid:902202754; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2f:65:39:10:77:63:dd:c6:d4:24:0a:5d:bd:e6:25:b1:83:1a:2e:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f6539107763ddc6d4240a5dbde625b1831a2e04/; sid:902202755; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"11:26:47:18:92:e6:45:ba:b2:4a:fb:aa:6e:2b:db:97:84:42:5d:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1126471892e645bab24afbaa6e2bdb9784425d04/; sid:902202756; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"eb:8d:f5:0d:4e:d4:c4:05:5d:bc:46:01:c3:f3:ee:31:4f:60:21:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb8df50d4ed4c4055dbc4601c3f3ee314f602168/; sid:902202757; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e9:50:61:ed:3d:62:87:3c:22:32:c2:fc:e2:72:44:97:8c:77:b2:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e95061ed3d62873c2232c2fce27244978c77b2d1/; sid:902202758; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bb:f3:e6:b6:0c:9d:ec:81:0f:cf:f6:cb:12:92:6a:eb:9d:76:e2:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbf3e6b60c9dec810fcff6cb12926aeb9d76e298/; sid:902202759; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8a:f6:71:bf:0c:5a:e8:40:6e:ef:17:c7:87:75:21:ca:e3:0d:1e:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8af671bf0c5ae8406eef17c7877521cae30d1ed3/; sid:902202760; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ab:e1:86:52:3f:ba:ea:20:47:2c:b3:0a:36:fc:8a:57:f5:91:9c:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abe186523fbaea20472cb30a36fc8a57f5919cf6/; sid:902202761; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6b:16:75:35:55:88:ac:8a:dc:1a:87:c3:02:ee:f2:d1:08:68:ca:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b1675355588ac8adc1a87c302eef2d10868caa8/; sid:902202762; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bc:43:a0:94:65:13:b2:25:0c:78:80:52:22:25:68:be:af:ec:19:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc43a0946513b2250c788052222568beafec1952/; sid:902202763; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c5:a5:62:5b:3e:d7:33:f2:f4:fa:83:b7:39:f1:56:a0:42:c7:25:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5a5625b3ed733f2f4fa83b739f156a042c72566/; sid:902202764; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"50:50:c6:c7:89:d7:1e:a7:af:3e:0a:14:11:29:7c:25:c5:79:45:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5050c6c789d71ea7af3e0a1411297c25c57945ed/; sid:902202765; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (njrat C&C)"; tls.fingerprint:"ec:bc:d8:41:f3:3e:c6:a4:0a:26:f3:ff:77:e0:e1:8f:8a:7e:49:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecbcd841f33ec6a40a26f3ff77e0e18f8a7e4949/; sid:902202766; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:f4:4f:fb:61:f1:62:16:3e:7a:9f:ed:95:33:ab:25:45:5b:6a:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30f44ffb61f162163e7a9fed9533ab25455b6add/; sid:902202767; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6e:38:3f:6a:df:ca:b3:66:6e:b5:75:2e:7c:1e:59:e0:76:08:54:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6e383f6adfcab3666eb5752e7c1e59e0760854e0/; sid:902202768; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a2:7e:73:18:74:ac:56:90:5e:7b:1b:81:db:55:64:20:fa:ee:98:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a27e731874ac56905e7b1b81db556420faee9868/; sid:902202769; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"09:b5:cd:f6:52:e8:85:ae:8e:d1:ec:f3:ab:ee:01:a1:c0:0b:04:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09b5cdf652e885ae8ed1ecf3abee01a1c00b0448/; sid:902202770; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"2a:fd:a3:72:73:f3:bc:b0:87:63:c3:65:25:bf:ee:f9:27:6d:7b:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2afda37273f3bcb08763c36525bfeef9276d7bee/; sid:902202771; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"93:2a:35:45:1d:9b:0d:16:35:ff:06:22:76:17:9a:fe:ae:69:c6:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/932a35451d9b0d1635ff062276179afeae69c62d/; sid:902202772; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"84:28:2d:72:ef:43:92:69:4b:94:6b:6a:34:ed:66:fa:dd:9f:fb:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84282d72ef4392694b946b6a34ed66fadd9ffb61/; sid:902202773; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7d:0e:5b:26:79:5b:bc:73:e7:8b:d0:a1:50:04:00:86:c9:3c:a0:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d0e5b26795bbc73e78bd0a150040086c93ca050/; sid:902202774; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"35:a8:8a:63:64:e2:ef:ef:db:a5:89:ec:2c:8a:9e:26:0d:c7:e9:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35a88a6364e2efefdba589ec2c8a9e260dc7e9a0/; sid:902202775; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ef:87:eb:fa:a1:a3:ea:b6:41:cb:60:2f:6d:7e:b1:25:45:49:43:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef87ebfaa1a3eab641cb602f6d7eb1254549434c/; sid:902202776; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"0d:cc:97:01:d2:b4:d9:16:ce:4e:c4:36:a8:a9:0d:cd:ae:24:cc:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dcc9701d2b4d916ce4ec436a8a90dcdae24ccb3/; sid:902202777; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"93:e7:a0:ba:fd:e1:77:f0:90:fc:96:2c:9e:25:98:33:37:47:64:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93e7a0bafde177f090fc962c9e25983337476473/; sid:902202778; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7b:a2:26:e0:53:8c:23:46:38:be:ae:09:1b:a5:3f:02:82:fa:9f:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ba226e0538c234638beae091ba53f0282fa9fb6/; sid:902202779; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"4c:a0:91:a9:9a:cc:47:c7:3f:94:8a:74:9a:62:1a:9f:50:b5:8a:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ca091a99acc47c73f948a749a621a9f50b58a5e/; sid:902202780; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e8:ab:ea:a1:0e:1b:bc:e2:2c:21:a0:ce:22:62:4d:90:d1:bc:1b:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8abeaa10e1bbce22c21a0ce22624d90d1bc1b6a/; sid:902202781; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RevCodeRAT C&C)"; tls.fingerprint:"60:7c:bc:bd:2e:d6:8c:74:97:c8:a0:70:94:89:f8:76:27:08:5d:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/607cbcbd2ed68c7497c8a0709489f87627085ddc/; sid:902202782; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"78:90:de:c7:1d:55:5e:50:cc:ff:00:fa:c9:94:33:65:b9:6a:23:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7890dec71d555e50ccff00fac9943365b96a23cc/; sid:902202783; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"83:1d:2a:a2:41:2a:6b:68:cd:49:99:d8:1e:0c:f1:57:38:f9:9c:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/831d2aa2412a6b68cd4999d81e0cf15738f99c4e/; sid:902202784; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"a5:62:49:d9:48:26:c1:37:76:65:a6:fe:d5:53:54:d3:21:31:18:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a56249d94826c1377665a6fed55354d321311803/; sid:902202785; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"48:6f:40:e1:9a:9e:3e:a5:3a:10:78:58:11:26:9d:da:df:ef:1e:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/486f40e19a9e3ea53a10785811269ddadfef1e8d/; sid:902202786; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"19:25:20:d8:85:c7:bc:29:28:cb:af:a3:92:41:66:4e:ac:d2:23:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/192520d885c7bc2928cbafa39241664eacd22351/; sid:902202787; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"5d:30:7f:dd:e2:d2:f6:78:05:6c:1b:6e:78:78:fc:89:f4:8f:ed:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d307fdde2d2f678056c1b6e7878fc89f48fed6f/; sid:902202788; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d3:4a:d0:2f:a2:32:33:b6:49:3e:36:3d:63:37:e8:35:8d:97:47:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d34ad02fa23233b6493e363d6337e8358d9747d7/; sid:902202789; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8b:b6:c7:c3:ab:95:13:15:ac:88:df:cb:12:79:84:ea:03:43:e3:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bb6c7c3ab951315ac88dfcb127984ea0343e34d/; sid:902202790; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"24:c1:09:a9:3c:82:0c:38:12:f0:be:52:5e:50:88:30:a7:bc:81:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24c109a93c820c3812f0be525e508830a7bc811d/; sid:902202791; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"59:71:1b:d3:b8:23:35:1f:b5:ff:e6:85:10:0a:db:6e:7b:15:49:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59711bd3b823351fb5ffe685100adb6e7b1549cd/; sid:902202792; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"e8:92:d0:0a:bc:af:52:81:e6:d7:5a:e0:a3:3a:88:1c:83:dc:5d:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e892d00abcaf5281e6d75ae0a33a881c83dc5d3f/; sid:902202793; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"33:b2:cc:de:b5:9f:88:e8:e0:71:ce:cb:23:c7:02:dc:7f:ee:32:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33b2ccdeb59f88e8e071cecb23c702dc7fee3227/; sid:902202794; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"25:45:22:39:31:25:8e:62:61:9e:8f:8f:83:f7:13:ec:86:1d:47:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2545223931258e62619e8f8f83f713ec861d47be/; sid:902202795; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c4:fe:0b:e3:5a:d3:cc:04:16:50:e8:dc:97:57:04:ee:eb:b9:ec:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4fe0be35ad3cc041650e8dc975704eeebb9eccf/; sid:902202796; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f5:b7:4b:d5:ce:11:a6:11:40:4d:6c:91:11:3f:47:f6:92:43:e1:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5b74bd5ce11a611404d6c91113f47f69243e1e9/; sid:902202797; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"3e:a5:7c:b7:d6:45:5f:30:e3:d7:e9:42:01:3b:80:80:92:86:7e:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ea57cb7d6455f30e3d7e942013b808092867e3d/; sid:902202798; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4d:39:75:51:7f:83:52:48:a5:c4:28:d2:10:f9:69:73:34:4c:53:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d3975517f835248a5c428d210f96973344c534b/; sid:902202799; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"14:45:44:c8:d0:ce:87:91:b3:d3:2c:fb:77:a2:7f:48:40:a2:fa:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/144544c8d0ce8791b3d32cfb77a27f4840a2fac8/; sid:902202800; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ae:48:6e:a3:aa:0f:a0:c0:d4:84:f1:02:de:28:60:42:fb:86:0a:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae486ea3aa0fa0c0d484f102de286042fb860a44/; sid:902202801; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"86:48:32:b2:7d:ad:f4:e5:a2:41:cb:d3:8f:0c:ed:26:d8:75:f9:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/864832b27dadf4e5a241cbd38f0ced26d875f946/; sid:902202802; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"f5:1b:dd:17:ab:a2:00:14:68:c9:65:ed:10:d5:01:15:5c:da:cc:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f51bdd17aba2001468c965ed10d501155cdacca1/; sid:902202803; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"04:c3:74:16:1b:21:54:3a:c1:f2:90:0b:65:45:38:e1:64:b5:57:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/04c374161b21543ac1f2900b654538e164b5570a/; sid:902202804; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8d:99:32:7f:fd:97:4b:82:ff:d7:88:64:9d:a4:88:7b:3b:c0:c0:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d99327ffd974b82ffd788649da4887b3bc0c006/; sid:902202805; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"72:20:d8:f5:5a:6b:ae:aa:b5:c6:43:20:01:70:8c:e1:09:ba:bb:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7220d8f55a6baeaab5c6432001708ce109babba4/; sid:902202806; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"43:18:d6:68:06:72:f3:3c:22:27:30:a0:b9:e4:a7:cc:57:a7:c1:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4318d6680672f33c222730a0b9e4a7cc57a7c101/; sid:902202807; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"fd:b1:b3:15:4f:75:d7:95:72:a3:20:c1:36:3d:d2:56:fd:d3:2f:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdb1b3154f75d79572a320c1363dd256fdd32f24/; sid:902202808; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b0:40:79:30:dc:d7:c3:86:15:c8:e6:60:c4:d3:91:21:37:5b:11:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0407930dcd7c38615c8e660c4d39121375b1172/; sid:902202809; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"60:42:3a:f3:f1:cd:13:4c:c8:f5:21:9c:f1:28:a1:99:88:33:52:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60423af3f1cd134cc8f5219cf128a199883352d2/; sid:902202810; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ed:95:a9:9e:d1:c5:48:d8:46:36:98:88:9f:2e:11:3e:a5:43:46:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed95a99ed1c548d8463698889f2e113ea54346a9/; sid:902202811; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d1:fe:e1:0f:34:03:12:c8:76:10:64:d6:b1:93:03:6a:c5:fd:36:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1fee10f340312c8761064d6b193036ac5fd36a0/; sid:902202812; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"94:c9:6b:10:a4:3c:6a:48:b4:a2:f0:7d:d0:73:ab:95:8c:c6:1e:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94c96b10a43c6a48b4a2f07dd073ab958cc61e94/; sid:902202813; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:be:ae:4f:e4:b8:03:45:ca:bb:17:fe:d8:2a:cf:e0:48:68:c4:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9beae4fe4b80345cabb17fed82acfe04868c458/; sid:902202814; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"6d:28:e9:c2:2d:ea:11:8c:b6:2e:54:3f:c3:66:b8:32:60:a8:6e:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d28e9c22dea118cb62e543fc366b83260a86e0d/; sid:902202815; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ce:7f:ab:bc:43:94:51:1c:f9:be:45:d7:76:d2:c9:44:a7:09:b5:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce7fabbc4394511cf9be45d776d2c944a709b53e/; sid:902202816; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b6:6f:d6:79:bd:cc:36:1c:30:36:b3:7f:f1:83:0c:7e:18:e2:58:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b66fd679bdcc361c3036b37ff1830c7e18e25804/; sid:902202817; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"ac:89:4d:d3:a6:2d:49:8c:3f:63:17:a4:5c:d6:e2:2d:cc:f1:bd:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac894dd3a62d498c3f6317a45cd6e22dccf1bdd2/; sid:902202818; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"b2:d0:d8:f0:03:f0:6f:10:48:66:e0:d4:16:b4:b7:56:a9:ec:0a:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2d0d8f003f06f104866e0d416b4b756a9ec0aaf/; sid:902202819; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"aa:f8:7e:4d:1b:4c:9e:c7:db:69:45:29:29:32:27:c5:5e:00:0c:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aaf87e4d1b4c9ec7db694529293227c55e000c32/; sid:902202820; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"75:98:8b:85:4b:33:e2:72:c7:58:b2:bd:14:21:92:37:95:de:f0:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75988b854b33e272c758b2bd1421923795def02c/; sid:902202821; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5f:64:10:20:7f:da:5a:bb:e0:1b:9a:dd:33:a7:74:18:e5:67:b7:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f6410207fda5abbe01b9add33a77418e567b71a/; sid:902202822; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a5:1f:49:92:32:c7:fc:8c:b1:3d:3d:37:20:32:88:26:c5:ef:4b:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a51f499232c7fc8cb13d3d3720328826c5ef4b8b/; sid:902202823; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"75:6d:22:9b:87:5d:e9:51:63:74:93:30:de:2b:61:cf:2d:79:0b:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/756d229b875de95163749330de2b61cf2d790b39/; sid:902202824; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"88:ac:12:a7:fb:e8:28:e7:6d:9a:bb:12:fa:06:5a:7c:d4:7d:91:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88ac12a7fbe828e76d9abb12fa065a7cd47d91c3/; sid:902202825; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"39:fa:8e:88:0e:a3:17:47:75:e1:42:75:bb:46:13:f4:0a:5f:52:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39fa8e880ea3174775e14275bb4613f40a5f522f/; sid:902202826; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"79:46:c5:20:6f:32:ef:54:33:b3:88:40:e7:c3:51:9a:ac:cf:6d:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7946c5206f32ef5433b38840e7c3519aaccf6dbd/; sid:902202827; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"55:3c:bb:17:c6:5d:59:0a:03:74:04:8c:65:48:9c:a9:02:1f:f2:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/553cbb17c65d590a0374048c65489ca9021ff249/; sid:902202828; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"94:af:8c:88:f2:bf:b4:67:6b:2d:bb:c5:82:62:d0:76:78:46:33:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94af8c88f2bfb4676b2dbbc58262d07678463311/; sid:902202829; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9a:be:56:b1:85:7c:bd:c5:d5:76:fd:99:71:a2:4b:c3:c9:00:92:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9abe56b1857cbdc5d576fd9971a24bc3c9009220/; sid:902202830; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7f:0a:f1:cb:4f:4d:7d:f7:8d:04:1c:41:11:58:7a:fe:c6:28:41:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f0af1cb4f4d7df78d041c4111587afec62841e6/; sid:902202831; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e3:83:88:e7:9c:a7:c5:9f:6c:ba:7a:81:76:76:7b:6f:9c:77:be:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e38388e79ca7c59f6cba7a8176767b6f9c77becc/; sid:902202832; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5b:61:e2:84:4b:4d:b1:a4:b1:75:7d:c0:d7:95:90:ae:d7:cb:89:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b61e2844b4db1a4b1757dc0d79590aed7cb89ca/; sid:902202833; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Bolek C&C)"; tls.fingerprint:"e8:79:10:5e:d7:21:9b:0b:88:4a:87:73:61:1a:dd:ae:6c:50:6e:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e879105ed7219b0b884a8773611addae6c506e1f/; sid:902202834; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"93:56:b1:52:df:66:34:37:a7:21:96:b5:a1:b4:43:89:e8:5f:f6:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9356b152df663437a72196b5a1b44389e85ff6ac/; sid:902202835; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:a0:a4:d3:b7:8a:7d:09:e3:83:d7:ea:06:6a:5c:72:31:eb:09:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0a0a4d3b78a7d09e383d7ea066a5c7231eb0976/; sid:902202836; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4c:3a:66:ec:93:87:19:d1:b9:2d:00:18:cf:ed:49:50:0a:a9:aa:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c3a66ec938719d1b92d0018cfed49500aa9aac6/; sid:902202837; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9b:aa:51:75:65:2e:63:4c:3f:e4:9d:0a:af:05:dc:ec:88:f2:99:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9baa5175652e634c3fe49d0aaf05dcec88f29965/; sid:902202838; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"e1:86:4e:8f:7f:6d:63:cf:17:5f:98:41:71:84:bb:a1:03:4f:da:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1864e8f7f6d63cf175f98417184bba1034fda63/; sid:902202839; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"74:5e:f3:ba:79:66:07:bf:12:68:40:e1:a0:f9:fe:f8:64:9b:2d:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/745ef3ba796607bf126840e1a0f9fef8649b2dda/; sid:902202840; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ae:b9:22:4f:65:87:5c:e0:95:c7:92:70:cb:61:64:3f:c0:0a:b2:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aeb9224f65875ce095c79270cb61643fc00ab232/; sid:902202841; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"54:c0:30:c8:d7:b5:6f:42:50:2f:a9:c8:6f:a7:05:57:48:09:44:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54c030c8d7b56f42502fa9c86fa705574809445f/; sid:902202842; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6c:b4:50:b7:3f:cb:23:50:cd:1b:6e:de:f6:39:2a:7e:59:bc:bc:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cb450b73fcb2350cd1b6edef6392a7e59bcbc88/; sid:902202843; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"45:3f:2f:89:5d:94:40:2b:54:61:36:de:d9:f3:46:35:ee:c0:7b:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/453f2f895d94402b546136ded9f34635eec07b70/; sid:902202844; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"ea:fa:d7:4b:b7:ad:56:26:bb:cc:9c:f2:7c:c5:28:a3:9e:40:47:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eafad74bb7ad5626bbcc9cf27cc528a39e4047e6/; sid:902202845; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f9:3c:c7:c5:58:2b:a5:7a:77:a8:d4:29:96:28:98:f2:d0:8d:82:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f93cc7c5582ba57a77a8d429962898f2d08d82b7/; sid:902202846; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ce:30:b0:0c:f2:59:d1:f5:e5:27:91:89:53:d1:9e:7d:65:60:e5:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce30b00cf259d1f5e527918953d19e7d6560e5fa/; sid:902202847; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"43:63:26:2d:04:36:54:c2:57:e4:54:1b:3c:b0:14:f4:94:b8:d3:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4363262d043654c257e4541b3cb014f494b8d320/; sid:902202848; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"61:9c:a1:45:04:50:b9:1c:d1:72:b3:09:37:3a:79:c4:59:17:37:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/619ca1450450b91cd172b309373a79c459173787/; sid:902202849; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f7:4e:35:71:bd:6b:a6:68:0e:fe:3d:4f:2a:ae:c2:cc:ba:60:e5:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f74e3571bd6ba6680efe3d4f2aaec2ccba60e5a5/; sid:902202850; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ef:4d:21:0c:97:77:02:9a:72:92:b6:bd:44:77:a9:9e:6a:02:eb:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef4d210c9777029a7292b6bd4477a99e6a02eb27/; sid:902202851; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ea:99:2c:0b:18:a3:31:35:4a:09:58:a4:a6:d9:6b:2e:ad:99:82:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea992c0b18a331354a0958a4a6d96b2ead99829b/; sid:902202852; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"88:1e:44:b0:8a:81:0b:2d:87:ac:ca:60:df:f8:84:df:ab:06:49:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/881e44b08a810b2d87acca60dff884dfab064900/; sid:902202853; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"89:31:0b:5c:35:e5:07:26:e8:52:a5:83:42:f5:6e:3d:36:24:46:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89310b5c35e50726e852a58342f56e3d362446f3/; sid:902202854; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ac:0f:e8:1c:b6:26:2b:0b:78:7c:25:ed:7d:f6:b3:98:70:0c:6d:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac0fe81cb6262b0b787c25ed7df6b398700c6d21/; sid:902202855; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"09:8b:92:9b:42:4b:b0:9c:bc:9f:97:f4:a6:29:b6:c8:85:59:a9:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/098b929b424bb09cbc9f97f4a629b6c88559a971/; sid:902202856; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"2b:06:b5:38:ec:42:5b:54:3c:e2:bd:07:70:17:80:fb:18:68:21:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b06b538ec425b543ce2bd07701780fb1868218e/; sid:902202857; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2f:b5:d4:e1:69:d7:d0:3b:13:ab:55:46:27:31:c6:ed:43:9b:36:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2fb5d4e169d7d03b13ab55462731c6ed439b363a/; sid:902202858; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e8:a9:f3:0e:99:e3:a9:f6:4e:32:aa:37:5c:2b:0c:2e:ce:06:ad:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8a9f30e99e3a9f64e32aa375c2b0c2ece06ade7/; sid:902202859; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b4:15:8d:49:43:1c:9d:2c:27:e2:a9:9c:b9:ea:41:84:b7:2c:b9:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4158d49431c9d2c27e2a99cb9ea4184b72cb9dd/; sid:902202860; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b6:c0:21:1b:e4:e0:20:1d:2e:41:29:89:f7:ae:98:61:4c:d9:55:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c0211be4e0201d2e412989f7ae98614cd9552f/; sid:902202861; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d1:a6:7e:96:26:98:f2:d8:62:10:a6:0d:b4:36:6f:d0:28:ae:f0:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1a67e962698f2d86210a60db4366fd028aef0f3/; sid:902202862; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"54:04:fc:7e:89:27:63:f1:6a:d1:10:8e:5c:ee:82:5a:5d:b6:fc:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5404fc7e892763f16ad1108e5cee825a5db6fc69/; sid:902202863; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"05:8e:72:36:08:c0:fb:2a:c0:1f:d1:f4:2e:cf:2b:03:c2:6a:f7:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/058e723608c0fb2ac01fd1f42ecf2b03c26af7ec/; sid:902202864; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware.Nemty C&C)"; tls.fingerprint:"d8:08:69:05:32:67:94:d0:e5:53:bd:6a:7a:d9:a0:64:98:b1:ce:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8086905326794d0e553bd6a7ad9a06498b1ce4d/; sid:902202865; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a4:1f:53:75:72:9b:32:73:b8:2a:5d:81:0f:ba:67:b4:c0:25:4b:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a41f5375729b3273b82a5d810fba67b4c0254b08/; sid:902202866; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d7:11:b3:4f:3a:6c:d9:ee:82:a6:76:99:18:3e:ae:e8:69:59:cb:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d711b34f3a6cd9ee82a67699183eaee86959cb3d/; sid:902202867; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ba:b5:68:47:4e:fe:17:dc:22:df:62:9f:43:4c:25:74:c8:ba:52:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bab568474efe17dc22df629f434c2574c8ba52d4/; sid:902202868; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"18:65:68:55:3a:81:a8:b3:fd:3e:33:2e:a3:36:a9:fc:e2:41:60:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/186568553a81a8b3fd3e332ea336a9fce24160f1/; sid:902202869; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e9:18:a5:6b:ea:e7:5a:eb:dc:7a:a1:4a:9e:78:2e:5d:1a:19:d7:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e918a56beae75aebdc7aa14a9e782e5d1a19d780/; sid:902202870; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f8:2e:93:d6:08:e6:a8:8c:95:36:0e:1b:92:75:f8:b5:a6:58:00:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f82e93d608e6a88c95360e1b9275f8b5a65800e0/; sid:902202871; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"11:6a:86:e0:c7:03:10:d1:35:22:1b:48:cd:fe:88:93:5a:3e:7a:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/116a86e0c70310d135221b48cdfe88935a3e7a49/; sid:902202872; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"71:f8:7d:11:e5:10:73:60:95:73:f5:91:fb:92:67:70:ef:45:07:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71f87d11e51073609573f591fb926770ef450758/; sid:902202873; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d8:77:d1:3c:4d:a2:90:c0:90:5c:cb:94:a0:fd:dc:5e:33:63:3e:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d877d13c4da290c0905ccb94a0fddc5e33633ef9/; sid:902202874; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:79:50:9f:e8:3c:09:19:5f:bd:d5:12:09:49:70:1e:b5:22:43:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2279509fe83c09195fbdd5120949701eb5224371/; sid:902202875; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:82:1d:7f:7c:20:6b:c0:f9:22:6c:2d:9d:45:99:4c:83:2e:bd:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78821d7f7c206bc0f9226c2d9d45994c832ebda9/; sid:902202876; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"94:a1:6d:3f:87:db:44:95:75:64:e9:8f:1b:2d:ab:9f:8f:f0:ec:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94a16d3f87db44957564e98f1b2dab9f8ff0ec46/; sid:902202877; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TinyNuke C&C)"; tls.fingerprint:"23:92:b4:19:6b:28:ba:ea:c7:94:43:74:b1:69:6d:55:63:18:77:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2392b4196b28baeac7944374b1696d55631877e7/; sid:902202878; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c3:63:f3:0a:f6:02:1c:5b:f3:3e:31:b6:ef:4f:83:29:b6:cd:08:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c363f30af6021c5bf33e31b6ef4f8329b6cd0868/; sid:902202879; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"80:f6:f9:e3:19:05:07:c2:7f:b6:3f:74:48:5c:7e:3b:c0:6a:72:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80f6f9e3190507c27fb63f74485c7e3bc06a726a/; sid:902202880; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"08:6d:4c:63:83:2e:3a:07:20:f3:58:81:0f:80:c7:59:21:75:81:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/086d4c63832e3a0720f358810f80c759217581a6/; sid:902202881; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"08:eb:b0:03:d3:dd:a1:6b:c8:1d:7b:b2:f6:5b:2e:58:be:1a:b9:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08ebb003d3dda16bc81d7bb2f65b2e58be1ab971/; sid:902202882; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d5:d8:e4:8a:94:e1:ae:53:59:cd:e5:83:1e:bf:dd:36:b0:35:26:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5d8e48a94e1ae5359cde5831ebfdd36b0352629/; sid:902202883; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b0:39:28:40:a4:4b:49:05:13:e4:79:44:92:0d:12:fa:8f:af:20:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0392840a44b490513e47944920d12fa8faf20c4/; sid:902202884; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"30:92:68:db:81:18:6f:49:14:bb:0c:08:c4:41:33:a6:95:2d:d6:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/309268db81186f4914bb0c08c44133a6952dd603/; sid:902202885; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:86:a5:a6:a6:62:fc:44:9b:25:58:81:1d:a6:41:78:0d:63:51:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2786a5a6a662fc449b2558811da641780d635113/; sid:902202886; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"51:9b:f0:66:84:eb:db:7e:51:72:bc:61:53:18:1d:9a:a8:5f:27:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/519bf06684ebdb7e5172bc6153181d9aa85f27cd/; sid:902202887; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2d:3a:ff:96:a0:a8:dc:98:01:5d:e8:1e:2d:cd:8b:7c:9b:92:d3:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d3aff96a0a8dc98015de81e2dcd8b7c9b92d376/; sid:902202888; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"83:cf:65:96:16:c2:2b:7d:3d:ef:b0:57:75:d6:0a:ef:95:3e:e6:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83cf659616c22b7d3defb05775d60aef953ee6ca/; sid:902202889; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"19:b1:9d:33:2a:6f:48:20:9e:e9:dd:51:0b:3f:e1:d2:17:8c:88:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19b19d332a6f48209ee9dd510b3fe1d2178c8806/; sid:902202890; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"47:3b:fc:a8:b7:e8:85:56:48:27:31:54:9a:be:b9:65:9a:a1:b8:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/473bfca8b7e88556482731549abeb9659aa1b8f8/; sid:902202891; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d7:ff:f5:48:76:76:b1:8d:ef:88:d8:3f:43:91:4f:d4:34:99:0c:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7fff5487676b18def88d83f43914fd434990c0a/; sid:902202892; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"93:92:da:5f:2d:05:49:98:86:1e:88:a6:b8:0e:52:74:19:aa:38:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9392da5f2d054998861e88a6b80e527419aa384c/; sid:902202893; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"37:dc:ed:e9:3c:35:6b:1e:87:c9:59:4c:2f:f7:62:19:d1:7e:14:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37dcede93c356b1e87c9594c2ff76219d17e14a6/; sid:902202894; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:47:3f:7c:39:23:a5:33:02:5f:20:68:83:69:d9:f6:63:28:35:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3473f7c3923a533025f20688369d9f663283594/; sid:902202895; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5c:87:38:46:24:ab:2b:04:c9:2f:b7:03:c6:44:6c:44:ab:5c:9e:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c87384624ab2b04c92fb703c6446c44ab5c9ecd/; sid:902202896; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"bb:56:e3:d9:b3:70:cf:f3:37:69:c1:18:12:e1:0f:e0:94:b3:18:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb56e3d9b370cff33769c11812e10fe094b31800/; sid:902202897; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"de:98:64:31:ff:37:f7:dc:bd:7c:70:13:aa:47:be:d4:f2:14:83:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de986431ff37f7dcbd7c7013aa47bed4f21483c3/; sid:902202898; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"fb:a3:fd:ed:74:31:cf:44:2f:6d:c0:e6:df:95:6c:7b:c6:63:bf:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fba3fded7431cf442f6dc0e6df956c7bc663bfed/; sid:902202899; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1c:ce:2d:93:40:3e:74:8a:7a:a1:75:51:1d:89:7e:2d:a6:f5:09:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cce2d93403e748a7aa175511d897e2da6f50920/; sid:902202900; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5e:f5:f7:05:a9:a5:b2:97:cb:e5:fe:8e:41:2b:b7:58:2c:20:9b:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ef5f705a9a5b297cbe5fe8e412bb7582c209bfd/; sid:902202901; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"74:86:ac:5b:2a:f4:44:13:00:36:97:96:8d:5c:2f:46:fa:a6:49:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7486ac5b2af44413003697968d5c2f46faa649ca/; sid:902202902; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"1b:61:d0:2d:82:0b:d7:11:08:7c:85:05:57:a8:1b:bf:af:53:24:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b61d02d820bd711087c850557a81bbfaf53246c/; sid:902202903; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c1:cd:0d:73:ac:78:05:18:21:a3:d8:2c:4a:1c:81:6d:57:f0:90:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1cd0d73ac78051821a3d82c4a1c816d57f0909d/; sid:902202904; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8c:95:e6:7d:32:1e:82:9d:0a:40:eb:f5:64:59:76:17:c2:61:cc:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c95e67d321e829d0a40ebf564597617c261cc4c/; sid:902202905; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"3b:05:34:8b:3f:4d:e2:b8:33:cf:93:5a:6c:9e:03:a2:cb:7c:bd:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b05348b3f4de2b833cf935a6c9e03a2cb7cbde9/; sid:902202906; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"7c:f9:02:ff:50:b3:86:9c:ca:a4:71:5b:25:bb:ea:3c:b1:8a:18:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7cf902ff50b3869ccaa4715b25bbea3cb18a18b5/; sid:902202907; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"ea:c4:ce:d3:59:ad:5f:02:8e:6f:89:44:06:9e:bb:97:77:bc:79:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eac4ced359ad5f028e6f8944069ebb9777bc79db/; sid:902202908; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"69:53:08:12:18:a0:bd:02:29:b1:b0:bf:63:97:37:8e:ad:06:60:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6953081218a0bd0229b1b0bf6397378ead0660cf/; sid:902202909; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"93:45:1c:ec:2f:b6:85:3f:bd:6f:b5:05:3b:ae:74:71:62:e0:fe:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93451cec2fb6853fbd6fb5053bae747162e0feaf/; sid:902202910; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"52:b6:df:64:f9:2c:c9:53:79:36:5c:79:b2:27:cd:f6:fe:1f:ad:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52b6df64f92cc95379365c79b227cdf6fe1fad5d/; sid:902202911; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"9d:51:76:3b:a3:fd:4d:4f:b1:60:13:49:82:6f:0e:8a:58:45:22:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d51763ba3fd4d4fb1601349826f0e8a58452275/; sid:902202912; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"11:df:78:8f:84:13:86:01:eb:ca:db:ff:9f:fe:a9:02:cb:41:63:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11df788f84138601ebcadbff9ffea902cb41637e/; sid:902202913; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"df:68:a8:78:f3:ea:a3:56:72:a3:ba:ed:6e:1b:d4:ff:b3:36:84:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df68a878f3eaa35672a3baed6e1bd4ffb336842d/; sid:902202914; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"53:58:49:69:dc:1d:06:b9:15:3c:78:ef:29:84:6d:b0:45:7e:fa:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53584969dc1d06b9153c78ef29846db0457efa87/; sid:902202915; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"1f:62:8f:0b:2c:d0:ec:19:28:9d:ba:30:b3:0d:59:13:2f:df:1d:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f628f0b2cd0ec19289dba30b30d59132fdf1d18/; sid:902202916; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:44:14:fa:fd:eb:e3:ea:c6:f6:2c:8c:77:58:f6:20:3b:cb:03:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c4414fafdebe3eac6f62c8c7758f6203bcb03ee/; sid:902202917; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"00:50:1d:89:a8:80:f6:3b:bf:9c:a4:79:32:b8:5b:8c:2a:1f:23:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00501d89a880f63bbf9ca47932b85b8c2a1f2373/; sid:902202918; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"2a:2b:4b:a8:e3:67:65:e6:ee:f4:46:15:21:db:6d:7a:67:9a:84:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a2b4ba8e36765e6eef4461521db6d7a679a8409/; sid:902202919; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:3a:e8:65:54:dc:d9:55:11:74:db:8b:4b:ee:d8:2f:fa:50:ff:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/303ae86554dcd9551174db8b4beed82ffa50ff36/; sid:902202920; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:a3:b9:35:85:b4:19:30:5a:c1:64:63:d0:3a:89:37:c8:86:f0:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7aa3b93585b419305ac16463d03a8937c886f0ee/; sid:902202921; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"0b:43:b1:f1:7f:c3:b4:8e:f0:7a:bd:df:6c:61:fe:16:05:d9:31:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b43b1f17fc3b48ef07abddf6c61fe1605d93121/; sid:902202922; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"50:2c:91:89:52:ce:c3:3e:f1:f0:30:94:f9:11:3c:70:e6:7d:4f:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/502c918952cec33ef1f03094f9113c70e67d4f1a/; sid:902202923; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e2:6e:60:3c:56:3b:41:ed:e2:9b:e1:b8:0a:5a:f0:8e:2a:59:96:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e26e603c563b41ede29be1b80a5af08e2a599627/; sid:902202924; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"69:8c:3c:d0:be:c7:a9:e0:f5:41:cf:b0:25:03:02:00:e0:4e:54:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/698c3cd0bec7a9e0f541cfb025030200e04e54a6/; sid:902202925; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"39:c4:83:c2:57:2f:69:65:93:3e:45:c9:7c:5e:5a:be:a1:a2:fc:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39c483c2572f6965933e45c97c5e5abea1a2fc35/; sid:902202926; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"27:b0:de:ea:c2:3c:90:ea:fa:a5:9a:41:0d:e5:e1:1f:3e:6c:4f:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27b0deeac23c90eafaa59a410de5e11f3e6c4f17/; sid:902202927; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:c6:71:31:3a:b3:0e:22:9c:f2:bf:12:b4:92:c5:dc:bb:ea:b5:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2c671313ab30e229cf2bf12b492c5dcbbeab591/; sid:902202928; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c7:34:40:bd:ea:2b:f8:eb:4c:3c:4a:3a:a9:5e:d3:9e:4f:e1:c8:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c73440bdea2bf8eb4c3c4a3aa95ed39e4fe1c8fa/; sid:902202929; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"64:4b:15:12:af:6f:bc:bb:3a:a4:cc:ee:4b:12:cb:ed:fe:4f:3c:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/644b1512af6fbcbb3aa4ccee4b12cbedfe4f3cf9/; sid:902202930; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"62:28:c3:9f:bc:97:54:4e:af:f5:34:ff:b4:cb:11:a2:c3:b9:8d:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6228c39fbc97544eaff534ffb4cb11a2c3b98d58/; sid:902202931; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b6:ba:50:48:64:44:a1:6a:a6:02:bb:2e:f5:9d:6d:3e:87:2f:80:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6ba50486444a16aa602bb2ef59d6d3e872f80c9/; sid:902202932; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"53:e7:c3:c6:cd:35:5e:ab:07:f4:3b:18:a8:06:04:83:4f:4c:e5:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53e7c3c6cd355eab07f43b18a80604834f4ce5fb/; sid:902202933; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"28:27:c4:10:ec:75:4e:24:2c:3c:8b:8f:ee:b9:bd:c4:86:81:2a:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2827c410ec754e242c3c8b8feeb9bdc486812a3b/; sid:902202934; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"20:8b:de:39:ff:57:b8:4f:63:ff:64:06:43:ae:17:e7:a0:c8:e3:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/208bde39ff57b84f63ff640643ae17e7a0c8e304/; sid:902202935; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"5c:e2:ba:0a:af:ba:41:6b:18:d5:ff:23:d5:c4:9a:94:1d:6d:a9:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ce2ba0aafba416b18d5ff23d5c49a941d6da9db/; sid:902202936; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobInt C&C)"; tls.fingerprint:"54:06:ec:e2:3c:12:68:54:8e:39:d2:83:88:c3:3c:e1:fc:4b:e3:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5406ece23c1268548e39d28388c33ce1fc4be310/; sid:902202937; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:09:6d:ef:de:6b:fa:8e:87:c9:07:7b:b8:3c:4f:2c:3e:6f:3d:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28096defde6bfa8e87c9077bb83c4f2c3e6f3ded/; sid:902202938; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c1:bd:a1:ea:8c:1f:4f:9e:ad:79:8d:74:95:a8:98:b3:d4:47:a7:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1bda1ea8c1f4f9ead798d7495a898b3d447a771/; sid:902202939; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"01:9a:14:cb:ea:17:1a:cd:0f:80:0d:fa:50:5f:d0:d1:41:8c:87:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/019a14cbea171acd0f800dfa505fd0d1418c876c/; sid:902202940; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PsiXBot C&C)"; tls.fingerprint:"41:e5:c1:47:58:3c:b7:e5:b5:d3:13:23:76:ae:f7:69:6d:53:dc:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41e5c147583cb7e5b5d3132376aef7696d53dc35/; sid:902202941; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"5c:e2:2c:06:00:6a:86:af:4b:70:b9:77:20:2c:94:c2:5c:ed:6c:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ce22c06006a86af4b70b977202c94c25ced6cc8/; sid:902202942; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"2e:9e:5d:5e:c3:be:fb:da:86:a3:21:31:d0:59:d8:7a:b5:e3:7e:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e9e5d5ec3befbda86a32131d059d87ab5e37e8d/; sid:902202943; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"51:a4:05:e1:79:1e:14:af:11:20:83:87:34:8a:13:99:e6:e6:31:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51a405e1791e14af11208387348a1399e6e63195/; sid:902202944; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PredatorStealer C&C)"; tls.fingerprint:"dc:09:cf:47:d9:29:6e:75:cd:51:40:18:26:99:73:82:15:ec:e3:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc09cf47d9296e75cd5140182699738215ece3fe/; sid:902202945; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"66:3c:92:61:c6:50:2f:85:6e:26:07:51:09:6f:67:78:e1:b1:b0:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/663c9261c6502f856e260751096f6778e1b1b00d/; sid:902202946; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"50:6b:d9:7e:7e:d0:f9:75:8b:c5:44:c3:00:f7:22:73:2c:01:b4:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/506bd97e7ed0f9758bc544c300f722732c01b49f/; sid:902202947; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"c6:fe:66:a3:4a:6f:c3:41:1b:a7:6a:f8:01:0e:eb:d5:3b:f5:03:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6fe66a34a6fc3411ba76af8010eebd53bf5034f/; sid:902202948; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"97:53:06:e7:5e:de:7c:ad:22:80:74:db:0e:ed:4b:42:c6:bb:5f:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/975306e75ede7cad228074db0eed4b42c6bb5fb7/; sid:902202949; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fe:98:96:aa:1f:bb:77:92:a2:a0:0d:e5:02:d4:97:14:16:32:ed:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe9896aa1fbb7792a2a00de502d497141632ed80/; sid:902202950; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"73:2b:1b:65:8b:4a:87:8c:23:88:8f:61:3c:68:46:f1:b5:30:06:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/732b1b658b4a878c23888f613c6846f1b530067b/; sid:902202951; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobInt C&C)"; tls.fingerprint:"b4:b6:0b:4a:4a:7d:2f:ca:07:e2:68:59:e6:5c:4b:56:36:00:af:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4b60b4a4a7d2fca07e26859e65c4b563600af04/; sid:902202952; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"31:1a:67:f7:98:67:4c:c2:cf:94:6a:be:94:65:aa:f1:17:d6:44:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/311a67f798674cc2cf946abe9465aaf117d644ac/; sid:902202953; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"aa:ab:6a:a3:05:aa:ae:a6:b0:83:c8:08:50:1a:f6:25:2e:41:91:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aaab6aa305aaaea6b083c808501af6252e41915a/; sid:902202954; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"56:b2:e4:2c:07:c9:26:6f:59:9b:57:b3:7f:4b:04:04:bc:e6:e9:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56b2e42c07c9266f599b57b37f4b0404bce6e911/; sid:902202955; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"53:6d:b0:b0:6c:be:1c:92:f3:0d:81:7f:24:b6:46:cf:84:94:ce:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/536db0b06cbe1c92f30d817f24b646cf8494ce31/; sid:902202956; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a8:3b:24:59:41:cc:15:56:44:2e:0c:c3:de:6b:2e:dd:2b:36:4e:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a83b245941cc1556442e0cc3de6b2edd2b364ed7/; sid:902202957; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"7b:0e:12:41:de:d2:78:9e:6a:82:eb:fa:c3:a2:d6:d1:9a:44:30:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b0e1241ded2789e6a82ebfac3a2d6d19a44305b/; sid:902202958; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c4:7e:db:00:55:a4:15:9e:45:68:37:b5:3c:c2:0f:72:7a:73:22:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c47edb0055a4159e456837b53cc20f727a7322e1/; sid:902202959; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"02:f7:8f:67:2f:41:0c:d3:12:3a:2f:7c:a0:15:87:02:dc:ef:7e:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02f78f672f410cd3123a2f7ca0158702dcef7e6a/; sid:902202960; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"20:02:39:a8:0d:d9:6c:66:74:1e:30:33:db:e2:43:a5:09:5e:39:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/200239a80dd96c66741e3033dbe243a5095e3979/; sid:902202961; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"45:44:f8:91:cb:3c:19:03:66:bc:5d:0d:33:1a:e1:7e:25:4b:26:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4544f891cb3c190366bc5d0d331ae17e254b26e6/; sid:902202962; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PredatorStealer C&C)"; tls.fingerprint:"d8:ae:dd:31:da:f3:85:b5:38:25:5e:1f:a5:87:9e:19:19:db:64:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8aedd31daf385b538255e1fa5879e1919db64b1/; sid:902202963; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"3c:14:e7:aa:18:06:1e:9a:dc:c7:80:44:c4:60:77:66:b4:a8:d0:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c14e7aa18061e9adcc78044c4607766b4a8d0c0/; sid:902202964; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6c:c9:5d:cc:35:ca:96:32:6b:c7:89:34:98:4a:19:0f:09:e1:0d:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cc95dcc35ca96326bc78934984a190f09e10d03/; sid:902202965; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"02:f3:bd:8a:37:54:b2:0f:1d:6e:b1:40:02:25:f3:23:0c:c4:d1:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02f3bd8a3754b20f1d6eb1400225f3230cc4d11f/; sid:902202966; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"22:1d:03:5e:44:1c:0e:e3:59:5e:24:d3:e4:de:bd:ca:87:8d:0b:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/221d035e441c0ee3595e24d3e4debdca878d0bfb/; sid:902202967; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"43:17:d4:68:33:51:1a:21:7f:6f:0b:1c:c0:1d:ed:62:8c:af:fa:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4317d46833511a217f6f0b1cc01ded628caffa7a/; sid:902202968; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:99:b5:92:2e:98:85:90:85:3f:1a:d8:3c:08:32:2e:7b:b5:b2:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2999b5922e988590853f1ad83c08322e7bb5b2b0/; sid:902202969; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"40:8f:38:7e:3e:fe:fa:21:0c:b5:cc:e3:67:d4:40:d8:f8:88:a8:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/408f387e3efefa210cb5cce367d440d8f888a814/; sid:902202970; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"14:7a:2b:14:54:1b:2a:55:bb:cc:2a:79:cd:5e:19:76:ba:8c:e6:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/147a2b14541b2a55bbcc2a79cd5e1976ba8ce611/; sid:902202971; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"85:79:2a:f2:0e:1a:8d:e4:c1:5d:a9:cc:3a:b9:7a:64:96:ff:c8:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85792af20e1a8de4c15da9cc3ab97a6496ffc8a3/; sid:902202972; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"26:10:87:ae:80:29:e6:84:6d:f0:b2:46:17:a5:a0:43:89:b3:ba:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/261087ae8029e6846df0b24617a5a04389b3ba45/; sid:902202973; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"dd:44:2a:61:a3:79:08:de:83:0e:20:26:c2:62:59:40:c1:bc:c7:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd442a61a37908de830e2026c2625940c1bcc79a/; sid:902202974; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"59:61:5b:46:2f:9c:39:58:a9:be:ac:ba:c2:db:85:60:6d:6c:23:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59615b462f9c3958a9beacbac2db85606d6c2357/; sid:902202975; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"09:5b:d6:46:3c:d2:d1:f6:fb:08:80:e3:14:c6:51:bc:b6:ce:db:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/095bd6463cd2d1f6fb0880e314c651bcb6cedba6/; sid:902202976; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"f0:3e:d0:35:45:7b:c1:31:92:4f:77:a4:65:99:01:4f:af:c4:bc:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f03ed035457bc131924f77a46599014fafc4bc9d/; sid:902202977; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"51:79:ef:06:82:0b:d5:32:3b:5b:2b:1f:02:49:79:4c:d7:f2:5d:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5179ef06820bd5323b5b2b1f0249794cd7f25d4e/; sid:902202978; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"9e:d3:2c:f2:1c:a2:44:a7:85:da:6a:62:54:c2:a7:b8:f4:1e:61:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ed32cf21ca244a785da6a6254c2a7b8f41e6153/; sid:902202979; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PredatorStealer C&C)"; tls.fingerprint:"ac:2f:cc:2c:6a:6f:d7:75:7e:24:f2:69:a8:f9:3f:21:87:f0:4a:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac2fcc2c6a6fd7757e24f269a8f93f2187f04a6e/; sid:902202980; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"23:8d:8b:89:fb:1d:48:57:7f:e7:2d:4b:fc:6a:bf:f8:34:83:35:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/238d8b89fb1d48577fe72d4bfc6abff83483358b/; sid:902202981; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"10:80:27:05:c6:5f:12:3e:98:97:97:bf:e0:ba:46:ba:33:b3:9d:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10802705c65f123e989797bfe0ba46ba33b39d70/; sid:902202982; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"ac:bb:66:69:8b:5c:41:ea:5d:5a:7c:9c:7a:91:e9:79:03:80:00:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acbb66698b5c41ea5d5a7c9c7a91e97903800031/; sid:902202983; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"4c:cb:e2:1d:74:a8:b2:06:6c:14:3e:18:39:0e:5b:c8:6c:4a:43:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ccbe21d74a8b2066c143e18390e5bc86c4a4368/; sid:902202984; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"47:9d:98:c9:37:fa:9d:89:e7:6c:db:c2:76:d4:13:6c:bb:7e:2c:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/479d98c937fa9d89e76cdbc276d4136cbb7e2c8a/; sid:902202985; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:2c:e4:db:da:f0:34:4b:d7:34:db:f9:87:74:42:36:41:e4:8f:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e42ce4dbdaf0344bd734dbf98774423641e48f5a/; sid:902202986; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"72:f2:4c:a3:d5:65:83:a2:8c:c3:ec:90:ae:ff:6b:16:e2:2d:1e:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72f24ca3d56583a28cc3ec90aeff6b16e22d1eea/; sid:902202987; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b6:c2:e9:2c:67:63:f0:d8:f5:ab:53:e7:f8:58:cf:c9:4c:05:c3:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c2e92c6763f0d8f5ab53e7f858cfc94c05c319/; sid:902202988; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"4d:c1:bd:19:a1:cc:3d:43:23:2e:ee:ea:1f:99:76:56:1e:a4:d2:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4dc1bd19a1cc3d43232eeeea1f9976561ea4d215/; sid:902202989; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:10:b1:f8:e6:8a:e3:6b:c9:a8:e4:ef:71:8d:93:17:e5:d6:d5:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d110b1f8e68ae36bc9a8e4ef718d9317e5d6d54c/; sid:902202990; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dc:97:fb:4b:f1:32:fc:0e:02:68:87:c1:66:4b:a1:57:27:5b:6f:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc97fb4bf132fc0e026887c1664ba157275b6fe4/; sid:902202991; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:87:1c:09:96:03:18:6c:a2:6b:9c:51:d5:9d:d7:89:f2:b3:68:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06871c099603186ca26b9c51d59dd789f2b3686b/; sid:902202992; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"85:c9:0c:84:64:37:43:d7:88:99:28:22:1f:ba:7e:a7:7b:5d:1a:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85c90c84643743d7889928221fba7ea77b5d1a5a/; sid:902202993; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"da:54:72:c3:04:25:1f:99:b7:9d:94:4c:71:38:d7:51:3c:8d:d2:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da5472c304251f99b79d944c7138d7513c8dd264/; sid:902202994; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"1d:9c:0e:06:ae:5d:47:0d:d3:83:c3:5c:2f:1a:e0:df:46:77:f1:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d9c0e06ae5d470dd383c35c2f1ae0df4677f16e/; sid:902202995; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"dc:9e:e1:57:94:1c:a7:f6:ef:e4:9c:2a:e6:4b:a9:51:4e:8a:e4:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc9ee157941ca7f6efe49c2ae64ba9514e8ae40d/; sid:902202996; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"17:57:dd:01:25:ca:88:a5:9c:56:b4:ea:84:42:21:87:e8:e4:2e:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1757dd0125ca88a59c56b4ea84422187e8e42ea6/; sid:902202997; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"0e:12:b2:db:c3:e8:99:2b:84:0c:fd:2f:fd:6b:ce:c3:8c:18:af:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e12b2dbc3e8992b840cfd2ffd6bcec38c18af13/; sid:902202998; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:ec:77:26:94:ed:6d:11:5a:82:d2:1f:a0:ca:8a:e4:bb:1f:2c:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3aec772694ed6d115a82d21fa0ca8ae4bb1f2c35/; sid:902202999; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"f0:a9:25:3d:e5:cb:31:fa:dc:1c:5f:2e:65:29:05:f5:02:27:e5:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0a9253de5cb31fadc1c5f2e652905f50227e576/; sid:902203000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"eb:dc:eb:40:38:c9:48:1d:12:0e:2f:2c:f6:e6:fa:f2:02:eb:d1:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebdceb4038c9481d120e2f2cf6e6faf202ebd1df/; sid:902203001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:80:f2:e9:60:4f:d6:e1:ff:63:75:1b:64:48:06:51:71:cc:d4:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0880f2e9604fd6e1ff63751b6448065171ccd439/; sid:902203002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:3a:52:d0:14:bd:eb:3b:e6:da:ee:6d:ab:0f:c2:76:bb:c1:98:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a3a52d014bdeb3be6daee6dab0fc276bbc19867/; sid:902203003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b7:3f:50:53:99:a8:47:31:6d:e1:05:b8:c6:78:39:9f:37:a7:3a:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b73f505399a847316de105b8c678399f37a73a66/; sid:902203004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"cf:bf:a6:72:45:15:b3:82:9c:c7:84:35:91:80:94:c8:6d:60:84:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfbfa6724515b3829cc78435918094c86d608429/; sid:902203005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"69:25:0d:36:91:c4:2a:53:70:8c:b5:82:ab:6c:1b:44:ef:94:a2:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69250d3691c42a53708cb582ab6c1b44ef94a2fd/; sid:902203006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"1f:ac:b1:de:1a:46:3d:e4:b6:d5:21:3c:7c:cd:62:83:5d:2b:6a:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1facb1de1a463de4b6d5213c7ccd62835d2b6a36/; sid:902203007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"db:20:b7:39:72:0e:a6:0c:0d:11:0e:8a:2e:2a:08:77:3b:1d:5b:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db20b739720ea60c0d110e8a2e2a08773b1d5b1d/; sid:902203008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"dd:08:2f:01:b9:7f:6e:f1:69:96:25:07:23:6c:ee:42:83:49:83:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd082f01b97f6ef169962507236cee4283498316/; sid:902203009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"21:b3:c9:01:e7:f0:1e:d6:59:0e:19:8a:d3:51:2c:b5:31:05:f0:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21b3c901e7f01ed6590e198ad3512cb53105f018/; sid:902203010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"5f:4a:f8:75:f9:0b:39:d1:53:1b:f9:52:61:36:7e:bc:f8:fc:df:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f4af875f90b39d1531bf95261367ebcf8fcdfba/; sid:902203011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ab:84:a1:e1:77:14:93:f5:64:6e:3b:d5:e5:d4:d9:cc:42:79:80:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab84a1e1771493f5646e3bd5e5d4d9cc42798023/; sid:902203012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cd:56:f2:d6:56:89:a9:b3:c5:d1:ea:71:80:18:c4:d9:14:c2:ce:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd56f2d65689a9b3c5d1ea718018c4d914c2ced3/; sid:902203013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:8a:9b:e6:de:d4:ea:f8:64:bd:5c:1b:06:de:0d:c3:37:ba:ca:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c8a9be6ded4eaf864bd5c1b06de0dc337baca84/; sid:902203014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"89:79:5b:38:4e:7e:f8:ed:70:12:3f:37:6d:4e:e1:36:0a:67:32:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89795b384e7ef8ed70123f376d4ee1360a673235/; sid:902203015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"da:4c:0b:87:92:8e:be:31:0f:ac:27:74:43:fe:d9:78:f1:36:16:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da4c0b87928ebe310fac277443fed978f13616d7/; sid:902203016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c2:28:17:61:69:b8:c5:83:6f:b6:3a:b1:44:17:ad:46:8b:bd:dc:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c228176169b8c5836fb63ab14417ad468bbddc26/; sid:902203017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2d:2e:5f:4d:60:47:4c:9e:3f:a6:84:ce:3d:3d:dd:3f:be:36:a3:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d2e5f4d60474c9e3fa684ce3d3ddd3fbe36a351/; sid:902203018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"db:bb:73:cf:1c:a8:79:29:c2:3b:9c:fb:8f:2c:ee:17:ec:91:0a:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbbb73cf1ca87929c23b9cfb8f2cee17ec910ae3/; sid:902203019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"09:90:4c:da:16:b5:60:12:9e:70:39:d2:f7:48:2b:8e:ca:04:a1:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09904cda16b560129e7039d2f7482b8eca04a19f/; sid:902203020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dc:53:a8:eb:e9:86:74:f5:97:4e:cd:10:ea:79:ed:9f:d0:40:df:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc53a8ebe98674f5974ecd10ea79ed9fd040df43/; sid:902203021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:9d:b7:a9:94:98:89:16:49:f3:fe:3e:38:14:61:2c:46:b6:7e:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/389db7a99498891649f3fe3e3814612c46b67e9f/; sid:902203022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"ae:04:24:d2:37:03:82:13:99:89:ac:0f:12:26:8e:f8:86:ca:a2:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae0424d2370382139989ac0f12268ef886caa2ce/; sid:902203023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"69:18:39:fb:ea:d7:0a:e9:fe:a3:14:83:73:dd:09:ae:65:51:4d:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/691839fbead70ae9fea3148373dd09ae65514d73/; sid:902203024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"6f:13:e7:41:25:1c:10:7d:b3:29:4c:c4:d1:d8:e8:52:2c:4b:81:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f13e741251c107db3294cc4d1d8e8522c4b810c/; sid:902203025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e3:4c:59:dd:e0:48:59:fb:3b:6a:37:85:7e:d2:53:50:1a:52:d2:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e34c59dde04859fb3b6a37857ed253501a52d288/; sid:902203026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"51:c0:5b:bc:b0:ba:ae:64:81:37:0c:47:d6:c6:38:fd:e8:68:59:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51c05bbcb0baae6481370c47d6c638fde8685925/; sid:902203027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:08:08:03:96:c6:ed:01:d9:74:0b:f6:cb:48:89:1b:75:eb:38:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7608080396c6ed01d9740bf6cb48891b75eb3838/; sid:902203028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"d9:94:42:3f:92:11:8b:75:52:12:75:40:90:c0:4f:c6:96:44:76:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d994423f92118b755212754090c04fc696447685/; sid:902203029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0b:64:77:99:3a:1b:5c:5c:b1:94:ed:72:18:5d:05:2d:61:20:6d:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b6477993a1b5c5cb194ed72185d052d61206dc5/; sid:902203030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"9d:1f:c9:0b:3a:11:ae:53:ec:56:63:9e:02:b6:fe:89:d0:48:a7:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d1fc90b3a11ae53ec56639e02b6fe89d048a775/; sid:902203031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fc:96:05:c4:95:76:ad:dc:f5:c9:ee:2f:5f:2b:46:d4:6d:83:c6:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc9605c49576addcf5c9ee2f5f2b46d46d83c688/; sid:902203032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:2b:b0:f4:07:48:23:3a:18:6c:70:b3:ec:ad:cb:80:7d:66:0e:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff2bb0f40748233a186c70b3ecadcb807d660e97/; sid:902203033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b6:9e:3b:cc:8e:51:e1:08:74:1f:15:26:a5:57:48:af:35:07:27:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b69e3bcc8e51e108741f1526a55748af350727cf/; sid:902203034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"9b:a7:96:f1:69:21:84:25:c8:f8:6a:98:92:80:2b:9b:1b:c7:03:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ba796f169218425c8f86a9892802b9b1bc703ee/; sid:902203035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cd:b0:cd:3b:9b:a7:71:e9:5c:69:64:37:25:3c:26:04:79:dc:4c:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cdb0cd3b9ba771e95c696437253c260479dc4cd3/; sid:902203036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f3:96:ac:0e:e9:19:65:54:d7:8e:aa:c0:55:db:54:24:1c:88:2a:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f396ac0ee9196554d78eaac055db54241c882a6c/; sid:902203037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"75:86:73:e3:0b:58:67:1f:f3:ad:1a:40:e2:39:2b:76:f0:31:db:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/758673e30b58671ff3ad1a40e2392b76f031dbc1/; sid:902203038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7b:af:03:31:6e:2b:a9:01:27:ff:3c:9b:da:a7:2f:57:1e:d8:96:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7baf03316e2ba90127ff3c9bdaa72f571ed896b0/; sid:902203039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"59:fb:36:6e:b9:59:18:82:85:a8:c3:22:b5:4a:99:ed:3a:74:ed:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59fb366eb959188285a8c322b54a99ed3a74ed8d/; sid:902203040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f0:d7:ca:0b:90:d6:5d:b6:5b:85:da:cb:e6:26:7d:be:23:25:bd:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0d7ca0b90d65db65b85dacbe6267dbe2325bdf1/; sid:902203041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d6:15:c6:29:33:1e:e5:2a:ab:9a:e2:d1:2d:14:1b:7c:b3:d7:97:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d615c629331ee52aab9ae2d12d141b7cb3d797e0/; sid:902203042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"88:89:59:65:65:d7:df:c6:68:bc:0e:fb:6e:22:dd:72:86:9b:06:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8889596565d7dfc668bc0efb6e22dd72869b06e7/; sid:902203043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"9d:3d:77:b1:51:a1:71:0f:6b:16:05:23:64:e5:0c:ff:17:12:03:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d3d77b151a1710f6b16052364e50cff17120358/; sid:902203044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"cd:78:c1:8b:97:45:4e:69:3f:41:c3:e9:70:4c:b8:42:88:33:05:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd78c18b97454e693f41c3e9704cb8428833054f/; sid:902203045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"45:39:35:d1:b1:91:a9:d0:d7:47:6a:5a:3a:c2:42:88:75:f1:bd:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/453935d1b191a9d0d7476a5a3ac2428875f1bd91/; sid:902203046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e2:72:c0:00:25:b2:78:47:f2:e4:39:01:62:45:ec:3a:9e:8f:84:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e272c00025b27847f2e439016245ec3a9e8f844d/; sid:902203047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"88:eb:b2:16:92:b2:ad:ad:dc:52:0c:e5:e7:b6:c4:74:90:7a:25:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88ebb21692b2adaddc520ce5e7b6c474907a2504/; sid:902203048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fa:5e:c7:35:95:62:e2:d9:d4:91:70:ac:aa:10:d5:3d:e7:44:19:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa5ec7359562e2d9d49170acaa10d53de7441946/; sid:902203049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"79:66:1a:64:20:d2:42:be:f7:34:13:97:63:e0:3d:53:79:7a:b6:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79661a6420d242bef734139763e03d53797ab6fc/; sid:902203050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d2:84:1f:be:cd:05:f9:3c:93:b7:a6:91:5e:d7:16:64:9b:ce:92:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2841fbecd05f93c93b7a6915ed716649bce9264/; sid:902203051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:32:ce:5b:1e:60:d7:7d:af:fd:96:3b:6f:6f:cc:4f:c2:f9:a3:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2832ce5b1e60d77daffd963b6f6fcc4fc2f9a39c/; sid:902203052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"48:ad:ff:04:1d:35:a8:9c:c2:a9:df:5d:80:fd:65:79:c2:40:c8:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48adff041d35a89cc2a9df5d80fd6579c240c8b8/; sid:902203053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"24:d6:c9:af:c6:c8:99:1f:63:f8:42:cf:65:35:4d:46:14:9e:01:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24d6c9afc6c8991f63f842cf65354d46149e01fa/; sid:902203054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"06:fc:7f:f6:35:8b:b6:9a:a2:95:16:5a:d7:8f:22:f9:c5:70:0a:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06fc7ff6358bb69aa295165ad78f22f9c5700aa0/; sid:902203055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ac:5f:ad:f9:63:54:c7:dd:78:f5:47:3a:0a:27:38:7d:e9:b1:2d:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac5fadf96354c7dd78f5473a0a27387de9b12d5e/; sid:902203056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3a:42:59:57:b8:9d:51:04:8f:13:65:57:55:9a:cb:df:5f:95:a8:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a425957b89d51048f136557559acbdf5f95a818/; sid:902203057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"be:e3:3d:5a:9b:29:c0:29:38:b3:1c:f8:e8:ab:99:5c:4a:36:71:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bee33d5a9b29c02938b31cf8e8ab995c4a3671e1/; sid:902203058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5f:1b:33:d7:61:4d:f1:32:36:52:37:0c:e6:a8:92:ce:72:d5:14:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f1b33d7614df1323652370ce6a892ce72d514f7/; sid:902203059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"44:00:75:f2:65:0e:94:31:11:08:73:35:c9:20:02:c6:d6:da:20:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/440075f2650e943111087335c92002c6d6da20b7/; sid:902203060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"31:96:0e:6e:70:fa:4e:d2:27:0a:55:42:b8:bb:3f:ec:98:4a:3a:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31960e6e70fa4ed2270a5542b8bb3fec984a3a32/; sid:902203061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"1d:f8:c7:cc:29:f0:6b:37:6f:35:35:91:d0:4f:94:a0:c2:3b:c5:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1df8c7cc29f06b376f353591d04f94a0c23bc5e3/; sid:902203062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"25:cb:de:5d:ed:2a:6b:43:27:06:2e:8a:64:5c:a5:02:9e:7c:b7:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25cbde5ded2a6b4327062e8a645ca5029e7cb79d/; sid:902203063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (KPOTStealer C&C)"; tls.fingerprint:"7a:4d:12:17:95:8c:45:7b:a2:68:f6:cc:c0:d3:be:6a:70:34:57:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a4d1217958c457ba268f6ccc0d3be6a70345751/; sid:902203064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BlueBot C&C)"; tls.fingerprint:"49:89:34:34:5c:f3:5b:fb:00:83:d3:ed:7f:64:db:39:39:b8:a8:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/498934345cf35bfb0083d3ed7f64db3939b8a839/; sid:902203065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"05:e7:04:d1:ec:2a:e8:54:3e:12:b0:d4:92:b8:a5:f2:b9:31:af:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05e704d1ec2ae8543e12b0d492b8a5f2b931af38/; sid:902203066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f9:9e:33:b9:12:b9:73:3d:99:16:4d:36:9c:68:dd:76:c1:c7:d2:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f99e33b912b9733d99164d369c68dd76c1c7d248/; sid:902203067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e8:af:d1:1a:9f:68:e0:37:f4:81:11:61:23:db:53:20:a5:ce:f8:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8afd11a9f68e037f481116123db5320a5cef884/; sid:902203068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"48:82:87:ca:d1:0b:68:0d:d3:ab:4b:41:6b:8f:b0:a2:6a:fa:67:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/488287cad10b680dd3ab4b416b8fb0a26afa67c9/; sid:902203069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"80:e3:8f:4f:18:28:2b:4c:6e:e0:c6:65:8e:a7:9b:c0:f2:5d:84:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80e38f4f18282b4c6ee0c6658ea79bc0f25d84db/; sid:902203070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"3e:8b:07:8b:c4:7e:ec:1a:74:d1:d3:0c:f6:dd:a7:44:af:d5:87:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e8b078bc47eec1a74d1d30cf6dda744afd58783/; sid:902203071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ea:fd:09:fc:5b:dc:36:76:67:6f:6a:0c:ee:d1:91:90:ad:18:49:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eafd09fc5bdc3676676f6a0ceed19190ad18497c/; sid:902203072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ca:9d:37:39:ef:a5:75:e4:27:1a:47:ce:7f:12:b7:32:51:d6:1a:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca9d3739efa575e4271a47ce7f12b73251d61a21/; sid:902203073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ec:f0:bd:4a:55:d1:34:3c:e7:1f:55:ed:5e:46:bf:6a:fa:08:18:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ecf0bd4a55d1343ce71f55ed5e46bf6afa08185f/; sid:902203074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"38:d2:8a:d2:bc:28:56:54:c7:be:d8:3a:7e:2b:0d:eb:ef:0e:b7:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38d28ad2bc285654c7bed83a7e2b0debef0eb791/; sid:902203075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e9:fe:e6:69:8c:79:1c:33:fa:36:d1:a8:da:3e:80:73:c1:2f:a6:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9fee6698c791c33fa36d1a8da3e8073c12fa6da/; sid:902203076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"30:39:3a:46:86:c7:32:eb:de:f6:0e:3a:2a:b4:2b:b2:7f:73:b3:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30393a4686c732ebdef60e3a2ab42bb27f73b363/; sid:902203077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b5:aa:4d:d3:80:99:be:1c:e3:c9:e3:de:7f:ad:e8:c8:1a:65:13:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5aa4dd38099be1ce3c9e3de7fade8c81a651354/; sid:902203078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"01:2d:14:0b:f8:1b:0f:b8:e0:b7:71:fd:37:b1:05:35:77:05:68:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/012d140bf81b0fb8e0b771fd37b105357705686a/; sid:902203079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"35:30:8e:ea:e2:55:b7:d8:c5:53:88:84:60:82:1c:76:18:1b:85:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35308eeae255b7d8c553888460821c76181b8563/; sid:902203080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"93:2b:da:3c:73:f8:be:1d:c5:4b:cc:57:bc:55:fc:72:5e:55:44:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/932bda3c73f8be1dc54bcc57bc55fc725e5544e7/; sid:902203081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c6:07:36:30:d4:9a:7e:3a:5c:45:ac:ad:e6:e5:0e:e5:a1:57:19:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6073630d49a7e3a5c45acade6e50ee5a1571944/; sid:902203082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"19:60:a5:92:cd:34:6a:93:4f:82:8c:7b:1d:a1:7d:e1:75:ba:59:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1960a592cd346a934f828c7b1da17de175ba59d4/; sid:902203083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:5f:66:4c:2f:3a:8e:8e:21:6d:96:59:b3:e7:30:65:7d:85:3b:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/255f664c2f3a8e8e216d9659b3e730657d853b14/; sid:902203084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1b:2c:eb:32:ec:9c:55:27:dd:38:ad:5f:dc:ba:c4:85:b1:dc:6a:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b2ceb32ec9c5527dd38ad5fdcbac485b1dc6afc/; sid:902203085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"fd:8a:a2:d4:e1:c4:ea:68:5f:04:66:b5:0f:c6:ef:d4:c1:cc:2d:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd8aa2d4e1c4ea685f0466b50fc6efd4c1cc2deb/; sid:902203086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cd:88:cc:0a:59:86:99:a7:81:86:4b:de:f1:8f:50:da:b0:6f:81:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd88cc0a598699a781864bdef18f50dab06f818d/; sid:902203087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5f:62:3f:b2:13:f6:8f:95:fe:6a:c5:3c:93:c8:bf:da:dc:31:95:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f623fb213f68f95fe6ac53c93c8bfdadc3195c1/; sid:902203088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"35:35:b6:16:a0:08:41:9a:52:3c:eb:d5:05:af:91:19:b4:a1:bd:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3535b616a008419a523cebd505af9119b4a1bd49/; sid:902203089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"d9:96:af:9a:b6:c5:90:a2:7a:73:35:8d:df:37:7a:dd:5b:f8:c0:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d996af9ab6c590a27a73358ddf377add5bf8c05e/; sid:902203090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a3:d5:54:82:a8:e9:03:7d:9b:ee:bb:4e:1e:6b:24:5e:ef:5e:95:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3d55482a8e9037d9beebb4e1e6b245eef5e9594/; sid:902203091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:1b:35:5e:d8:21:a8:50:85:24:67:20:a4:15:ce:7e:b0:60:c3:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f71b355ed821a85085246720a415ce7eb060c388/; sid:902203092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f9:3d:b0:8a:b8:40:ec:dd:62:39:e3:3c:56:5f:5b:78:c3:ea:e9:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f93db08ab840ecdd6239e33c565f5b78c3eae9c8/; sid:902203093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"84:f2:4e:c9:f4:0f:e8:65:c8:fa:d7:eb:7d:7c:89:71:82:8f:ca:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84f24ec9f40fe865c8fad7eb7d7c8971828fcae1/; sid:902203094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"98:55:23:60:7f:59:4e:fc:15:5b:64:22:90:88:cd:ae:c7:79:b3:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/985523607f594efc155b64229088cdaec779b317/; sid:902203095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"35:fc:ae:f2:ea:a6:d3:ad:df:86:74:5c:59:c1:c1:2b:08:21:29:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35fcaef2eaa6d3addf86745c59c1c12b08212960/; sid:902203096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8f:f4:f4:e0:82:f6:20:6b:eb:d7:09:4c:76:20:3a:38:7d:aa:7d:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ff4f4e082f6206bebd7094c76203a387daa7d7f/; sid:902203097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d5:10:f1:21:2e:bf:e3:21:a4:70:13:94:1f:d9:81:4e:73:16:f9:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d510f1212ebfe321a47013941fd9814e7316f9e2/; sid:902203098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"fc:f8:ef:46:c2:4d:ee:5c:d4:48:24:65:e5:a2:df:bf:20:26:78:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcf8ef46c24dee5cd4482465e5a2dfbf20267808/; sid:902203099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"83:9f:4f:ae:14:ec:31:19:d5:12:8f:5d:e8:2d:00:0a:1c:0e:6d:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/839f4fae14ec3119d5128f5de82d000a1c0e6d1d/; sid:902203100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a0:be:43:66:2c:34:c6:f0:fe:99:73:02:83:61:3a:d5:36:99:a5:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0be43662c34c6f0fe99730283613ad53699a5b5/; sid:902203101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3d:d4:b6:10:ff:09:31:00:31:3c:a7:db:e2:4f:06:2c:a8:0a:d6:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3dd4b610ff093100313ca7dbe24f062ca80ad6e1/; sid:902203102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"5f:d1:16:bc:f7:92:17:4f:f8:43:3b:84:32:b5:77:d3:f3:8d:ab:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fd116bcf792174ff8433b8432b577d3f38dabd9/; sid:902203103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f9:6d:5a:a2:bc:ee:a3:e4:3c:00:bb:45:aa:1a:b1:48:be:b4:5b:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f96d5aa2bceea3e43c00bb45aa1ab148beb45b09/; sid:902203104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Loki C&C)"; tls.fingerprint:"f1:4a:78:59:61:f8:55:f5:d0:80:2c:5f:20:42:9a:84:8f:36:ac:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f14a785961f855f5d0802c5f20429a848f36acee/; sid:902203105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1a:87:61:28:e6:63:0d:6a:04:31:ef:91:2f:6a:d1:2a:08:4d:8e:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a876128e6630d6a0431ef912f6ad12a084d8e26/; sid:902203106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"84:de:1f:d3:3d:95:40:77:84:d0:b3:77:3e:49:d9:5d:96:b2:a0:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84de1fd33d95407784d0b3773e49d95d96b2a0a3/; sid:902203107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7a:f1:e6:1f:e7:2a:16:25:f9:ec:0b:aa:f5:0f:86:ea:00:ae:83:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7af1e61fe72a1625f9ec0baaf50f86ea00ae8356/; sid:902203108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"42:e1:0c:df:46:f9:9d:2b:42:dc:c2:c3:5f:71:25:49:15:de:e1:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42e10cdf46f99d2b42dcc2c35f71254915dee156/; sid:902203109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"3d:cf:2a:17:ae:cd:0a:f2:67:f9:8e:e5:ef:b6:fc:73:9c:80:b8:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3dcf2a17aecd0af267f98ee5efb6fc739c80b84d/; sid:902203110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"95:f1:55:21:e6:37:f0:5a:57:93:22:6b:68:f9:0e:3b:62:3f:0d:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95f15521e637f05a5793226b68f90e3b623f0d64/; sid:902203111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"97:7a:d4:55:90:3f:76:6e:8b:6f:92:95:c9:19:1a:a2:4e:4f:ef:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/977ad455903f766e8b6f9295c9191aa24e4fef9a/; sid:902203112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"7b:88:36:5a:eb:50:8b:48:83:da:fd:96:30:6c:70:95:34:45:55:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b88365aeb508b4883dafd96306c7095344555a3/; sid:902203113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:10:e8:de:bb:f9:58:55:be:7c:5d:ec:eb:ac:2a:8c:3b:0b:2b:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c510e8debbf95855be7c5decebac2a8c3b0b2bcd/; sid:902203114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"3e:c2:49:84:83:f9:40:60:4a:30:66:6d:f9:40:86:21:65:43:01:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ec2498483f940604a30666df94086216543017a/; sid:902203115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"ed:a1:c1:28:8c:ea:6b:37:2a:b4:8f:92:a6:c7:fa:d7:82:f6:4e:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eda1c1288cea6b372ab48f92a6c7fad782f64e50/; sid:902203116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"15:bc:80:0a:09:76:f2:fa:a4:f2:a8:a2:57:41:ba:72:1c:0d:64:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15bc800a0976f2faa4f2a8a25741ba721c0d64e0/; sid:902203117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ab:31:5c:68:7a:15:3e:56:b0:31:ea:c2:44:9e:c1:46:b7:22:21:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab315c687a153e56b031eac2449ec146b72221d1/; sid:902203118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"20:75:62:21:56:ef:e6:14:90:38:8a:aa:95:e5:62:86:d5:ab:c4:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2075622156efe61490388aaa95e56286d5abc42a/; sid:902203119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"83:21:71:b1:08:d6:f9:e2:a0:a9:d4:53:3e:1c:6a:cc:fb:ba:80:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/832171b108d6f9e2a0a9d4533e1c6accfbba8072/; sid:902203120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"60:10:01:8e:50:5e:1f:c3:1f:96:ae:a5:02:2b:fa:9f:eb:d2:9c:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6010018e505e1fc31f96aea5022bfa9febd29c14/; sid:902203121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"20:ec:8a:d2:08:df:3a:d4:ed:a2:9e:32:9d:0f:9f:0b:fd:1f:54:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20ec8ad208df3ad4eda29e329d0f9f0bfd1f5479/; sid:902203122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PredatorStealer C&C)"; tls.fingerprint:"ed:d6:ac:43:eb:c2:44:9f:0c:31:8c:4b:49:e0:e1:78:6e:d8:01:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edd6ac43ebc2449f0c318c4b49e0e1786ed801c8/; sid:902203123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"a8:2e:6d:70:fd:4e:25:df:80:ea:0c:69:a6:f3:1b:d5:02:ab:89:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a82e6d70fd4e25df80ea0c69a6f31bd502ab8904/; sid:902203124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"00:95:7e:ee:82:55:63:1a:04:de:ef:57:9b:1c:ca:9c:39:5f:e9:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00957eee8255631a04deef579b1cca9c395fe910/; sid:902203125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"15:18:2a:b8:43:2f:cd:20:ac:10:a1:58:2b:4b:96:27:f9:71:65:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15182ab8432fcd20ac10a1582b4b9627f971658f/; sid:902203126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ab:87:1d:a0:1c:cb:96:e4:8e:d3:63:45:18:55:62:62:f5:b7:35:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab871da01ccb96e48ed3634518556262f5b735ae/; sid:902203127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"81:0a:a4:8d:49:e5:7d:8e:47:cc:c0:78:46:e3:ca:88:c5:7e:36:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/810aa48d49e57d8e47ccc07846e3ca88c57e360c/; sid:902203128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:d3:e1:d4:14:c3:0d:1e:a3:40:09:f7:06:ff:e0:98:da:7d:01:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30d3e1d414c30d1ea34009f706ffe098da7d01d3/; sid:902203129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"bd:a4:a5:99:7f:23:20:09:c2:12:7b:c2:40:79:eb:de:71:5e:91:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bda4a5997f232009c2127bc24079ebde715e91bd/; sid:902203130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cb:1e:bc:b2:68:4b:2c:12:7f:67:31:9b:11:17:ae:39:e7:65:b1:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb1ebcb2684b2c127f67319b1117ae39e765b1b7/; sid:902203131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"4e:74:83:6a:fe:9e:ec:15:4e:68:39:d3:d0:54:54:e2:55:fe:e2:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e74836afe9eec154e6839d3d05454e255fee2a3/; sid:902203132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4a:90:b8:95:6d:73:dc:5d:1a:2f:c8:63:3f:6b:b4:8c:e9:23:90:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a90b8956d73dc5d1a2fc8633f6bb48ce9239068/; sid:902203133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"46:07:3f:8b:c2:f9:94:bb:8f:79:31:f1:54:91:8e:1a:20:0c:d5:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46073f8bc2f994bb8f7931f154918e1a200cd52d/; sid:902203134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"46:81:f0:e7:e7:b6:ea:90:cd:ea:22:23:ca:9c:d7:01:66:b0:46:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4681f0e7e7b6ea90cdea2223ca9cd70166b046a1/; sid:902203135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"6b:98:9a:d3:18:44:a8:9c:4c:ef:09:49:83:cf:a6:7a:c0:4e:ed:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b989ad31844a89c4cef094983cfa67ac04eed37/; sid:902203136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"81:35:29:39:1d:64:37:65:ec:6b:a5:51:67:a9:5a:36:17:10:30:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/813529391d643765ec6ba55167a95a36171030fc/; sid:902203137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"9c:f4:86:c4:e0:96:6c:63:68:55:8b:8a:1f:dd:b6:9d:ea:27:da:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cf486c4e0966c6368558b8a1fddb69dea27daf4/; sid:902203138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"87:eb:3e:4d:61:8b:9a:54:ea:d2:36:3e:0f:d2:07:f6:74:89:89:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87eb3e4d618b9a54ead2363e0fd207f674898965/; sid:902203139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ce:ef:f1:60:54:54:fa:d0:64:68:33:35:f9:e9:0f:69:60:21:f3:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ceeff1605454fad064683335f9e90f696021f331/; sid:902203140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:02:22:85:51:4f:71:07:04:ea:14:69:13:f0:fc:75:5a:53:b1:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b022285514f710704ea146913f0fc755a53b1f0/; sid:902203141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:0e:01:c6:7a:a2:23:6f:12:7c:8d:78:eb:f6:e5:f1:39:3a:a2:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/870e01c67aa2236f127c8d78ebf6e5f1393aa257/; sid:902203142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8f:6b:f7:cb:cf:01:4b:ee:0a:42:ec:65:2b:c9:6a:2f:a9:8a:ee:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f6bf7cbcf014bee0a42ec652bc96a2fa98aee36/; sid:902203143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"86:d7:71:37:92:bf:d1:ee:51:61:5c:80:8b:8b:d6:92:0a:05:30:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86d7713792bfd1ee51615c808b8bd6920a0530af/; sid:902203144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:46:7c:ee:53:2f:c0:a8:25:f9:37:7a:58:2d:8b:fe:43:17:ce:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9467cee532fc0a825f9377a582d8bfe4317ce93/; sid:902203145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2f:cd:3c:ac:db:38:7d:ee:75:62:36:f6:c7:b7:99:37:78:7d:0c:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2fcd3cacdb387dee756236f6c7b79937787d0ce5/; sid:902203146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:f8:39:a5:a9:3a:49:c8:97:02:4a:25:b6:e4:13:df:00:6d:88:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5f839a5a93a49c897024a25b6e413df006d88cb/; sid:902203147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"50:39:c2:e2:95:8a:26:39:3e:50:03:7f:ac:04:46:c5:24:8f:7f:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5039c2e2958a26393e50037fac0446c5248f7f88/; sid:902203148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:2c:f0:af:e3:7d:b0:99:d9:8d:3e:c9:52:37:49:42:4e:0f:fd:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/792cf0afe37db099d98d3ec9523749424e0ffdd4/; sid:902203149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:9c:f6:e5:14:4e:a7:dd:ab:c4:c2:1f:1f:ba:69:61:92:7e:2e:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/769cf6e5144ea7ddabc4c21f1fba6961927e2ea8/; sid:902203150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ea:cc:28:7e:57:7d:b9:9e:61:04:32:cb:cc:87:59:79:79:31:05:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eacc287e577db99e610432cbcc87597979310536/; sid:902203151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:ac:70:dc:37:af:67:cf:18:46:0e:6e:bd:04:b9:58:16:24:ce:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44ac70dc37af67cf18460e6ebd04b9581624ce4a/; sid:902203152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c2:b6:70:4d:1a:2d:2f:34:98:44:fe:10:c3:82:62:11:4b:87:94:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c2b6704d1a2d2f349844fe10c38262114b879473/; sid:902203153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:2d:ad:49:76:89:75:f1:e3:20:e1:45:a3:14:0b:92:7d:31:c2:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/692dad49768975f1e320e145a3140b927d31c2a1/; sid:902203154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"39:b1:49:a6:69:a5:0b:67:94:0d:da:a3:58:8a:8b:13:4f:e5:52:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39b149a669a50b67940ddaa3588a8b134fe552e8/; sid:902203155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6d:a8:9e:aa:62:a7:f1:2d:c6:a3:d0:ef:4c:07:49:38:d5:60:f1:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6da89eaa62a7f12dc6a3d0ef4c074938d560f14f/; sid:902203156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8b:ca:5f:91:82:5d:0d:b7:96:56:52:bd:16:c2:31:70:72:7b:68:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bca5f91825d0db7965652bd16c23170727b68c8/; sid:902203157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a6:9d:3b:36:59:04:9a:dd:79:86:2c:54:e0:96:43:b0:13:60:16:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a69d3b3659049add79862c54e09643b013601669/; sid:902203158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"52:db:97:a8:0c:dc:42:b4:24:cd:84:2f:1b:2f:c0:3c:8c:ee:66:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52db97a80cdc42b424cd842f1b2fc03c8cee66d9/; sid:902203159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"af:f7:e8:66:dd:ef:40:f6:29:13:69:51:31:be:ad:1a:55:e7:ce:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aff7e866ddef40f62913695131bead1a55e7ce34/; sid:902203160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"07:c6:fc:9d:40:31:32:47:f8:7b:18:e0:b2:60:f3:e5:7f:c1:c5:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07c6fc9d40313247f87b18e0b260f3e57fc1c525/; sid:902203161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e3:cc:23:ba:7f:b9:b1:cc:67:6b:c6:d7:19:b8:6c:78:7c:1b:06:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3cc23ba7fb9b1cc676bc6d719b86c787c1b06d5/; sid:902203162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"68:a5:06:44:7d:7c:0e:82:9a:8c:e8:32:88:6e:b4:6f:70:b4:4a:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68a506447d7c0e829a8ce832886eb46f70b44afe/; sid:902203163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:18:2c:4e:27:c1:fb:9a:09:e2:22:c4:c9:46:46:53:7d:10:b3:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23182c4e27c1fb9a09e222c4c94646537d10b3d4/; sid:902203164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"99:ef:3d:6a:22:a0:ae:44:1b:97:2e:13:fc:3f:c9:35:c5:30:d3:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99ef3d6a22a0ae441b972e13fc3fc935c530d305/; sid:902203165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9f:12:91:2f:9b:c3:41:9e:06:70:a7:29:f9:c4:c1:6e:d8:fb:43:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f12912f9bc3419e0670a729f9c4c16ed8fb43fa/; sid:902203166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:02:7f:40:af:91:b7:cf:5f:77:c0:d9:04:9e:8b:b2:49:f2:b8:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70027f40af91b7cf5f77c0d9049e8bb249f2b81e/; sid:902203167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"84:fa:28:bc:4a:69:56:1a:09:fd:1c:41:9c:5b:ea:68:7a:7d:a5:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84fa28bc4a69561a09fd1c419c5bea687a7da58a/; sid:902203168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"20:37:3e:4d:4d:11:ba:0e:83:93:78:73:7e:e9:fc:49:cb:16:4b:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20373e4d4d11ba0e839378737ee9fc49cb164bbd/; sid:902203169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"86:44:71:15:45:fc:8d:1b:a0:2f:d4:e4:42:42:90:a0:68:15:c3:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8644711545fc8d1ba02fd4e4424290a06815c320/; sid:902203170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"e5:d4:9e:0b:12:01:2e:40:49:8c:c9:91:ae:58:6b:3c:e0:5b:f2:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e5d49e0b12012e40498cc991ae586b3ce05bf2f6/; sid:902203171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"19:cf:21:e6:32:6b:61:25:b0:23:c5:3d:f2:3b:74:06:0f:4e:78:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19cf21e6326b6125b023c53df23b74060f4e786e/; sid:902203172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"08:1c:f5:0a:56:f5:9b:e9:b1:f9:50:48:58:a2:25:b8:0f:23:3c:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/081cf50a56f59be9b1f9504858a225b80f233cb2/; sid:902203173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"65:39:0d:83:44:f3:82:e2:95:d8:a8:9d:f6:d8:6a:98:c4:58:8e:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65390d8344f382e295d8a89df6d86a98c4588edb/; sid:902203174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"b4:43:0a:3e:29:13:a5:67:05:4b:c8:cf:62:4a:f0:c4:2b:13:a9:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4430a3e2913a567054bc8cf624af0c42b13a9fd/; sid:902203175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"41:05:81:1b:72:d6:ff:fc:f4:29:84:a5:bd:0c:0b:5a:e2:13:cb:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4105811b72d6fffcf42984a5bd0c0b5ae213cbec/; sid:902203176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1a:82:3c:07:cd:b4:6e:c9:42:d7:91:ec:94:99:76:42:80:c2:cd:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a823c07cdb46ec942d791ec9499764280c2cdbb/; sid:902203177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RevengeRAT C&C)"; tls.fingerprint:"74:9b:34:da:4a:c8:9c:bb:e6:4c:f3:80:5f:98:16:16:25:7f:b8:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/749b34da4ac89cbbe64cf3805f981616257fb85b/; sid:902203178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"34:a1:63:99:8d:af:24:8a:58:ae:f5:40:47:00:7d:f6:a3:5e:af:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34a163998daf248a58aef54047007df6a35eaf55/; sid:902203179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8f:3d:ae:90:fa:f0:f9:a4:70:61:11:17:d9:c6:cb:3d:df:3e:64:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f3dae90faf0f9a470611117d9c6cb3ddf3e64e3/; sid:902203180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"dd:38:f4:45:87:45:16:92:9c:53:1f:f4:22:25:48:ba:1d:f4:e5:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd38f445874516929c531ff4222548ba1df4e5cb/; sid:902203181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"08:68:cd:5f:13:80:f6:a7:68:8c:b6:5f:6e:e3:69:4f:83:c6:88:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0868cd5f1380f6a7688cb65f6ee3694f83c68806/; sid:902203182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fa:30:aa:ba:52:30:37:79:78:45:5b:b7:27:94:68:5e:a4:fc:ed:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa30aaba5230377978455bb72794685ea4fcedba/; sid:902203183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b5:16:cf:a2:67:3a:c7:d5:ff:05:5a:e2:cb:23:1a:78:1e:39:47:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b516cfa2673ac7d5ff055ae2cb231a781e3947f6/; sid:902203184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5b:82:f4:50:82:30:9b:45:5d:50:a2:fe:8a:34:6d:87:f9:85:8a:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b82f45082309b455d50a2fe8a346d87f9858adf/; sid:902203185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"03:c6:32:b6:eb:7d:a7:e4:6e:e1:97:e9:c6:c4:1f:81:e0:d7:d4:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03c632b6eb7da7e46ee197e9c6c41f81e0d7d4cd/; sid:902203186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"23:51:fc:81:1f:3b:b2:77:d9:17:02:e8:58:19:91:c9:2f:6c:03:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2351fc811f3bb277d91702e8581991c92f6c036c/; sid:902203187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:97:aa:49:4f:e0:2b:5f:f2:93:ec:69:cb:dc:1a:25:b5:5e:35:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc97aa494fe02b5ff293ec69cbdc1a25b55e35f4/; sid:902203188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:48:b6:51:c0:b5:45:47:d8:9d:98:31:2e:00:54:fb:84:41:cf:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0848b651c0b54547d89d98312e0054fb8441cffc/; sid:902203189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"26:f0:65:74:9a:bc:56:8d:f0:a7:13:aa:c4:50:7f:9a:40:48:f0:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26f065749abc568df0a713aac4507f9a4048f0e4/; sid:902203190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:5f:7f:b8:2e:25:a2:b4:a7:f7:1e:d6:56:bc:5a:c2:7f:29:ef:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/055f7fb82e25a2b4a7f71ed656bc5ac27f29effe/; sid:902203191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5f:e1:db:57:77:40:5c:41:ef:f2:ad:91:40:bb:f2:ce:31:31:5e:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fe1db5777405c41eff2ad9140bbf2ce31315ec6/; sid:902203192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8e:0e:60:4a:c6:12:cc:ed:e3:94:61:d0:05:da:57:ce:0b:2d:b3:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e0e604ac612ccede39461d005da57ce0b2db32f/; sid:902203193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:98:73:89:7b:db:cc:ae:a0:ee:ed:b9:df:13:ce:a9:38:7b:90:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/799873897bdbccaea0eeedb9df13cea9387b906f/; sid:902203194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"95:35:1c:56:e6:e3:bd:18:eb:0f:5d:53:f0:1c:f6:41:d2:bb:bd:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95351c56e6e3bd18eb0f5d53f01cf641d2bbbd32/; sid:902203195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a0:1e:50:8e:82:3a:bb:b7:dd:19:fa:b5:51:48:e6:60:e0:f4:af:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a01e508e823abbb7dd19fab55148e660e0f4af69/; sid:902203196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6d:9c:39:e6:b7:81:fe:48:25:38:f8:ba:56:4d:b4:d7:71:0d:9a:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d9c39e6b781fe482538f8ba564db4d7710d9af8/; sid:902203197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"25:74:5a:c1:e2:25:f6:56:82:7d:67:ad:fa:0b:56:2f:b7:7e:45:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25745ac1e225f656827d67adfa0b562fb77e45ef/; sid:902203198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"ef:05:4f:54:df:0f:a6:7f:c4:54:bf:88:94:c6:43:e4:4c:28:ec:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef054f54df0fa67fc454bf8894c643e44c28ec3a/; sid:902203199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:18:d4:13:5c:c5:16:3d:2c:ea:df:a6:42:48:a0:c4:55:f7:a4:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2818d4135cc5163d2ceadfa64248a0c455f7a4f7/; sid:902203200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"72:35:cf:3e:e7:b6:19:a2:c4:9d:bd:e0:25:56:a8:7b:88:9b:43:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7235cf3ee7b619a2c49dbde02556a87b889b43df/; sid:902203201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ca:d2:32:bb:fe:05:d3:e9:a1:12:e3:a0:53:f3:90:f0:b4:fc:0d:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cad232bbfe05d3e9a112e3a053f390f0b4fc0d41/; sid:902203202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1a:62:6a:33:ec:91:a6:3d:9a:a3:80:e5:33:81:02:52:41:9d:46:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a626a33ec91a63d9aa380e533810252419d469b/; sid:902203203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d1:a1:cc:52:62:31:86:1e:2e:a9:aa:69:b2:58:34:e2:79:86:1d:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1a1cc526231861e2ea9aa69b25834e279861d38/; sid:902203204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ea:c9:48:ef:2a:ea:a0:42:c7:e1:31:1e:3f:36:75:1b:e3:3a:af:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eac948ef2aeaa042c7e1311e3f36751be33aafed/; sid:902203205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"49:b7:67:73:6a:0c:ee:6c:3c:04:70:f1:de:fa:1a:58:6d:8e:b9:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49b767736a0cee6c3c0470f1defa1a586d8eb96a/; sid:902203206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fb:4c:48:55:c6:ad:0e:a2:2e:bf:94:e5:31:fe:56:dc:61:67:42:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb4c4855c6ad0ea22ebf94e531fe56dc61674273/; sid:902203207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f8:92:b7:93:a9:9d:67:d6:cc:a8:72:6b:06:30:2a:44:16:65:c4:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f892b793a99d67d6cca8726b06302a441665c417/; sid:902203208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:96:6d:7c:27:5e:9d:28:93:52:74:d8:dd:31:a6:59:8b:7b:85:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44966d7c275e9d28935274d8dd31a6598b7b8579/; sid:902203209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"26:3e:25:63:ab:cd:a9:9f:db:65:e1:5e:ea:47:12:f9:de:03:11:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/263e2563abcda99fdb65e15eea4712f9de031178/; sid:902203210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"c6:72:48:45:35:0b:17:45:f0:2d:14:30:a5:d2:75:78:a4:4a:9e:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6724845350b1745f02d1430a5d27578a44a9e19/; sid:902203211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b0:da:a3:91:38:e2:28:d7:37:01:80:55:5d:32:dc:34:1d:31:9e:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0daa39138e228d7370180555d32dc341d319e71/; sid:902203212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ce:1c:1a:0e:53:d3:10:d7:fc:e4:ba:51:6c:cd:9b:11:cc:4d:fd:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce1c1a0e53d310d7fce4ba516ccd9b11cc4dfd08/; sid:902203213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"e5:7c:d2:58:01:ee:f1:0b:78:74:40:7a:41:3c:86:42:0b:b8:be:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e57cd25801eef10b7874407a413c86420bb8be50/; sid:902203214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"54:fd:0d:8d:91:88:29:0f:21:c4:70:e9:64:b0:e4:4d:ab:0b:19:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54fd0d8d9188290f21c470e964b0e44dab0b19dc/; sid:902203215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"04:47:ac:2b:c5:a1:fd:a9:71:06:58:f1:5a:eb:bf:70:a8:fd:a6:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0447ac2bc5a1fda9710658f15aebbf70a8fda667/; sid:902203216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8c:2a:10:d9:fd:c2:27:84:76:22:5f:cf:f9:a3:ba:f0:25:5a:1d:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c2a10d9fdc2278476225fcff9a3baf0255a1d05/; sid:902203217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"de:53:8f:f2:47:ff:d4:5f:7b:d0:41:28:c7:cb:99:23:32:1f:e1:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de538ff247ffd45f7bd04128c7cb9923321fe11a/; sid:902203218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"99:b8:7e:84:b8:3e:16:80:48:4c:cd:c5:a0:2f:cc:6f:2a:0a:8f:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99b87e84b83e1680484ccdc5a02fcc6f2a0a8fc1/; sid:902203219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"64:75:fe:ce:0d:52:e4:eb:38:73:31:07:3d:60:fa:86:80:2d:03:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6475fece0d52e4eb387331073d60fa86802d033d/; sid:902203220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0c:4d:4b:af:62:c4:7d:ed:cc:53:47:4a:bf:22:73:73:a1:68:ed:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c4d4baf62c47dedcc53474abf227373a168edd4/; sid:902203221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"c7:01:8c:e8:ca:b9:27:7d:61:49:d2:18:d2:3c:9f:81:70:91:33:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c7018ce8cab9277d6149d218d23c9f81709133da/; sid:902203222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"32:ca:92:79:9c:de:5f:05:8c:48:a4:18:95:62:cd:8a:cb:a9:07:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32ca92799cde5f058c48a4189562cd8acba9076e/; sid:902203223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"9b:b3:1f:52:6f:68:35:d3:b0:21:00:99:9e:ec:a4:2f:46:aa:2b:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bb31f526f6835d3b02100999eeca42f46aa2b1d/; sid:902203224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"8d:a3:df:71:aa:80:c8:40:18:cd:a6:95:dc:2b:79:c5:23:44:f5:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8da3df71aa80c84018cda695dc2b79c52344f53b/; sid:902203225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"5c:b6:4c:59:c5:a9:58:2e:6a:fc:fd:b1:09:bb:63:9a:09:aa:48:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5cb64c59c5a9582e6afcfdb109bb639a09aa48c3/; sid:902203226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"cf:33:04:bd:32:1b:3b:20:9d:f0:78:78:f2:4d:52:8c:5f:1b:55:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf3304bd321b3b209df07878f24d528c5f1b5557/; sid:902203227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:12:b0:09:ef:49:9a:f2:78:57:77:7b:45:9e:aa:b5:b2:16:b4:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0112b009ef499af27857777b459eaab5b216b49d/; sid:902203228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"9a:8b:74:cf:a6:30:48:0b:22:4e:ae:f0:6e:96:0c:a1:54:ab:df:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a8b74cfa630480b224eaef06e960ca154abdffb/; sid:902203229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"89:f9:bf:31:8b:85:ab:fb:7a:33:3c:4e:2e:7b:7c:2f:a6:24:44:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89f9bf318b85abfb7a333c4e2e7b7c2fa62444a1/; sid:902203230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"ee:1c:f7:03:9a:79:2a:95:3a:d0:aa:33:50:33:da:8d:0d:16:22:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee1cf7039a792a953ad0aa335033da8d0d1622b5/; sid:902203231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"f7:05:1a:8e:b2:7e:dc:f7:41:a3:f2:fd:03:45:e9:27:57:8e:a8:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7051a8eb27edcf741a3f2fd0345e927578ea893/; sid:902203232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"10:6b:0e:e8:3c:92:40:47:ca:99:4e:3f:6c:be:ed:94:c1:48:fb:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/106b0ee83c924047ca994e3f6cbeed94c148fbff/; sid:902203233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"8d:35:95:ce:e5:06:d4:85:5f:e3:45:cc:eb:aa:12:c8:39:e6:8f:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d3595cee506d4855fe345ccebaa12c839e68ff8/; sid:902203234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"43:dc:ed:0f:b9:41:5d:53:df:98:0c:f3:bb:80:bc:89:2e:1d:cb:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43dced0fb9415d53df980cf3bb80bc892e1dcb94/; sid:902203235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"82:50:11:3c:6e:43:e8:0c:65:59:6e:b9:d5:db:f9:c0:c9:94:87:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8250113c6e43e80c65596eb9d5dbf9c0c994879f/; sid:902203236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"b2:c3:8a:5b:49:5e:2c:49:06:80:ce:a7:cd:71:22:8a:56:bf:cb:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2c38a5b495e2c490680cea7cd71228a56bfcb44/; sid:902203237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"14:2d:6b:4f:56:73:ad:e8:dd:09:fa:3d:70:5b:e3:29:ad:fb:75:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/142d6b4f5673ade8dd09fa3d705be329adfb7531/; sid:902203238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"2c:14:95:47:0f:7d:45:37:f2:c7:6d:50:16:b3:6f:3f:d0:70:6f:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c1495470f7d4537f2c76d5016b36f3fd0706fad/; sid:902203239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"1f:1f:c1:a9:23:5b:9b:51:4f:00:e2:95:90:25:48:13:7d:5c:01:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f1fc1a9235b9b514f00e295902548137d5c01c9/; sid:902203240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"22:a7:01:74:5f:df:a2:08:0e:44:c9:f3:39:a9:11:f9:7a:d1:7b:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22a701745fdfa2080e44c9f339a911f97ad17bd0/; sid:902203241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"01:a8:0c:68:68:94:2b:d8:e7:6d:5b:d2:11:95:2d:c5:70:9a:ea:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01a80c6868942bd8e76d5bd211952dc5709aeae1/; sid:902203242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c2:38:c6:22:ca:6e:48:ce:f9:eb:ab:e4:08:67:4f:31:db:7f:79:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c238c622ca6e48cef9ebabe408674f31db7f79b9/; sid:902203243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"68:12:6a:31:06:49:a2:4b:20:3b:32:b1:2d:c4:88:a5:4b:60:25:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68126a310649a24b203b32b12dc488a54b602580/; sid:902203244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ee:cf:ab:4c:20:72:e9:e1:e3:1b:cc:71:04:bf:6a:c8:34:e1:d5:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eecfab4c2072e9e1e31bcc7104bf6ac834e1d5af/; sid:902203245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f1:d7:c7:94:7e:3b:96:6f:6e:62:7a:fe:85:0f:a0:1f:83:56:29:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1d7c7947e3b966f6e627afe850fa01f835629e4/; sid:902203246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"ce:75:30:87:87:70:6e:09:e3:bd:c1:90:b9:9d:f4:9b:a8:d7:f5:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce75308787706e09e3bdc190b99df49ba8d7f59b/; sid:902203247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f0:5a:89:8b:08:ce:2b:b6:3a:4f:a9:3c:11:4c:b0:03:0f:da:03:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f05a898b08ce2bb63a4fa93c114cb0030fda03e8/; sid:902203248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"22:9d:13:a4:9d:fa:e4:8a:d6:d4:33:22:6d:e2:60:20:f2:b8:d9:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/229d13a49dfae48ad6d433226de26020f2b8d9e5/; sid:902203249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ff:f9:31:0e:e2:eb:b0:13:60:f0:2c:6b:54:2d:e5:2d:75:af:fc:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fff9310ee2ebb01360f02c6b542de52d75affc35/; sid:902203250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8f:d2:8e:bc:f7:7a:f7:51:b8:4d:5b:88:7b:ec:9d:12:83:ff:7e:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fd28ebcf77af751b84d5b887bec9d1283ff7ea0/; sid:902203251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d3:ef:e0:96:0e:22:39:fa:6d:d8:77:e0:22:41:4c:82:32:1d:d3:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3efe0960e2239fa6dd877e022414c82321dd396/; sid:902203252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5a:9b:ab:13:82:67:f8:d1:9b:17:bc:07:ef:f7:d8:49:ce:f7:db:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a9bab138267f8d19b17bc07eff7d849cef7db1e/; sid:902203253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"a6:dc:d9:2f:f1:12:e9:82:7f:cd:65:48:d1:8a:66:de:26:c6:dc:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6dcd92ff112e9827fcd6548d18a66de26c6dc3c/; sid:902203254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"e8:dd:fc:b2:44:57:e0:64:2c:69:f5:67:e5:8e:51:d0:36:54:61:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8ddfcb24457e0642c69f567e58e51d03654614c/; sid:902203255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ad:7a:c3:6b:f6:a1:c8:b8:ac:a4:60:b8:72:78:c4:4d:bf:77:94:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad7ac36bf6a1c8b8aca460b87278c44dbf77946b/; sid:902203256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"0a:1e:17:13:c9:9e:6e:cf:fd:91:93:b0:05:4e:a1:0c:a5:65:20:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a1e1713c99e6ecffd9193b0054ea10ca56520df/; sid:902203257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"61:28:3e:ae:0d:2b:41:04:c1:ae:72:55:57:4c:da:72:be:c1:28:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61283eae0d2b4104c1ae7255574cda72bec128bd/; sid:902203258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"87:b9:01:1d:00:d5:06:95:26:65:a9:e4:e4:c1:08:4e:60:50:59:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87b9011d00d506952665a9e4e4c1084e605059c3/; sid:902203259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"84:fd:82:83:d1:73:6f:a4:18:c6:a3:ea:51:61:ff:1d:e7:9e:b2:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84fd8283d1736fa418c6a3ea5161ff1de79eb2dd/; sid:902203260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"96:a4:9f:e8:7b:e0:f4:75:99:a1:b0:f2:bd:cf:fc:93:26:13:1e:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96a49fe87be0f47599a1b0f2bdcffc9326131e65/; sid:902203261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"61:76:11:98:63:32:d2:56:d2:2a:bb:7c:75:0b:6f:42:3d:b4:22:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/617611986332d256d22abb7c750b6f423db4223a/; sid:902203262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"fd:01:f8:e1:90:37:89:cf:6f:3c:7f:7d:9b:26:66:b8:76:c9:e0:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd01f8e1903789cf6f3c7f7d9b2666b876c9e027/; sid:902203263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"b1:aa:79:cd:8a:c3:49:d4:3c:61:77:1f:1d:03:f2:94:3c:fc:c3:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1aa79cd8ac349d43c61771f1d03f2943cfcc313/; sid:902203264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"51:bc:52:46:5d:5a:60:28:cc:93:9f:0c:df:93:98:1b:ef:69:62:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51bc52465d5a6028cc939f0cdf93981bef6962a5/; sid:902203265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"20:f5:77:ce:75:9b:61:da:91:51:a1:43:ce:02:97:ae:44:d4:6b:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20f577ce759b61da9151a143ce0297ae44d46b23/; sid:902203266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"dc:40:2f:c3:11:de:f4:fe:a7:96:1e:23:5b:2f:7a:23:ec:ae:f3:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc402fc311def4fea7961e235b2f7a23ecaef3c9/; sid:902203267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0a:a1:21:a6:be:e3:f6:3c:7e:91:0b:0a:c0:54:9c:d5:af:2b:95:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0aa121a6bee3f63c7e910b0ac0549cd5af2b95d9/; sid:902203268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5f:67:60:02:9d:36:49:33:e8:f7:af:7d:6b:45:a4:6c:4a:17:77:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f6760029d364933e8f7af7d6b45a46c4a177703/; sid:902203269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"43:95:47:15:33:83:c5:33:97:26:49:ed:02:68:c9:2e:da:9f:fb:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/439547153383c533972649ed0268c92eda9ffb48/; sid:902203270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"21:c6:03:fd:0d:9a:1c:11:73:fe:04:f0:3a:80:e6:7b:b9:7a:3a:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21c603fd0d9a1c1173fe04f03a80e67bb97a3a98/; sid:902203271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d3:fc:dc:be:1f:d7:16:4f:32:78:b8:53:c0:cf:d3:8c:63:2f:94:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3fcdcbe1fd7164f3278b853c0cfd38c632f9499/; sid:902203272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8b:5f:bb:3b:f6:7c:d9:91:f0:13:4a:fe:ea:03:62:39:44:22:ef:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b5fbb3bf67cd991f0134afeea0362394422ef46/; sid:902203273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2a:9d:e6:2e:24:07:0e:3f:1b:a4:18:dc:3a:79:94:c6:3c:c3:dd:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a9de62e24070e3f1ba418dc3a7994c63cc3dd8e/; sid:902203274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"da:5d:c1:da:ca:79:89:db:13:16:6f:03:37:20:62:bf:2a:11:c1:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da5dc1daca7989db13166f03372062bf2a11c1eb/; sid:902203275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"d9:c8:f9:70:3d:8b:30:e8:52:53:30:40:1d:24:9f:e8:d9:fc:e0:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9c8f9703d8b30e8525330401d249fe8d9fce0aa/; sid:902203276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"96:57:22:d5:9c:7f:d9:d8:2e:3a:b4:35:11:33:2e:ae:38:e9:25:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/965722d59c7fd9d82e3ab43511332eae38e92543/; sid:902203277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"94:4b:42:8c:4c:e8:89:dc:49:88:f8:f3:31:2f:df:66:41:4e:ec:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/944b428c4ce889dc4988f8f3312fdf66414eecaf/; sid:902203278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"c3:3c:0d:d2:e1:15:cc:7a:8a:bb:3a:06:69:95:4f:00:01:a8:59:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c33c0dd2e115cc7a8abb3a0669954f0001a85973/; sid:902203279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a4:37:4d:a4:f2:b0:d7:0c:73:0b:46:67:07:8b:4e:c8:a1:ce:c6:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4374da4f2b0d70c730b4667078b4ec8a1cec6be/; sid:902203280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"4e:29:3e:89:99:10:ef:74:35:ae:25:e2:8c:08:24:20:d7:48:f8:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e293e899910ef7435ae25e28c082420d748f8bd/; sid:902203281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c9:12:ab:3c:45:a9:bc:88:da:39:87:61:13:e6:37:5d:8f:4b:b9:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c912ab3c45a9bc88da39876113e6375d8f4bb902/; sid:902203282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"da:15:d5:5a:f3:86:46:99:36:1f:8e:af:83:a0:cb:c2:4b:76:44:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da15d55af3864699361f8eaf83a0cbc24b764459/; sid:902203283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2e:8a:4b:1b:2a:be:35:17:7d:34:3d:1c:81:dd:25:22:c1:6b:b4:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e8a4b1b2abe35177d343d1c81dd2522c16bb48b/; sid:902203284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:e6:ed:e1:10:79:5f:a5:42:c0:e6:d3:50:16:59:69:89:71:ab:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7be6ede110795fa542c0e6d3501659698971abec/; sid:902203285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"31:de:61:95:0f:11:fa:1b:00:43:1b:e0:48:41:2f:0e:85:48:24:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31de61950f11fa1b00431be048412f0e85482495/; sid:902203286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"4f:e2:75:b2:94:02:d8:7b:94:53:b7:6b:e7:2f:63:a1:b5:d7:64:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4fe275b29402d87b9453b76be72f63a1b5d764b6/; sid:902203287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"53:eb:e9:16:28:43:2d:2d:1d:fd:42:cb:2a:99:8b:dc:61:bb:02:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53ebe91628432d2d1dfd42cb2a998bdc61bb024d/; sid:902203288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"2e:ab:b5:3c:05:fd:86:97:24:10:34:68:e4:62:6f:f6:2b:d5:cc:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2eabb53c05fd869724103468e4626ff62bd5ccdf/; sid:902203289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"db:e3:28:14:42:90:58:d0:19:e9:c0:42:a8:e2:32:8f:5f:c4:ed:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbe32814429058d019e9c042a8e2328f5fc4ed75/; sid:902203290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"44:0c:3b:49:5f:95:2a:16:cc:5a:82:fc:b4:ec:01:e5:0a:e7:b8:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/440c3b495f952a16cc5a82fcb4ec01e50ae7b836/; sid:902203291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:3f:32:76:bd:d7:96:07:0e:22:a3:0a:0a:18:c0:8a:40:d7:c7:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/223f3276bdd796070e22a30a0a18c08a40d7c7b8/; sid:902203292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"d0:db:c0:1b:5f:fe:6f:80:18:16:b4:8a:f9:d8:57:d0:17:6d:eb:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0dbc01b5ffe6f801816b48af9d857d0176debce/; sid:902203293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"4a:6d:e8:60:d4:83:63:7c:00:65:7e:d0:31:50:cf:20:a6:f2:56:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a6de860d483637c00657ed03150cf20a6f25633/; sid:902203294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"22:cb:55:b8:8a:ee:ec:8b:08:42:d3:0f:8e:13:77:b3:cc:e3:32:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22cb55b88aeeec8b0842d30f8e1377b3cce3322c/; sid:902203295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"e6:31:9c:4c:8f:4e:17:66:a0:cd:e0:f8:fc:85:8a:d4:32:53:86:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6319c4c8f4e1766a0cde0f8fc858ad4325386bf/; sid:902203296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b9:f4:a4:6d:a2:f6:4e:64:68:c6:f5:68:e3:44:a6:b6:63:7e:7e:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9f4a46da2f64e6468c6f568e344a6b6637e7e00/; sid:902203297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"6c:d2:4e:ef:0f:84:ba:ba:4f:2a:4b:2a:55:a9:c5:fc:b7:bf:44:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cd24eef0f84baba4f2a4b2a55a9c5fcb7bf44a6/; sid:902203298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (GuLoader C&C)"; tls.fingerprint:"32:f2:4b:21:94:78:5f:96:96:49:11:54:f2:d1:b5:b0:e1:70:d0:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32f24b2194785f9696491154f2d1b5b0e170d0bb/; sid:902203299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"36:18:65:6f:ed:15:f9:c1:69:9b:47:e4:e0:e8:69:bf:45:c9:39:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3618656fed15f9c1699b47e4e0e869bf45c939e7/; sid:902203300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"a8:0e:28:d6:62:47:4d:38:b4:68:da:fc:f3:0c:a9:2f:0f:6a:d9:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a80e28d662474d38b468dafcf30ca92f0f6ad920/; sid:902203301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"10:71:5a:12:08:04:d5:b6:4e:83:d9:87:d6:c8:58:e6:b2:9a:89:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10715a120804d5b64e83d987d6c858e6b29a89b0/; sid:902203302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2c:9b:72:ae:66:eb:d1:4c:bf:55:8c:8a:b0:d3:83:7a:44:40:9b:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c9b72ae66ebd14cbf558c8ab0d3837a44409b98/; sid:902203303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:ac:ad:b5:00:7c:3b:5a:71:09:a9:d3:6e:fe:d3:cc:ec:73:f3:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3acadb5007c3b5a7109a9d36efed3ccec73f345/; sid:902203304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"59:b3:65:97:9c:ba:4a:77:0b:42:5e:f8:db:cc:71:d0:a4:20:c4:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59b365979cba4a770b425ef8dbcc71d0a420c4ab/; sid:902203305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FindPOS C&C)"; tls.fingerprint:"20:46:64:bb:32:39:06:34:63:ef:17:97:d1:11:a0:1f:90:ea:d0:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/204664bb3239063463ef1797d111a01f90ead09c/; sid:902203306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"60:25:76:3d:1c:f7:61:d5:10:ca:13:99:14:42:bd:62:e6:34:a9:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6025763d1cf761d510ca13991442bd62e634a9d6/; sid:902203307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"54:40:e8:d0:18:7c:d8:73:4e:c2:40:9b:89:67:41:7f:29:23:e6:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5440e8d0187cd8734ec2409b8967417f2923e615/; sid:902203308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:67:20:e8:f8:6f:5d:dc:61:c7:74:88:53:2f:bf:45:46:87:df:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff6720e8f86f5ddc61c77488532fbf454687df0b/; sid:902203309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"e3:f0:0a:c1:9c:a0:47:ba:89:d4:3a:74:a9:a2:c3:12:f4:1d:60:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3f00ac19ca047ba89d43a74a9a2c312f41d6039/; sid:902203310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"50:ee:4f:d6:82:be:ec:0b:48:26:40:b4:cd:45:b1:70:d8:d5:44:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50ee4fd682beec0b482640b4cd45b170d8d544a3/; sid:902203311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"24:61:a9:76:7f:1a:8b:5b:0c:13:70:2f:63:3b:1d:ea:59:eb:80:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2461a9767f1a8b5b0c13702f633b1dea59eb805b/; sid:902203312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f6:6c:dd:6a:14:94:13:29:71:15:ee:b7:28:a9:d4:fb:e7:25:a4:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f66cdd6a149413297115eeb728a9d4fbe725a47a/; sid:902203313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d7:35:69:72:95:bf:1a:a4:1b:2e:b5:fd:ab:b4:15:f5:da:61:8e:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d735697295bf1aa41b2eb5fdabb415f5da618ee4/; sid:902203314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"a6:b1:dd:db:e0:72:3b:5c:bb:68:18:c5:23:5e:dc:bd:5e:b9:33:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6b1dddbe0723b5cbb6818c5235edcbd5eb9331c/; sid:902203315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"eb:bb:b6:05:44:7a:cd:81:2b:22:d5:91:1c:3c:31:0a:37:84:c5:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebbbb605447acd812b22d5911c3c310a3784c598/; sid:902203316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"15:3a:7e:a3:a7:ac:b4:76:fd:66:d2:14:e6:1e:51:bb:35:b4:a2:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/153a7ea3a7acb476fd66d214e61e51bb35b4a24b/; sid:902203317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d5:df:9f:23:b3:d4:de:6c:d3:8e:30:e0:e0:29:f3:a8:71:5c:d9:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5df9f23b3d4de6cd38e30e0e029f3a8715cd9f6/; sid:902203318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"b9:5b:ea:f3:0f:84:51:1c:9a:03:b3:a8:47:29:b1:44:e1:69:5a:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b95beaf30f84511c9a03b3a84729b144e1695a9a/; sid:902203319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"5a:57:d7:c6:4f:50:5d:46:92:3a:46:65:46:ac:1f:d0:36:55:75:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a57d7c64f505d46923a466546ac1fd036557566/; sid:902203320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"c5:4c:9f:72:7f:72:c5:54:9c:6e:6a:d5:b6:53:6a:e5:c1:3e:eb:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c54c9f727f72c5549c6e6ad5b6536ae5c13eebe1/; sid:902203321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"8c:c5:9a:2c:86:a6:dc:85:4f:28:94:e0:1f:d6:32:48:07:84:ed:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8cc59a2c86a6dc854f2894e01fd632480784ed8b/; sid:902203322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f3:19:97:12:22:6d:e3:80:42:c0:a7:65:a4:88:9e:b3:3e:8d:52:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3199712226de38042c0a765a4889eb33e8d52bf/; sid:902203323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"c2:ca:c9:c1:c6:45:87:be:0f:10:b1:d2:90:ec:ed:1e:25:15:b2:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c2cac9c1c64587be0f10b1d290eced1e2515b2af/; sid:902203324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"94:12:17:d7:f1:94:d0:5b:08:6d:b5:13:2e:e0:4a:63:91:8e:a6:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/941217d7f194d05b086db5132ee04a63918ea6c4/; sid:902203325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"46:7b:e7:ac:ee:fb:78:e7:95:ad:38:52:1d:4b:4f:91:91:99:24:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/467be7aceefb78e795ad38521d4b4f9191992467/; sid:902203326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"19:4e:f9:fd:19:62:68:31:69:11:25:0b:cb:90:a1:0f:ed:ff:cc:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/194ef9fd196268316911250bcb90a10fedffccf6/; sid:902203327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"52:ea:d7:a0:3c:1c:66:89:b2:9f:23:42:90:ab:5a:49:ca:0b:00:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52ead7a03c1c6689b29f234290ab5a49ca0b0070/; sid:902203328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"6a:76:8a:c6:0b:ce:87:55:38:39:53:33:13:7a:fb:38:5f:8e:6a:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a768ac60bce875538395333137afb385f8e6a10/; sid:902203329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"60:21:14:ea:68:aa:61:e7:d5:a2:45:64:3c:c4:f4:a6:6f:fb:17:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/602114ea68aa61e7d5a245643cc4f4a66ffb1757/; sid:902203330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4b:fd:1a:63:d2:4e:3e:b1:02:c2:00:d9:db:ee:28:83:5f:5a:d7:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4bfd1a63d24e3eb102c200d9dbee28835f5ad77b/; sid:902203331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"11:bb:f8:60:62:c5:46:9d:5c:3e:e8:ba:1c:b3:cd:8f:5b:8d:0e:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11bbf86062c5469d5c3ee8ba1cb3cd8f5b8d0ea2/; sid:902203332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:d5:25:da:0e:ae:f5:6f:12:a9:ea:04:dd:f6:f8:52:96:59:c2:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9d525da0eaef56f12a9ea04ddf6f8529659c2f5/; sid:902203333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"dc:b0:d3:7a:8c:10:7a:0e:84:2b:e4:ed:bb:f6:1e:c2:33:29:77:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dcb0d37a8c107a0e842be4edbbf61ec2332977f6/; sid:902203334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"77:32:38:47:51:57:62:73:3c:94:63:db:65:12:91:e7:fd:ac:e9:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77323847515762733c9463db651291e7fdace94f/; sid:902203335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2e:d0:70:ce:aa:32:02:93:2b:75:e7:bf:63:eb:e1:5d:38:ef:89:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ed070ceaa3202932b75e7bf63ebe15d38ef89f3/; sid:902203336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"15:ef:78:c6:16:02:7d:df:46:02:e0:39:a7:1f:50:5a:22:d6:75:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15ef78c616027ddf4602e039a71f505a22d67565/; sid:902203337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:da:5d:00:3e:8a:ea:d2:22:05:b8:ee:fc:4c:16:67:5d:63:73:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32da5d003e8aead22205b8eefc4c16675d637373/; sid:902203338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"c1:9f:d8:ca:51:fc:94:81:63:f7:2f:21:46:36:dd:92:a4:2d:d7:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c19fd8ca51fc948163f72f214636dd92a42dd7b2/; sid:902203339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"86:b5:c4:46:13:02:fe:88:f9:36:95:8e:b5:5a:ff:55:11:28:f0:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86b5c4461302fe88f936958eb55aff551128f02a/; sid:902203340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"1e:92:bd:b5:f1:e5:66:41:8e:9e:30:b6:da:a8:da:80:63:94:cc:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e92bdb5f1e566418e9e30b6daa8da806394cc5e/; sid:902203341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"ca:f3:c8:9b:04:7e:80:73:ac:c4:96:2f:f6:a5:9f:d8:db:7c:86:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/caf3c89b047e8073acc4962ff6a59fd8db7c868e/; sid:902203342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"2a:dc:56:20:0a:fc:05:57:4c:8a:c4:c1:03:94:cb:31:9f:84:d4:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2adc56200afc05574c8ac4c10394cb319f84d453/; sid:902203343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"87:43:e0:30:cd:1a:78:91:0a:cb:8d:eb:15:e2:a6:84:95:6f:68:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8743e030cd1a78910acb8deb15e2a684956f68bc/; sid:902203344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"e4:60:84:aa:c2:0e:91:96:34:c3:81:41:f1:c9:b4:4b:a0:56:23:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e46084aac20e919634c38141f1c9b44ba05623ee/; sid:902203345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"3e:d1:6c:c4:f0:dd:eb:ca:7f:78:9a:f2:c2:49:fc:3c:da:c4:e1:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ed16cc4f0ddebca7f789af2c249fc3cdac4e177/; sid:902203346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"44:f8:ad:ec:42:af:1f:cd:02:80:99:6c:46:b5:10:86:27:39:17:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44f8adec42af1fcd0280996c46b51086273917b1/; sid:902203347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"da:5d:2a:4e:6b:40:45:55:ba:5b:a9:9c:89:1b:18:cb:6f:96:e0:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da5d2a4e6b404555ba5ba99c891b18cb6f96e056/; sid:902203348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:cb:f2:7d:a2:b4:3d:e2:70:27:a2:da:0f:a6:65:62:60:7d:b8:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7cbf27da2b43de27027a2da0fa66562607db8d9/; sid:902203349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1c:31:7a:7d:72:81:91:ee:04:e4:0e:6f:11:b2:4c:4d:8d:14:df:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c317a7d728191ee04e40e6f11b24c4d8d14dfcf/; sid:902203350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"40:1f:41:fc:ea:fb:ed:65:a1:56:7b:5a:3f:45:b2:fd:84:f1:9b:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/401f41fceafbed65a1567b5a3f45b2fd84f19b15/; sid:902203351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"6e:da:ce:53:50:99:7a:b9:c9:32:85:0b:1d:8f:0b:a3:5a:00:eb:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6edace5350997ab9c932850b1d8f0ba35a00ebe8/; sid:902203352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"55:d3:5f:b2:df:02:0f:40:68:e6:90:90:9e:68:db:67:79:23:e1:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55d35fb2df020f4068e690909e68db677923e19b/; sid:902203353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"32:aa:3d:19:42:69:f0:92:cd:a5:d3:ec:24:9c:28:ea:2f:bc:b5:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32aa3d194269f092cda5d3ec249c28ea2fbcb576/; sid:902203354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4a:a0:28:28:56:7a:23:27:98:76:3f:75:31:ce:90:e0:16:7e:f9:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4aa02828567a232798763f7531ce90e0167ef9ab/; sid:902203355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"a8:db:30:3f:1b:5a:ec:ce:ae:b4:a9:23:52:df:35:af:88:0c:5a:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8db303f1b5aecceaeb4a92352df35af880c5ab4/; sid:902203356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"22:6c:62:e4:b2:17:d4:8f:e3:73:76:e9:77:fa:f2:a0:17:18:bd:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/226c62e4b217d48fe37376e977faf2a01718bd14/; sid:902203357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2f:7f:f3:f6:a8:56:a2:2d:a9:17:79:83:3b:f6:6f:a5:0f:c5:1b:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f7ff3f6a856a22da91779833bf66fa50fc51be2/; sid:902203358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"2d:41:0c:4c:b7:49:34:3c:0d:32:2c:2a:07:4b:3b:28:d9:33:c3:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d410c4cb749343c0d322c2a074b3b28d933c3fc/; sid:902203359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"39:d0:9b:d8:4e:03:8a:58:d2:55:cc:b5:77:51:88:73:11:c6:d6:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39d09bd84e038a58d255ccb57751887311c6d6a3/; sid:902203360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f4:88:4b:0e:e6:8f:73:7d:75:9e:85:14:bb:ff:da:20:a1:ea:f0:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4884b0ee68f737d759e8514bbffda20a1eaf01f/; sid:902203361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e6:e1:a4:eb:3c:d2:20:23:1e:06:e2:8b:1a:4e:09:b2:c2:ea:82:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6e1a4eb3cd220231e06e28b1a4e09b2c2ea822a/; sid:902203362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"48:74:59:4c:fb:32:ce:7c:38:d4:53:b3:ef:56:b8:35:d4:3d:d2:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4874594cfb32ce7c38d453b3ef56b835d43dd2ac/; sid:902203363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"a7:14:42:e6:5b:ba:03:e9:dd:5d:ee:f8:3e:eb:34:42:b0:14:17:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a71442e65bba03e9dd5deef83eeb3442b014170b/; sid:902203364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"aa:22:ba:d8:9a:ba:bb:32:72:d3:ba:0e:83:9a:ed:32:04:b8:95:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa22bad89ababb3272d3ba0e839aed3204b89555/; sid:902203365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"dd:4f:68:c4:56:e0:f0:a5:c2:67:03:3e:7f:7a:fd:73:14:e5:0a:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd4f68c456e0f0a5c267033e7f7afd7314e50a5a/; sid:902203366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"15:17:a3:7e:be:bd:3f:c6:bf:95:ab:70:d3:37:53:96:55:40:0e:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1517a37ebebd3fc6bf95ab70d337539655400ead/; sid:902203367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f3:dc:18:df:65:88:4e:fc:ea:e0:94:56:e7:99:30:e6:62:0d:4d:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3dc18df65884efceae09456e79930e6620d4df3/; sid:902203368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"94:30:7f:c2:31:54:3b:66:fd:1f:07:c8:34:4d:c0:1e:ec:70:07:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94307fc231543b66fd1f07c8344dc01eec70073c/; sid:902203369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"52:7b:13:ac:93:09:4f:4e:7c:8e:ce:75:ff:68:78:f0:68:52:41:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/527b13ac93094f4e7c8ece75ff6878f0685241ec/; sid:902203370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"ea:c1:fb:26:86:08:36:ab:6e:c4:9a:9f:7f:73:d4:39:56:23:ac:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eac1fb26860836ab6ec49a9f7f73d4395623ac47/; sid:902203371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"56:98:37:e0:cb:e3:5a:f9:90:1d:82:aa:3e:fb:d0:2e:ae:87:35:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/569837e0cbe35af9901d82aa3efbd02eae8735bc/; sid:902203372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f2:9b:b1:e3:b9:19:be:7c:af:be:9c:bb:b2:75:34:25:78:01:af:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f29bb1e3b919be7cafbe9cbbb27534257801af7a/; sid:902203373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"49:74:f2:b8:ff:67:4e:b3:af:28:b8:52:a4:c8:54:e6:a3:43:29:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4974f2b8ff674eb3af28b852a4c854e6a34329a8/; sid:902203374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"1f:fb:be:e0:95:a8:0d:29:2d:5c:83:3f:2d:ef:84:58:57:11:21:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ffbbee095a80d292d5c833f2def8458571121db/; sid:902203375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"47:ed:36:56:a9:3e:a5:bb:e5:35:0d:aa:aa:b2:88:dc:35:6d:97:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47ed3656a93ea5bbe5350daaaab288dc356d9707/; sid:902203376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"6b:c7:b5:68:6c:d0:1f:59:09:41:ac:52:60:3d:95:53:4f:7d:48:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bc7b5686cd01f590941ac52603d95534f7d4812/; sid:902203377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"45:ee:dc:15:20:73:58:26:14:e2:cd:38:2c:e5:28:63:f5:70:bf:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45eedc152073582614e2cd382ce52863f570bf35/; sid:902203378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a6:a6:13:88:a4:b3:79:bd:c6:c6:80:ec:11:60:c5:be:f7:62:21:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6a61388a4b379bdc6c680ec1160c5bef762212f/; sid:902203379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"c0:dc:9c:a0:bf:92:bd:06:9e:a1:28:54:35:bc:c4:cc:7b:b4:55:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0dc9ca0bf92bd069ea1285435bcc4cc7bb4557e/; sid:902203380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"86:91:47:52:0f:af:5c:ca:14:3b:56:a4:1f:7c:b9:ce:f7:ba:4e:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/869147520faf5cca143b56a41f7cb9cef7ba4ea0/; sid:902203381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"fe:dd:be:e5:af:de:60:f1:c2:a0:7e:8b:32:2d:de:c3:2a:a4:50:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/feddbee5afde60f1c2a07e8b322ddec32aa45068/; sid:902203382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"92:9f:7e:2f:73:6a:21:a8:02:b5:18:e6:0e:d1:76:3c:d6:e1:d4:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/929f7e2f736a21a802b518e60ed1763cd6e1d4c3/; sid:902203383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"61:bb:6f:3d:ad:35:07:16:e7:1a:f3:26:7a:a0:80:08:76:f3:a1:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61bb6f3dad350716e71af3267aa0800876f3a106/; sid:902203384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"b6:7a:ff:5e:0d:5e:c8:63:27:00:8a:1e:d3:5f:c0:3e:2c:c4:d3:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b67aff5e0d5ec86327008a1ed35fc03e2cc4d3da/; sid:902203385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"28:8c:ed:57:36:9a:c7:20:fc:97:db:30:ee:db:25:07:15:b1:a7:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/288ced57369ac720fc97db30eedb250715b1a781/; sid:902203386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"34:ec:29:28:47:22:3c:d5:60:08:96:fd:6e:45:7b:9a:09:c4:f9:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34ec292847223cd5600896fd6e457b9a09c4f9c5/; sid:902203387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"4e:4a:0b:29:f8:f5:76:5f:07:f7:f8:4b:24:4c:18:53:16:c5:b9:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e4a0b29f8f5765f07f7f84b244c185316c5b96a/; sid:902203388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"ce:c8:ef:ab:6c:0d:76:7f:fd:c8:de:9f:da:a5:50:ea:a7:9c:45:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cec8efab6c0d767ffdc8de9fdaa550eaa79c4596/; sid:902203389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"02:85:30:66:d5:40:80:dd:09:fd:a4:23:ed:53:1d:9c:96:39:3a:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02853066d54080dd09fda423ed531d9c96393a6f/; sid:902203390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b2:6d:84:ef:a4:79:90:b9:13:5c:5b:0c:e1:8e:31:37:b2:79:e8:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b26d84efa47990b9135c5b0ce18e3137b279e8eb/; sid:902203391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"6c:1c:d5:f3:b4:f1:a6:da:97:a1:99:39:7b:1b:ae:82:26:aa:c7:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c1cd5f3b4f1a6da97a199397b1bae8226aac7bc/; sid:902203392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"7e:11:e7:0a:c0:b2:55:b6:4a:9e:7e:ce:14:e9:00:42:ab:bc:24:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e11e70ac0b255b64a9e7ece14e90042abbc242d/; sid:902203393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:92:33:b5:9e:8f:46:67:aa:f8:47:90:c2:f0:7a:ed:41:03:1f:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f59233b59e8f4667aaf84790c2f07aed41031f79/; sid:902203394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0b:c4:b6:85:a2:ac:da:72:36:30:10:0c:1c:53:5c:f7:b0:d3:fc:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bc4b685a2acda723630100c1c535cf7b0d3fc19/; sid:902203395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"cc:c0:59:dd:47:06:d4:32:cc:56:00:e8:ed:0a:78:7b:79:c1:0b:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ccc059dd4706d432cc5600e8ed0a787b79c10b25/; sid:902203396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"5b:c6:e4:8d:df:84:24:b5:2f:1d:af:1b:61:08:c8:f9:35:16:cd:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5bc6e48ddf8424b52f1daf1b6108c8f93516cdfb/; sid:902203397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"38:ec:c7:c5:43:c9:0d:25:57:1e:ae:05:fb:d1:94:8a:31:07:61:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38ecc7c543c90d25571eae05fbd1948a310761b7/; sid:902203398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:46:9d:62:12:b5:66:ad:90:5c:3e:55:65:43:be:cc:d4:20:f6:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23469d6212b566ad905c3e556543beccd420f610/; sid:902203399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5b:5f:e5:7a:16:8a:ca:ee:77:58:0b:b8:b9:d5:48:18:a9:64:24:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b5fe57a168acaee77580bb8b9d54818a964243d/; sid:902203400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"d9:7a:03:1c:c4:fa:1c:d9:a0:82:a6:90:23:0e:94:28:a0:cc:21:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d97a031cc4fa1cd9a082a690230e9428a0cc2156/; sid:902203401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"21:56:dc:a1:e3:9a:76:ff:b0:31:89:b3:72:1b:f2:af:5b:d5:0f:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2156dca1e39a76ffb03189b3721bf2af5bd50fe4/; sid:902203402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"25:ff:66:2d:8d:6f:25:f1:5c:4c:b6:9d:75:d4:33:9b:a0:2d:25:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25ff662d8d6f25f15c4cb69d75d4339ba02d2539/; sid:902203403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"91:9d:db:61:01:18:c8:48:a7:40:55:fa:57:26:56:91:7d:e2:a4:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/919ddb610118c848a74055fa572656917de2a4af/; sid:902203404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"86:c7:98:4a:b3:48:a4:c8:4d:8f:83:73:36:79:21:c4:71:94:f8:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86c7984ab348a4c84d8f8373367921c47194f8f3/; sid:902203405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"d3:90:20:96:14:12:ee:ce:df:65:4d:b4:94:33:2d:cb:0b:76:ca:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d39020961412eecedf654db494332dcb0b76ca71/; sid:902203406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"22:9b:73:0d:6a:ab:35:54:0a:31:dd:85:e3:03:be:21:53:48:1a:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/229b730d6aab35540a31dd85e303be2153481a30/; sid:902203407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"6a:37:4c:bb:f0:04:4a:47:d7:10:1d:9f:1d:26:4d:6e:38:fd:af:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a374cbbf0044a47d7101d9f1d264d6e38fdaf2a/; sid:902203408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"f1:a8:2a:ea:23:22:a8:d4:cc:e5:eb:62:99:a9:bb:de:09:43:d8:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1a82aea2322a8d4cce5eb6299a9bbde0943d800/; sid:902203409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"09:9d:b7:d1:71:9f:fd:df:83:5c:71:83:0d:27:0a:af:5e:7b:fc:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/099db7d1719ffddf835c71830d270aaf5e7bfcc8/; sid:902203410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2e:a5:8d:6d:87:98:dd:fc:22:e6:3b:64:85:18:ee:e1:0c:c9:3d:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ea58d6d8798ddfc22e63b648518eee10cc93d7b/; sid:902203411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"2b:97:1d:44:5c:7f:21:25:74:71:7c:7f:8c:3c:6c:28:fb:a7:a1:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b971d445c7f212574717c7f8c3c6c28fba7a18a/; sid:902203412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"3f:18:b7:68:e3:0c:dd:dc:ec:50:88:57:73:7e:eb:d4:fe:22:ef:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f18b768e30cdddcec508857737eebd4fe22ef1e/; sid:902203413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"fc:e7:65:46:64:8e:22:7e:bf:a6:70:08:25:09:cc:7d:50:84:9d:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fce76546648e227ebfa670082509cc7d50849d61/; sid:902203414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"bf:7e:e4:fa:fa:df:73:9f:8d:76:7c:50:be:c5:f0:e4:71:cc:ad:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf7ee4fafadf739f8d767c50bec5f0e471ccad3d/; sid:902203415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"2e:f2:ab:8e:da:49:5f:cd:0a:a2:40:d7:62:8f:16:b6:33:41:62:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ef2ab8eda495fcd0aa240d7628f16b633416209/; sid:902203416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"b2:1e:50:2f:ab:5b:5d:68:4d:29:b0:ae:73:75:1e:af:65:38:46:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b21e502fab5b5d684d29b0ae73751eaf65384677/; sid:902203417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"73:70:13:b1:83:03:4e:74:9e:52:4a:76:1c:17:10:77:cc:b3:eb:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/737013b183034e749e524a761c171077ccb3eb11/; sid:902203418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"69:4f:d8:70:9e:b5:a1:8e:7e:94:75:50:f7:68:4f:b3:c9:63:4b:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/694fd8709eb5a18e7e947550f7684fb3c9634b70/; sid:902203419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f4:b3:a1:2d:75:ef:34:ed:1d:e7:48:c4:da:a7:d3:5c:52:5b:b6:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4b3a12d75ef34ed1de748c4daa7d35c525bb690/; sid:902203420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"34:07:d4:12:77:19:e1:cf:0d:c9:96:b5:c8:72:32:17:a9:eb:82:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3407d4127719e1cf0dc996b5c8723217a9eb8218/; sid:902203421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"62:d3:a2:5a:a7:46:c7:1c:d7:4f:b2:ee:c2:d9:e3:0d:43:c0:12:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62d3a25aa746c71cd74fb2eec2d9e30d43c0127a/; sid:902203422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"1e:3c:13:ce:5b:42:cb:60:f4:61:f5:03:22:27:4f:ba:ac:72:cc:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e3c13ce5b42cb60f461f50322274fbaac72ccf1/; sid:902203423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"fa:48:73:1c:bf:53:5d:fc:43:a3:d4:2d:32:07:e5:86:22:00:66:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa48731cbf535dfc43a3d42d3207e586220066c6/; sid:902203424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"93:f1:58:ff:bb:ed:ce:d5:ac:14:cf:dd:f3:e0:08:15:8a:b7:11:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93f158ffbbedced5ac14cfddf3e008158ab711b3/; sid:902203425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"34:f4:46:58:c0:96:e5:a0:b4:75:4d:e5:69:61:4e:ce:b0:d1:70:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34f44658c096e5a0b4754de569614eceb0d170fc/; sid:902203426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"6f:7b:94:53:f0:71:34:38:06:88:c7:23:26:95:c1:d3:13:9e:41:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f7b9453f07134380688c7232695c1d3139e4111/; sid:902203427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"e6:2c:7d:7f:f9:56:5b:65:1f:24:a9:8a:c1:8e:c9:63:4a:57:28:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e62c7d7ff9565b651f24a98ac18ec9634a572896/; sid:902203428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:11:4d:e6:90:dc:2f:7c:6a:22:39:aa:23:39:17:f9:30:09:bd:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b114de690dc2f7c6a2239aa233917f93009bd9f/; sid:902203429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f6:42:63:25:d3:83:17:9f:47:35:56:51:08:cf:1f:24:78:88:a8:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6426325d383179f4735565108cf1f247888a8b0/; sid:902203430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"e0:89:cf:29:d8:49:4a:9e:19:03:a3:0a:8b:c9:9c:45:61:43:63:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e089cf29d8494a9e1903a30a8bc99c456143633d/; sid:902203431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"43:52:d5:4c:89:7d:e9:b2:35:e8:da:dc:ff:70:cb:04:6d:df:0a:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4352d54c897de9b235e8dadcff70cb046ddf0ab2/; sid:902203432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"59:3c:93:08:f5:96:5f:dc:0b:b7:8d:6b:90:55:cd:33:c9:4c:2b:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/593c9308f5965fdc0bb78d6b9055cd33c94c2b7d/; sid:902203433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:fc:70:a7:d2:f5:2b:ff:0f:b3:58:38:82:1a:51:f8:31:39:36:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4fc70a7d2f52bff0fb35838821a51f8313936e7/; sid:902203434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"60:4f:56:f4:02:3d:b5:be:c9:f4:00:65:18:03:af:5c:c1:a8:17:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/604f56f4023db5bec9f400651803af5cc1a81729/; sid:902203435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"37:f7:3e:af:ae:db:e5:ba:e1:67:01:ea:93:7b:11:46:d9:6d:08:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37f73eafaedbe5bae16701ea937b1146d96d080a/; sid:902203436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b2:c2:06:21:9c:ee:24:13:86:a3:5e:0d:32:9b:5b:31:78:28:37:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2c206219cee241386a35e0d329b5b31782837db/; sid:902203437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"5f:a3:c5:18:f6:fc:2b:1e:65:60:1b:71:c7:8d:b1:d3:48:73:89:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fa3c518f6fc2b1e65601b71c78db1d34873898a/; sid:902203438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:d5:6d:86:cd:6e:5f:56:e0:7a:07:3e:fb:fe:01:67:3c:6b:8e:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30d56d86cd6e5f56e07a073efbfe01673c6b8e0b/; sid:902203439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:5c:0d:65:00:6e:bd:f7:2b:8f:7b:c6:1a:c3:44:25:db:d4:1e:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/875c0d65006ebdf72b8f7bc61ac34425dbd41e54/; sid:902203440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"3d:d0:fb:ef:1a:06:38:e0:c1:ca:9b:2b:1a:f7:cd:61:91:54:d4:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3dd0fbef1a0638e0c1ca9b2b1af7cd619154d4df/; sid:902203441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"96:5f:e4:54:90:92:8e:22:12:53:0d:3a:de:73:f2:ad:ba:d0:26:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/965fe45490928e2212530d3ade73f2adbad02676/; sid:902203442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"a1:2f:2e:1d:7a:5d:22:fd:a1:a3:6a:6c:ca:ed:1d:d9:b9:99:64:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a12f2e1d7a5d22fda1a36a6ccaed1dd9b9996457/; sid:902203443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"fe:39:1f:ce:69:28:24:a6:5c:22:a2:5d:4a:87:15:10:3d:43:2e:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe391fce692824a65c22a25d4a8715103d432e50/; sid:902203444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:f0:58:43:71:90:60:6c:bd:7f:96:38:16:5c:b4:c8:ae:58:24:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdf058437190606cbd7f9638165cb4c8ae5824ea/; sid:902203445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"03:54:b0:3b:ae:fd:0b:c5:85:33:6c:c0:98:32:51:2f:05:42:68:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0354b03baefd0bc585336cc09832512f05426876/; sid:902203446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"bd:dc:c0:2c:86:65:92:a8:d7:ad:f6:d9:08:2e:1b:9d:53:eb:9a:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bddcc02c866592a8d7adf6d9082e1b9d53eb9a33/; sid:902203447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"7c:7c:a5:ce:91:b1:c5:38:67:e2:29:92:96:56:ae:86:52:da:08:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c7ca5ce91b1c53867e229929656ae8652da086a/; sid:902203448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"59:da:de:e6:d8:37:d3:f4:9f:e0:4d:42:2f:ec:d2:a6:aa:fa:20:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59dadee6d837d3f49fe04d422fecd2a6aafa2029/; sid:902203449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"90:16:69:15:ce:29:49:07:79:f2:f3:3e:d9:6f:fb:ed:fc:34:70:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90166915ce29490779f2f33ed96ffbedfc3470e9/; sid:902203450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"df:77:1d:b4:4d:52:07:09:fb:82:46:62:45:71:f9:d1:44:9f:1f:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df771db44d520709fb8246624571f9d1449f1fe2/; sid:902203451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"21:2e:66:5e:a0:de:ce:f6:1a:a4:de:dd:4d:94:5f:f0:c4:95:3a:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/212e665ea0decef61aa4dedd4d945ff0c4953a91/; sid:902203452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"9b:a8:a5:9a:c8:e0:7a:96:d5:00:4c:40:64:09:86:97:93:c3:09:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ba8a59ac8e07a96d5004c406409869793c30992/; sid:902203453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"78:fb:d2:0c:5c:d2:78:50:14:0f:e4:fa:bc:86:9b:72:ce:78:2c:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78fbd20c5cd27850140fe4fabc869b72ce782c05/; sid:902203454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"f8:09:a5:69:7c:17:b1:57:cd:db:6b:cd:35:45:0d:bb:44:16:8b:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f809a5697c17b157cddb6bcd35450dbb44168b02/; sid:902203455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Dridex C&C)"; tls.fingerprint:"55:0e:1c:de:5c:59:d0:3b:6f:3b:9b:d3:eb:fc:4a:f6:c7:db:ec:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/550e1cde5c59d03b6f3b9bd3ebfc4af6c7dbec48/; sid:902203456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"29:57:ca:08:9c:c5:41:29:01:d1:6f:14:c9:83:f6:24:17:c7:27:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2957ca089cc5412901d16f14c983f62417c72710/; sid:902203457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"a3:df:b6:86:09:d1:49:a6:e0:57:41:6b:1d:20:af:f9:8a:e4:cd:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3dfb68609d149a6e057416b1d20aff98ae4cd7d/; sid:902203458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"63:f3:87:29:0b:40:6a:e5:8b:fc:63:83:e0:4c:1f:2f:21:51:84:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63f387290b406ae58bfc6383e04c1f2f2151845a/; sid:902203459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"49:b7:75:b0:cd:ae:27:93:14:1e:49:23:bb:56:41:47:d8:3f:82:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49b775b0cdae2793141e4923bb564147d83f82d4/; sid:902203460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:31:86:e1:01:5b:f0:38:8e:0f:a3:c3:32:4e:80:2c:9f:1a:b2:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/323186e1015bf0388e0fa3c3324e802c9f1ab23a/; sid:902203461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"1c:b9:9c:ec:ea:15:16:d9:d6:d5:91:b8:10:33:dd:35:3a:e5:41:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cb99cecea1516d9d6d591b81033dd353ae54125/; sid:902203462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d5:f2:a9:a6:f5:8b:d4:a4:0f:19:ac:ba:bc:ad:04:c5:b6:8e:83:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5f2a9a6f58bd4a40f19acbabcad04c5b68e83e7/; sid:902203463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"93:5b:23:94:da:5f:69:52:4c:fd:29:c5:53:88:72:f2:67:c8:25:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/935b2394da5f69524cfd29c5538872f267c8253b/; sid:902203464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f0:92:55:71:28:5e:91:bd:7b:58:16:6a:b1:35:9a:ae:c8:cc:86:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f0925571285e91bd7b58166ab1359aaec8cc8698/; sid:902203465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ac:c3:56:21:f4:ff:67:9f:60:b1:08:0a:4f:13:f8:96:76:6a:d2:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acc35621f4ff679f60b1080a4f13f896766ad2cb/; sid:902203466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"60:21:b6:82:53:43:5c:0a:98:d2:b2:d1:93:c9:5e:d1:c1:8c:45:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6021b68253435c0a98d2b2d193c95ed1c18c4572/; sid:902203467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a1:04:6c:8b:b4:9e:fd:a5:73:d1:87:f5:5e:3d:52:22:f2:c8:06:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1046c8bb49efda573d187f55e3d5222f2c8066f/; sid:902203468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"1b:2b:f7:86:8b:70:33:11:12:91:04:fc:b9:be:49:08:a8:f7:38:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b2bf7868b703311129104fcb9be4908a8f73879/; sid:902203469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"71:ea:04:fc:ee:9f:ba:d2:cc:62:6a:f1:4e:88:83:30:48:b8:22:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71ea04fcee9fbad2cc626af14e88833048b82209/; sid:902203470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"7b:37:a7:15:de:1a:c0:cd:a3:53:88:18:4b:8e:95:e6:06:a7:84:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b37a715de1ac0cda35388184b8e95e606a78453/; sid:902203471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"45:4b:35:f9:7d:64:5e:68:1d:ec:92:f2:c0:40:41:67:db:16:68:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/454b35f97d645e681dec92f2c0404167db166810/; sid:902203472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bb:69:41:69:ba:e7:ce:98:f5:ba:83:89:0f:e4:51:5f:41:ab:c8:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb694169bae7ce98f5ba83890fe4515f41abc805/; sid:902203473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f9:e8:2f:f9:dd:de:b3:18:b6:fe:97:ff:b8:17:64:55:0a:30:34:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9e82ff9dddeb318b6fe97ffb81764550a30341d/; sid:902203474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DiamondFox C&C)"; tls.fingerprint:"eb:b1:d5:b5:ca:c9:c0:c1:c2:56:a8:e9:6c:4b:38:7d:fd:10:83:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebb1d5b5cac9c0c1c256a8e96c4b387dfd1083b1/; sid:902203475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d1:4c:a3:af:34:27:b4:21:4a:94:91:27:52:a8:66:db:72:d7:0a:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d14ca3af3427b4214a94912752a866db72d70abf/; sid:902203476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"61:93:e1:45:d0:7a:d6:b8:3c:38:79:d9:87:58:72:9a:2b:fd:77:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6193e145d07ad6b83c3879d98758729a2bfd77ff/; sid:902203477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f6:8d:8f:96:e1:74:31:fa:23:f2:f8:81:95:bd:09:b2:6e:15:57:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f68d8f96e17431fa23f2f88195bd09b26e1557ce/; sid:902203478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"b1:c2:48:28:ee:61:74:86:9f:68:52:65:7a:9d:ee:68:19:85:0e:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1c24828ee6174869f6852657a9dee6819850e08/; sid:902203479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"9d:88:bd:71:42:89:50:a5:49:75:2e:6c:26:ea:f5:97:ea:94:e9:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d88bd71428950a549752e6c26eaf597ea94e990/; sid:902203480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"01:b5:2b:fc:ee:87:55:75:75:d6:9b:78:ae:5f:4c:7e:82:24:7c:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01b52bfcee87557575d69b78ae5f4c7e82247c0f/; sid:902203481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"39:1f:20:c8:39:c2:42:fc:3c:5c:91:0e:90:59:e2:90:13:9f:d3:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/391f20c839c242fc3c5c910e9059e290139fd399/; sid:902203482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2c:a9:48:8a:77:c8:62:71:08:39:82:6d:ff:ac:ce:81:aa:ea:2c:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ca9488a77c862710839826dffacce81aaea2cb2/; sid:902203483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:1e:2e:d5:90:77:a4:27:03:31:5c:fa:b9:40:a4:e8:f7:c2:ae:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a1e2ed59077a42703315cfab940a4e8f7c2ae59/; sid:902203484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"a2:cf:23:f5:81:98:f0:b1:78:f5:9e:50:0a:f4:76:e5:7e:f2:dd:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2cf23f58198f0b178f59e500af476e57ef2dd06/; sid:902203485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:67:75:f7:3c:71:cc:9d:ae:50:9e:13:79:50:f3:08:be:ca:b4:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f46775f73c71cc9dae509e137950f308becab4cd/; sid:902203486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"f1:e4:89:7d:ce:73:c9:ee:3e:05:23:47:8c:8f:87:93:72:c0:d7:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1e4897dce73c9ee3e0523478c8f879372c0d700/; sid:902203487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6d:78:06:88:da:b9:bc:cd:02:2d:ca:ed:a9:4a:53:23:6a:83:50:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d780688dab9bccd022dcaeda94a53236a83500a/; sid:902203488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"bf:24:d6:9a:09:84:d0:84:e5:93:6b:40:ad:e1:29:e2:be:40:ae:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf24d69a0984d084e5936b40ade129e2be40aee8/; sid:902203489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"ee:07:3d:eb:e8:80:91:b5:3d:40:90:11:90:0b:7e:c2:83:b2:57:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee073debe88091b53d409011900b7ec283b2572b/; sid:902203490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"8b:f9:db:8f:ff:02:7b:7c:42:b5:3e:2e:0e:80:08:d7:65:31:20:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bf9db8fff027b7c42b53e2e0e8008d765312047/; sid:902203491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"63:16:c8:73:f5:fa:10:91:9b:ef:9a:7a:b4:0a:2b:a3:16:fc:88:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6316c873f5fa10919bef9a7ab40a2ba316fc882e/; sid:902203492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"7d:bc:4f:75:62:21:01:a9:27:b0:4a:27:18:b3:7a:8d:22:80:b5:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dbc4f75622101a927b04a2718b37a8d2280b5a6/; sid:902203493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b0:bd:fb:8d:ae:a3:8d:57:46:1f:bc:9d:77:7a:44:14:d6:2c:9a:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0bdfb8daea38d57461fbc9d777a4414d62c9a2b/; sid:902203494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:25:b3:d9:7a:5e:f5:fa:6d:ee:de:d9:04:38:d8:08:12:10:76:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1225b3d97a5ef5fa6deeded90438d808121076a3/; sid:902203495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"76:2e:0c:38:78:52:9a:1d:09:df:ab:ca:4e:f8:df:26:ca:6b:77:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/762e0c3878529a1d09dfabca4ef8df26ca6b7712/; sid:902203496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"ad:78:9f:68:90:c3:2e:a4:f1:5a:de:da:f2:06:94:1a:a8:40:e2:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad789f6890c32ea4f15adedaf206941aa840e2f6/; sid:902203497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QNodeService C&C)"; tls.fingerprint:"72:df:11:5b:1c:98:12:d7:d8:77:4a:2c:fe:69:5a:e4:29:c1:d6:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72df115b1c9812d7d8774a2cfe695ae429c1d6d5/; sid:902203498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"09:9b:a3:46:c5:b1:f4:43:2e:39:b7:37:7b:22:ac:d7:fb:a0:eb:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/099ba346c5b1f4432e39b7377b22acd7fba0ebf8/; sid:902203499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ac:9c:26:3c:bf:3c:21:bd:7f:9a:bf:32:b6:e1:31:13:53:74:f6:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac9c263cbf3c21bd7f9abf32b6e131135374f6dc/; sid:902203500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"90:c9:bc:91:7a:d2:21:fa:8a:98:b2:1e:b3:8d:a8:8c:f1:63:8a:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90c9bc917ad221fa8a98b21eb38da88cf1638a27/; sid:902203501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"fa:62:92:08:ab:c9:b9:a2:d9:ab:c1:b2:05:99:d4:82:91:9f:01:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa629208abc9b9a2d9abc1b20599d482919f014f/; sid:902203502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"85:99:bb:3a:ee:4b:0e:e4:60:b3:7d:b2:6d:bb:a3:a8:06:b1:a2:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8599bb3aee4b0ee460b37db26dbba3a806b1a29d/; sid:902203503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8c:2c:9e:7c:f1:b0:b4:fe:14:33:c1:0f:a0:ca:df:e2:22:e3:23:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c2c9e7cf1b0b4fe1433c10fa0cadfe222e32358/; sid:902203504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"93:fa:a2:7d:7a:5f:dd:4e:45:fc:7d:ae:ff:83:5f:db:31:bc:37:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93faa27d7a5fdd4e45fc7daeff835fdb31bc379e/; sid:902203505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"1e:24:bd:29:83:7c:17:67:d8:44:ec:d8:65:58:e8:fb:90:08:74:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e24bd29837c1767d844ecd86558e8fb900874fe/; sid:902203506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"36:6d:7e:58:65:18:76:de:4f:70:08:12:eb:61:3c:26:0e:00:bc:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/366d7e58651876de4f700812eb613c260e00bc08/; sid:902203507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:da:4d:c3:73:19:6c:20:17:2e:4c:a7:0d:49:a8:e7:b3:54:da:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4da4dc373196c20172e4ca70d49a8e7b354daf9/; sid:902203508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"fa:58:6b:92:b3:b7:86:ff:68:71:84:d1:f0:8f:7c:2c:d8:f6:be:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa586b92b3b786ff687184d1f08f7c2cd8f6beea/; sid:902203509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"14:87:3a:6f:cc:dc:7c:37:ff:f2:f9:72:0a:55:7e:d4:01:65:8d:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14873a6fccdc7c37fff2f9720a557ed401658d93/; sid:902203510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"7e:e0:d0:3c:2d:d9:65:72:90:5a:4d:86:bc:0a:6d:ac:25:c7:37:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ee0d03c2dd96572905a4d86bc0a6dac25c7377d/; sid:902203511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"4a:b7:11:73:65:79:18:b6:b7:fd:00:cb:db:a6:b5:72:f4:6e:ba:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ab71173657918b6b7fd00cbdba6b572f46eba79/; sid:902203512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"54:84:db:ef:83:46:7a:ba:83:c0:e6:38:c0:66:1b:7e:31:2b:b1:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5484dbef83467aba83c0e638c0661b7e312bb1f0/; sid:902203513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"6c:0c:d4:44:06:74:c8:e4:c7:f8:d6:c1:bd:44:fa:e8:93:4f:a8:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c0cd4440674c8e4c7f8d6c1bd44fae8934fa869/; sid:902203514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:35:70:45:62:40:bf:ca:ac:84:c5:77:3c:17:cf:c1:4b:e6:c8:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/873570456240bfcaac84c5773c17cfc14be6c8ad/; sid:902203515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"4d:6c:e6:30:30:ce:d8:5f:18:32:31:c5:a6:de:c5:0b:35:de:e7:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d6ce63030ced85f183231c5a6dec50b35dee7ce/; sid:902203516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"46:ca:79:cb:fe:52:87:4f:ba:e2:98:10:8c:3a:75:c4:91:1b:ca:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46ca79cbfe52874fbae298108c3a75c4911bca0a/; sid:902203517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"6c:c6:b5:a8:76:5a:38:92:2d:65:01:f2:1c:b0:e8:ea:b5:59:51:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cc6b5a8765a38922d6501f21cb0e8eab559516e/; sid:902203518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ab:06:96:29:b9:bc:ff:d4:a7:61:6d:b3:df:65:de:e2:c8:77:a4:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab069629b9bcffd4a7616db3df65dee2c877a465/; sid:902203519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:ec:76:d8:38:6c:aa:ac:d7:8f:d9:06:62:a7:77:c2:3d:cc:8b:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44ec76d8386caaacd78fd90662a777c23dcc8b4b/; sid:902203520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"63:ac:5b:c0:c4:b0:dc:07:2a:9e:c6:6f:d0:69:8a:a7:2e:f5:10:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63ac5bc0c4b0dc072a9ec66fd0698aa72ef5103b/; sid:902203521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"66:6f:b7:be:4d:5c:54:74:25:e2:df:a6:3e:a5:5f:b5:ea:03:b0:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/666fb7be4d5c547425e2dfa63ea55fb5ea03b0c6/; sid:902203522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c0:c1:44:ea:af:e3:23:91:89:1e:1e:d1:27:0b:da:c6:cd:0f:f1:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0c144eaafe32391891e1ed1270bdac6cd0ff1ab/; sid:902203523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0d:55:a4:dd:72:ea:a9:c0:ef:e8:48:9e:18:2b:ff:36:cd:a1:04:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d55a4dd72eaa9c0efe8489e182bff36cda1046c/; sid:902203524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"81:bb:1a:e8:ba:48:25:6d:19:e1:b8:26:a0:57:07:3b:7b:f8:e6:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81bb1ae8ba48256d19e1b826a057073b7bf8e6f0/; sid:902203525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"de:73:dc:a7:d1:58:b3:81:49:5f:57:63:27:87:ed:7a:83:f6:03:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de73dca7d158b381495f57632787ed7a83f603f0/; sid:902203526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"ba:f1:01:6e:1e:94:30:96:72:f7:15:f0:d9:7d:ec:72:9d:63:9a:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/baf1016e1e94309672f715f0d97dec729d639aa0/; sid:902203527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"09:86:f6:59:df:dc:d1:dc:c5:85:05:28:a0:95:50:9d:4d:d3:44:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0986f659dfdcd1dcc5850528a095509d4dd344a6/; sid:902203528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"7c:91:9d:19:25:69:24:5d:ec:a6:ae:6c:00:0d:d8:52:53:14:16:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c919d192569245deca6ae6c000dd85253141655/; sid:902203529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"fc:a2:b0:92:1e:57:42:23:41:3d:b7:cb:85:ef:8f:e1:8b:af:1d:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fca2b0921e574223413db7cb85ef8fe18baf1da6/; sid:902203530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5c:88:e4:8e:29:cc:af:88:43:78:b0:6c:0b:7f:a1:30:7f:29:e0:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c88e48e29ccaf884378b06c0b7fa1307f29e0a8/; sid:902203531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:3a:54:63:a0:94:0a:85:87:d3:61:b2:3b:3b:db:1f:05:70:89:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d3a5463a0940a8587d361b23b3bdb1f0570895f/; sid:902203532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"80:3c:69:a4:57:c4:0a:fe:a5:3b:98:77:31:59:03:b5:cc:64:a0:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/803c69a457c40afea53b9877315903b5cc64a026/; sid:902203533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1b:69:f3:68:71:7d:71:5d:3f:49:a1:67:3a:0a:6b:cf:f7:2e:6f:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b69f368717d715d3f49a1673a0a6bcff72e6f2a/; sid:902203534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"21:45:df:a3:9e:0e:50:70:2a:ee:09:ae:a1:b6:8a:9a:1e:75:55:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2145dfa39e0e50702aee09aea1b68a9a1e7555c3/; sid:902203535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"0c:c2:06:db:b1:5e:1b:d6:56:86:12:52:c2:00:ee:36:d4:20:17:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0cc206dbb15e1bd656861252c200ee36d42017af/; sid:902203536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"15:8e:10:29:0c:7a:44:fa:66:1f:91:3f:66:b3:bf:77:9c:70:8d:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/158e10290c7a44fa661f913f66b3bf779c708d45/; sid:902203537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"93:98:66:50:81:c9:40:43:36:0a:0b:48:b3:5e:a8:4b:ee:5d:88:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9398665081c94043360a0b48b35ea84bee5d883d/; sid:902203538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"54:71:51:1e:19:ee:d1:a6:4e:f4:ca:4d:47:11:94:80:41:74:5f:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5471511e19eed1a64ef4ca4d4711948041745f21/; sid:902203539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5a:3b:91:b1:d2:71:55:12:67:c8:10:df:de:3d:50:a3:cf:5d:22:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a3b91b1d271551267c810dfde3d50a3cf5d222b/; sid:902203540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b9:db:1f:c8:b7:7c:ee:b2:ba:86:1e:57:6a:e1:bc:64:38:b2:49:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b9db1fc8b77ceeb2ba861e576ae1bc6438b24962/; sid:902203541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9a:6e:34:7e:4b:c5:44:ec:c2:69:ca:2f:ea:7b:a2:92:99:8c:bf:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a6e347e4bc544ecc269ca2fea7ba292998cbf83/; sid:902203542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"46:f0:f0:3f:6f:c9:8c:7f:c6:e7:0f:d2:d7:bd:ef:cd:d5:11:6f:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46f0f03f6fc98c7fc6e70fd2d7bdefcdd5116f73/; sid:902203543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TA505 C&C)"; tls.fingerprint:"b7:16:ac:6b:4c:a6:4d:9d:9c:42:e2:42:e9:ab:96:62:92:52:3f:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b716ac6b4ca64d9d9c42e242e9ab966292523f29/; sid:902203544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"ab:bc:90:75:2a:3d:95:3d:55:af:2f:9a:b9:2d:ec:cc:3d:12:8d:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abbc90752a3d953d55af2f9ab92deccc3d128d03/; sid:902203545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:fc:4b:65:8c:64:f9:f7:de:fb:82:5a:9d:85:5c:bf:a6:5c:37:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7fc4b658c64f9f7defb825a9d855cbfa65c3781/; sid:902203546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"68:ce:c2:a6:a6:c4:61:bb:01:9d:d9:25:f0:6a:99:ad:20:70:db:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68cec2a6a6c461bb019dd925f06a99ad2070dbe9/; sid:902203547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"0f:76:00:60:86:3d:b3:bb:b1:c4:25:89:a5:f8:ba:12:bb:6a:09:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f760060863db3bbb1c42589a5f8ba12bb6a09c1/; sid:902203548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ab:cb:07:7b:00:58:47:9a:ff:49:35:29:23:50:1f:26:ed:45:ce:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abcb077b0058479aff49352923501f26ed45ce81/; sid:902203549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"17:8d:91:59:f0:95:c3:6e:fb:00:7f:18:ac:11:f7:5e:06:0b:c9:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/178d9159f095c36efb007f18ac11f75e060bc964/; sid:902203550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"08:3f:01:cb:4a:fa:e8:bc:97:ca:a2:5f:86:a1:fb:c8:c0:71:80:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/083f01cb4afae8bc97caa25f86a1fbc8c0718098/; sid:902203551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"27:ab:0c:2a:75:9d:6c:81:82:c7:ec:a9:a2:c5:3f:3b:fc:08:54:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27ab0c2a759d6c8182c7eca9a2c53f3bfc0854db/; sid:902203552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"87:91:b4:7a:ef:86:7b:5b:ff:df:a3:3c:9b:46:81:93:4e:e5:bf:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8791b47aef867b5bffdfa33c9b4681934ee5bf75/; sid:902203553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"27:13:a6:c1:fa:a1:45:72:df:4c:c9:49:36:32:df:d2:e4:0b:b8:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2713a6c1faa14572df4cc9493632dfd2e40bb8d3/; sid:902203554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"f8:9d:3c:49:6e:ec:13:be:93:70:6f:bb:dc:0b:db:74:5e:44:87:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f89d3c496eec13be93706fbbdc0bdb745e44875f/; sid:902203555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"f7:14:e0:b5:18:45:83:0d:79:52:77:49:9a:42:91:2b:a8:c3:9f:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f714e0b51845830d795277499a42912ba8c39f0e/; sid:902203556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"93:51:cf:a5:eb:d1:fe:ec:af:8a:0e:0d:1c:af:34:32:3e:86:e8:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9351cfa5ebd1feecaf8a0e0d1caf34323e86e8fa/; sid:902203557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"3d:1d:67:c6:1b:6c:f9:69:45:10:74:19:df:68:75:c3:54:f1:e1:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d1d67c61b6cf96945107419df6875c354f1e186/; sid:902203558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"3c:40:1a:1f:40:c5:fd:68:d7:f1:c7:6e:ff:cb:6c:73:91:e4:b0:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c401a1f40c5fd68d7f1c76effcb6c7391e4b026/; sid:902203559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ce:ad:cb:b8:ab:06:ce:4e:23:75:92:49:5d:2b:66:9c:e7:b2:5c:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ceadcbb8ab06ce4e237592495d2b669ce7b25cfa/; sid:902203560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"84:3f:76:bd:25:ed:15:70:ee:90:86:de:2a:e1:9c:01:5d:3b:53:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/843f76bd25ed1570ee9086de2ae19c015d3b5394/; sid:902203561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"01:87:6b:9f:02:de:ee:c3:69:d6:2b:28:85:e7:04:f6:26:da:73:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01876b9f02deeec369d62b2885e704f626da738b/; sid:902203562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"3f:2b:5f:89:2b:5e:56:5d:b4:dd:cc:19:b3:98:db:2b:d0:bf:57:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f2b5f892b5e565db4ddcc19b398db2bd0bf57fe/; sid:902203563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"1e:a9:f9:1d:a2:97:8d:b6:3d:85:7c:0b:5c:ff:b9:a8:af:68:9b:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ea9f91da2978db63d857c0b5cffb9a8af689b5c/; sid:902203564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"56:2a:2a:14:8a:57:d8:3f:6d:81:aa:64:b0:8f:26:fc:b8:20:58:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/562a2a148a57d83f6d81aa64b08f26fcb82058f9/; sid:902203565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:a9:03:dc:37:e5:95:8d:62:b2:0e:e9:86:4c:1c:f7:35:ed:35:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69a903dc37e5958d62b20ee9864c1cf735ed3546/; sid:902203566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8c:2f:1d:4f:1b:e9:09:4d:83:6c:0c:16:0d:6e:0b:e6:9e:66:b4:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c2f1d4f1be9094d836c0c160d6e0be69e66b4d9/; sid:902203567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"c1:0b:aa:a4:07:51:e2:d2:c5:47:ae:62:7f:ee:7a:60:30:e8:40:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c10baaa40751e2d2c547ae627fee7a6030e84015/; sid:902203568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"d5:ae:ff:a5:54:7f:ce:ff:7d:6c:3e:c1:1e:47:4d:db:10:ef:4d:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5aeffa5547fceff7d6c3ec11e474ddb10ef4dae/; sid:902203569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ac:7c:42:30:6d:77:7f:c0:de:51:13:29:08:90:ce:ae:2a:4a:a2:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac7c42306d777fc0de5113290890ceae2a4aa255/; sid:902203570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a1:1c:dc:ce:e9:59:cc:41:ef:cd:11:80:f8:fa:52:32:2d:07:18:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a11cdccee959cc41efcd1180f8fa52322d0718b9/; sid:902203571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"22:81:2a:d3:87:63:2e:1b:4d:1c:cf:5e:91:16:86:fd:c5:aa:26:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/22812ad387632e1b4d1ccf5e911686fdc5aa265f/; sid:902203572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"28:57:9b:e6:7c:f5:80:41:a2:2f:b8:b8:2c:8c:31:18:a6:7d:70:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28579be67cf58041a22fb8b82c8c3118a67d70f8/; sid:902203573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"78:39:b6:07:3e:05:91:98:40:ba:0c:75:47:4c:97:ca:9a:82:ab:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7839b6073e05919840ba0c75474c97ca9a82ab7f/; sid:902203574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"4f:cc:70:af:dd:ff:d8:34:95:14:33:cd:38:e0:8a:55:a0:d4:e9:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4fcc70afddffd834951433cd38e08a55a0d4e900/; sid:902203575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"86:61:2c:00:60:0b:a1:41:18:be:76:c7:f8:7d:dd:e7:e7:4d:d5:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86612c00600ba14118be76c7f87ddde7e74dd5bb/; sid:902203576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8d:37:70:56:10:b0:4f:8a:62:e3:87:c0:f0:b1:87:bd:eb:ac:5a:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d37705610b04f8a62e387c0f0b187bdebac5a19/; sid:902203577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"99:5f:27:6f:64:b4:c1:27:c8:29:52:60:4e:ca:b8:49:89:61:5e:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/995f276f64b4c127c82952604ecab84989615e1b/; sid:902203578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ostap C&C)"; tls.fingerprint:"41:c8:2d:5d:c9:bd:75:f6:7b:77:6b:b0:d3:41:f5:76:a0:df:ae:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41c82d5dc9bd75f67b776bb0d341f576a0dfae30/; sid:902203579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"48:db:2a:ea:3e:cb:1a:b4:44:13:38:68:5d:35:b9:65:3e:24:f4:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48db2aea3ecb1ab4441338685d35b9653e24f4e8/; sid:902203580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"49:32:9a:24:bc:b2:98:d8:fb:92:47:fd:b2:d7:79:c5:13:cc:e6:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49329a24bcb298d8fb9247fdb2d779c513cce642/; sid:902203581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"b2:f5:b8:4c:0d:70:dd:02:ef:e6:59:cd:88:30:26:a9:a8:57:83:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2f5b84c0d70dd02efe659cd883026a9a85783be/; sid:902203582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"15:b4:28:53:84:76:98:3a:bd:09:c3:84:b4:4f:18:b3:a5:b7:98:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15b428538476983abd09c384b44f18b3a5b798be/; sid:902203583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"af:35:90:c1:31:3e:dc:bd:4b:9a:3b:89:61:7b:31:77:bf:41:60:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af3590c1313edcbd4b9a3b89617b3177bf41600c/; sid:902203584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"37:76:dc:a6:8d:8e:92:54:ef:ce:85:3f:c0:d7:63:82:b3:2e:ce:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3776dca68d8e9254efce853fc0d76382b32eceb4/; sid:902203585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9f:cc:5c:1e:8e:c3:2f:56:e9:75:ba:43:c9:23:db:fa:16:a8:f9:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9fcc5c1e8ec32f56e975ba43c923dbfa16a8f946/; sid:902203586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"f1:3c:65:01:f6:08:3f:86:75:74:df:e8:6f:04:d9:52:99:d6:2b:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f13c6501f6083f867574dfe86f04d95299d62b0a/; sid:902203587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"67:c7:3b:14:45:6f:e6:e2:41:18:bd:aa:d3:ae:f7:fb:78:0f:94:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67c73b14456fe6e24118bdaad3aef7fb780f94bb/; sid:902203588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a7:31:59:07:c3:cf:4c:29:60:d8:20:9d:58:46:77:7e:48:a1:72:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7315907c3cf4c2960d8209d5846777e48a172d0/; sid:902203589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"01:80:d9:0c:d6:95:9e:42:9b:28:10:4e:e1:8c:2a:18:ed:d8:a6:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0180d90cd6959e429b28104ee18c2a18edd8a6b0/; sid:902203590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"01:f1:f7:5b:48:f2:05:ac:b9:2f:1e:23:20:48:69:39:4b:37:b9:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01f1f75b48f205acb92f1e23204869394b37b91f/; sid:902203591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:24:ab:f6:a6:6c:b9:d2:0f:fc:ad:12:4a:9d:9b:9f:40:5c:8e:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c324abf6a66cb9d20ffcad124a9d9b9f405c8e82/; sid:902203592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"10:0f:4a:41:ba:ef:e2:23:40:0c:f4:14:ad:ef:7c:dc:bd:f9:2d:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/100f4a41baefe223400cf414adef7cdcbdf92d41/; sid:902203593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"73:2a:cc:7b:f9:75:ac:bd:32:43:b5:f0:8c:68:ad:29:68:c3:92:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/732acc7bf975acbd3243b5f08c68ad2968c39228/; sid:902203594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"25:f6:47:5d:1a:6d:c6:cc:5e:c2:53:e0:64:e8:b1:0d:f6:fb:57:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25f6475d1a6dc6cc5ec253e064e8b10df6fb5752/; sid:902203595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"c8:43:2b:e3:ad:d8:1d:08:3b:3e:af:67:23:5e:be:54:6d:e9:d7:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8432be3add81d083b3eaf67235ebe546de9d7b7/; sid:902203596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:a2:82:60:ea:17:90:6f:5c:13:3d:f4:b8:82:e3:e5:a8:36:b1:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ca28260ea17906f5c133df4b882e3e5a836b118/; sid:902203597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"d8:46:02:41:18:49:9c:9c:1e:e2:ce:c7:48:c9:26:5f:18:a2:df:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d846024118499c9c1ee2cec748c9265f18a2df6c/; sid:902203598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e3:f0:b8:e9:4b:65:fe:39:9d:fb:c0:97:99:84:e2:d0:49:53:32:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3f0b8e94b65fe399dfbc0979984e2d049533251/; sid:902203599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"43:48:b0:d3:40:cb:dc:f6:d4:05:d0:c7:fa:4e:e2:b8:4d:9d:bd:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4348b0d340cbdcf6d405d0c7fa4ee2b84d9dbd35/; sid:902203600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"fb:7e:70:ef:2f:34:e4:85:87:b5:5b:f8:14:91:fa:44:9a:80:5b:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb7e70ef2f34e48587b55bf81491fa449a805b0f/; sid:902203601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"fd:c0:ad:a7:86:68:f4:22:a8:0f:3c:cb:d8:11:81:69:cc:c0:93:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdc0ada78668f422a80f3ccbd8118169ccc093e9/; sid:902203602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"28:91:71:4b:f4:9e:14:50:99:fa:ff:05:fc:16:47:fd:ba:90:6f:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2891714bf49e145099faff05fc1647fdba906ff1/; sid:902203603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"4e:c0:fb:f2:d4:48:86:eb:eb:8b:96:0d:15:07:27:26:24:80:ac:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ec0fbf2d44886ebeb8b960d150727262480ac01/; sid:902203604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"25:e0:3f:95:70:a0:20:b8:33:d4:20:41:f5:15:56:34:27:8b:d9:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25e03f9570a020b833d42041f5155634278bd9ca/; sid:902203605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"cf:d8:c3:f0:06:8b:d5:b8:18:80:f3:8e:be:1b:a6:25:39:b7:46:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfd8c3f0068bd5b81880f38ebe1ba62539b746b9/; sid:902203606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"1e:15:3b:4c:cc:da:96:fd:cf:7f:41:5f:4c:a1:46:18:13:04:40:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e153b4cccda96fdcf7f415f4ca146181304408b/; sid:902203607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"8a:5a:d7:98:b4:54:2c:f6:8f:3a:dd:68:bc:1a:a3:e7:bb:a9:f5:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a5ad798b4542cf68f3add68bc1aa3e7bba9f533/; sid:902203608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"6e:fb:3e:d8:55:02:b2:e1:9c:31:e2:e5:ac:ef:93:cd:6e:e1:41:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6efb3ed85502b2e19c31e2e5acef93cd6ee141a7/; sid:902203609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"7b:6b:d2:c9:4e:f8:05:fe:e0:d6:a6:f4:17:e6:b8:8b:92:bb:10:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b6bd2c94ef805fee0d6a6f417e6b88b92bb1012/; sid:902203610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"09:a7:25:1e:27:7c:a6:76:59:71:75:fe:ed:29:1d:a4:40:3a:05:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09a7251e277ca676597175feed291da4403a054b/; sid:902203611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"46:f5:e2:fd:0e:15:3d:61:90:04:45:f9:bb:d5:d9:00:26:db:91:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46f5e2fd0e153d61900445f9bbd5d90026db917c/; sid:902203612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"2d:9f:b5:76:1f:3c:2a:36:9e:1b:65:25:0b:3b:62:30:d9:1b:85:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d9fb5761f3c2a369e1b65250b3b6230d91b8547/; sid:902203613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"7e:25:58:75:b6:e8:17:5a:68:54:85:02:32:c5:60:d6:c5:de:93:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e255875b6e8175a6854850232c560d6c5de935f/; sid:902203614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"c9:93:d8:81:ed:ee:5a:d2:eb:bf:e4:58:5d:3b:39:a3:9d:3e:fe:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c993d881edee5ad2ebbfe4585d3b39a39d3efe60/; sid:902203615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"39:12:fa:ee:f7:8e:1e:5f:6c:9c:ca:a3:52:ea:37:f6:76:14:e6:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3912faeef78e1e5f6c9ccaa352ea37f67614e640/; sid:902203616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:92:51:92:10:5b:bd:88:75:d0:d5:bb:58:bd:da:e9:ee:be:e8:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1925192105bbd8875d0d5bb58bddae9eebee85c/; sid:902203617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"6d:6d:4f:29:82:8c:c0:86:37:04:eb:5c:fe:fb:a7:79:ce:3b:71:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d6d4f29828cc0863704eb5cfefba779ce3b714d/; sid:902203618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3c:ef:91:7b:bc:88:ff:17:ae:96:fa:bb:7a:4e:76:53:95:62:d2:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cef917bbc88ff17ae96fabb7a4e76539562d22e/; sid:902203619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:2c:8d:ba:70:1a:07:a3:ca:4d:6f:c4:73:f3:b3:d0:52:f7:fe:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c2c8dba701a07a3ca4d6fc473f3b3d052f7fe98/; sid:902203620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ef:c4:05:0b:55:58:b3:3c:dd:6b:29:c1:ef:6c:9b:0a:cc:cb:35:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efc4050b5558b33cdd6b29c1ef6c9b0acccb352f/; sid:902203621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:fb:2f:7d:88:1c:43:69:fc:7b:d0:72:f6:fc:9e:b7:10:db:c2:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9fb2f7d881c4369fc7bd072f6fc9eb710dbc23b/; sid:902203622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:70:a7:17:e8:ac:d9:11:21:07:c5:8d:c5:1b:13:b9:a9:e5:41:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0170a717e8acd9112107c58dc51b13b9a9e541f0/; sid:902203623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:43:cb:e3:68:29:9c:6e:5e:cb:67:d5:5f:63:88:2f:4b:4a:df:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e443cbe368299c6e5ecb67d55f63882f4b4adfc8/; sid:902203624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bf:98:9c:f0:42:a2:b1:4c:28:c1:1b:ba:56:4c:dd:da:9b:35:54:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf989cf042a2b14c28c11bba564cddda9b3554e4/; sid:902203625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"56:e8:cc:4d:4d:c3:d8:9a:87:ef:f6:8d:2c:e5:28:69:92:dc:7e:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56e8cc4d4dc3d89a87eff68d2ce5286992dc7e2c/; sid:902203626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4d:8a:e6:2d:0c:e1:2e:00:ef:3a:4b:1b:14:b3:13:9a:76:1c:be:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d8ae62d0ce12e00ef3a4b1b14b3139a761cbe66/; sid:902203627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"82:23:96:8f:a0:f4:e8:b3:86:a6:15:43:fc:03:96:8b:38:a8:46:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8223968fa0f4e8b386a61543fc03968b38a84682/; sid:902203628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f4:d2:5d:53:ac:68:ed:0f:7a:a1:67:fa:a9:e4:5c:3a:5f:81:a6:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4d25d53ac68ed0f7aa167faa9e45c3a5f81a6df/; sid:902203629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5d:7a:8c:d9:c0:2e:2a:22:37:f5:ff:7c:99:1b:df:9c:de:22:26:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d7a8cd9c02e2a2237f5ff7c991bdf9cde222612/; sid:902203630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2d:71:c5:c2:74:74:9e:83:89:49:88:e8:4f:57:6b:80:2f:57:41:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d71c5c274749e83894988e84f576b802f57418b/; sid:902203631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"7e:9a:9e:35:fc:b7:53:96:15:72:8d:08:c2:75:4b:87:21:56:01:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e9a9e35fcb7539615728d08c2754b8721560134/; sid:902203632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:a0:66:95:ed:5c:94:18:a8:d4:1d:d5:fc:87:54:0a:f2:0a:73:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0aa06695ed5c9418a8d41dd5fc87540af20a73a6/; sid:902203633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bc:bf:c9:ba:9e:b0:55:36:dc:92:24:bb:39:50:2b:90:86:bf:80:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcbfc9ba9eb05536dc9224bb39502b9086bf80eb/; sid:902203634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e9:c1:98:25:6d:a3:76:cc:76:fb:7a:df:82:87:bd:66:9f:ec:d3:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9c198256da376cc76fb7adf8287bd669fecd3ec/; sid:902203635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"13:50:e4:0c:1d:96:db:e3:71:06:e3:d3:8b:c9:68:76:92:f1:4c:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1350e40c1d96dbe37106e3d38bc9687692f14cdc/; sid:902203636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"56:8f:b3:8f:29:a4:46:a9:9c:63:bc:31:ee:a7:94:85:30:36:de:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/568fb38f29a446a99c63bc31eea794853036deea/; sid:902203637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:90:4f:5e:96:d7:49:91:95:f2:e5:49:4b:5d:b4:bc:9d:78:0e:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94904f5e96d7499195f2e5494b5db4bc9d780e60/; sid:902203638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0d:e2:2b:ad:56:15:78:e8:ba:0c:d9:7c:c7:de:b4:f5:6c:01:5e:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0de22bad561578e8ba0cd97cc7deb4f56c015e8d/; sid:902203639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"d0:9e:0d:c7:56:b7:43:ef:a0:4f:10:61:73:7a:fc:e1:9f:a3:e7:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d09e0dc756b743efa04f1061737afce19fa3e7c3/; sid:902203640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"89:64:f9:ca:f2:c4:e6:88:a3:95:f4:66:6d:b0:72:b1:65:f9:c2:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8964f9caf2c4e688a395f4666db072b165f9c28e/; sid:902203641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"63:1f:c2:f6:60:70:ec:88:38:57:a6:66:39:9f:51:d3:f5:9c:08:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/631fc2f66070ec883857a666399f51d3f59c0817/; sid:902203642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"65:84:57:42:57:f3:2a:01:c5:4d:a4:e0:b1:25:f6:09:1d:6a:54:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6584574257f32a01c54da4e0b125f6091d6a5400/; sid:902203643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a8:fe:3b:60:b2:eb:ca:d5:04:2a:4c:61:a8:50:cd:e1:e1:3e:b0:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8fe3b60b2ebcad5042a4c61a850cde1e13eb076/; sid:902203644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"20:0a:f7:af:a0:a9:3a:12:e8:77:19:9a:07:80:b9:ee:5f:5c:99:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/200af7afa0a93a12e877199a0780b9ee5f5c99fe/; sid:902203645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9a:1b:73:c2:1f:19:bc:8f:81:1c:96:ff:e5:05:11:c9:b6:49:89:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a1b73c21f19bc8f811c96ffe50511c9b6498902/; sid:902203646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:e5:fc:53:79:91:ac:80:eb:8b:62:94:95:bc:0a:68:6b:71:8f:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5e5fc537991ac80eb8b629495bc0a686b718f44/; sid:902203647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:59:32:bb:dc:35:52:24:6b:9e:a2:f3:b9:0f:02:2a:8c:72:6f:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/015932bbdc3552246b9ea2f3b90f022a8c726f05/; sid:902203648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"63:ae:55:6f:43:79:b1:ca:a7:3c:09:b3:7f:72:6e:ba:cf:35:72:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63ae556f4379b1caa73c09b37f726ebacf3572d0/; sid:902203649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"78:36:ec:df:37:af:a3:d9:d0:ae:ad:74:65:e4:3c:14:64:08:2a:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7836ecdf37afa3d9d0aead7465e43c1464082a35/; sid:902203650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:6d:62:48:22:55:b1:e8:07:fc:a8:ba:f4:f6:e2:1f:f4:99:49:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d16d62482255b1e807fca8baf4f6e21ff4994946/; sid:902203651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:60:93:43:69:b6:b0:86:06:1e:81:fe:5e:2f:24:ea:c1:41:00:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2560934369b6b086061e81fe5e2f24eac1410079/; sid:902203652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b3:2d:3c:88:03:38:2a:86:72:aa:6a:3f:49:32:91:32:dc:51:df:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b32d3c8803382a8672aa6a3f49329132dc51df8a/; sid:902203653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c9:72:56:ba:14:23:b9:dd:72:4a:89:bd:c8:dc:4b:8a:88:2f:54:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c97256ba1423b9dd724a89bdc8dc4b8a882f54e7/; sid:902203654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"98:7e:f1:c3:59:d7:98:80:b9:e5:d2:9f:22:ab:63:b9:48:a0:b0:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/987ef1c359d79880b9e5d29f22ab63b948a0b09e/; sid:902203655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"48:a1:17:ae:e3:bd:89:22:8d:f6:5f:09:78:07:3a:12:b2:61:53:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48a117aee3bd89228df65f0978073a12b2615340/; sid:902203656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:67:fd:34:6d:51:55:d7:39:30:08:64:a0:b1:97:40:89:b0:b4:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7567fd346d5155d739300864a0b1974089b0b430/; sid:902203657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"88:4b:85:29:0c:10:96:35:c5:6d:9f:77:68:40:cf:d3:70:e0:e2:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/884b85290c109635c56d9f776840cfd370e0e2d4/; sid:902203658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ac:d3:43:27:0a:fb:ba:88:a4:3e:ef:d1:1d:8b:30:e4:bb:02:02:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acd343270afbba88a43eefd11d8b30e4bb0202c8/; sid:902203659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"17:7a:b8:7c:04:42:21:96:eb:25:6d:66:e1:f9:e4:1d:79:45:e8:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/177ab87c04422196eb256d66e1f9e41d7945e8c9/; sid:902203660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:af:4d:ad:d4:65:07:73:1b:d8:90:95:87:31:25:b0:ab:0e:b2:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5af4dadd46507731bd89095873125b0ab0eb269/; sid:902203661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"60:07:91:a6:50:99:5e:12:04:89:61:fd:79:66:da:f6:0c:da:7a:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/600791a650995e12048961fd7966daf60cda7a2b/; sid:902203662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"ec:08:89:20:79:47:5e:b3:6c:23:04:65:f6:9d:26:10:4f:05:07:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec08892079475eb36c230465f69d26104f05077c/; sid:902203663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ba:2d:fb:2d:c7:e3:ad:2b:e5:35:bd:87:db:5c:ac:64:1d:84:07:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba2dfb2dc7e3ad2be535bd87db5cac641d840724/; sid:902203664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"54:b1:a9:52:c0:46:bf:cf:c3:2f:24:7c:e1:08:dd:79:15:6a:aa:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54b1a952c046bfcfc32f247ce108dd79156aaa64/; sid:902203665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"08:70:e7:fc:88:a0:4d:83:d4:af:16:59:c8:ae:34:8e:a0:c1:c7:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0870e7fc88a04d83d4af1659c8ae348ea0c1c701/; sid:902203666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"02:91:d4:2d:d1:d6:71:ae:32:08:8b:9b:cd:06:55:55:4f:9a:6b:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0291d42dd1d671ae32088b9bcd0655554f9a6b79/; sid:902203667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fe:80:cd:4d:b0:34:b8:18:50:a6:75:52:39:a1:a4:63:01:ef:e2:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe80cd4db034b81850a6755239a1a46301efe2a9/; sid:902203668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"27:94:7b:1c:98:26:ea:3c:bf:c3:be:c8:b6:03:1c:9e:79:0d:c9:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27947b1c9826ea3cbfc3bec8b6031c9e790dc9da/; sid:902203669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"18:3d:41:c0:8e:50:fb:28:df:d2:65:56:ce:c8:99:29:a5:ea:e8:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/183d41c08e50fb28dfd26556cec89929a5eae8af/; sid:902203670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:01:21:08:90:3a:08:56:21:40:bd:74:4a:3d:74:83:07:2f:f0:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94012108903a08562140bd744a3d7483072ff02c/; sid:902203671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:1c:0e:6c:f0:e5:02:4f:44:05:b7:ce:ae:bc:b5:12:76:6b:43:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/591c0e6cf0e5024f4405b7ceaebcb512766b4380/; sid:902203672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"52:5d:11:86:84:48:63:e1:85:93:60:61:9b:e7:d4:af:21:65:af:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/525d1186844863e1859360619be7d4af2165af1d/; sid:902203673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"92:45:fc:d5:92:e3:f8:a4:3b:c0:4b:d0:03:b8:fb:74:14:10:fd:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9245fcd592e3f8a43bc04bd003b8fb741410fdef/; sid:902203674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"9b:84:0e:75:73:79:c1:00:e6:c6:b6:b1:7a:6d:0d:2d:d2:83:23:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b840e757379c100e6c6b6b17a6d0d2dd2832320/; sid:902203675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"2e:37:72:1f:75:2b:4d:df:d8:0a:b9:1b:04:f2:63:8a:14:04:60:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e37721f752b4ddfd80ab91b04f2638a140460a7/; sid:902203676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ransomware.DarkSide C&C)"; tls.fingerprint:"4a:e5:a5:79:db:e6:c2:a2:30:fd:18:21:ec:b9:9e:2f:3c:cd:fb:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ae5a579dbe6c2a230fd1821ecb99e2f3ccdfbe9/; sid:902203677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0d:fb:21:3b:0a:ac:91:62:9c:97:e8:3f:1c:fe:3e:60:a0:59:93:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0dfb213b0aac91629c97e83f1cfe3e60a05993db/; sid:902203678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8d:e7:ce:b1:cd:c1:bf:1a:03:bc:60:f2:45:de:8d:09:99:98:ea:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8de7ceb1cdc1bf1a03bc60f245de8d099998ea60/; sid:902203679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4d:56:1c:67:46:10:b1:52:1a:1e:0b:2b:22:32:79:93:0c:47:00:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d561c674610b1521a1e0b2b223279930c47007e/; sid:902203680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:1a:b5:94:e9:29:6a:e3:a7:72:d0:11:8c:72:a8:89:2a:8e:57:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e01ab594e9296ae3a772d0118c72a8892a8e5751/; sid:902203681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0f:b8:9c:51:ab:b8:d1:99:55:eb:5b:61:b1:2a:7c:21:ac:29:c7:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0fb89c51abb8d19955eb5b61b12a7c21ac29c76f/; sid:902203682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d5:57:cd:4e:dc:37:e8:32:9b:00:b8:dc:09:a4:75:b9:71:97:f5:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d557cd4edc37e8329b00b8dc09a475b97197f584/; sid:902203683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"4e:b5:69:e3:00:34:fd:38:9f:24:af:2b:bc:74:74:03:56:40:38:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4eb569e30034fd389f24af2bbc74740356403854/; sid:902203684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"41:f0:33:bf:58:d1:ad:cf:45:6c:dc:56:c1:3f:23:4e:dc:c6:95:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41f033bf58d1adcf456cdc56c13f234edcc695d8/; sid:902203685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"83:85:37:c0:8c:4b:d5:65:64:49:b3:7f:e3:57:e3:7f:d1:73:ee:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/838537c08c4bd5656449b37fe357e37fd173ee39/; sid:902203686; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4f:47:7d:33:bd:99:56:32:c6:f4:6f:bb:82:81:25:b2:b8:32:e5:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f477d33bd995632c6f46fbb828125b2b832e5c2/; sid:902203687; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:eb:47:4d:40:49:48:1f:54:78:db:ad:b4:5c:af:66:e9:5f:c4:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5eb474d4049481f5478dbadb45caf66e95fc442/; sid:902203688; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:be:d7:df:4f:96:4d:7a:c8:3f:2c:6e:c9:ef:c6:be:c5:be:3c:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1dbed7df4f964d7ac83f2c6ec9efc6bec5be3c42/; sid:902203689; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"14:5e:5b:0a:2e:9f:dc:fa:e8:ba:a4:78:4a:2b:92:f7:20:16:80:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/145e5b0a2e9fdcfae8baa4784a2b92f7201680ba/; sid:902203690; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"64:97:25:b1:1e:d7:93:67:15:4d:36:d2:07:d7:79:6a:71:64:c0:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/649725b11ed79367154d36d207d7796a7164c058/; sid:902203691; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c1:16:0e:b9:72:66:2b:e9:7e:30:ba:2c:41:ff:3c:0f:81:75:2c:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1160eb972662be97e30ba2c41ff3c0f81752c59/; sid:902203692; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f8:94:13:6e:f7:89:94:87:4d:e3:b3:de:9c:e2:57:e3:08:f3:03:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f894136ef78994874de3b3de9ce257e308f303a8/; sid:902203693; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b6:5f:f0:e2:f1:a6:1c:ee:55:39:2f:b6:23:91:36:ae:c3:bd:2c:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b65ff0e2f1a61cee55392fb6239136aec3bd2ce5/; sid:902203694; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"81:7c:b6:ba:e5:34:2a:5f:72:06:ed:67:fa:ac:9b:a5:f7:ab:a9:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/817cb6bae5342a5f7206ed67faac9ba5f7aba910/; sid:902203695; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bb:ff:b5:a9:08:66:ba:64:d9:0b:69:1d:40:de:60:9a:1a:a5:fc:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbffb5a90866ba64d90b691d40de609a1aa5fc81/; sid:902203696; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:40:5b:d5:25:86:69:dc:d6:89:73:2a:ec:ef:e9:0d:f2:50:ae:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a405bd5258669dcd689732aecefe90df250ae2c/; sid:902203697; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:01:8f:74:bd:bf:eb:57:60:ae:a1:7f:ab:bd:0b:9e:01:2b:86:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff018f74bdbfeb5760aea17fabbd0b9e012b86d7/; sid:902203698; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:07:4b:66:25:43:f3:04:1a:db:04:bf:e0:1f:4a:08:8d:49:86:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3074b662543f3041adb04bfe01f4a088d498698/; sid:902203699; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"59:4a:00:cb:f1:3e:2a:75:f3:ab:fa:ec:d0:e4:ce:b0:c4:fe:46:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/594a00cbf13e2a75f3abfaecd0e4ceb0c4fe462b/; sid:902203700; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"36:78:82:bf:c2:b9:cf:af:5a:ec:fa:f9:c9:20:c0:7c:92:04:3e:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/367882bfc2b9cfaf5aecfaf9c920c07c92043ea1/; sid:902203701; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:e8:af:29:08:49:82:f5:e8:66:89:06:a1:21:0a:0d:a6:90:e6:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32e8af29084982f5e8668906a1210a0da690e6ad/; sid:902203702; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9b:d0:28:59:23:be:a2:c2:bc:66:34:ed:b6:22:9d:4c:44:da:d5:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bd0285923bea2c2bc6634edb6229d4c44dad537/; sid:902203703; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"16:d2:a4:99:d2:27:a4:99:be:98:43:1d:a1:c9:12:ff:48:76:16:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16d2a499d227a499be98431da1c912ff48761646/; sid:902203704; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d8:90:87:16:fa:08:a1:c1:f2:17:8c:f8:f9:85:71:98:fb:8c:5b:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8908716fa08a1c1f2178cf8f9857198fb8c5b0b/; sid:902203705; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"cd:6f:ef:4f:94:83:65:72:2a:ff:07:eb:62:f7:b7:4a:84:9a:9b:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd6fef4f948365722aff07eb62f7b74a849a9b86/; sid:902203706; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:6a:eb:da:6f:f7:b5:2f:89:56:4f:6c:96:e1:c3:66:b2:af:54:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/146aebda6ff7b52f89564f6c96e1c366b2af5401/; sid:902203707; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c7:3e:04:0c:a8:0d:69:28:31:79:8b:d1:49:e5:a5:1d:05:0d:d9:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c73e040ca80d692831798bd149e5a51d050dd9ab/; sid:902203708; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fc:8a:5b:be:db:6b:c5:6b:80:91:0d:20:9c:e6:eb:94:df:50:c1:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc8a5bbedb6bc56b80910d209ce6eb94df50c1eb/; sid:902203709; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c4:13:de:c0:d8:5e:70:ab:16:f6:97:21:9d:e0:00:8a:f5:81:ed:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c413dec0d85e70ab16f697219de0008af581ed92/; sid:902203710; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"86:c3:a1:61:a9:00:00:dc:bb:6b:75:54:2a:0f:79:d8:11:52:08:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86c3a161a90000dcbb6b75542a0f79d81152081d/; sid:902203711; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e6:55:e7:85:06:cb:fb:32:d4:08:63:26:33:66:f2:6d:74:92:d7:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e655e78506cbfb32d40863263366f26d7492d715/; sid:902203712; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (njrat C&C)"; tls.fingerprint:"6d:c6:2b:a3:d4:43:22:3e:31:c4:19:bc:41:88:29:02:66:3d:58:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6dc62ba3d443223e31c419bc41882902663d5833/; sid:902203713; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:fe:0f:e2:ae:50:63:b3:ff:96:b2:43:ca:9b:46:c9:a9:2f:0f:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6fe0fe2ae5063b3ff96b243ca9b46c9a92f0f27/; sid:902203714; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4d:3e:57:0b:fe:82:4d:29:55:63:a2:90:60:5b:b1:34:03:9a:ba:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d3e570bfe824d295563a290605bb134039aba24/; sid:902203715; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"27:80:ff:b6:db:a7:b5:6d:f6:c0:e2:8a:0e:e7:c2:7f:84:0f:ba:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2780ffb6dba7b56df6c0e28a0ee7c27f840fba48/; sid:902203716; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"47:88:4c:3f:ad:44:95:0d:d4:6e:e5:ba:b7:53:ea:8a:df:82:34:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47884c3fad44950dd46ee5bab753ea8adf823418/; sid:902203717; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e0:1d:41:01:fa:93:0f:ae:38:2a:95:be:9d:51:15:6a:6c:37:d9:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e01d4101fa930fae382a95be9d51156a6c37d9c2/; sid:902203718; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:d0:4d:7c:4c:83:72:ff:8a:a8:fb:42:dc:d1:32:b4:ff:aa:d2:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01d04d7c4c8372ff8aa8fb42dcd132b4ffaad20e/; sid:902203719; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"d5:c7:e0:50:11:a9:f2:ff:fb:21:4d:0a:d2:21:b4:5d:9b:e2:e2:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5c7e05011a9f2fffb214d0ad221b45d9be2e214/; sid:902203720; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"64:64:d7:e4:c9:63:3c:ae:8e:97:46:d0:87:aa:91:3a:b0:3c:1d:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6464d7e4c9633cae8e9746d087aa913ab03c1d2f/; sid:902203721; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8b:c4:1e:0d:91:76:e9:4b:47:12:da:03:a8:8a:61:3e:01:bb:cf:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bc41e0d9176e94b4712da03a88a613e01bbcf2c/; sid:902203722; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:5d:38:2d:12:01:a4:0e:81:ce:ed:69:7a:08:e9:0f:a0:93:49:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e5d382d1201a40e81ceed697a08e90fa09349b0/; sid:902203723; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1b:a2:78:e4:8f:1a:b7:ff:01:7f:37:66:f5:83:f4:64:2b:38:76:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ba278e48f1ab7ff017f3766f583f4642b38768c/; sid:902203724; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"da:f1:bf:d2:5c:fb:24:e7:ab:bb:ee:90:99:1a:cc:20:c9:7f:a2:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/daf1bfd25cfb24e7abbbee90991acc20c97fa248/; sid:902203725; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:fe:37:77:df:7a:27:bb:b2:aa:ac:03:d4:4e:83:a0:8c:26:b4:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28fe3777df7a27bbb2aaac03d44e83a08c26b4d7/; sid:902203726; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c1:1e:5e:77:55:f2:45:22:12:0c:d6:e6:d3:17:95:cf:6a:79:a3:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c11e5e7755f24522120cd6e6d31795cf6a79a319/; sid:902203727; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"34:b6:b3:80:f1:c3:2f:d9:2a:4d:58:e1:a5:18:5d:52:67:e0:5f:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34b6b380f1c32fd92a4d58e1a5185d5267e05fd4/; sid:902203728; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a8:a1:dc:5d:20:88:cb:b3:3e:bb:61:ed:c9:1c:30:62:59:5d:9a:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8a1dc5d2088cbb33ebb61edc91c3062595d9a4e/; sid:902203729; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"18:c4:52:9d:48:6d:de:a8:6b:ca:5f:65:fc:f5:10:2d:84:18:91:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18c4529d486ddea86bca5f65fcf5102d841891d0/; sid:902203730; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"16:b8:ca:a7:89:ab:ef:f2:c4:9b:0d:a4:35:19:b0:cb:f3:f7:70:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16b8caa789abeff2c49b0da43519b0cbf3f7707c/; sid:902203731; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"26:3a:0a:4e:67:31:40:d0:79:ee:bf:a2:c8:8d:91:ec:3c:8d:df:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/263a0a4e673140d079eebfa2c88d91ec3c8ddfc6/; sid:902203732; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ef:5c:96:8a:af:51:83:9c:90:96:4c:17:a9:8c:05:4c:7b:69:b9:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ef5c968aaf51839c90964c17a98c054c7b69b93d/; sid:902203733; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bd:bb:46:f5:12:c7:5e:53:c6:52:86:9a:28:0b:2d:76:fc:1a:64:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdbb46f512c75e53c652869a280b2d76fc1a6404/; sid:902203734; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"d6:ff:fe:f0:fd:e4:a1:cc:a7:ef:02:47:a5:81:2b:3f:6a:ba:06:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6fffef0fde4a1cca7ef0247a5812b3f6aba06db/; sid:902203735; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"bf:a4:43:98:ae:e9:15:fc:ff:0e:2a:83:98:70:05:27:49:0e:c7:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfa44398aee915fcff0e2a8398700527490ec721/; sid:902203736; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"47:5d:44:3b:1c:1f:06:36:dc:b6:8b:8d:85:13:a1:fc:99:65:fc:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/475d443b1c1f0636dcb68b8d8513a1fc9965fc70/; sid:902203737; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"09:ae:8b:1d:55:28:38:b4:5f:cf:67:3c:bf:e0:1e:30:6e:bf:f6:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09ae8b1d552838b45fcf673cbfe01e306ebff64d/; sid:902203738; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"fb:28:46:a2:df:ef:fb:12:17:3a:99:42:65:22:f6:b3:f5:c4:c5:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb2846a2dfeffb12173a99426522f6b3f5c4c574/; sid:902203739; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"db:b7:ed:30:9f:6e:b4:5e:65:44:12:33:63:2a:04:2b:2f:d6:80:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbb7ed309f6eb45e65441233632a042b2fd6804a/; sid:902203740; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:cc:f4:24:ed:71:87:1b:05:1b:c0:86:27:67:0e:9a:fd:20:a6:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88ccf424ed71871b051bc08627670e9afd20a6f0/; sid:902203741; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"07:4f:7f:3b:d6:da:25:69:b3:db:52:e2:0f:1b:9d:c7:c4:46:e3:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/074f7f3bd6da2569b3db52e20f1b9dc7c446e388/; sid:902203742; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"09:6c:0d:d9:5c:b8:c4:24:2d:4a:50:93:77:23:68:2a:5e:ac:cb:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/096c0dd95cb8c4242d4a50937723682a5eaccb95/; sid:902203743; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"19:c0:7a:ec:70:f0:1f:79:8c:a6:93:78:cb:45:4f:89:75:42:5f:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19c07aec70f01f798ca69378cb454f8975425f93/; sid:902203744; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"73:dc:75:23:cc:c6:be:65:b1:b1:2a:9f:a8:24:09:a4:45:c7:33:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73dc7523ccc6be65b1b12a9fa82409a445c733cf/; sid:902203745; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1e:44:c8:d7:64:7a:41:df:d9:89:3a:6d:2a:43:a7:37:2c:c4:f2:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e44c8d7647a41dfd9893a6d2a43a7372cc4f2e2/; sid:902203746; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (njrat C&C)"; tls.fingerprint:"32:7b:b0:d9:ab:df:f7:b4:c0:ac:35:34:12:75:43:51:04:b5:d5:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/327bb0d9abdff7b4c0ac35341275435104b5d5bf/; sid:902203747; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"dd:af:18:c7:83:4a:57:29:a1:05:e5:08:06:a6:fd:78:40:f7:31:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddaf18c7834a5729a105e50806a6fd7840f73191/; sid:902203748; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"61:28:8d:93:74:81:22:07:05:07:cb:d3:7d:b0:38:c3:bb:3c:47:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61288d93748122070507cbd37db038c3bb3c4741/; sid:902203749; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"91:d3:28:5d:2a:72:d2:63:32:15:46:90:c3:7f:06:a4:91:6c:ab:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91d3285d2a72d26332154690c37f06a4916cabfe/; sid:902203750; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"55:09:e9:5f:73:31:a6:f6:54:27:dd:9a:3c:82:a9:16:69:e0:c5:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5509e95f7331a6f65427dd9a3c82a91669e0c554/; sid:902203751; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (FIN7)"; tls.fingerprint:"18:e3:37:e7:2e:f9:ad:e6:5b:79:2b:50:0d:f7:54:91:8e:11:88:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18e337e72ef9ade65b792b500df754918e1188af/; sid:902203752; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:9e:b3:ae:78:bb:d2:3b:8f:1a:b1:2a:17:c8:c8:a3:df:07:ec:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b9eb3ae78bbd23b8f1ab12a17c8c8a3df07ec6e/; sid:902203753; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"f7:5f:6e:50:37:f2:c9:07:50:9a:bb:67:90:4c:02:4d:87:a8:a0:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f75f6e5037f2c907509abb67904c024d87a8a0f0/; sid:902203754; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"79:63:8e:1c:d0:d8:0f:38:c9:4b:84:40:46:9b:da:af:93:68:bd:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79638e1cd0d80f38c94b8440469bdaaf9368bdf9/; sid:902203755; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"70:8f:3b:3a:f3:a2:02:71:15:a7:e7:3d:6e:f7:2d:69:a1:3e:37:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/708f3b3af3a2027115a7e73d6ef72d69a13e37fe/; sid:902203756; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:32:1c:f3:06:5c:f5:c3:d8:f5:03:ee:36:5e:72:01:be:0d:31:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32321cf3065cf5c3d8f503ee365e7201be0d317e/; sid:902203757; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"53:86:b2:1e:8d:f0:7d:72:96:cd:93:3d:e2:40:c6:09:da:54:64:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5386b21e8df07d7296cd933de240c609da5464ad/; sid:902203758; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"c5:8a:93:fe:aa:2e:7c:75:29:59:3c:8f:5c:07:af:04:e9:4a:be:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c58a93feaa2e7c7529593c8f5c07af04e94abeef/; sid:902203759; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:80:ef:00:d7:f1:b8:58:95:af:bb:e0:78:94:61:dd:27:f5:90:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c580ef00d7f1b85895afbbe0789461dd27f590c1/; sid:902203760; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"64:2c:55:be:bd:7d:a9:5c:30:65:8b:f9:b3:bc:c9:07:85:d3:2c:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/642c55bebd7da95c30658bf9b3bcc90785d32cd7/; sid:902203761; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8f:ae:62:c9:28:55:6c:3c:3f:e7:07:a4:cb:d3:0f:17:fe:be:99:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fae62c928556c3c3fe707a4cbd30f17febe9944/; sid:902203762; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"4a:69:12:32:21:0a:de:b5:83:e1:1d:54:99:9d:4f:3c:c9:0e:c8:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a691232210adeb583e11d54999d4f3cc90ec82a/; sid:902203763; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"b0:51:66:f5:42:9e:c4:7c:2d:58:23:37:a0:43:bb:23:98:67:24:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b05166f5429ec47c2d582337a043bb23986724ab/; sid:902203764; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"58:5c:be:8a:a2:b6:d5:01:07:c1:6d:29:a0:f9:e2:7d:a7:ad:51:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/585cbe8aa2b6d50107c16d29a0f9e27da7ad51d1/; sid:902203765; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"57:dc:c7:f7:fa:dc:43:04:6b:6a:1e:4a:2e:a0:fc:4c:55:8c:54:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57dcc7f7fadc43046b6a1e4a2ea0fc4c558c5464/; sid:902203766; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"39:99:30:29:44:cf:1b:07:ab:f8:27:00:87:71:c4:5d:cf:69:f6:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3999302944cf1b07abf827008771c45dcf69f6fe/; sid:902203767; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"63:b9:86:96:50:92:46:c6:b7:9a:c7:45:c0:e9:59:ac:0d:7b:93:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63b98696509246c6b79ac745c0e959ac0d7b9316/; sid:902203768; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"92:ef:e0:bb:e6:81:fb:be:3c:f5:f5:36:b0:05:6e:5f:08:fe:59:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92efe0bbe681fbbe3cf5f536b0056e5f08fe59b6/; sid:902203769; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"74:3e:0f:39:6d:6e:0b:ae:34:45:0c:82:16:63:3c:65:2b:c2:90:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/743e0f396d6e0bae34450c8216633c652bc2902a/; sid:902203770; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5b:73:79:d1:04:ce:79:02:1f:8b:5a:ba:c5:49:49:e1:8f:12:38:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b7379d104ce79021f8b5abac54949e18f123855/; sid:902203771; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"d2:1b:16:ed:88:94:e7:c2:3a:40:24:83:31:a6:37:f6:69:15:e0:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d21b16ed8894e7c23a40248331a637f66915e068/; sid:902203772; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"aa:cb:94:1b:4f:9c:4b:df:c1:1f:a4:24:af:c1:e9:7f:6e:e0:5e:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aacb941b4f9c4bdfc11fa424afc1e97f6ee05e8b/; sid:902203773; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"1c:60:15:f3:dd:25:f7:2b:91:78:82:79:e0:16:6d:6e:ad:7d:2c:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c6015f3dd25f72b91788279e0166d6ead7d2c94/; sid:902203774; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3f:47:68:28:cf:24:d1:fd:bd:17:6a:ce:93:d7:4a:66:6e:b7:0a:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f476828cf24d1fdbd176ace93d74a666eb70a16/; sid:902203775; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"90:b2:20:1f:73:e3:ed:1c:36:89:47:ae:ed:55:ec:19:67:00:1e:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90b2201f73e3ed1c368947aeed55ec1967001eb0/; sid:902203776; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b8:a0:e2:a0:2f:3f:73:d0:d0:c0:06:35:92:cb:df:48:1a:bf:03:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8a0e2a02f3f73d0d0c0063592cbdf481abf0316/; sid:902203777; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:91:7e:4c:4d:0a:6b:b7:dd:33:51:45:6f:12:94:8d:f7:45:bc:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23917e4c4d0a6bb7dd3351456f12948df745bce4/; sid:902203778; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0d:b4:db:5a:66:62:a6:a3:b5:3d:7a:1d:f4:bd:43:00:86:42:52:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0db4db5a6662a6a3b53d7a1df4bd4300864252a4/; sid:902203779; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"5d:bd:10:b5:50:39:fc:df:e8:e4:9a:ea:53:45:79:4d:4f:e2:19:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5dbd10b55039fcdfe8e49aea5345794d4fe2194f/; sid:902203780; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f5:92:62:b5:3a:42:ca:b3:8c:c6:14:f5:ab:41:54:8f:a2:96:a2:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f59262b53a42cab38cc614f5ab41548fa296a252/; sid:902203781; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"03:04:fa:2f:49:0e:14:5e:0e:0d:d4:33:61:41:a2:c5:1b:73:2c:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0304fa2f490e145e0e0dd4336141a2c51b732c08/; sid:902203782; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"ba:0f:36:f7:c8:d5:de:d0:ec:58:5d:57:0e:ce:03:02:25:26:9a:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba0f36f7c8d5ded0ec585d570ece030225269a11/; sid:902203783; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:e5:78:f1:e0:94:e3:a9:b0:20:cd:a1:dd:a6:f9:62:12:c5:23:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25e578f1e094e3a9b020cda1dda6f96212c52334/; sid:902203784; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"07:f5:0f:14:1a:76:00:9f:e7:9b:ab:2a:cc:7f:f5:59:88:7a:51:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07f50f141a76009fe79bab2acc7ff559887a5174/; sid:902203785; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1a:a8:63:af:b2:7b:9d:4f:9b:2b:1c:55:6e:ce:86:9e:01:79:e9:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1aa863afb27b9d4f9b2b1c556ece869e0179e909/; sid:902203786; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"7d:5a:71:8a:2a:41:d2:6a:15:e4:45:2d:a7:b2:cb:36:f3:39:e8:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d5a718a2a41d26a15e4452da7b2cb36f339e8f5/; sid:902203787; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"43:a3:78:a9:e7:c6:57:2e:55:79:e5:7a:0e:16:c4:c7:6f:08:92:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43a378a9e7c6572e5579e57a0e16c4c76f089288/; sid:902203788; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"77:5c:58:1b:08:96:48:0e:d3:29:89:20:83:62:68:ed:c3:08:53:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/775c581b0896480ed3298920836268edc30853db/; sid:902203789; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"d3:dd:5d:3e:e3:45:ee:6e:de:be:e2:e8:3d:e1:3d:c9:ad:98:81:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3dd5d3ee345ee6edebee2e83de13dc9ad98818d/; sid:902203790; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:fd:d9:0d:ed:f3:cc:5f:13:b6:9e:68:00:b2:79:d4:07:a2:d7:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02fdd90dedf3cc5f13b69e6800b279d407a2d750/; sid:902203791; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"86:99:8d:9d:df:a7:ad:bf:a2:6c:2c:a4:99:5f:e7:0f:dd:cf:18:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86998d9ddfa7adbfa26c2ca4995fe70fddcf18e4/; sid:902203792; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:6f:f1:e5:c1:97:ad:24:22:15:0f:6c:5e:15:9c:d2:52:0a:2e:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f6ff1e5c197ad2422150f6c5e159cd2520a2eaf/; sid:902203793; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"d7:c6:d4:8d:71:25:46:c5:5b:9a:da:70:c0:f8:2f:2e:34:ac:86:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7c6d48d712546c55b9ada70c0f82f2e34ac86c9/; sid:902203794; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a5:b4:20:6a:b6:6b:bd:e8:54:c2:28:1e:e1:52:f9:49:a1:b5:50:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5b4206ab66bbde854c2281ee152f949a1b550bc/; sid:902203795; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:25:c5:40:f9:83:25:a6:6a:60:69:a4:91:3b:1d:19:31:03:e2:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd25c540f98325a66a6069a4913b1d193103e296/; sid:902203796; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:78:3a:db:ed:bf:02:e3:60:d6:5e:ea:17:22:e8:aa:e7:7b:f7:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7783adbedbf02e360d65eea1722e8aae77bf77c/; sid:902203797; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"41:21:50:da:c6:5e:08:54:8f:cd:43:b1:ce:d8:85:76:96:c5:06:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/412150dac65e08548fcd43b1ced8857696c50630/; sid:902203798; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"10:36:27:16:74:fe:c5:d8:7c:85:5e:9a:81:b8:20:a8:43:f3:8d:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1036271674fec5d87c855e9a81b820a843f38d39/; sid:902203799; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"78:a0:e7:f7:3b:08:eb:b2:23:e1:e1:4a:ba:50:d6:7c:35:fd:2f:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78a0e7f73b08ebb223e1e14aba50d67c35fd2f0c/; sid:902203800; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"71:8e:06:df:0d:91:e4:07:aa:e8:05:3a:19:17:d2:52:6e:58:11:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/718e06df0d91e407aae8053a1917d2526e581130/; sid:902203801; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"46:da:b7:a0:86:be:27:7c:88:d4:ef:c7:b2:a0:87:47:5d:c3:09:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46dab7a086be277c88d4efc7b2a087475dc30949/; sid:902203802; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"47:ae:bd:b0:a0:83:6d:26:cd:34:2e:37:57:cf:a2:2e:eb:de:8b:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47aebdb0a0836d26cd342e3757cfa22eebde8baa/; sid:902203803; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"59:4d:3c:2a:38:71:d1:55:e4:9e:33:b0:97:e7:f4:d1:7f:a1:76:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/594d3c2a3871d155e49e33b097e7f4d17fa17655/; sid:902203804; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"39:a4:12:47:93:25:72:9f:5f:66:0e:85:a2:7f:35:9a:99:c5:b8:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39a412479325729f5f660e85a27f359a99c5b84c/; sid:902203805; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"0f:7f:0e:d6:f4:f0:aa:de:6e:d2:a1:cb:cd:87:df:da:65:75:28:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f7f0ed6f4f0aade6ed2a1cbcd87dfda657528f1/; sid:902203806; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazarCall malware distribution)"; tls.fingerprint:"3a:e3:c3:0d:9a:0a:79:c5:6d:ff:ad:bc:44:7a:fd:ec:e4:5e:eb:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ae3c30d9a0a79c56dffadbc447afdece45eebc4/; sid:902203807; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazarCall malware distribution)"; tls.fingerprint:"19:20:e1:29:2a:41:70:b9:e7:e3:d4:de:f9:c0:03:03:8d:6b:8e:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1920e1292a4170b9e7e3d4def9c003038d6b8ef4/; sid:902203808; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"3b:89:36:58:bd:45:dc:0e:09:a5:9b:ce:3d:e2:84:33:37:56:65:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b893658bd45dc0e09a59bce3de2843337566505/; sid:902203809; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazarCall C&C)"; tls.fingerprint:"4e:82:fd:e5:5c:2c:52:7c:1d:2c:3a:3a:5b:56:9e:e6:1c:4c:c3:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e82fde55c2c527c1d2c3a3a5b569ee61c4cc3a1/; sid:902203810; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"c8:68:65:82:d7:f6:4b:07:6a:a5:28:0d:ad:da:c5:61:0e:11:fb:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8686582d7f64b076aa5280daddac5610e11fb22/; sid:902203811; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:d9:62:46:96:5a:7f:d7:46:dd:44:54:be:7b:55:e4:5a:a4:83:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02d96246965a7fd746dd4454be7b55e45aa483a7/; sid:902203812; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"52:f6:4f:54:e2:3f:6a:c4:de:36:ea:6e:6e:d9:88:57:22:7c:bd:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52f64f54e23f6ac4de36ea6e6ed98857227cbd5e/; sid:902203813; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ca:44:6e:f0:1f:71:39:16:9b:6f:ef:ce:44:d9:4b:02:34:df:20:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca446ef01f7139169b6fefce44d94b0234df20e0/; sid:902203814; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"ab:3b:0d:4e:55:70:00:e7:9a:f4:35:4b:e2:39:16:87:3d:df:92:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab3b0d4e557000e79af4354be23916873ddf92f0/; sid:902203815; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"d3:ba:8f:88:67:32:af:ee:1c:c0:b6:9d:9a:3a:59:23:71:21:dc:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3ba8f886732afee1cc0b69d9a3a59237121dca7/; sid:902203816; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"c2:7d:13:14:aa:df:96:61:64:c5:55:fb:05:d7:87:5b:db:71:f0:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c27d1314aadf966164c555fb05d7875bdb71f003/; sid:902203817; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e6:9e:10:2d:d8:fc:10:96:5e:5b:24:dc:8e:dc:e3:9e:71:aa:9c:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e69e102dd8fc10965e5b24dc8edce39e71aa9cbf/; sid:902203818; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"f8:b0:43:c2:f0:c3:48:ee:54:e4:57:bb:bc:4d:e9:2e:7c:32:68:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8b043c2f0c348ee54e457bbbc4de92e7c326857/; sid:902203819; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"f2:c0:bc:0e:8a:a1:b9:58:5f:70:1d:b2:53:d8:41:dd:8e:30:ac:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2c0bc0e8aa1b9585f701db253d841dd8e30ac4d/; sid:902203820; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"0e:95:71:7d:24:ca:a2:18:bd:d1:d5:ba:35:87:67:7b:42:7a:89:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e95717d24caa218bdd1d5ba3587677b427a8933/; sid:902203821; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"52:a2:52:a7:14:d3:91:22:8c:4f:79:1b:4a:0b:fe:e1:3d:f3:6a:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52a252a714d391228c4f791b4a0bfee13df36a93/; sid:902203822; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"3f:5e:78:5b:93:24:17:d8:00:d4:80:ed:03:b2:92:ad:f2:1f:c9:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f5e785b932417d800d480ed03b292adf21fc913/; sid:902203823; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazarCall C&C)"; tls.fingerprint:"db:b4:e3:f0:b3:93:27:68:cc:fb:bb:73:84:d1:c0:95:c7:a4:f7:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbb4e3f0b3932768ccfbbb7384d1c095c7a4f7b1/; sid:902203824; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazarCall C&C)"; tls.fingerprint:"99:d9:53:42:24:01:7d:b5:bd:28:70:9a:e3:d0:6f:1f:89:fc:0e:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99d9534224017db5bd28709ae3d06f1f89fc0e48/; sid:902203825; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9f:8b:ab:c9:28:2d:3c:eb:83:3d:d6:33:34:e6:e6:54:04:23:bb:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f8babc9282d3ceb833dd63334e6e6540423bb74/; sid:902203826; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"24:07:aa:41:7a:9f:0b:f5:64:1f:bd:04:bb:9e:cb:47:9b:a8:46:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2407aa417a9f0bf5641fbd04bb9ecb479ba84626/; sid:902203827; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"cd:25:06:a1:93:2f:cc:b6:72:1b:ec:43:7b:6f:22:84:9c:39:28:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd2506a1932fccb6721bec437b6f22849c392859/; sid:902203828; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"a9:f9:5a:26:02:c4:82:0c:3f:94:88:24:1f:61:b5:c4:84:59:ae:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9f95a2602c4820c3f9488241f61b5c48459ae87/; sid:902203829; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1c:8f:24:d6:25:93:10:79:c2:1d:02:c1:a3:f4:0f:a7:c9:d9:55:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c8f24d625931079c21d02c1a3f40fa7c9d95550/; sid:902203830; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"61:3c:86:8a:52:bd:f1:c7:d4:d8:c6:e6:70:b0:1d:21:7e:d6:f4:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/613c868a52bdf1c7d4d8c6e670b01d217ed6f44a/; sid:902203831; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"c1:1a:6e:50:81:bc:8d:13:c9:48:3d:b2:af:04:f5:28:82:ec:1b:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c11a6e5081bc8d13c9483db2af04f52882ec1bf0/; sid:902203832; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"2c:5b:df:fc:53:5c:b0:8b:23:bc:ff:4e:cd:5d:d9:ec:b7:69:ba:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c5bdffc535cb08b23bcff4ecd5dd9ecb769badf/; sid:902203833; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"70:44:43:ff:be:38:0f:b0:b9:3d:12:21:1e:03:b3:d8:ef:ee:20:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/704443ffbe380fb0b93d12211e03b3d8efee20fb/; sid:902203834; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"5e:1f:1e:82:f2:34:de:08:9b:87:6c:3e:79:b1:ad:fe:ca:3b:d7:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e1f1e82f234de089b876c3e79b1adfeca3bd716/; sid:902203835; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"1c:e2:50:3b:89:ff:03:64:cb:65:9a:ef:e1:b4:69:e1:94:09:9d:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ce2503b89ff0364cb659aefe1b469e194099d2c/; sid:902203836; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"db:51:7c:5a:64:bd:5d:2c:4e:8e:08:49:21:ba:04:ad:28:20:63:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db517c5a64bd5d2c4e8e084921ba04ad28206391/; sid:902203837; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"a4:b0:d9:11:8e:83:69:88:76:90:90:a5:0f:84:0e:65:cc:3b:b1:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4b0d9118e836988769090a50f840e65cc3bb103/; sid:902203838; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"5f:a1:04:2e:38:d8:a3:b3:d3:a6:a6:4e:85:97:a8:4a:91:75:43:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fa1042e38d8a3b3d3a6a64e8597a84a91754357/; sid:902203839; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"8c:4f:2b:ee:35:97:16:94:ac:ee:60:3a:5e:16:6e:02:97:97:ed:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c4f2bee35971694acee603a5e166e029797ed40/; sid:902203840; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"40:c1:f6:88:7d:46:38:7b:18:5e:a9:3d:ef:fc:95:43:ab:6e:21:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40c1f6887d46387b185ea93deffc9543ab6e21fe/; sid:902203841; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"25:69:e5:5f:5f:42:54:19:42:da:cd:20:16:db:43:aa:39:18:7d:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2569e55f5f42541942dacd2016db43aa39187d1e/; sid:902203842; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c8:41:e4:71:e9:c0:c2:76:1f:5e:d5:1f:e8:ae:c2:d6:b0:8e:a8:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c841e471e9c0c2761f5ed51fe8aec2d6b08ea871/; sid:902203843; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"a6:0f:ad:8b:a7:ad:a0:9b:99:83:6e:22:39:a5:d9:09:42:2c:0f:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a60fad8ba7ada09b99836e2239a5d909422c0fa1/; sid:902203844; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"68:a9:c2:fb:c4:c7:ff:d0:1a:f5:32:02:f9:72:79:36:6b:0d:3b:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68a9c2fbc4c7ffd01af53202f97279366b0d3bae/; sid:902203845; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"40:bd:b6:64:eb:08:4b:0e:e4:32:6d:48:72:ce:df:13:e0:c3:b4:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40bdb664eb084b0ee4326d4872cedf13e0c3b4c0/; sid:902203846; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"77:94:30:20:f2:37:f2:f1:9e:ae:25:63:eb:4e:61:86:93:a5:b3:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77943020f237f2f19eae2563eb4e618693a5b37b/; sid:902203847; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BuerLoader C&C)"; tls.fingerprint:"53:be:8a:62:36:8d:11:ca:6d:90:51:bb:a2:89:4d:19:db:c1:3e:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53be8a62368d11ca6d9051bba2894d19dbc13e98/; sid:902203848; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9e:54:7a:78:47:11:8e:02:fb:82:ab:63:58:a1:e8:53:49:34:c9:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e547a7847118e02fb82ab6358a1e8534934c912/; sid:902203849; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ec:e6:be:6f:19:ff:b8:76:66:a8:66:00:c5:fd:b5:a5:cc:82:52:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ece6be6f19ffb87666a86600c5fdb5a5cc82520e/; sid:902203850; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:9f:a7:d7:fa:5d:c9:93:e0:82:33:71:c8:e3:74:e9:de:13:62:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f9fa7d7fa5dc993e0823371c8e374e9de136265/; sid:902203851; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"35:b9:d1:cf:1a:0d:23:fa:bf:3b:7d:41:92:99:e4:df:39:5f:8a:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35b9d1cf1a0d23fabf3b7d419299e4df395f8a1a/; sid:902203852; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"a6:4d:a9:de:2a:18:2f:c4:18:49:ff:c7:ed:8b:02:85:05:2a:30:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a64da9de2a182fc41849ffc7ed8b0285052a3031/; sid:902203853; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"64:05:ee:a1:c8:a1:f5:a4:36:c9:d3:b0:fc:53:0e:28:c5:cb:c1:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6405eea1c8a1f5a436c9d3b0fc530e28c5cbc10f/; sid:902203854; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"60:19:48:d4:49:5b:08:3f:24:dd:80:a2:97:76:ac:48:1b:0e:fb:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/601948d4495b083f24dd80a29776ac481b0efbd0/; sid:902203855; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"18:54:93:1d:f5:6d:04:1c:0a:33:74:4a:9b:01:11:e1:15:50:de:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1854931df56d041c0a33744a9b0111e11550deac/; sid:902203856; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9f:f0:68:90:76:72:09:8a:14:ff:91:61:92:d5:d6:a8:36:15:9e:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ff068907672098a14ff916192d5d6a836159e24/; sid:902203857; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3f:91:f6:bf:6f:18:08:e5:bd:12:e8:ed:58:b2:a0:fe:23:df:a3:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f91f6bf6f1808e5bd12e8ed58b2a0fe23dfa3aa/; sid:902203858; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"39:ee:7e:5a:a0:09:0a:1d:06:e4:a6:e2:e4:c0:a2:75:0f:55:b5:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39ee7e5aa0090a1d06e4a6e2e4c0a2750f55b5be/; sid:902203859; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"18:9f:94:dc:99:9d:22:a0:7e:08:14:de:34:a7:74:51:16:1a:71:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/189f94dc999d22a07e0814de34a77451161a7108/; sid:902203860; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ba:6a:bc:5d:16:5a:65:c5:0b:17:c9:aa:da:0d:8f:b2:80:ff:75:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba6abc5d165a65c50b17c9aada0d8fb280ff7586/; sid:902203861; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"0c:4b:08:8d:37:60:9b:99:60:fb:54:d6:b2:9a:23:f5:a3:46:2a:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c4b088d37609b9960fb54d6b29a23f5a3462abb/; sid:902203862; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"f5:c1:53:5a:67:2a:a6:26:47:a8:dd:b8:f3:5d:da:7b:e9:d6:83:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5c1535a672aa62647a8ddb8f35dda7be9d683c1/; sid:902203863; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"db:16:d1:8d:72:49:9c:0f:97:ed:98:34:29:e7:6d:77:06:7b:08:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db16d18d72499c0f97ed983429e76d77067b0867/; sid:902203864; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"00:4f:0b:18:d6:2f:53:29:a9:b7:f5:54:8c:87:40:9e:fd:40:85:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/004f0b18d62f5329a9b7f5548c87409efd408517/; sid:902203865; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"5b:86:f5:a2:ee:79:0c:df:db:bb:e1:aa:e1:4a:30:88:88:df:0e:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b86f5a2ee790cdfdbbbe1aae14a308888df0e4c/; sid:902203866; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"16:38:ad:39:9a:a7:5d:f8:3e:ef:61:3d:82:7f:54:9b:21:b5:43:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1638ad399aa75df83eef613d827f549b21b54331/; sid:902203867; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"76:73:af:21:a6:0a:70:f5:06:91:d9:b1:a0:7b:b5:17:c4:d9:a2:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7673af21a60a70f50691d9b1a07bb517c4d9a228/; sid:902203868; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"9f:79:b2:09:ec:51:39:07:87:18:96:63:79:6c:43:3d:90:5d:f5:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f79b209ec51390787189663796c433d905df50c/; sid:902203869; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e9:aa:08:bc:79:ed:d6:ad:35:a8:e0:6b:e5:76:44:f8:73:5d:8e:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9aa08bc79edd6ad35a8e06be57644f8735d8e1d/; sid:902203870; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"5b:29:ac:19:ae:b7:2d:28:7d:08:01:25:10:9f:51:33:0b:e0:7c:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b29ac19aeb72d287d080125109f51330be07c4d/; sid:902203871; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"db:3e:4f:8d:b9:0b:e1:2a:a8:38:16:91:90:d6:6e:af:0f:0d:dc:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db3e4f8db90be12aa838169190d66eaf0f0ddccf/; sid:902203872; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"bd:39:7b:05:41:a5:83:d8:6f:22:ef:87:78:b5:99:67:40:45:ca:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd397b0541a583d86f22ef8778b599674045ca5e/; sid:902203873; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"91:9b:f4:02:cf:40:4d:4c:ec:d9:b2:63:d3:19:a6:86:87:f3:60:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/919bf402cf404d4cecd9b263d319a68687f360a3/; sid:902203874; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"3e:fa:84:2c:76:1c:8d:da:5f:34:83:a2:b9:e3:47:85:2b:c7:a0:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3efa842c761c8dda5f3483a2b9e347852bc7a017/; sid:902203875; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"00:21:80:a5:97:24:ed:ba:9e:bd:19:c5:72:d4:c2:3f:ff:8a:78:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/002180a59724edba9ebd19c572d4c23fff8a78bc/; sid:902203876; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a8:0d:37:87:92:97:25:ec:fd:01:27:0b:e5:78:07:bf:bc:33:04:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a80d3787929725ecfd01270be57807bfbc3304e6/; sid:902203877; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"68:a7:5e:9a:ec:bc:1d:ab:86:c3:05:e4:b1:dd:60:bf:37:90:63:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68a75e9aecbc1dab86c305e4b1dd60bf379063b0/; sid:902203878; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e9:4d:a8:a3:d6:af:46:6b:e9:2a:0e:c0:23:a1:a8:a5:06:e2:c4:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e94da8a3d6af466be92a0ec023a1a8a506e2c446/; sid:902203879; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"ba:24:54:d5:22:ed:c4:91:35:50:5d:d3:fb:e8:71:ed:94:c7:bb:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba2454d522edc49135505dd3fbe871ed94c7bbbd/; sid:902203880; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:98:36:14:b6:0e:d7:f3:36:0a:7d:a3:9f:e4:5c:8d:1e:94:c7:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44983614b60ed7f3360a7da39fe45c8d1e94c76e/; sid:902203881; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"43:88:6c:9b:f4:29:3f:78:da:e0:b6:a1:1c:bc:3d:07:75:d0:2f:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43886c9bf4293f78dae0b6a11cbc3d0775d02f7d/; sid:902203882; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"cf:44:b5:75:fe:40:69:ba:dd:8f:1e:8a:13:55:cd:e6:f9:94:61:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf44b575fe4069badd8f1e8a1355cde6f99461a5/; sid:902203883; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"28:94:99:be:c9:0a:5c:76:77:4b:dc:4e:aa:6a:a6:ab:3d:12:ee:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/289499bec90a5c76774bdc4eaa6aa6ab3d12eef7/; sid:902203884; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"4a:d5:9d:3b:f6:43:ce:1b:35:da:6e:bc:b5:64:af:03:59:f0:f0:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ad59d3bf643ce1b35da6ebcb564af0359f0f036/; sid:902203885; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"32:66:0e:3b:48:7d:c5:8b:5f:97:db:12:49:2a:27:44:af:44:9a:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32660e3b487dc58b5f97db12492a2744af449a94/; sid:902203886; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"16:bd:34:8c:ab:33:88:07:9a:73:75:d7:7d:04:5d:ae:ce:8e:64:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16bd348cab3388079a7375d77d045daece8e6468/; sid:902203887; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"02:93:0a:bf:56:91:0a:b9:1d:3b:33:27:2e:13:e6:b2:5c:e5:aa:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02930abf56910ab91d3b33272e13e6b25ce5aadc/; sid:902203888; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"22:65:74:4f:51:47:da:60:98:28:af:cd:23:d0:58:af:d4:3a:68:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2265744f5147da609828afcd23d058afd43a6823/; sid:902203889; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"52:c8:81:ea:52:f0:d2:90:47:3b:6a:05:95:c1:94:2d:0c:87:85:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52c881ea52f0d290473b6a0595c1942d0c8785ec/; sid:902203890; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"db:65:29:fa:03:25:31:0d:9e:0b:74:f8:41:ec:ea:06:70:4d:8b:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db6529fa0325310d9e0b74f841ecea06704d8bed/; sid:902203891; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"35:35:5b:2b:06:da:6c:70:f5:fe:2f:c2:61:b9:7a:84:7b:02:6f:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35355b2b06da6c70f5fe2fc261b97a847b026f45/; sid:902203892; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"35:c3:ee:a1:2c:ba:d1:3e:91:60:8f:78:aa:e0:e6:19:f1:88:14:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35c3eea12cbad13e91608f78aae0e619f1881477/; sid:902203893; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"52:8d:9d:1d:ec:94:e3:46:b8:34:d4:20:b7:d8:aa:79:c9:dc:43:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/528d9d1dec94e346b834d420b7d8aa79c9dc434e/; sid:902203894; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a4:0e:c8:50:16:a0:8c:59:05:38:68:c7:9e:23:14:70:d4:5c:15:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a40ec85016a08c59053868c79e231470d45c1583/; sid:902203895; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"5d:f4:6a:0f:65:a8:99:03:1f:df:54:cb:cc:ec:1c:4a:88:a8:a9:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5df46a0f65a899031fdf54cbccec1c4a88a8a939/; sid:902203896; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"46:bd:92:97:85:9e:03:9f:95:33:98:0e:27:0f:fc:d3:c2:3b:02:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46bd9297859e039f9533980e270ffcd3c23b0295/; sid:902203897; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"44:c1:62:6e:49:64:d8:69:b5:28:26:1b:44:b0:f2:02:fd:89:98:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44c1626e4964d869b528261b44b0f202fd8998b0/; sid:902203898; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7e:ff:f0:9f:97:44:31:14:ea:57:e5:cf:34:09:47:6a:fc:63:06:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7efff09f97443114ea57e5cf3409476afc63064c/; sid:902203899; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f6:e3:84:42:d9:67:71:a0:65:47:78:0e:07:fc:2b:50:00:cb:b4:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6e38442d96771a06547780e07fc2b5000cbb419/; sid:902203900; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"81:77:aa:39:6c:1c:82:c0:ed:7d:d4:85:48:e1:36:47:de:85:3a:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8177aa396c1c82c0ed7dd48548e13647de853ac4/; sid:902203901; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"62:fe:a6:72:d5:bd:77:c0:a9:b6:e7:ea:50:2e:22:16:f0:77:1f:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62fea672d5bd77c0a9b6e7ea502e2216f0771f87/; sid:902203902; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:04:c8:ab:c1:5e:27:71:65:54:f3:b3:1d:2c:bd:a9:b7:5e:10:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d104c8abc15e27716554f3b31d2cbda9b75e10fc/; sid:902203903; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f3:9f:cb:33:09:f8:78:9d:ba:f1:5b:89:07:b2:cf:16:50:31:41:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f39fcb3309f8789dbaf15b8907b2cf1650314123/; sid:902203904; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"05:3f:6a:7a:8c:46:64:d1:0b:4e:2c:f9:0f:cf:0d:e0:ab:a4:ad:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/053f6a7a8c4664d10b4e2cf90fcf0de0aba4ad40/; sid:902203905; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"51:28:27:b9:db:3a:35:da:94:e5:80:7a:71:dd:f2:d1:28:54:d6:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/512827b9db3a35da94e5807a71ddf2d12854d615/; sid:902203906; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"15:f1:21:ad:9c:6e:43:0d:4a:46:5d:8f:f6:0d:1d:0e:61:66:d7:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15f121ad9c6e430d4a465d8ff60d1d0e6166d741/; sid:902203907; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"27:87:94:36:52:61:83:bf:04:7b:7f:b9:9e:64:f5:a3:49:09:3c:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27879436526183bf047b7fb99e64f5a349093c61/; sid:902203908; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"39:93:c8:5a:c1:78:8e:b4:e7:f3:6b:02:7f:13:5a:a6:55:57:3d:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3993c85ac1788eb4e7f36b027f135aa655573d82/; sid:902203909; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"50:c8:3b:60:06:ba:47:61:e2:60:aa:97:fa:95:f9:8f:90:85:ec:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/50c83b6006ba4761e260aa97fa95f98f9085ec82/; sid:902203910; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"0e:f7:5b:1c:b1:93:5a:d2:1b:bd:4f:d9:40:cc:b3:8d:e3:e6:97:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ef75b1cb1935ad21bbd4fd940ccb38de3e6976e/; sid:902203911; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"d1:8d:01:4f:cf:4e:4f:01:73:ed:93:d6:80:ce:77:45:0b:09:8b:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d18d014fcf4e4f0173ed93d680ce77450b098b65/; sid:902203912; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"cb:90:97:e2:7d:1c:16:ff:6d:05:74:c2:cc:e0:fc:0d:06:6f:0f:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb9097e27d1c16ff6d0574c2cce0fc0d066f0f8d/; sid:902203913; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"e1:47:32:19:da:d1:eb:82:d9:e4:3c:ab:21:bf:a6:78:9b:d6:1c:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1473219dad1eb82d9e43cab21bfa6789bd61c63/; sid:902203914; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"9e:b5:0f:5c:28:72:d0:ce:0a:41:06:48:d8:96:60:57:69:f9:1f:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9eb50f5c2872d0ce0a410648d896605769f91fce/; sid:902203915; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"ed:0c:16:6e:2a:f7:f7:98:74:a8:9c:97:d0:38:34:9e:10:e9:ce:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed0c166e2af7f79874a89c97d038349e10e9cea9/; sid:902203916; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"85:42:00:19:11:dd:97:5b:3f:49:3b:89:2e:8c:77:a4:53:e6:dc:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8542001911dd975b3f493b892e8c77a453e6dc13/; sid:902203917; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e8:74:e1:5c:eb:c2:e8:de:0a:1f:37:24:36:6d:84:1e:9d:b1:0a:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e874e15cebc2e8de0a1f3724366d841e9db10a0d/; sid:902203918; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"25:26:0c:f7:dc:0c:50:67:94:63:e0:a2:9a:4d:f5:b9:0f:82:9f:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25260cf7dc0c50679463e0a29a4df5b90f829fe8/; sid:902203919; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1f:84:15:dc:09:69:5f:a6:72:3d:2c:ed:33:50:f6:9f:bd:4c:6e:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f8415dc09695fa6723d2ced3350f69fbd4c6ed8/; sid:902203920; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a6:fe:c0:74:54:16:0a:fc:2e:a2:27:e4:28:5c:4b:fc:30:3c:83:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6fec07454160afc2ea227e4285c4bfc303c8317/; sid:902203921; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b8:6b:cc:f6:f9:bf:d7:82:f1:5e:2b:0d:25:2a:b3:de:59:3e:be:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b86bccf6f9bfd782f15e2b0d252ab3de593ebe4b/; sid:902203922; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"74:67:e9:d4:e4:66:f5:ff:f2:54:3d:0e:19:66:38:f2:a2:e2:36:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7467e9d4e466f5fff2543d0e196638f2a2e2365b/; sid:902203923; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:bf:be:77:d7:03:22:36:61:cb:ec:89:3b:4e:7c:b5:d9:ce:2c:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1bfbe77d703223661cbec893b4e7cb5d9ce2cd0/; sid:902203924; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9d:4f:2e:f6:65:a7:85:dc:c9:b9:a3:73:30:fa:b1:af:c9:30:ad:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d4f2ef665a785dcc9b9a37330fab1afc930ad05/; sid:902203925; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:c0:6b:bf:06:34:02:b6:68:f9:2d:01:4a:a3:a4:92:1b:25:66:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79c06bbf063402b668f92d014aa3a4921b256668/; sid:902203926; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d3:51:12:fd:83:56:06:f9:10:65:db:e2:04:3e:9a:2c:a2:bf:60:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d35112fd835606f91065dbe2043e9a2ca2bf60ba/; sid:902203927; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1a:4c:35:0a:d0:8f:5f:81:f5:a0:5b:67:d1:fa:d3:4b:1d:6c:1e:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a4c350ad08f5f81f5a05b67d1fad34b1d6c1e49/; sid:902203928; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:5a:45:f8:4f:05:73:48:52:e2:af:57:af:8e:ee:ff:bc:fc:c2:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/785a45f84f05734852e2af57af8eeeffbcfcc269/; sid:902203929; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7f:21:ad:9d:82:8b:fd:85:02:ab:3e:c8:96:eb:74:6d:71:0c:fe:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f21ad9d828bfd8502ab3ec896eb746d710cfe47/; sid:902203930; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"89:28:ff:0d:7b:5a:f2:01:97:4b:07:3f:e0:50:65:49:0e:88:13:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8928ff0d7b5af201974b073fe05065490e88138e/; sid:902203931; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:2d:ce:4f:d4:da:52:5d:cb:35:71:c1:e4:0f:68:4b:7c:a1:f7:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b92dce4fd4da525dcb3571c1e40f684b7ca1f7ff/; sid:902203932; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"69:b2:f2:34:92:2d:ea:d5:31:49:11:c1:5c:18:ca:f6:1a:66:6d:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69b2f234922dead5314911c15c18caf61a666db6/; sid:902203933; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"1e:17:a8:38:63:f2:bf:04:49:ab:e6:f4:b0:7b:08:0a:c7:19:7c:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e17a83863f2bf0449abe6f4b07b080ac7197c34/; sid:902203934; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c6:39:fc:88:cd:67:5f:76:e6:c2:9e:36:d2:14:7c:ee:31:55:32:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c639fc88cd675f76e6c29e36d2147cee31553238/; sid:902203935; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"5a:00:6b:5d:23:a5:bd:86:ca:c4:cc:a0:69:74:5b:c8:13:6b:04:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5a006b5d23a5bd86cac4cca069745bc8136b04a6/; sid:902203936; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"30:6a:40:fc:53:26:f0:13:94:6d:38:c8:fb:ed:45:2e:54:f5:90:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/306a40fc5326f013946d38c8fbed452e54f590cd/; sid:902203937; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d8:73:ec:4c:00:99:93:2e:dc:d9:4b:41:cb:ee:ab:70:04:8c:59:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d873ec4c0099932edcd94b41cbeeab70048c598a/; sid:902203938; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"55:2b:28:7c:36:d5:3f:9d:00:c2:61:51:09:0e:c6:d9:48:2e:a3:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/552b287c36d53f9d00c26151090ec6d9482ea341/; sid:902203939; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:32:25:b6:36:c3:41:1f:9e:7d:b0:eb:5d:5d:13:28:4f:52:9b:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/223225b636c3411f9e7db0eb5d5d13284f529b23/; sid:902203940; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot malware distribution)"; tls.fingerprint:"8c:8a:f1:72:31:66:75:2e:4d:2f:2c:e9:11:76:1a:e3:f9:61:bf:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c8af1723166752e4d2f2ce911761ae3f961bf3b/; sid:902203941; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (TrickBot malware distribution)"; tls.fingerprint:"07:7c:e4:41:45:38:fc:37:bd:1e:6b:1a:cf:8c:fe:dc:8c:26:f8:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/077ce4414538fc37bd1e6b1acf8cfedc8c26f813/; sid:902203942; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f4:c7:20:ff:5c:ec:e4:eb:36:9a:1d:24:54:d6:f6:23:4b:aa:f2:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f4c720ff5cece4eb369a1d2454d6f6234baaf2f5/; sid:902203943; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"97:32:f0:d1:34:71:69:e4:49:b7:ed:83:93:a3:07:b6:e6:50:98:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9732f0d1347169e449b7ed8393a307b6e65098cb/; sid:902203944; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7c:80:e0:2d:0d:e3:44:fe:45:db:dc:a5:00:eb:f4:ec:ca:dd:02:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c80e02d0de344fe45dbdca500ebf4eccadd0262/; sid:902203945; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1b:55:e7:1e:5b:64:1a:7b:a5:ea:0e:99:ee:0e:6f:19:80:ec:9a:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b55e71e5b641a7ba5ea0e99ee0e6f1980ec9ae3/; sid:902203946; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ca:2b:30:3e:e7:38:3e:1d:d7:12:5d:3a:42:b9:3e:d3:86:ee:ab:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca2b303ee7383e1dd7125d3a42b93ed386eeab4a/; sid:902203947; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8e:44:30:89:f6:c3:70:d2:39:05:3c:93:f9:d8:69:cd:60:52:44:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e443089f6c370d239053c93f9d869cd60524469/; sid:902203948; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"45:18:61:a4:64:eb:4f:85:17:d8:44:42:a6:19:48:98:39:f8:e4:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/451861a464eb4f8517d84442a619489839f8e491/; sid:902203949; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"72:e9:ae:f3:00:8a:5b:24:cd:04:8c:15:0d:b3:ec:6a:6b:f9:59:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72e9aef3008a5b24cd048c150db3ec6a6bf959d7/; sid:902203950; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"0b:d4:3c:31:26:de:1b:43:7f:75:ef:c2:83:44:f0:2f:06:80:13:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bd43c3126de1b437f75efc28344f02f06801333/; sid:902203951; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"8d:f6:77:e9:dd:1a:a9:28:92:c9:f6:b0:ba:d7:69:66:6f:79:75:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8df677e9dd1aa92892c9f6b0bad769666f797521/; sid:902203952; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CloudStalker C&C)"; tls.fingerprint:"f4:31:16:4b:5e:eb:0f:20:39:dc:68:4c:80:20:e6:c0:2c:3f:b5:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f431164b5eeb0f2039dc684c8020e6c02c3fb579/; sid:902203953; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7d:7f:4a:bd:d7:ba:8a:7a:8f:56:85:34:c9:4d:63:89:36:f3:53:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d7f4abdd7ba8a7a8f568534c94d638936f35399/; sid:902203954; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"24:5a:54:30:ee:b7:96:49:4c:44:08:ca:cc:ce:06:ff:6b:aa:de:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/245a5430eeb796494c4408caccce06ff6baaded6/; sid:902203955; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0c:56:c0:ab:db:89:a9:85:b7:3c:6c:26:eb:cf:f8:8d:bf:0b:04:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c56c0abdb89a985b73c6c26ebcff88dbf0b0464/; sid:902203956; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:4a:5a:ed:ca:ae:8a:11:0b:36:25:4b:8d:f7:a6:8c:1a:65:2c:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f74a5aedcaae8a110b36254b8df7a68c1a652c8c/; sid:902203957; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f2:ab:36:3c:c4:9b:b1:25:b0:a3:6c:a7:cf:d1:ba:8f:50:70:d9:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2ab363cc49bb125b0a36ca7cfd1ba8f5070d98e/; sid:902203958; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1c:0c:d2:c2:65:fe:ed:1d:7d:ad:51:02:95:72:3d:8b:d8:b2:95:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c0cd2c265feed1d7dad510295723d8bd8b29534/; sid:902203959; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"f5:44:c9:82:9f:10:7d:c7:cd:dc:0d:18:8c:a6:b1:21:b8:e6:37:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f544c9829f107dc7cddc0d188ca6b121b8e63726/; sid:902203960; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:04:01:a4:68:bd:fa:d2:0c:d6:16:6d:91:11:f7:b9:ed:3f:1b:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c90401a468bdfad20cd6166d9111f7b9ed3f1b9d/; sid:902203961; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"05:f5:5a:a7:51:b5:cf:4a:35:44:3b:83:49:e7:ea:5d:11:6d:ba:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05f55aa751b5cf4a35443b8349e7ea5d116dba64/; sid:902203962; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0a:f6:a3:2f:06:6a:5d:5a:82:9b:4f:0b:ae:9b:0d:38:56:28:7c:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0af6a32f066a5d5a829b4f0bae9b0d3856287c73/; sid:902203963; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"82:95:35:3c:13:fa:c9:75:dc:94:0b:df:e7:a5:bd:a3:80:a7:71:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8295353c13fac975dc940bdfe7a5bda380a7716f/; sid:902203964; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b6:42:c4:37:2c:c6:6b:e4:5b:ff:cc:4e:df:74:16:1e:1b:53:c9:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b642c4372cc66be45bffcc4edf74161e1b53c9c0/; sid:902203965; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:8e:ec:2f:38:47:c5:f3:b0:8d:91:42:f4:f6:ef:1e:b5:04:5e:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b98eec2f3847c5f3b08d9142f4f6ef1eb5045ef7/; sid:902203966; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9d:07:8c:3a:02:a0:c1:8a:5b:0c:fe:55:3d:ce:4b:e3:5c:0e:b0:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d078c3a02a0c18a5b0cfe553dce4be35c0eb0a2/; sid:902203967; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:43:f3:1e:05:8a:f8:95:db:fe:9e:47:f4:fe:e3:62:0f:4c:94:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b143f31e058af895dbfe9e47f4fee3620f4c94ab/; sid:902203968; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"60:6e:9d:7b:f5:a0:28:e1:b0:13:bf:8b:f3:6b:47:f7:13:d9:4b:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/606e9d7bf5a028e1b013bf8bf36b47f713d94b37/; sid:902203969; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d3:c4:86:b5:a0:bf:9a:41:d8:58:02:33:7e:22:18:15:b0:dc:90:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3c486b5a0bf9a41d85802337e221815b0dc9088/; sid:902203970; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"10:f8:c2:b1:f1:ea:10:c1:2f:7f:c1:56:f9:d5:84:c3:7d:3d:98:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10f8c2b1f1ea10c12f7fc156f9d584c37d3d98be/; sid:902203971; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"12:ab:0e:4e:2c:b1:fa:58:18:b3:a7:71:87:1f:14:41:86:40:4c:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12ab0e4e2cb1fa5818b3a771871f144186404cdc/; sid:902203972; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2a:1d:3b:3f:b3:21:29:24:13:b3:89:4d:08:6a:dd:f3:d6:84:ae:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a1d3b3fb321292413b3894d086addf3d684aeca/; sid:902203973; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"bb:da:52:d7:c5:69:f9:72:59:77:04:f1:dd:ff:bb:72:2a:79:8f:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbda52d7c569f972597704f1ddffbb722a798f8e/; sid:902203974; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:5a:11:84:69:c5:d7:fc:08:7d:35:54:14:20:86:42:66:e0:b3:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/925a118469c5d7fc087d35541420864266e0b323/; sid:902203975; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"35:96:2b:05:f2:de:fd:df:e3:34:a4:59:e9:12:21:9a:32:ed:32:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/35962b05f2defddfe334a459e912219a32ed325c/; sid:902203976; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware distribution)"; tls.fingerprint:"9e:3a:7e:6a:df:ae:7c:39:07:a5:24:59:63:27:b0:6a:b6:c1:4d:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e3a7e6adfae7c3907a524596327b06ab6c14d9d/; sid:902203977; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"bc:7e:e3:4c:c1:06:3a:83:55:83:cf:c9:a4:4c:ce:bc:9c:f2:f9:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc7ee34cc1063a835583cfc9a44ccebc9cf2f903/; sid:902203978; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d0:0b:96:37:37:a7:79:ff:fd:ea:3b:e7:80:4d:21:3f:8b:77:b7:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d00b963737a779fffdea3be7804d213f8b77b7b4/; sid:902203979; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8f:a4:f1:cb:96:bf:d2:50:40:cf:e4:e4:f0:95:d3:1c:5b:a0:a8:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fa4f1cb96bfd25040cfe4e4f095d31c5ba0a806/; sid:902203980; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7c:c7:34:5c:83:8f:4c:85:39:cf:52:0a:7e:29:25:5a:9a:46:93:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7cc7345c838f4c8539cf520a7e29255a9a469366/; sid:902203981; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:a2:1c:17:c6:c9:bf:8a:d2:af:e6:e3:53:38:5d:be:55:6e:69:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59a21c17c6c9bf8ad2afe6e353385dbe556e69ca/; sid:902203982; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"40:1d:df:f3:19:e4:6d:1a:25:06:6d:7d:ff:7e:45:c2:de:d8:c0:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/401ddff319e46d1a25066d7dff7e45c2ded8c0db/; sid:902203983; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"8d:c9:0d:59:f9:c7:92:74:f1:28:26:9f:eb:c4:a3:bc:3d:a0:79:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dc90d59f9c79274f128269febc4a3bc3da079d1/; sid:902203984; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f6:04:c8:0d:2c:60:cb:6b:9e:dc:c3:40:55:11:07:84:1a:74:b8:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f604c80d2c60cb6b9edcc340551107841a74b8cd/; sid:902203985; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"71:64:e7:a7:57:0c:ac:95:f4:ee:b6:c7:28:ba:37:dc:d1:23:ab:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7164e7a7570cac95f4eeb6c728ba37dcd123ab94/; sid:902203986; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"7b:57:9d:4d:c2:95:bb:c4:d6:05:70:a4:4a:77:e0:aa:8e:1d:75:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b579d4dc295bbc4d60570a44a77e0aa8e1d75db/; sid:902203987; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:a4:0d:f9:f2:da:46:32:51:2f:68:43:ec:e0:68:6a:79:71:35:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92a40df9f2da4632512f6843ece0686a79713564/; sid:902203988; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"60:7f:ed:0b:f5:2c:70:07:8f:67:2c:69:7d:b6:85:ed:e6:2f:6e:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/607fed0bf52c70078f672c697db685ede62f6ef5/; sid:902203989; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:d6:b4:30:f1:48:d5:24:93:fe:c0:17:3a:ce:29:58:46:12:eb:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78d6b430f148d52493fec0173ace29584612ebb4/; sid:902203990; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"b7:31:87:68:1b:57:3a:5c:ed:e7:82:a8:1d:85:7b:76:56:0a:d2:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b73187681b573a5cede782a81d857b76560ad2b0/; sid:902203991; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c1:38:91:59:e5:e3:e9:54:d9:d7:1b:13:e3:c5:d4:d8:5c:46:cd:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1389159e5e3e954d9d71b13e3c5d4d85c46cde8/; sid:902203992; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bf:56:37:89:af:16:0d:4a:32:c9:01:d8:3f:f6:b6:58:12:8c:03:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf563789af160d4a32c901d83ff6b658128c0327/; sid:902203993; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"eb:ee:b7:38:6a:ab:76:9f:4d:b8:8f:ec:70:32:2e:ac:46:a2:29:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebeeb7386aab769f4db88fec70322eac46a229b0/; sid:902203994; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"49:4d:4b:a8:55:f1:3e:46:a4:90:fb:92:12:e2:14:b8:81:4b:fe:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/494d4ba855f13e46a490fb9212e214b8814bfea1/; sid:902203995; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:74:46:77:21:6a:12:e4:cc:4e:d0:90:f8:2f:a3:59:c3:21:76:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1744677216a12e4cc4ed090f82fa359c3217613/; sid:902203996; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"61:c2:14:d6:16:d9:a8:0a:18:77:4d:77:ed:bc:99:27:6e:b6:30:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61c214d616d9a80a18774d77edbc99276eb630a1/; sid:902203997; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ca:c6:21:8f:d6:81:83:c9:5a:65:c8:9e:e7:d0:b9:47:47:d7:fa:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cac6218fd68183c95a65c89ee7d0b94747d7faa8/; sid:902203998; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"10:e7:05:48:dd:ee:0f:f5:3f:e6:22:47:bf:1b:70:75:a3:0a:a5:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10e70548ddee0ff53fe62247bf1b7075a30aa5a2/; sid:902203999; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b7:13:68:c8:77:9f:24:88:98:88:f4:6e:14:54:2f:55:82:97:81:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b71368c8779f24889888f46e14542f55829781a4/; sid:902204000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ce:8a:33:9e:03:1b:96:16:86:95:8a:64:5e:4b:47:66:fb:5c:62:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce8a339e031b961686958a645e4b4766fb5c621d/; sid:902204001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"77:16:9e:38:c7:83:ce:cb:65:a7:d1:e8:90:79:45:5d:dd:1a:4e:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77169e38c783cecb65a7d1e89079455ddd1a4ef6/; sid:902204002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ad:1b:fc:7d:f1:e8:72:81:6f:8b:06:67:33:45:ae:da:51:48:cd:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad1bfc7df1e872816f8b06673345aeda5148cdf3/; sid:902204003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ae:4e:28:15:55:55:78:6c:41:d4:94:ac:de:64:9c:08:7b:14:1e:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae4e28155555786c41d494acde649c087b141ef4/; sid:902204004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bb:82:a5:fe:49:ee:29:a7:21:80:7b:06:63:7e:c7:14:1b:62:22:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb82a5fe49ee29a721807b06637ec7141b622278/; sid:902204005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AceRAT C&C)"; tls.fingerprint:"56:a5:df:00:77:0d:cf:c1:05:ad:5f:48:9c:9a:d4:77:b9:0d:f7:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56a5df00770dcfc105ad5f489c9ad477b90df7d6/; sid:902204006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"83:9b:99:01:72:b7:34:9f:5d:5b:a8:04:58:47:b6:84:9c:e7:df:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/839b990172b7349f5d5ba8045847b6849ce7dff9/; sid:902204007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d9:14:52:83:92:41:8a:85:ab:4f:93:87:7a:d5:86:fe:cf:b1:a1:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d914528392418a85ab4f93877ad586fecfb1a140/; sid:902204008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"77:65:39:48:2e:a8:31:7c:8c:59:df:9e:05:2b:bb:b1:fc:cc:d5:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/776539482ea8317c8c59df9e052bbbb1fcccd507/; sid:902204009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:01:89:bf:37:d0:83:19:63:30:28:a8:73:87:ae:f0:5a:4c:a3:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/020189bf37d08319633028a87387aef05a4ca38c/; sid:902204010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"07:36:53:ab:d6:79:06:9d:73:26:60:34:95:51:a2:44:6e:cd:66:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/073653abd679069d732660349551a2446ecd6656/; sid:902204011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:c9:e3:4b:9f:00:e3:c9:2e:18:e8:37:b3:d2:f8:77:1b:0f:31:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bc9e34b9f00e3c92e18e837b3d2f8771b0f3180/; sid:902204012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"74:2e:6b:cc:97:7a:03:c5:12:d0:5a:4a:1c:0b:10:e0:81:be:90:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/742e6bcc977a03c512d05a4a1c0b10e081be901f/; sid:902204013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"9b:e4:71:70:09:5e:6c:82:8f:cb:a7:47:20:5c:12:be:0f:87:07:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9be47170095e6c828fcba747205c12be0f8707ec/; sid:902204014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"16:00:4c:0b:55:75:45:3b:3b:ff:2f:a2:f2:33:28:fc:26:70:c5:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16004c0b5575453b3bff2fa2f23328fc2670c50d/; sid:902204015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"46:de:9d:8b:9e:02:63:74:01:bd:24:28:06:ba:18:dc:fa:c8:fd:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46de9d8b9e02637401bd242806ba18dcfac8fd4e/; sid:902204016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:4f:1c:be:c1:03:28:67:33:e4:bd:67:0f:41:a3:f5:52:3f:92:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b24f1cbec103286733e4bd670f41a3f5523f9236/; sid:902204017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:03:05:3b:b7:9f:22:56:15:3b:17:31:4d:58:72:4a:07:f1:33:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf03053bb79f2256153b17314d58724a07f133b1/; sid:902204018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:1d:d2:f7:92:02:0a:bd:27:be:bc:92:a3:22:67:63:c2:97:93:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f51dd2f792020abd27bebc92a3226763c29793ac/; sid:902204019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"95:49:95:cb:4b:df:d0:dd:61:26:a3:bb:79:b9:5c:9e:05:1a:a1:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/954995cb4bdfd0dd6126a3bb79b95c9e051aa139/; sid:902204020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ae:fd:27:3b:b6:cf:4b:f2:ce:87:f6:1a:a8:2a:2c:55:bf:a7:14:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aefd273bb6cf4bf2ce87f61aa82a2c55bfa7146e/; sid:902204021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:38:b9:d3:ed:9c:98:8c:b1:2d:3e:f3:8c:0f:b9:73:74:2d:5a:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2238b9d3ed9c988cb12d3ef38c0fb973742d5a3d/; sid:902204022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:ce:92:86:98:f7:a4:87:4a:77:41:73:4d:03:22:f3:df:e0:fb:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70ce928698f7a4874a7741734d0322f3dfe0fb1a/; sid:902204023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"1e:9a:bb:af:e2:65:e8:59:49:f1:55:be:ee:44:c0:ce:89:3d:be:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e9abbafe265e85949f155beee44c0ce893dbe8e/; sid:902204024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"11:84:ae:b6:47:0a:b8:e1:49:ed:b1:0b:d8:16:13:fa:87:1f:7e:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1184aeb6470ab8e149edb10bd81613fa871f7ef6/; sid:902204025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d1:6d:b8:ec:f1:6e:60:46:8b:d0:19:9b:07:c8:40:08:b0:07:f4:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d16db8ecf16e60468bd0199b07c84008b007f496/; sid:902204026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"4c:d5:9b:2f:cd:10:70:2a:00:1c:19:0a:3b:01:d8:84:71:d7:53:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cd59b2fcd10702a001c190a3b01d88471d7533e/; sid:902204027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"36:93:5f:20:83:b0:88:81:07:d9:bc:09:7c:24:c6:2a:c5:c6:c8:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36935f2083b0888107d9bc097c24c62ac5c6c8c4/; sid:902204028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"6b:ce:07:f1:a1:11:83:9e:ad:9d:39:47:ca:f0:1c:94:f7:f6:54:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bce07f1a111839ead9d3947caf01c94f7f65493/; sid:902204029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"1b:f3:86:bc:c5:b9:92:f9:60:f9:a1:40:1f:c3:2b:ea:a7:37:97:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1bf386bcc5b992f960f9a1401fc32beaa737978b/; sid:902204030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"c1:f1:a2:6e:4d:7e:2a:fe:19:c6:90:a0:81:32:89:89:de:44:0f:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1f1a26e4d7e2afe19c690a081328989de440fc6/; sid:902204031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"76:5d:95:3e:a8:36:74:76:91:96:d3:0d:e3:29:b1:b9:a3:21:fa:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/765d953ea83674769196d30de329b1b9a321fa4a/; sid:902204032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"9e:e1:e2:f7:25:0a:98:73:49:b3:ce:13:7c:b7:33:b0:fe:5e:51:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ee1e2f7250a987349b3ce137cb733b0fe5e51c8/; sid:902204033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"3d:a7:37:37:90:6c:66:5a:36:b1:9e:eb:e0:31:4f:5c:97:c4:6c:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3da73737906c665a36b19eebe0314f5c97c46c12/; sid:902204034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8c:70:43:84:14:b6:57:1d:7e:3b:18:d0:70:a7:3b:6b:05:d7:06:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c70438414b6571d7e3b18d070a73b6b05d706ae/; sid:902204035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c0:91:00:e7:c4:09:e1:e5:d9:a2:b4:ab:9d:20:70:4b:6a:3f:29:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c09100e7c409e1e5d9a2b4ab9d20704b6a3f2932/; sid:902204036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"db:c6:8d:66:ea:e2:83:37:b8:90:c2:f5:8b:b6:fc:2a:bd:09:bd:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbc68d66eae28337b890c2f58bb6fc2abd09bd50/; sid:902204037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0f:01:69:eb:7b:f6:6b:ae:d5:07:97:6a:31:d6:80:54:e2:41:f7:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f0169eb7bf66baed507976a31d68054e241f7d5/; sid:902204038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ab:19:89:b9:d8:6f:6b:6b:be:ee:3e:7d:04:cd:eb:fd:0d:89:75:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab1989b9d86f6b6bbeee3e7d04cdebfd0d897561/; sid:902204039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ce:67:2e:4f:99:47:e5:d5:b7:c9:ca:3f:a8:38:bc:d6:e5:1f:fc:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce672e4f9947e5d5b7c9ca3fa838bcd6e51ffcf2/; sid:902204040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"68:b5:79:ac:dc:07:90:f1:e6:27:ab:17:79:b7:a5:da:2a:60:37:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68b579acdc0790f1e627ab1779b7a5da2a60378e/; sid:902204041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0d:5b:2a:16:b4:5c:c9:82:0f:84:26:73:28:f6:a3:0a:81:2d:00:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d5b2a16b45cc9820f84267328f6a30a812d0042/; sid:902204042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:d4:52:87:8d:7d:d9:02:85:d2:b1:0a:50:d4:28:13:41:cf:3a:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ed452878d7dd90285d2b10a50d4281341cf3aba/; sid:902204043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:0c:11:8b:69:5c:9c:91:1e:60:38:88:5c:ba:37:17:32:ec:05:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f50c118b695c9c911e6038885cba371732ec05ba/; sid:902204044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"67:65:06:06:60:f3:bc:a1:15:77:5f:e4:42:6a:13:52:d8:ee:4a:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6765060660f3bca115775fe4426a1352d8ee4af9/; sid:902204045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e2:dd:65:fc:90:a9:29:68:99:4d:76:c1:ec:49:2a:4d:8f:d1:cc:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2dd65fc90a92968994d76c1ec492a4d8fd1ccee/; sid:902204046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"43:6b:7c:fa:7e:2f:a5:fd:57:ea:db:1c:4e:63:f0:14:28:3a:be:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/436b7cfa7e2fa5fd57eadb1c4e63f014283abec1/; sid:902204047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fb:1b:7d:d8:d8:27:10:11:c9:d5:79:46:6b:21:2b:b5:4f:6c:a7:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb1b7dd8d8271011c9d579466b212bb54f6ca7e6/; sid:902204048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:46:43:54:2a:d5:08:3b:7b:98:e8:26:c3:67:32:f3:6e:cb:f1:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/124643542ad5083b7b98e826c36732f36ecbf1be/; sid:902204049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"5b:38:9e:fe:b4:ad:f5:e0:70:45:f9:c8:eb:41:43:ea:e0:0d:ae:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b389efeb4adf5e07045f9c8eb4143eae00dae78/; sid:902204050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"de:46:9d:74:34:2c:b8:e7:72:01:6e:fb:c0:84:95:e4:3b:7b:75:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de469d74342cb8e772016efbc08495e43b7b75de/; sid:902204051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fe:b1:61:fa:ce:11:eb:16:8a:bf:38:95:15:4a:12:09:53:b1:fd:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/feb161face11eb168abf3895154a120953b1fd87/; sid:902204052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"b0:45:37:49:7c:48:2e:28:3f:41:f8:2c:02:ec:81:c6:7f:43:22:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b04537497c482e283f41f82c02ec81c67f43224c/; sid:902204053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:05:0c:4a:44:be:78:89:8c:56:c4:06:84:c6:f8:55:14:a5:8c:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78050c4a44be78898c56c40684c6f85514a58cb3/; sid:902204054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"47:88:87:50:b5:6a:10:52:63:fd:a9:0a:5a:87:35:4c:41:f4:3b:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47888750b56a105263fda90a5a87354c41f43ba7/; sid:902204055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b7:4f:34:39:2c:6d:36:a7:10:2f:ad:9b:72:d8:ba:a1:e7:f6:fc:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b74f34392c6d36a7102fad9b72d8baa1e7f6fc41/; sid:902204056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c2:7a:c6:f1:cf:c1:54:59:28:ec:bd:ff:fa:69:6d:e3:c2:7a:42:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c27ac6f1cfc1545928ecbdfffa696de3c27a42af/; sid:902204057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7c:8f:bb:4f:62:13:6b:1f:2a:d1:81:51:72:a0:a8:c1:79:d2:b7:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c8fbb4f62136b1f2ad1815172a0a8c179d2b722/; sid:902204058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fd:fb:8c:76:6b:53:ba:00:d8:1c:88:d6:5d:73:bb:c2:f4:0a:03:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdfb8c766b53ba00d81c88d65d73bbc2f40a0357/; sid:902204059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f5:59:45:67:de:0a:fd:12:99:75:b0:93:a0:f1:88:1e:f9:38:3b:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5594567de0afd129975b093a0f1881ef9383b3f/; sid:902204060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"75:36:93:73:88:8f:ec:b5:a1:e0:cc:4f:cd:c4:6d:bf:c1:b1:9a:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75369373888fecb5a1e0cc4fcdc46dbfc1b19a41/; sid:902204061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:4f:e2:4d:90:e3:11:d4:53:88:16:ce:6f:28:79:c5:ef:22:89:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc4fe24d90e311d4538816ce6f2879c5ef228910/; sid:902204062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d3:41:04:26:72:8a:10:5c:50:6b:63:1a:e5:a9:04:8e:d2:10:df:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3410426728a105c506b631ae5a9048ed210df46/; sid:902204063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"54:3b:6a:df:0c:67:94:e2:7e:18:1f:8f:12:81:70:0e:00:f6:97:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/543b6adf0c6794e27e181f8f1281700e00f697a0/; sid:902204064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9b:61:ca:62:82:4b:5a:79:0c:ef:04:a3:44:bf:95:7a:5d:46:7d:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b61ca62824b5a790cef04a344bf957a5d467d17/; sid:902204065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"73:52:fe:07:1b:95:e7:26:c1:c5:ff:cb:f2:58:c4:d2:91:eb:20:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7352fe071b95e726c1c5ffcbf258c4d291eb20fe/; sid:902204066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"32:f1:8c:5b:f6:c1:d3:31:c3:4b:78:e4:00:2b:d5:1a:a3:37:b7:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32f18c5bf6c1d331c34b78e4002bd51aa337b7fd/; sid:902204067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8d:ae:a5:2a:3a:b6:c0:c2:1a:c9:92:a7:63:4d:00:06:80:b4:7c:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8daea52a3ab6c0c21ac992a7634d000680b47c94/; sid:902204068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"53:95:12:b4:5a:6b:0e:13:c5:73:3e:3e:f5:0a:d7:ab:66:95:e1:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/539512b45a6b0e13c5733e3ef50ad7ab6695e1bf/; sid:902204069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5c:af:10:5f:ba:f4:05:9b:bc:51:6a:52:4d:9e:ba:3d:2f:a8:da:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5caf105fbaf4059bbc516a524d9eba3d2fa8da9a/; sid:902204070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"cd:92:7a:05:cf:cb:7b:e3:27:52:eb:c0:22:b6:6e:67:b7:da:69:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd927a05cfcb7be32752ebc022b66e67b7da69df/; sid:902204071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"18:f0:ae:d8:c8:31:84:27:e3:b7:aa:69:94:dd:ea:59:e6:37:45:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/18f0aed8c8318427e3b7aa6994ddea59e637456e/; sid:902204072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0b:51:89:9b:5c:c5:9f:22:2b:e2:a6:d0:fb:ea:35:a9:13:61:86:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b51899b5cc59f222be2a6d0fbea35a913618616/; sid:902204073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:ab:6e:29:1b:b5:d7:f2:1b:60:be:c9:51:7a:15:0c:f6:d1:c4:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92ab6e291bb5d7f21b60bec9517a150cf6d1c4f5/; sid:902204074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"0d:43:48:c0:a5:f3:82:5a:13:50:f8:ef:86:e0:e8:5e:91:a1:8d:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d4348c0a5f3825a1350f8ef86e0e85e91a18d91/; sid:902204075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"70:8c:15:56:7f:05:16:f3:a3:a4:b1:c9:8c:1a:b0:03:75:91:f8:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/708c15567f0516f3a3a4b1c98c1ab0037591f82f/; sid:902204076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"47:a0:2a:f8:d6:65:c8:71:0f:c4:31:b4:52:cc:ba:46:fa:17:29:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47a02af8d665c8710fc431b452ccba46fa172984/; sid:902204077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"de:2a:e7:13:ec:a7:05:0f:1b:5a:a1:e9:f8:8f:2b:f0:35:11:76:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de2ae713eca7050f1b5aa1e9f88f2bf0351176f7/; sid:902204078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:25:e4:a3:ee:19:39:af:ce:7f:01:78:1c:04:ba:c2:e3:1c:54:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a25e4a3ee1939afce7f01781c04bac2e31c5430/; sid:902204079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"8f:b8:31:fa:2b:9e:ed:40:e8:b4:18:ea:ab:8e:15:60:23:ef:6b:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fb831fa2b9eed40e8b418eaab8e156023ef6b8c/; sid:902204080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"20:2f:6d:7d:9a:cb:c1:93:6c:72:d8:b7:6a:25:ac:01:a0:18:33:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/202f6d7d9acbc1936c72d8b76a25ac01a018331a/; sid:902204081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"a0:8e:a0:d1:bf:17:67:2f:47:8c:90:d0:b4:9c:f6:f6:80:97:7c:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a08ea0d1bf17672f478c90d0b49cf6f680977c70/; sid:902204082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:e3:79:9a:f1:c7:db:6e:28:ef:c9:41:ac:da:1a:17:88:d7:4a:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eee3799af1c7db6e28efc941acda1a1788d74a47/; sid:902204083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"02:04:df:a0:93:e2:7b:72:f1:61:7c:ce:a6:07:6b:cc:e5:d0:a4:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0204dfa093e27b72f1617ccea6076bcce5d0a482/; sid:902204084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"19:ff:cd:b0:4e:53:dc:98:bd:96:f7:6f:45:7d:ec:3f:5f:63:41:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19ffcdb04e53dc98bd96f76f457dec3f5f634157/; sid:902204085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"46:2e:d4:06:26:79:36:13:c7:39:dd:04:56:a9:8d:bb:ad:10:a8:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/462ed40626793613c739dd0456a98dbbad10a818/; sid:902204086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"07:09:95:18:db:33:23:3e:68:6d:3b:44:ba:06:6c:7a:41:c9:40:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07099518db33233e686d3b44ba066c7a41c94099/; sid:902204087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"94:61:eb:51:bf:2b:ae:4f:d9:ba:15:23:93:54:ac:2d:77:1e:83:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9461eb51bf2bae4fd9ba15239354ac2d771e8372/; sid:902204088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"73:6c:e3:2a:a0:38:d7:23:89:17:71:80:1c:b7:ed:5c:76:a9:6a:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/736ce32aa038d723891771801cb7ed5c76a96aa2/; sid:902204089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"67:5e:b5:15:bc:1c:3c:50:cd:ce:9a:e9:09:0b:af:ba:44:db:b4:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/675eb515bc1c3c50cdce9ae9090bafba44dbb4be/; sid:902204090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"3a:f6:1c:2d:7b:1e:30:84:9c:d1:dc:9f:14:bb:da:e2:bf:1b:2d:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3af61c2d7b1e30849cd1dc9f14bbdae2bf1b2d53/; sid:902204091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"73:14:ef:4b:ed:b9:c0:a5:b8:5a:6b:3e:9c:9d:63:cf:82:e2:07:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7314ef4bedb9c0a5b85a6b3e9c9d63cf82e207bb/; sid:902204092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"37:6b:ba:56:e4:ea:4a:f8:77:8e:1d:c8:00:83:3a:7e:66:c7:09:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/376bba56e4ea4af8778e1dc800833a7e66c70923/; sid:902204093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:9e:de:fe:6b:bd:8b:f1:89:a0:47:6e:6b:8a:aa:28:24:17:05:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c99edefe6bbd8bf189a0476e6b8aaa28241705c1/; sid:902204094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7d:e0:1a:6d:63:00:c5:f9:af:c4:7f:bf:45:f2:d5:30:c1:d0:c9:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7de01a6d6300c5f9afc47fbf45f2d530c1d0c9de/; sid:902204095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"69:80:ef:37:67:03:a3:a8:b4:2f:c7:a8:61:f6:30:45:f3:9f:0e:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6980ef376703a3a8b42fc7a861f63045f39f0e20/; sid:902204096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6a:f1:2e:34:3b:64:35:2e:19:a7:79:a1:a5:04:fc:e6:72:1e:a8:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6af12e343b64352e19a779a1a504fce6721ea8e7/; sid:902204097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"97:69:2e:bd:03:cf:fb:41:ed:bc:13:f3:1e:57:d3:ff:01:ca:a2:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97692ebd03cffb41edbc13f31e57d3ff01caa249/; sid:902204098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5d:bb:15:33:b0:40:67:0c:bd:cc:7d:a4:af:53:0d:d9:89:6e:11:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5dbb1533b040670cbdcc7da4af530dd9896e1185/; sid:902204099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"45:bd:0d:3b:c9:2e:c0:4a:4e:c6:4d:63:8e:18:63:b0:6d:3a:8d:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45bd0d3bc92ec04a4ec64d638e1863b06d3a8d4a/; sid:902204100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3d:93:3d:d9:2b:be:6a:a0:f4:fc:05:5a:a5:d6:72:60:44:02:56:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d933dd92bbe6aa0f4fc055aa5d67260440256b0/; sid:902204101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7e:8d:6e:cd:36:19:0c:85:64:80:85:94:d7:05:52:85:1d:e3:f6:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e8d6ecd36190c8564808594d70552851de3f6e8/; sid:902204102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"31:10:10:a3:40:d9:ee:b2:11:c8:6d:55:35:ef:0a:5d:68:b7:15:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/311010a340d9eeb211c86d5535ef0a5d68b7154c/; sid:902204103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"64:73:2f:98:95:df:35:62:7b:a0:82:8d:64:c6:d2:7a:71:d9:e4:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64732f9895df35627ba0828d64c6d27a71d9e419/; sid:902204104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:be:5e:97:33:b0:b9:f5:c4:ea:c5:ff:c3:89:9c:b6:40:18:c0:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bbe5e9733b0b9f5c4eac5ffc3899cb64018c015/; sid:902204105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"e0:4f:0b:86:55:bd:73:2e:d8:62:5e:ed:26:cd:f1:94:17:08:2b:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e04f0b8655bd732ed8625eed26cdf19417082b1e/; sid:902204106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"8e:33:a7:24:2a:64:05:78:03:16:21:c6:9d:e7:cf:31:eb:ff:ec:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e33a7242a640578031621c69de7cf31ebffec63/; sid:902204107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"15:74:23:2b:01:3f:f0:8e:47:71:df:9b:70:fd:b1:7e:38:f2:56:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1574232b013ff08e4771df9b70fdb17e38f25695/; sid:902204108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c0:cd:4f:71:a9:c1:92:0a:a4:d2:d0:71:1f:d5:55:be:1e:1b:de:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0cd4f71a9c1920aa4d2d0711fd555be1e1bde8c/; sid:902204109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"84:9f:be:aa:22:29:71:31:0d:a7:6f:aa:d5:63:1e:bb:46:27:65:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/849fbeaa222971310da76faad5631ebb462765dd/; sid:902204110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"bc:b6:5e:65:8a:6d:21:d8:2a:7d:1e:b1:d4:e4:e7:26:86:a7:02:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcb65e658a6d21d82a7d1eb1d4e4e72686a7028a/; sid:902204111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ea:91:1d:f5:7d:64:f2:fa:b3:d0:aa:d9:b5:15:7e:c7:e7:dc:ae:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea911df57d64f2fab3d0aad9b5157ec7e7dcaebd/; sid:902204112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c8:ba:3c:1b:9d:ae:95:39:63:78:00:7f:1b:b5:56:37:9c:1a:1a:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8ba3c1b9dae95396378007f1bb556379c1a1afa/; sid:902204113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:b1:9b:f4:34:11:8d:75:ad:c1:4c:66:97:3c:fd:e3:e4:da:fc:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59b19bf434118d75adc14c66973cfde3e4dafcea/; sid:902204114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:ba:11:bc:18:d2:6a:31:fa:a7:62:70:29:9d:45:6a:a6:2b:c4:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cba11bc18d26a31faa76270299d456aa62bc44c/; sid:902204115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9b:73:cd:49:f8:4f:44:ef:b0:1c:c5:b0:f4:5d:63:6c:02:9b:36:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b73cd49f84f44efb01cc5b0f45d636c029b36e3/; sid:902204116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"ee:73:d4:ae:1d:aa:d8:68:ad:d7:28:ad:ae:3d:58:48:7a:4d:67:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee73d4ae1daad868add728adae3d58487a4d67d1/; sid:902204117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"21:78:0e:91:02:4a:45:a1:b8:06:7a:f4:c0:90:3d:65:7c:30:d9:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21780e91024a45a1b8067af4c0903d657c30d922/; sid:902204118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"81:3a:f3:8c:cb:46:96:1c:68:c2:59:46:73:d4:b2:ae:7e:6d:09:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/813af38ccb46961c68c2594673d4b2ae7e6d0991/; sid:902204119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ee:4b:05:2c:62:6b:1c:c9:13:75:88:34:96:26:d1:07:98:b2:00:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee4b052c626b1cc9137588349626d10798b2000b/; sid:902204120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e5:e6:e4:7e:7d:0b:6a:28:28:f9:83:60:47:75:e0:57:9b:cf:00:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e5e6e47e7d0b6a2828f983604775e0579bcf0002/; sid:902204121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"56:67:05:fc:52:97:6b:71:a9:ab:48:c4:10:8f:62:d9:87:09:9f:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/566705fc52976b71a9ab48c4108f62d987099fc0/; sid:902204122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"26:61:bc:b4:bf:73:8b:ee:64:5b:c9:88:1b:0d:48:a6:6f:77:81:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2661bcb4bf738bee645bc9881b0d48a66f778167/; sid:902204123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"4c:d7:fe:36:f5:5c:c8:ea:d2:3e:76:4e:8c:0e:ac:47:67:e7:52:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cd7fe36f55cc8ead23e764e8c0eac4767e752ba/; sid:902204124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"97:c0:ea:f8:95:ca:d2:c9:ab:a3:31:1f:e3:85:83:09:e9:b3:9c:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97c0eaf895cad2c9aba3311fe3858309e9b39cfa/; sid:902204125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0b:23:d6:17:5e:f8:ff:6c:8e:e8:b2:24:51:4a:10:81:f9:8e:ec:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b23d6175ef8ff6c8ee8b224514a1081f98eecac/; sid:902204126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:d1:29:4d:f9:44:2a:b0:3d:50:74:5c:bf:87:9b:ba:77:7a:09:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9d1294df9442ab03d50745cbf879bba777a09cd/; sid:902204127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"02:45:ea:cb:18:c9:a5:6a:ae:76:15:33:38:19:17:85:97:d0:62:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0245eacb18c9a56aae7615333819178597d062f1/; sid:902204128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"8e:af:58:22:3b:10:a7:c1:44:b2:0c:ca:d3:d3:b1:b0:6c:6d:09:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8eaf58223b10a7c144b20ccad3d3b1b06c6d0970/; sid:902204129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"49:0e:cc:e4:ca:e8:a0:b1:ea:80:7b:b6:d3:66:3c:2d:08:f7:c6:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/490ecce4cae8a0b1ea807bb6d3663c2d08f7c659/; sid:902204130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0b:f2:be:de:35:68:a3:2c:45:6c:dc:dd:bc:10:46:35:b2:19:6c:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0bf2bede3568a32c456cdcddbc104635b2196c95/; sid:902204131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"7f:23:d0:bf:55:7e:5b:c5:8c:b7:81:da:34:a5:48:67:69:18:3d:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f23d0bf557e5bc58cb781da34a5486769183db8/; sid:902204132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"47:7d:f7:4e:79:b9:30:fe:aa:f9:2b:f5:04:a2:29:ea:ec:f8:eb:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/477df74e79b930feaaf92bf504a229eaecf8eb25/; sid:902204133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"0f:a7:37:e6:06:9d:65:0d:70:14:f0:1e:be:67:9f:47:b6:28:8a:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0fa737e6069d650d7014f01ebe679f47b6288a93/; sid:902204134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"3f:78:31:d6:dd:20:bd:d6:d9:95:93:ca:e7:f3:98:71:8d:a0:4e:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f7831d6dd20bdd6d99593cae7f398718da04ef6/; sid:902204135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"44:f7:f3:c8:42:a6:f6:d0:be:d5:dc:fe:cf:34:65:17:9b:2a:8c:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44f7f3c842a6f6d0bed5dcfecf3465179b2a8cd3/; sid:902204136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"ff:42:c4:d8:52:ed:4e:c1:2c:76:eb:ed:ef:25:59:42:54:b7:6f:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff42c4d852ed4ec12c76ebedef25594254b76f0d/; sid:902204137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"25:ab:5c:ec:7a:d9:8e:df:30:61:f7:f9:f6:72:7b:a4:fb:81:0b:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25ab5cec7ad98edf3061f7f9f6727ba4fb810b90/; sid:902204138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1f:04:28:ee:84:ba:ca:e5:bd:a9:53:db:e1:c8:89:46:af:e0:83:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f0428ee84bacae5bda953dbe1c88946afe08346/; sid:902204139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"01:ce:96:0c:b7:e7:9b:8a:9f:87:94:54:5b:ed:24:93:4c:8d:4c:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01ce960cb7e79b8a9f8794545bed24934c8d4c69/; sid:902204140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:3c:b6:6e:d1:fb:ee:0f:68:fe:cd:a8:d2:57:d9:6b:8d:e6:23:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b3cb66ed1fbee0f68fecda8d257d96b8de623cf/; sid:902204141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0b:53:10:23:d7:2a:b3:13:47:46:67:ef:f0:d0:a1:b3:3d:da:f1:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b531023d72ab313474667eff0d0a1b33ddaf127/; sid:902204142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0e:c9:45:5d:6b:40:b2:01:79:1e:d8:17:00:3f:3d:cc:23:2b:28:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ec9455d6b40b201791ed817003f3dcc232b28b3/; sid:902204143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"4d:86:d1:63:00:c8:2f:a5:3d:30:62:90:91:2e:c4:af:e2:74:9f:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d86d16300c82fa53d306290912ec4afe2749f36/; sid:902204144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7a:4e:7e:c9:0f:7b:39:0d:d8:2b:67:ec:cb:a8:e7:75:42:0b:76:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a4e7ec90f7b390dd82b67eccba8e775420b7645/; sid:902204145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ce:e8:ba:23:db:82:bc:5f:4c:18:83:09:43:aa:57:a5:a4:5b:3d:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cee8ba23db82bc5f4c18830943aa57a5a45b3da2/; sid:902204146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"48:87:f0:1e:3b:9a:b0:aa:94:4c:c5:fe:4c:c7:cd:7c:59:5c:66:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4887f01e3b9ab0aa944cc5fe4cc7cd7c595c6659/; sid:902204147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"67:c0:18:27:98:55:6a:6a:0e:97:d9:d2:a3:1f:6e:38:1f:3c:db:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67c0182798556a6a0e97d9d2a31f6e381f3cdb5d/; sid:902204148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ae:0e:9c:61:66:5a:89:41:ca:72:f2:7a:bc:05:01:f7:4d:8f:3e:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae0e9c61665a8941ca72f27abc0501f74d8f3e88/; sid:902204149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8b:1c:37:e3:03:43:ca:2e:cb:e1:7b:59:06:95:9b:aa:43:0f:ec:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b1c37e30343ca2ecbe17b5906959baa430fecc2/; sid:902204150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"8b:cf:4b:42:9d:a1:a4:2b:07:7d:8e:73:50:a5:b4:c6:fa:0b:be:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bcf4b429da1a42b077d8e7350a5b4c6fa0bbe2a/; sid:902204151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"e3:c5:98:93:af:55:09:9a:aa:f2:f0:b1:bb:bc:51:d5:f5:b6:92:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3c59893af55099aaaf2f0b1bbbc51d5f5b69296/; sid:902204152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"89:44:24:2f:a3:fc:77:af:ba:95:50:98:12:a9:17:67:4f:fe:a6:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8944242fa3fc77afba95509812a917674ffea6e6/; sid:902204153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d7:31:63:33:1b:6b:f5:12:a1:e8:f7:4c:e3:40:03:7c:54:97:98:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d73163331b6bf512a1e8f74ce340037c549798fc/; sid:902204154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"39:d7:75:11:81:d9:b7:af:45:0e:3e:25:b9:bb:92:0f:50:af:b5:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39d7751181d9b7af450e3e25b9bb920f50afb5dc/; sid:902204155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d3:83:30:c0:98:84:74:49:67:1c:08:46:d3:1a:f5:d9:da:00:79:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d38330c098847449671c0846d31af5d9da0079ff/; sid:902204156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f2:1e:8f:cf:83:ba:4b:78:2a:49:8f:1c:79:3f:dd:97:91:6c:6f:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f21e8fcf83ba4b782a498f1c793fdd97916c6ff1/; sid:902204157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ea:b6:d2:ce:07:f6:a2:17:82:32:2a:1c:93:8d:13:d6:db:04:38:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eab6d2ce07f6a21782322a1c938d13d6db0438d9/; sid:902204158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"4c:b7:81:6f:23:82:14:b3:50:70:ce:97:2e:cb:6d:38:8a:91:33:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cb7816f238214b35070ce972ecb6d388a913302/; sid:902204159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"c6:cf:08:84:52:03:a4:b1:fd:a6:67:d3:41:0a:b4:3b:9e:36:85:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6cf08845203a4b1fda667d3410ab43b9e368526/; sid:902204160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f7:9c:19:e9:65:cf:8f:50:66:60:91:40:84:8c:63:2e:b8:7d:33:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f79c19e965cf8f5066609140848c632eb87d337c/; sid:902204161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"05:34:e8:25:a4:16:c1:45:ef:06:43:fa:f0:a5:47:dc:31:6a:12:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0534e825a416c145ef0643faf0a547dc316a1297/; sid:902204162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"21:d0:1a:5a:57:d6:b7:7b:75:90:95:aa:9e:38:e7:aa:f0:db:9c:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21d01a5a57d6b77b759095aa9e38e7aaf0db9c04/; sid:902204163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a5:c9:57:a6:f5:a2:5e:4e:f5:47:d9:6a:41:84:a5:bf:a1:90:a6:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5c957a6f5a25e4ef547d96a4184a5bfa190a6c3/; sid:902204164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"07:8a:90:84:6e:1c:bd:6f:f2:e8:8f:7c:16:c7:a4:67:b8:58:f9:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/078a90846e1cbd6ff2e88f7c16c7a467b858f957/; sid:902204165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:cc:67:70:b2:61:de:7d:cf:48:02:29:e1:42:61:fc:c9:a4:55:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6cc6770b261de7dcf480229e14261fcc9a4551c/; sid:902204166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"05:62:46:aa:19:b9:60:f5:94:36:3c:21:b9:0d:f5:e7:60:66:da:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/056246aa19b960f594363c21b90df5e76066da3e/; sid:902204167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"41:bc:67:d1:c6:6f:84:50:16:c3:ad:ee:74:d5:99:5b:11:a4:c7:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41bc67d1c66f845016c3adee74d5995b11a4c77f/; sid:902204168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"6d:56:8e:22:bb:bf:43:91:04:f6:d3:84:2c:de:8a:b7:41:15:c4:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d568e22bbbf439104f6d3842cde8ab74115c472/; sid:902204169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"45:c5:2f:e7:22:77:ad:0a:ec:85:d0:6d:8d:33:5d:c7:e5:80:6c:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45c52fe72277ad0aec85d06d8d335dc7e5806c20/; sid:902204170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"49:6b:5d:55:92:9e:4d:f8:b6:d5:56:5c:30:10:0e:0d:27:c0:d0:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/496b5d55929e4df8b6d5565c30100e0d27c0d069/; sid:902204171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4f:dc:c6:2b:db:0a:66:c1:e3:2a:df:81:d9:9e:94:09:de:5d:76:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4fdcc62bdb0a66c1e32adf81d99e9409de5d767f/; sid:902204172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"34:dc:88:2d:28:b3:c1:7f:f3:df:9a:6b:be:40:61:45:44:9f:28:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34dc882d28b3c17ff3df9a6bbe406145449f288e/; sid:902204173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"0b:3a:18:9a:cf:9b:aa:b0:b3:d0:37:c7:63:ee:c8:14:72:19:03:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b3a189acf9baab0b3d037c763eec8147219037c/; sid:902204174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b6:ed:27:4a:89:07:4c:5b:d5:02:37:cd:5d:72:f2:11:ba:37:ed:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6ed274a89074c5bd50237cd5d72f211ba37edbd/; sid:902204175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"24:3c:88:c0:ec:b2:da:0f:20:1e:5e:12:39:08:03:5a:f0:55:db:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/243c88c0ecb2da0f201e5e123908035af055db34/; sid:902204176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"4c:af:3f:1c:c0:08:63:25:ff:30:06:b7:a2:64:a3:2d:2d:93:d3:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4caf3f1cc0086325ff3006b7a264a32d2d93d37a/; sid:902204177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"5d:64:57:87:98:fe:79:2c:1f:f4:c6:71:d3:c0:8d:b4:26:dc:55:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d64578798fe792c1ff4c671d3c08db426dc55ca/; sid:902204178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"99:25:d0:f7:7a:bb:06:4b:70:13:6c:1a:f6:6c:14:93:21:e5:c4:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9925d0f77abb064b70136c1af66c149321e5c42b/; sid:902204179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fb:46:98:64:3f:78:db:e5:89:1d:dd:32:29:c7:f8:51:0a:b8:ce:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb4698643f78dbe5891ddd3229c7f8510ab8ce2b/; sid:902204180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ae:bf:c4:25:91:6f:7d:41:19:d8:fa:01:6e:1b:18:fb:6c:24:e0:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aebfc425916f7d4119d8fa016e1b18fb6c24e04f/; sid:902204181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"95:27:b7:3e:be:ca:c9:eb:af:ce:58:9a:9f:f9:5c:18:e3:c7:25:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9527b73ebecac9ebafce589a9ff95c18e3c72565/; sid:902204182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d6:b0:b4:84:41:6a:8f:1a:76:df:3f:cf:9f:9d:46:42:5a:2e:72:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6b0b484416a8f1a76df3fcf9f9d46425a2e727b/; sid:902204183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"5b:cf:eb:c8:5e:95:1c:56:84:fa:b6:00:4d:a8:e4:52:83:ee:2c:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5bcfebc85e951c5684fab6004da8e45283ee2c2f/; sid:902204184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"45:a8:f1:de:a5:5d:94:7d:fb:d7:44:77:69:c1:58:2b:dd:ae:8e:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/45a8f1dea55d947dfbd7447769c1582bddae8e14/; sid:902204185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"71:9c:ce:11:b3:f0:ea:6f:1e:0f:ff:0f:b4:34:ec:bb:6c:aa:35:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/719cce11b3f0ea6f1e0fff0fb434ecbb6caa3540/; sid:902204186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"df:f6:ef:75:f8:f5:c8:8c:1a:4b:49:fd:29:99:d8:58:d0:9c:17:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dff6ef75f8f5c88c1a4b49fd2999d858d09c17b0/; sid:902204187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"2a:70:72:bd:26:a5:ad:be:ce:9a:a4:6e:62:c2:3a:a0:c0:99:41:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2a7072bd26a5adbece9aa46e62c23aa0c099419a/; sid:902204188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ae:5a:23:a8:83:6a:3c:9e:91:a8:cb:4c:51:0c:29:ad:4f:76:c2:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae5a23a8836a3c9e91a8cb4c510c29ad4f76c286/; sid:902204189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"3f:9f:f2:33:18:6c:f4:81:38:a9:01:90:b0:af:58:01:40:40:64:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f9ff233186cf48138a90190b0af5801404064f8/; sid:902204190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"fa:ab:eb:0c:d9:bf:15:b9:2a:63:20:b3:5b:bc:e8:6e:a8:a1:d0:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/faabeb0cd9bf15b92a6320b35bbce86ea8a1d0de/; sid:902204191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"30:fe:2b:51:ec:25:d0:d0:d5:5d:c8:d5:ca:e0:e7:99:ec:11:de:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30fe2b51ec25d0d0d55dc8d5cae0e799ec11de0c/; sid:902204192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"dd:5c:ba:59:93:74:d8:b5:88:98:6b:eb:eb:99:a0:c5:5b:9e:1c:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd5cba599374d8b588986bebeb99a0c55b9e1c4b/; sid:902204193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"df:a3:07:f4:b6:2f:f4:30:3b:42:4a:90:15:b6:16:67:89:df:7d:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfa307f4b62ff4303b424a9015b6166789df7dde/; sid:902204194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:32:1d:d6:67:6d:83:1d:aa:9b:c7:37:06:8e:22:22:00:f7:61:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7321dd6676d831daa9bc737068e222200f76115/; sid:902204195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"5a:db:38:72:bf:6c:63:f6:59:64:52:c5:2a:27:5b:41:aa:46:98:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5adb3872bf6c63f6596452c52a275b41aa4698cb/; sid:902204196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ab:6b:83:04:b7:13:0f:3d:fb:59:1f:40:ea:21:76:69:44:7b:9e:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab6b8304b7130f3dfb591f40ea217669447b9e4d/; sid:902204197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:f4:9c:54:cf:57:4b:9d:c3:e9:76:3e:85:85:00:3d:a0:31:b6:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3f49c54cf574b9dc3e9763e8585003da031b6bf/; sid:902204198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"53:4a:69:9d:a7:73:37:a8:c4:b7:6c:55:48:2a:50:38:cc:b6:17:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/534a699da77337a8c4b76c55482a5038ccb61702/; sid:902204199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"83:84:1b:27:ff:3a:40:66:b9:c1:67:51:33:26:eb:7d:3f:e5:7d:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83841b27ff3a4066b9c167513326eb7d3fe57db9/; sid:902204200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a0:3d:01:09:ff:27:ce:c2:0d:ec:a3:48:fd:4b:91:6a:31:68:a8:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a03d0109ff27cec20deca348fd4b916a3168a818/; sid:902204201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"82:4e:1d:88:6f:9c:04:85:79:ca:e1:82:3f:02:a5:98:19:a9:ab:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/824e1d886f9c048579cae1823f02a59819a9aba9/; sid:902204202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"06:12:5e:1e:4f:fd:77:5a:55:36:3a:61:5d:42:32:f3:6d:0e:22:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06125e1e4ffd775a55363a615d4232f36d0e223d/; sid:902204203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"77:6b:2a:57:37:a0:da:80:b9:84:c7:88:3e:d2:62:42:55:84:ac:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/776b2a5737a0da80b984c7883ed262425584ac7f/; sid:902204204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:6c:c8:c2:f4:ea:22:63:7c:2c:a1:24:62:ec:7d:a8:50:70:64:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/926cc8c2f4ea22637c2ca12462ec7da850706439/; sid:902204205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"15:1c:05:0b:ee:d5:89:50:5a:9a:8d:5c:cb:b4:a3:79:96:e9:2d:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/151c050beed589505a9a8d5ccbb4a37996e92d17/; sid:902204206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:31:ad:fa:0a:ac:3f:0c:7e:48:06:c4:b1:2d:d1:59:9e:52:f2:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b331adfa0aac3f0c7e4806c4b12dd1599e52f271/; sid:902204207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"64:8f:54:2b:07:00:eb:77:73:45:e1:19:b7:58:1e:aa:d7:5b:e1:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/648f542b0700eb777345e119b7581eaad75be123/; sid:902204208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:43:06:e4:da:10:3a:33:6e:76:88:d9:3f:e6:3d:bd:ac:89:49:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b14306e4da103a336e7688d93fe63dbdac89494b/; sid:902204209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"97:1b:ce:99:49:54:36:12:21:ba:fb:42:ae:fe:1a:74:e1:87:eb:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/971bce994954361221bafb42aefe1a74e187ebd4/; sid:902204210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6578ed18da0aa745926a909e681dcca56eecfb1/; sid:902204211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:9d:a6:bb:a2:4d:23:db:0a:f6:75:e4:31:22:5c:d5:96:f1:85:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/279da6bba24d23db0af675e431225cd596f185bb/; sid:902204212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bb:82:1a:be:67:3a:fa:8d:36:1f:f1:82:31:2c:9f:ef:3f:3a:a7:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb821abe673afa8d361ff182312c9fef3f3aa754/; sid:902204213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"43:9b:d7:27:93:00:82:01:64:d6:0e:fb:ff:01:6f:3b:51:ec:57:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/439bd7279300820164d60efbff016f3b51ec57ac/; sid:902204214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"86:7a:5f:ce:1b:f8:23:c5:87:78:8d:d6:8e:cd:ba:f4:e2:d1:c2:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/867a5fce1bf823c587788dd68ecdbaf4e2d1c25d/; sid:902204215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"38:38:41:42:8d:e1:5c:4c:b6:7b:d4:14:d0:7c:4c:95:68:82:b1:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/383841428de15c4cb67bd414d07c4c956882b1af/; sid:902204216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"0c:43:24:49:77:d2:81:39:83:38:b0:84:60:8d:20:e6:7e:66:58:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c43244977d281398338b084608d20e67e665818/; sid:902204217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8f:d4:77:fe:79:ea:a9:2a:13:bb:01:60:6d:81:00:bf:19:1b:57:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fd477fe79eaa92a13bb01606d8100bf191b5771/; sid:902204218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c8:57:16:8c:86:62:ce:35:63:06:61:a7:dc:b4:c9:62:be:03:d0:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c857168c8662ce35630661a7dcb4c962be03d06b/; sid:902204219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"93:6e:54:0a:f3:a2:cc:dc:95:f8:51:b5:ff:c4:14:b4:0c:60:b0:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/936e540af3a2ccdc95f851b5ffc414b40c60b09c/; sid:902204220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"ca:f1:3f:64:b4:7f:52:3d:8d:31:9a:fa:2b:55:d9:d6:32:fe:6f:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/caf13f64b47f523d8d319afa2b55d9d632fe6f13/; sid:902204221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"38:02:23:8d:f4:51:33:d9:f4:01:e3:2c:81:30:99:c2:7a:29:68:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3802238df45133d9f401e32c813099c27a2968c6/; sid:902204222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"14:0b:7a:09:d2:44:8d:68:8a:b2:56:9c:ee:7e:93:2d:ce:7c:c6:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/140b7a09d2448d688ab2569cee7e932dce7cc6dc/; sid:902204223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"fa:31:0d:e6:99:57:a0:73:ac:b8:32:19:eb:ea:d3:d3:d8:c2:b3:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa310de69957a073acb83219ebead3d3d8c2b380/; sid:902204224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"f7:60:ee:f1:7a:05:6d:0d:bc:a8:ff:a7:61:4a:c2:96:59:97:f8:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f760eef17a056d0dbca8ffa7614ac2965997f8eb/; sid:902204225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"1d:51:5b:db:77:1d:ad:48:0d:b0:77:e2:14:ac:7d:e9:47:e5:93:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d515bdb771dad480db077e214ac7de947e593ff/; sid:902204226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:1a:47:4a:59:a1:6e:53:6e:8b:69:21:27:5a:58:3c:66:98:f6:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a1a474a59a16e536e8b6921275a583c6698f6ec/; sid:902204227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"be:74:1a:50:45:c0:ca:95:f8:b7:86:83:d0:04:e4:a3:45:62:e3:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be741a5045c0ca95f8b78683d004e4a34562e3a9/; sid:902204228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"1a:ae:3d:a8:a4:99:44:a8:54:ec:12:c9:46:65:bc:e7:08:f4:89:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1aae3da8a49944a854ec12c94665bce708f48904/; sid:902204229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"fa:db:52:40:cc:9b:72:83:c4:36:a6:03:96:43:d9:59:3d:d4:3a:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fadb5240cc9b7283c436a6039643d9593dd43af1/; sid:902204230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"90:74:7d:75:6c:9f:29:6f:0b:a1:a3:a1:e8:b6:00:68:13:ea:70:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90747d756c9f296f0ba1a3a1e8b6006813ea70c8/; sid:902204231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"11:cd:13:8f:46:db:00:91:c0:b8:5b:16:b2:d0:e8:8a:f4:43:28:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11cd138f46db0091c0b85b16b2d0e88af44328ad/; sid:902204232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"af:1a:9c:46:11:65:0d:ce:08:bb:90:6a:e6:1a:be:b5:8f:76:a1:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af1a9c4611650dce08bb906ae61abeb58f76a170/; sid:902204233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"51:1c:df:e4:eb:4b:2a:a1:0b:6e:4e:15:3c:7f:8d:2f:de:0b:aa:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/511cdfe4eb4b2aa10b6e4e153c7f8d2fde0baaa0/; sid:902204234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BazaLoader C&C)"; tls.fingerprint:"14:d0:b9:02:ca:ad:60:43:5a:d3:c3:2a:02:5a:24:c1:f9:79:29:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14d0b902caad60435ad3c32a025a24c1f97929be/; sid:902204235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:53:df:3f:b3:62:84:32:10:3f:78:f9:b5:a1:56:15:7e:89:5e:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e753df3fb3628432103f78f9b5a156157e895ebd/; sid:902204236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:69:38:e8:5f:a4:94:c1:a2:f1:ae:f7:7d:65:a6:31:fd:7d:0b:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/786938e85fa494c1a2f1aef77d65a631fd7d0b6f/; sid:902204237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e3:57:b5:7c:8a:c4:10:c5:09:6c:3b:6a:09:c4:28:d7:eb:2d:8e:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e357b57c8ac410c5096c3b6a09c428d7eb2d8e8b/; sid:902204238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4c:b8:31:03:c4:63:05:22:35:b6:4c:3b:26:56:04:96:24:70:83:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4cb83103c463052235b64c3b2656049624708352/; sid:902204239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ae:77:c0:1a:08:0b:66:5a:b3:9b:d8:1e:f2:18:f0:59:68:61:1b:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae77c01a080b665ab39bd81ef218f05968611b49/; sid:902204240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"31:e1:9f:ee:08:ae:91:aa:e7:f2:54:79:79:e2:d5:7f:13:bd:a3:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/31e19fee08ae91aae7f2547979e2d57f13bda383/; sid:902204241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:b9:11:fd:af:55:03:b8:44:c9:b4:91:23:f0:6e:1b:65:74:f3:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80b911fdaf5503b844c9b49123f06e1b6574f327/; sid:902204242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"6c:8a:c0:9c:e6:68:d2:a4:b7:f3:c6:58:a5:ee:ce:30:65:02:5d:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c8ac09ce668d2a4b7f3c658a5eece3065025def/; sid:902204243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"6a:c9:eb:9a:04:4a:60:cf:67:1a:9d:dc:6c:dd:86:98:4c:1e:6a:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ac9eb9a044a60cf671a9ddc6cdd86984c1e6a74/; sid:902204244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:d0:ec:38:b7:d9:aa:07:e1:1f:68:35:98:7f:70:9d:3e:ea:37:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38d0ec38b7d9aa07e11f6835987f709d3eea3791/; sid:902204245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"a1:01:71:87:c8:52:e8:7b:30:08:68:03:4e:8a:ea:b1:a2:1f:73:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1017187c852e87b300868034e8aeab1a21f73f3/; sid:902204246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"20:5c:56:cc:37:03:f8:63:05:64:93:69:91:c3:68:ca:fd:9f:b2:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/205c56cc3703f8630564936991c368cafd9fb216/; sid:902204247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"ab:5e:96:61:95:6a:d1:cd:7c:3e:d0:9a:ae:f0:bf:55:49:d4:bd:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab5e9661956ad1cd7c3ed09aaef0bf5549d4bd9b/; sid:902204248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"27:e0:f8:8c:5e:c5:c4:1e:6a:03:0e:70:4c:d0:4f:b4:61:c8:71:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27e0f88c5ec5c41e6a030e704cd04fb461c871d0/; sid:902204249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"1a:22:6f:6a:a6:7b:f8:b8:00:f4:bf:db:17:a0:62:00:bd:c8:17:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1a226f6aa67bf8b800f4bfdb17a06200bdc817e8/; sid:902204250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b5:8a:d6:94:78:b0:0e:97:62:0a:70:81:8f:8c:f3:9b:b2:71:ba:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b58ad69478b00e97620a70818f8cf39bb271ba76/; sid:902204251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c8:bf:d0:12:db:4b:42:d4:92:f0:3e:53:d3:4f:6e:70:bf:c0:e8:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8bfd012db4b42d492f03e53d34f6e70bfc0e813/; sid:902204252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2b:21:b1:82:07:a4:fd:80:b4:a5:a6:28:d6:64:e5:25:24:f4:41:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b21b18207a4fd80b4a5a628d664e52524f441bb/; sid:902204253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:26:c5:d3:6a:ee:e3:89:b7:e8:37:b6:b7:9d:15:7b:57:c5:fe:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd26c5d36aeee389b7e837b6b79d157b57c5fe1f/; sid:902204254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6b:08:fa:26:e4:11:a2:da:f9:37:7b:7d:a2:f2:c7:0d:8d:91:ad:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b08fa26e411a2daf9377b7da2f2c70d8d91ade7/; sid:902204255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f9:f4:75:50:1c:6d:2b:11:02:a4:97:eb:1c:3d:52:c9:0b:8e:00:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9f475501c6d2b1102a497eb1c3d52c90b8e007e/; sid:902204256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ZLoader C&C)"; tls.fingerprint:"5e:b4:3e:37:e1:7b:5c:6c:85:6b:33:fd:de:78:17:7d:7b:8a:04:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5eb43e37e17b5c6c856b33fdde78177d7b8a0442/; sid:902204257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:74:68:80:63:84:49:ef:ab:e0:0e:00:92:9e:b4:01:4b:5d:fd:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a746880638449efabe00e00929eb4014b5dfd3d/; sid:902204258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"a9:a0:0d:37:40:ff:31:ba:5c:f7:16:a9:6f:e4:61:7a:53:b7:e8:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9a00d3740ff31ba5cf716a96fe4617a53b7e8f0/; sid:902204259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"6d:12:3a:e9:ca:8e:3a:a5:0e:59:a0:42:f0:a3:e4:f5:01:e9:1b:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d123ae9ca8e3aa50e59a042f0a3e4f501e91b3e/; sid:902204260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5b:a0:b7:14:72:11:b1:39:4d:a4:7e:06:64:8f:76:8f:a6:9a:1c:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ba0b7147211b1394da47e06648f768fa69a1c21/; sid:902204261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"3a:c3:44:36:87:3b:71:bd:7d:d1:44:45:34:fc:e2:bc:2b:a5:60:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ac34436873b71bd7dd1444534fce2bc2ba560e6/; sid:902204262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"98:20:7e:e7:26:ee:75:fc:f7:80:c0:c1:3b:d9:2b:b4:7d:4b:84:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98207ee726ee75fcf780c0c13bd92bb47d4b84fe/; sid:902204263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"12:02:21:38:04:fa:d8:a8:b6:f3:f7:97:a1:30:d1:0b:42:3d:38:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1202213804fad8a8b6f3f797a130d10b423d387b/; sid:902204264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"7b:95:d2:b5:01:02:07:67:6c:35:1e:9d:f8:87:6f:1e:a6:c3:f9:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b95d2b5010207676c351e9df8876f1ea6c3f9e4/; sid:902204265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b5:e6:47:3d:b8:64:ca:d7:5c:bb:11:f4:7c:41:12:1f:6e:84:61:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5e6473db864cad75cbb11f47c41121f6e84614c/; sid:902204266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"95:25:9b:06:70:61:3b:fa:cc:6f:81:56:40:a5:15:9c:e3:f4:f0:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95259b0670613bfacc6f815640a5159ce3f4f0e1/; sid:902204267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:da:df:c9:59:3f:2d:68:12:ac:40:62:12:15:5e:52:f3:5d:83:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6dadfc9593f2d6812ac406212155e52f35d8327/; sid:902204268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"27:f3:c8:38:69:db:fc:96:b1:aa:d8:ae:07:79:7d:e6:dc:3e:ae:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27f3c83869dbfc96b1aad8ae07797de6dc3eaede/; sid:902204269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5b:f6:77:92:48:39:22:b9:2a:67:df:11:c9:9c:03:b9:7e:5e:86:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5bf67792483922b92a67df11c99c03b97e5e86e7/; sid:902204270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"c7:37:88:bc:59:b4:f3:65:9e:79:6b:94:c2:f2:2a:0e:d0:92:e9:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c73788bc59b4f3659e796b94c2f22a0ed092e915/; sid:902204271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"13:6e:36:7e:18:50:c8:e7:43:84:ff:0c:54:32:fd:a7:bd:a8:ef:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/136e367e1850c8e74384ff0c5432fda7bda8ef89/; sid:902204272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"06:7e:94:ab:df:e8:cb:8e:71:e1:5e:f7:62:ea:45:6c:9f:a3:64:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/067e94abdfe8cb8e71e15ef762ea456c9fa364a2/; sid:902204273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ea:58:8f:f3:2f:4b:ce:1a:85:c2:11:d1:ba:09:db:6e:6b:b0:9e:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea588ff32f4bce1a85c211d1ba09db6e6bb09ebd/; sid:902204274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"7b:b4:16:b0:a0:d5:ac:87:f5:d3:bc:05:fd:23:c4:36:1b:14:29:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7bb416b0a0d5ac87f5d3bc05fd23c4361b14297d/; sid:902204275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"fa:77:c9:43:45:ed:23:38:53:ee:82:09:d8:eb:b6:a3:91:f8:c5:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa77c94345ed233853ee8209d8ebb6a391f8c5cf/; sid:902204276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"ad:cd:bb:46:71:22:9d:e1:5d:ce:69:a4:70:de:2e:f4:2c:b1:9e:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/adcdbb4671229de15dce69a470de2ef42cb19e58/; sid:902204277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"49:18:76:52:2b:d2:98:14:8c:46:93:7e:c5:b3:7b:b3:63:66:9d:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/491876522bd298148c46937ec5b37bb363669df7/; sid:902204278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"39:fe:99:eb:b1:58:a5:f0:6b:2c:87:29:18:ff:51:bb:c0:3e:3b:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39fe99ebb158a5f06b2c872918ff51bbc03e3b74/; sid:902204279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0f:62:28:7a:b3:d8:88:37:c8:6e:11:59:99:72:eb:ed:9a:be:2f:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f62287ab3d88837c86e11599972ebed9abe2fbe/; sid:902204280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:78:d6:65:31:d8:64:66:53:db:06:8c:3b:2a:3b:54:95:8f:28:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f478d66531d8646653db068c3b2a3b54958f28c3/; sid:902204281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"be:1b:5d:99:44:90:0f:eb:08:13:79:0b:f5:04:c7:0a:d2:ca:97:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be1b5d9944900feb0813790bf504c70ad2ca97e8/; sid:902204282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"cd:14:69:26:84:38:c0:17:5a:74:27:67:87:7e:cf:77:04:6e:1d:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd1469268438c0175a742767877ecf77046e1d49/; sid:902204283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"03:74:9d:c7:0a:07:d7:c1:c8:bc:32:87:70:f3:6b:e2:f7:b8:45:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03749dc70a07d7c1c8bc328770f36be2f7b8452b/; sid:902204284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"8b:73:bf:d6:64:00:4a:1a:37:b3:45:81:72:26:77:b3:58:19:70:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b73bfd664004a1a37b34581722677b3581970a1/; sid:902204285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"0b:24:04:69:f6:16:8b:6c:f5:29:bd:35:32:68:54:86:85:12:1e:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b240469f6168b6cf529bd353268548685121e22/; sid:902204286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dd:47:41:78:78:54:69:93:a5:38:94:91:73:a8:76:36:50:56:9b:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd47417878546993a538949173a8763650569b87/; sid:902204287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"23:eb:de:2e:74:81:c2:15:83:cd:6f:0d:c9:67:61:25:55:87:ae:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23ebde2e7481c21583cd6f0dc96761255587aee8/; sid:902204288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"82:96:7d:92:27:53:4b:d7:c5:34:43:08:11:8c:6f:80:3a:2b:10:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82967d9227534bd7c5344308118c6f803a2b10df/; sid:902204289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"21:1a:3b:76:93:71:8d:15:7e:ce:df:07:58:4e:dd:99:c6:9f:c3:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/211a3b7693718d157ecedf07584edd99c69fc3e2/; sid:902204290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:54:41:b6:82:56:5b:c9:ad:f5:db:85:4b:ad:84:e8:40:17:a5:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e5441b682565bc9adf5db854bad84e84017a521/; sid:902204291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a3:d6:e0:80:b1:65:3d:f8:62:0f:34:56:3a:fa:a3:53:8a:d6:42:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3d6e080b1653df8620f34563afaa3538ad642f9/; sid:902204292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"58:52:49:2e:6f:b4:11:9f:44:8f:15:4b:6f:7e:ce:11:25:1c:03:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5852492e6fb4119f448f154b6f7ece11251c03c7/; sid:902204293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"7b:19:f4:fd:b1:ef:ee:2e:c7:38:1d:d9:28:6e:93:9e:ae:cc:34:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b19f4fdb1efee2ec7381dd9286e939eaecc3491/; sid:902204294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"61:41:56:04:ee:0f:45:9d:84:90:12:b9:d3:14:b2:ef:ed:91:9b:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61415604ee0f459d849012b9d314b2efed919bac/; sid:902204295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"7b:60:7e:83:bc:a7:c1:52:ff:93:df:80:73:31:ff:4d:f6:76:31:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b607e83bca7c152ff93df807331ff4df6763183/; sid:902204296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"21:10:9f:c4:70:c3:0a:87:51:4a:41:20:d9:70:f3:06:2a:b7:47:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21109fc470c30a87514a4120d970f3062ab74728/; sid:902204297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e5:d6:2c:28:d4:3f:cd:35:8f:44:5e:30:c3:16:4f:7c:e4:cf:fd:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e5d62c28d43fcd358f445e30c3164f7ce4cffdc6/; sid:902204298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"a1:d4:06:d0:54:03:f2:35:c0:61:c5:af:75:52:ad:f7:03:d3:97:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1d406d05403f235c061c5af7552adf703d39737/; sid:902204299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"42:38:20:9c:55:76:2c:71:c6:f6:10:41:a9:84:37:ae:d7:fa:20:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4238209c55762c71c6f61041a98437aed7fa20d7/; sid:902204300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"e2:a7:79:c8:f6:85:b7:aa:54:e7:c5:4a:02:d7:91:d2:47:02:96:78"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2a779c8f685b7aa54e7c54a02d791d247029678/; sid:902204301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"3d:84:a2:c6:29:71:38:81:e2:6b:41:34:20:4b:5c:b4:f1:27:a1:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d84a2c629713881e26b4134204b5cb4f127a143/; sid:902204302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b3:3e:a7:89:c1:77:0a:72:36:c8:bd:a7:f1:43:b2:92:89:87:f7:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b33ea789c1770a7236c8bda7f143b2928987f799/; sid:902204303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"80:0f:1f:32:2b:78:ef:ff:c7:ba:6d:e1:d3:05:4b:5d:d8:8b:a9:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/800f1f322b78efffc7ba6de1d3054b5dd88ba9da/; sid:902204304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"77:4d:9e:a9:8b:04:8e:60:43:18:fd:52:aa:2e:5b:6b:ff:af:eb:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/774d9ea98b048e604318fd52aa2e5b6bffafeb82/; sid:902204305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:d1:78:79:86:81:cf:81:57:85:95:25:03:75:2a:f6:5b:9d:3a:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75d178798681cf815785952503752af65b9d3a53/; sid:902204306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"19:c0:7d:10:2a:bd:a2:a4:67:68:a7:03:68:f6:d1:cb:5f:db:fc:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19c07d102abda2a46768a70368f6d1cb5fdbfcd6/; sid:902204307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"76:d9:3e:08:06:5b:aa:09:df:32:a4:f8:67:8f:a9:9e:11:e8:0d:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76d93e08065baa09df32a4f8678fa99e11e80d73/; sid:902204308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"aa:a8:0d:a0:d9:fb:84:90:ca:73:1e:67:ee:78:20:7e:bf:f4:75:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aaa80da0d9fb8490ca731e67ee78207ebff4753c/; sid:902204309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"17:f5:cd:37:ce:81:82:11:f3:13:6c:46:69:ee:3b:6f:91:ef:d6:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17f5cd37ce818211f3136c4669ee3b6f91efd6ed/; sid:902204310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8f:50:f4:0c:14:49:5f:d7:ff:50:21:2e:34:35:f6:a9:03:23:9c:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f50f40c14495fd7ff50212e3435f6a903239c40/; sid:902204311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3f:0f:59:42:b0:98:01:aa:96:f3:bb:06:63:5d:c8:ee:e0:8b:d6:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f0f5942b09801aa96f3bb06635dc8eee08bd629/; sid:902204312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"00:b6:8e:49:16:55:2d:75:0a:6d:07:a2:88:9c:4d:d2:41:08:c9:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00b68e4916552d750a6d07a2889c4dd24108c90c/; sid:902204313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9b:b1:d7:08:9e:1b:eb:8f:ed:16:5d:8b:a9:ff:71:84:68:0f:4d:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bb1d7089e1beb8fed165d8ba9ff7184680f4d6b/; sid:902204314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8a:76:22:1f:cf:84:31:51:8a:d0:95:00:e2:e5:b3:ad:82:27:16:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a76221fcf8431518ad09500e2e5b3ad8227168a/; sid:902204315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d0:94:bc:ae:1e:ff:3b:8a:f4:78:11:ee:28:dc:2f:d8:67:76:39:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d094bcae1eff3b8af47811ee28dc2fd867763966/; sid:902204316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"99:cb:82:d4:ef:44:fd:ba:ef:3e:09:ad:59:d2:21:8c:e1:3f:1c:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99cb82d4ef44fdbaef3e09ad59d2218ce13f1ce6/; sid:902204317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"aa:24:d0:2b:71:19:07:08:79:08:12:e7:58:c4:7a:6a:ef:04:4c:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa24d02b71190708790812e758c47a6aef044cf2/; sid:902204318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1a:a7:15:b7:e4:ba:8c:33:eb:10:77:50:1e:16:df:02:76:3b:8f:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1aa715b7e4ba8c33eb1077501e16df02763b8f4f/; sid:902204319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:0f:c9:60:88:df:e6:48:31:59:52:27:b8:ec:33:ed:6b:30:8e:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b30fc96088dfe64831595227b8ec33ed6b308e2c/; sid:902204320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ab:c0:ee:b8:f6:b2:91:e2:da:f1:af:6e:c6:ff:74:ab:79:0f:ba:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abc0eeb8f6b291e2daf1af6ec6ff74ab790fba40/; sid:902204321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bf:c7:8d:1e:b6:63:1b:f1:75:50:47:4f:f4:35:1b:96:20:7e:98:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfc78d1eb6631bf17550474ff4351b96207e98f3/; sid:902204322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"38:5c:b6:85:5c:71:b3:ae:76:1e:8d:be:3d:ea:be:d4:03:ff:f0:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/385cb6855c71b3ae761e8dbe3deabed403fff023/; sid:902204323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"77:9e:4c:dc:ce:1e:e1:e9:db:3f:af:8d:cc:66:5c:ed:8e:4e:ee:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/779e4cdcce1ee1e9db3faf8dcc665ced8e4eeeea/; sid:902204324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f2:d6:9e:0e:a5:12:6b:24:e6:91:7b:ec:c1:de:31:1e:ef:db:42:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2d69e0ea5126b24e6917becc1de311eefdb4224/; sid:902204325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1c:64:a0:53:53:c2:5a:90:a1:f6:7b:af:e7:c0:58:0f:63:fe:85:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c64a05353c25a90a1f67bafe7c0580f63fe85c6/; sid:902204326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"2b:9b:0d:f9:03:71:bc:7a:0c:91:92:33:bf:72:4b:2a:6b:82:ae:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2b9b0df90371bc7a0c919233bf724b2a6b82aeae/; sid:902204327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"af:dd:b5:a1:91:ed:d9:4b:d5:55:42:59:fa:2e:05:1e:a1:17:20:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/afddb5a191edd94bd5554259fa2e051ea11720c0/; sid:902204328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"13:a2:02:5f:01:a3:9a:f2:f2:0a:25:8a:9b:ec:88:a3:6d:36:58:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/13a2025f01a39af2f20a258a9bec88a36d36584b/; sid:902204329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"84:76:c6:f2:8a:8e:7d:df:bf:9a:d2:bd:d2:77:cd:62:ac:98:9b:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8476c6f28a8e7ddfbf9ad2bdd277cd62ac989b7f/; sid:902204330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"51:f2:d3:af:6f:a3:fb:ec:03:1d:6b:60:6a:fb:6a:51:27:49:ce:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51f2d3af6fa3fbec031d6b606afb6a512749cede/; sid:902204331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"89:56:b7:11:c1:84:bc:52:43:4a:ea:0d:a5:68:c8:1e:16:8f:7d:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8956b711c184bc52434aea0da568c81e168f7de6/; sid:902204332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:99:1c:af:1d:06:b6:b4:d9:6b:68:ac:40:35:dc:26:b4:a5:67:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b991caf1d06b6b4d96b68ac4035dc26b4a56762/; sid:902204333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vjw0rm C&C)"; tls.fingerprint:"3b:67:0e:a0:f8:03:c1:63:c0:04:b5:4a:92:cf:7c:40:94:b5:68:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b670ea0f803c163c004b54a92cf7c4094b568fd/; sid:902204334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a7:69:52:94:3b:5e:d3:ca:2b:c1:d0:a5:2a:3f:00:64:f4:b5:c7:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a76952943b5ed3ca2bc1d0a52a3f0064f4b5c786/; sid:902204335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:f0:84:67:0c:52:0b:58:cb:35:cd:4c:35:5a:b9:82:df:bb:a3:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12f084670c520b58cb35cd4c355ab982dfbba399/; sid:902204336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:93:12:22:67:ee:73:88:b9:2e:e1:ee:cc:64:9d:67:14:72:a5:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2393122267ee7388b92ee1eecc649d671472a5c5/; sid:902204337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"71:61:0a:c2:b1:2a:f6:3e:56:8d:6f:3a:84:ed:fb:89:a6:6f:2f:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71610ac2b12af63e568d6f3a84edfb89a66f2f43/; sid:902204338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:b3:c1:01:bc:c5:8d:22:17:83:55:b7:44:59:30:90:4b:50:af:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88b3c101bcc58d22178355b7445930904b50afe6/; sid:902204339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:84:62:a0:2e:b4:46:02:01:d6:82:55:cb:3f:39:ce:4b:db:f0:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/758462a02eb4460201d68255cb3f39ce4bdbf0a5/; sid:902204340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c3:65:4a:25:2b:2d:2f:a4:ac:af:8a:59:29:50:21:d3:88:4b:f8:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3654a252b2d2fa4acaf8a59295021d3884bf8ab/; sid:902204341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:c7:c2:da:06:74:57:f5:52:d1:4f:6b:ec:dc:35:9f:cb:b4:02:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02c7c2da067457f552d14f6becdc359fcbb40261/; sid:902204342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AZORult C&C)"; tls.fingerprint:"24:3a:25:a1:1f:e0:62:05:83:1a:3f:65:16:e2:1c:3f:4f:33:80:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/243a25a11fe06205831a3f6516e21c3f4f33801f/; sid:902204343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"a8:3b:db:30:e7:59:41:ef:71:b7:d5:5d:48:62:ae:af:ad:57:e8:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a83bdb30e75941ef71b7d55d4862aeafad57e8b2/; sid:902204344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:b1:20:0d:6c:76:14:37:1b:ce:81:bc:69:d8:41:c0:97:e6:e9:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14b1200d6c7614371bce81bc69d841c097e6e916/; sid:902204345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5b:a5:af:60:9c:f3:3f:85:f7:d6:eb:92:94:0f:b2:86:b6:d1:64:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ba5af609cf33f85f7d6eb92940fb286b6d164f9/; sid:902204346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6a:ab:71:ca:a7:d4:a0:c4:46:03:c5:88:ec:33:0d:b1:0b:e0:51:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6aab71caa7d4a0c44603c588ec330db10be0518c/; sid:902204347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:a6:26:9e:31:f4:35:41:8e:1e:c8:24:96:71:cc:9e:b7:a4:7b:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ba6269e31f435418e1ec8249671cc9eb7a47b2f/; sid:902204348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"09:6d:12:20:0c:97:58:88:33:25:6d:fe:e4:99:24:94:64:2a:e6:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/096d12200c97588833256dfee4992494642ae677/; sid:902204349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"d5:bd:8c:22:62:d8:5d:ce:89:01:63:57:10:78:74:7e:05:a8:da:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5bd8c2262d85dce890163571078747e05a8da49/; sid:902204350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"00:1b:0e:1b:9e:6e:33:f5:b4:86:78:a1:78:0a:d1:bf:17:bd:9f:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/001b0e1b9e6e33f5b48678a1780ad1bf17bd9f96/; sid:902204351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:ef:cb:d4:c2:89:5f:8b:93:bb:fe:58:21:10:2a:c0:b0:94:fa:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38efcbd4c2895f8b93bbfe5821102ac0b094faf1/; sid:902204352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fe:d0:56:fa:3e:69:f6:a1:bd:95:0f:90:5a:bb:cf:6e:e4:d1:c9:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fed056fa3e69f6a1bd950f905abbcf6ee4d1c9ad/; sid:902204353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ab:9b:79:a4:02:2b:8b:4a:cc:9c:2e:43:a1:02:65:56:5a:6f:fc:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab9b79a4022b8b4acc9c2e43a10265565a6ffcc9/; sid:902204354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"dc:d6:23:10:9b:c4:80:8f:fc:36:24:35:ad:dc:d1:49:34:2f:fb:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dcd623109bc4808ffc362435addcd149342ffb73/; sid:902204355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d2:c2:be:eb:9f:ac:df:d1:2b:8c:a4:06:f8:e1:55:de:9d:70:84:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2c2beeb9facdfd12b8ca406f8e155de9d70849e/; sid:902204356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:f5:64:f5:b0:ec:55:49:f1:a9:c5:16:dc:34:df:21:b2:ab:95:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38f564f5b0ec5549f1a9c516dc34df21b2ab9523/; sid:902204357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"eb:59:9d:11:77:ef:6d:64:a8:b4:92:7c:0b:01:0e:57:5e:ec:05:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb599d1177ef6d64a8b4927c0b010e575eec0598/; sid:902204358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b4:cf:3f:78:78:6c:43:c6:de:23:be:91:bd:90:01:3a:8c:29:b3:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4cf3f78786c43c6de23be91bd90013a8c29b3ea/; sid:902204359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"df:7c:34:c7:97:89:65:4c:9d:2f:35:03:db:38:cd:55:ef:8d:84:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/df7c34c79789654c9d2f3503db38cd55ef8d8477/; sid:902204360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"13:4f:b5:4e:c3:2b:a1:3d:10:9d:39:b0:2b:7a:fc:e8:05:19:6e:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/134fb54ec32ba13d109d39b02b7afce805196e1a/; sid:902204361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"af:63:78:cd:74:97:5b:15:53:f8:ac:15:f3:ff:9d:71:ef:db:1b:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af6378cd74975b1553f8ac15f3ff9d71efdb1bda/; sid:902204362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e4:e1:51:95:a5:07:3d:df:3b:d0:f6:8b:f9:60:27:cc:b3:e6:1b:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4e15195a5073ddf3bd0f68bf96027ccb3e61bb6/; sid:902204363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fe:51:c7:3b:d6:32:48:40:4e:44:24:b3:37:7d:ed:8b:3b:3e:c5:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe51c73bd63248404e4424b3377ded8b3b3ec5e8/; sid:902204364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"50:85:13:3c:ce:da:8e:ce:76:0f:4e:66:e8:77:77:53:3c:d9:da:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5085133cceda8ece760f4e66e87777533cd9dafc/; sid:902204365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8a:78:9c:33:8e:cd:22:b9:aa:6f:f0:0f:0e:fc:c1:c7:48:e5:65:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a789c338ecd22b9aa6ff00f0efcc1c748e5654c/; sid:902204366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fb:82:57:ce:be:0b:a2:67:c2:59:26:c7:ac:59:fa:a0:cf:70:e7:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb8257cebe0ba267c25926c7ac59faa0cf70e765/; sid:902204367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b9:6b:2b:cc:55:e4:a1:b8:6c:b5:dc:24:34:f0:47:a9:6f:04:8a:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b96b2bcc55e4a1b86cb5dc2434f047a96f048a6a/; sid:902204368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"0a:21:37:03:13:50:64:39:2c:5b:3d:41:14:c0:82:db:06:f5:47:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a213703135064392c5b3d4114c082db06f547c3/; sid:902204369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"70:41:b7:80:30:cd:28:d9:7b:8d:f0:54:ec:bd:17:1f:7e:0f:25:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7041b78030cd28d97b8df054ecbd171f7e0f2530/; sid:902204370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"af:f9:fe:9c:e8:f5:7e:ac:a7:f5:41:c6:a6:c9:b8:d1:50:4d:8f:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aff9fe9ce8f57eaca7f541c6a6c9b8d1504d8f7b/; sid:902204371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"64:7a:d9:4b:b4:65:ba:cf:6b:27:10:59:c7:b8:22:c5:9a:ea:c7:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/647ad94bb465bacf6b271059c7b822c59aeac77f/; sid:902204372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"29:4c:be:3d:19:43:20:e7:8d:33:ba:84:78:7d:35:ba:77:57:f9:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/294cbe3d194320e78d33ba84787d35ba7757f911/; sid:902204373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"49:98:7f:4c:df:a4:d2:4a:c2:de:71:3f:a2:51:f3:73:3f:7d:f6:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49987f4cdfa4d24ac2de713fa251f3733f7df62d/; sid:902204374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e8:fa:66:2e:79:86:33:9f:ac:8f:35:48:72:9c:a6:27:d0:2a:78:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8fa662e7986339fac8f3548729ca627d02a78fa/; sid:902204375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f1:dc:b8:08:f1:57:21:50:37:a2:76:42:59:25:00:e2:e8:68:6c:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1dcb808f157215037a27642592500e2e8686c4c/; sid:902204376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vjw0rm C&C)"; tls.fingerprint:"a2:b7:76:68:53:16:bf:bc:6a:a7:19:94:61:cd:bc:13:2e:ee:5e:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2b776685316bfbc6aa7199461cdbc132eee5e6f/; sid:902204377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"c2:2c:7c:48:e7:00:c9:36:74:c1:41:fc:01:36:a7:82:3b:d0:4f:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c22c7c48e700c93674c141fc0136a7823bd04f16/; sid:902204378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"e7:30:fb:d6:f3:c4:ac:16:3e:08:bb:fa:b7:f7:c8:97:72:28:74:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e730fbd6f3c4ac163e08bbfab7f7c897722874c2/; sid:902204379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"6b:fe:f0:de:61:7a:6b:91:b2:8d:b4:73:38:d0:77:1d:d6:84:56:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bfef0de617a6b91b28db47338d0771dd68456c9/; sid:902204380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fc:62:87:67:55:8f:ab:f9:a5:24:27:33:cf:e7:92:f9:86:3f:93:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc628767558fabf9a5242733cfe792f9863f933d/; sid:902204381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:e3:e4:d2:ce:df:c5:b0:2b:32:7a:3c:7d:57:e0:97:80:2c:e2:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfe3e4d2cedfc5b02b327a3c7d57e097802ce2d5/; sid:902204382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"37:30:d5:57:d4:4c:e4:e6:be:97:4a:03:8d:43:43:d8:d6:79:76:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3730d557d44ce4e6be974a038d4343d8d67976da/; sid:902204383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"8c:87:2a:33:6b:8b:aa:11:ec:bf:7e:df:2c:ec:4f:d7:19:e3:3f:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8c872a336b8baa11ecbf7edf2cec4fd719e33fe7/; sid:902204384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DcRat C&C)"; tls.fingerprint:"d6:40:49:22:2b:4a:a4:ce:ab:27:96:11:26:4b:3b:82:78:0c:df:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d64049222b4aa4ceab279611264b3b82780cdf45/; sid:902204385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e8:59:a0:cb:76:eb:84:86:df:4f:c9:60:84:22:49:f4:9e:e9:b3:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e859a0cb76eb8486df4fc960842249f49ee9b3db/; sid:902204386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"87:df:1f:b4:8e:a4:ff:f8:b9:e9:5b:fc:6e:98:54:46:e4:5c:4d:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87df1fb48ea4fff8b9e95bfc6e985446e45c4df9/; sid:902204387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"83:18:86:1a:a6:90:c8:7c:2d:7a:1e:b6:52:12:ec:4c:bf:cb:73:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8318861aa690c87c2d7a1eb65212ec4cbfcb73e8/; sid:902204388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"60:31:fa:f2:73:af:88:45:3d:5d:ca:e1:4f:02:c1:ff:63:64:95:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6031faf273af88453d5dcae14f02c1ff6364950f/; sid:902204389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"1c:64:1e:4a:64:a8:27:88:d5:c3:09:bb:06:0b:6c:9b:1c:d1:ad:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c641e4a64a82788d5c309bb060b6c9b1cd1ad5e/; sid:902204390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"36:e6:be:16:d1:80:7a:d1:b5:d0:00:3f:6c:26:3f:d8:60:df:37:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36e6be16d1807ad1b5d0003f6c263fd860df3747/; sid:902204391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (hVNC C&C)"; tls.fingerprint:"14:da:2a:fe:54:2a:b4:93:57:64:56:47:bc:bc:01:2a:60:ca:8d:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14da2afe542ab49357645647bcbc012a60ca8d16/; sid:902204392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:e9:13:a8:fb:aa:2e:ac:c1:e7:9a:a6:58:3c:84:62:c2:5f:fd:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfe913a8fbaa2eacc1e79aa6583c8462c25ffda1/; sid:902204393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"57:cd:c8:e7:34:e5:5d:e5:bc:3e:01:2c:11:37:da:b3:af:9b:ab:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57cdc8e734e55de5bc3e012c1137dab3af9babbd/; sid:902204394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:d1:5e:80:90:6f:04:07:e3:a8:a1:69:40:4c:51:4a:14:c1:f4:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2cd15e80906f0407e3a8a169404c514a14c1f4d5/; sid:902204395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"4f:10:47:5e:13:d1:48:81:53:0a:ea:9e:f6:4f:67:f0:42:41:f1:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f10475e13d14881530aea9ef64f67f04241f14a/; sid:902204396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1f:dc:a4:30:40:73:1e:80:d0:ab:b1:1d:0e:2a:ae:69:6e:95:cd:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fdca43040731e80d0abb11d0e2aae696e95cd6a/; sid:902204397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c0:4b:a0:ac:48:76:d5:54:8b:aa:4b:cb:c2:7e:c3:d8:99:8a:f0:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c04ba0ac4876d5548baa4bcbc27ec3d8998af048/; sid:902204398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"27:c0:5c:ab:29:48:ea:9c:ec:a3:3a:98:29:6a:74:84:cd:1b:a8:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27c05cab2948ea9ceca33a98296a7484cd1ba830/; sid:902204399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"46:f7:88:b5:d3:91:5a:15:18:23:a5:d4:84:40:29:95:5e:4f:d6:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/46f788b5d3915a151823a5d4844029955e4fd6ee/; sid:902204400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"ab:72:62:ed:a1:fe:a6:9b:00:3c:c5:f2:b3:26:ab:c0:63:3d:61:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab7262eda1fea69b003cc5f2b326abc0633d6159/; sid:902204401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:e3:aa:65:a1:e1:7c:06:11:d5:ca:dd:e5:3d:d8:82:ee:43:7c:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9e3aa65a1e17c0611d5cadde53dd882ee437c10/; sid:902204402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:2e:5e:65:c6:b4:80:3a:64:4e:28:b8:33:eb:89:ed:5b:31:f7:ef"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e2e5e65c6b4803a644e28b833eb89ed5b31f7ef/; sid:902204403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:e1:cc:07:a4:31:a0:d0:fc:86:6b:ba:2f:ae:e2:0b:4e:14:ac:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/70e1cc07a431a0d0fc866bba2faee20b4e14ac9f/; sid:902204404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"99:91:db:97:7c:a6:f5:65:cf:b7:00:42:23:d6:97:91:5f:84:c2:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9991db977ca6f565cfb7004223d697915f84c2f4/; sid:902204405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"43:c9:a4:ce:d4:41:0b:fe:02:d4:ae:69:42:8d:76:4a:01:16:e7:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/43c9a4ced4410bfe02d4ae69428d764a0116e753/; sid:902204406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:d2:cd:5e:e6:b1:58:3e:78:99:91:13:e8:ac:25:28:2a:a0:8a:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7d2cd5ee6b1583e78999113e8ac25282aa08a36/; sid:902204407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"aa:20:c7:f0:82:e8:74:d9:2a:5c:eb:20:05:35:09:c2:1c:1d:57:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa20c7f082e874d92a5ceb20053509c21c1d5727/; sid:902204408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"49:ea:06:5d:ab:9d:ea:dc:76:61:45:e7:21:0e:c2:32:42:f3:8e:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49ea065dab9deadc766145e7210ec23242f38e27/; sid:902204409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fc:aa:d6:76:9c:12:62:c4:cb:43:77:5c:56:74:10:d0:2d:19:b3:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcaad6769c1262c4cb43775c567410d02d19b3f9/; sid:902204410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"bf:4d:87:ab:a6:77:c1:5c:9a:34:63:0f:8b:aa:0e:de:66:3a:11:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf4d87aba677c15c9a34630f8baa0ede663a115b/; sid:902204411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"12:90:a4:03:77:34:f8:f7:71:db:4d:d1:57:b0:c9:95:8d:05:2b:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1290a4037734f8f771db4dd157b0c9958d052b11/; sid:902204412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ac:2b:b7:28:16:fb:80:4c:43:20:ad:a7:7f:90:ca:ff:e4:95:15:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac2bb72816fb804c4320ada77f90caffe49515ba/; sid:902204413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a4:c6:c6:77:2e:ab:b4:8a:dc:16:27:12:41:05:7c:22:a0:40:9c:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4c6c6772eabb48adc16271241057c22a0409c36/; sid:902204414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"17:20:47:b8:22:34:39:ee:5f:24:ec:89:36:21:57:d2:79:d8:f1:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/172047b8223439ee5f24ec89362157d279d8f12d/; sid:902204415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2e:9f:0f:c9:7d:b1:fa:25:00:69:75:b8:af:f0:04:c5:5b:9a:b3:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e9f0fc97db1fa25006975b8aff004c55b9ab32e/; sid:902204416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"cf:cd:07:59:e2:0f:29:c3:99:c9:d4:21:0b:e6:14:e4:e0:20:be:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfcd0759e20f29c399c9d4210be614e4e020bee8/; sid:902204417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9b:54:30:b6:d6:c3:0d:2d:4e:3c:56:5f:12:83:57:ce:cb:b2:44:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b5430b6d6c30d2d4e3c565f128357cecbb244a0/; sid:902204418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b6:9f:cf:67:aa:11:4a:e3:e6:07:51:9f:92:7d:2b:82:b7:80:f9:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b69fcf67aa114ae3e607519f927d2b82b780f946/; sid:902204419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7c:f3:0d:a5:d9:70:8f:17:05:d9:f8:2f:ae:fc:20:57:c9:d3:0a:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7cf30da5d9708f1705d9f82faefc2057c9d30ac1/; sid:902204420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7e:85:56:d0:24:b3:9d:5b:69:24:e3:e0:b3:73:56:69:fb:38:ba:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e8556d024b39d5b6924e3e0b3735669fb38bac9/; sid:902204421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"95:87:93:99:4f:2e:5c:40:a2:26:4c:fd:cc:93:01:4b:69:39:54:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/958793994f2e5c40a2264cfdcc93014b693954cc/; sid:902204422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"23:8e:3f:7e:72:fc:27:84:f5:c7:b3:dc:57:60:f8:f0:2b:b1:77:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/238e3f7e72fc2784f5c7b3dc5760f8f02bb177c4/; sid:902204423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"78:3a:7c:78:df:32:da:d9:21:90:fb:ad:f0:96:0a:22:24:34:0a:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/783a7c78df32dad92190fbadf0960a2224340a08/; sid:902204424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"20:ea:6a:62:a3:71:fc:e9:39:33:09:e6:f3:c7:27:e0:b8:be:25:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20ea6a62a371fce9393309e6f3c727e0b8be250d/; sid:902204425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d9:f0:9e:18:ae:dd:c3:ed:5c:0a:5d:1c:8b:cb:b1:31:af:34:cf:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9f09e18aeddc3ed5c0a5d1c8bcbb131af34cf0f/; sid:902204426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"58:ac:4d:22:d3:1e:57:6a:72:94:0c:4b:45:b0:98:45:8a:cc:6a:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58ac4d22d31e576a72940c4b45b098458acc6a7c/; sid:902204427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"9c:e6:b5:cb:ef:1b:5a:5d:25:c7:ac:04:a9:cb:b4:9e:86:74:ff:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ce6b5cbef1b5a5d25c7ac04a9cbb49e8674ffd0/; sid:902204428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:0e:54:a7:77:51:95:74:4b:a8:b2:95:72:28:56:71:ab:dd:2e:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c0e54a7775195744ba8b29572285671abdd2e05/; sid:902204429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e6:e7:f7:3a:57:9c:d0:8f:00:0b:ea:cb:9f:d1:9f:7b:56:02:35:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6e7f73a579cd08f000beacb9fd19f7b56023534/; sid:902204430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"3e:c8:8a:fa:3b:12:31:34:71:3c:fa:e3:3c:0d:45:3b:3c:f1:31:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ec88afa3b123134713cfae33c0d453b3cf1316b/; sid:902204431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"aa:d7:1a:08:52:77:3e:76:fa:ea:27:ed:18:44:89:f6:9c:45:d1:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aad71a0852773e76faea27ed184489f69c45d181/; sid:902204432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:d5:05:4a:1f:0b:14:6c:fd:6e:eb:9e:68:33:c0:57:47:ad:48:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79d5054a1f0b146cfd6eeb9e6833c05747ad483a/; sid:902204433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0f:53:bc:19:ba:ee:63:76:5b:f7:11:a1:a3:4a:bf:76:2e:97:75:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f53bc19baee63765bf711a1a34abf762e977546/; sid:902204434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:ac:56:08:2c:d7:b4:9e:82:cd:4f:66:84:4a:a1:9e:f9:bb:81:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7bac56082cd7b49e82cd4f66844aa19ef9bb81d6/; sid:902204435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"06:9c:38:e7:fa:7d:82:27:85:a1:47:44:b1:47:99:1f:7b:e0:ab:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/069c38e7fa7d822785a14744b147991f7be0ab4b/; sid:902204436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:c2:c5:f2:c6:49:d1:79:87:d7:76:9e:1b:58:cb:e4:aa:ca:cf:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80c2c5f2c649d17987d7769e1b58cbe4aacacf2b/; sid:902204437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"18:1b:70:96:28:4e:bf:bf:a2:6a:d0:1a:d6:d5:86:85:49:99:62:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/181b7096284ebfbfa26ad01ad6d586854999621e/; sid:902204438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"56:33:6f:61:52:b2:3d:ca:86:0f:a1:89:97:52:04:58:9c:59:8b:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56336f6152b23dca860fa189975204589c598b5d/; sid:902204439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"60:9f:56:d0:68:fd:c8:8a:a5:4b:bb:55:9f:2a:d9:ad:ed:dc:71:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/609f56d068fdc88aa54bbb559f2ad9adeddc71cf/; sid:902204440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"78:aa:4a:83:bf:66:3f:c1:d6:d8:74:62:b7:db:35:2f:c4:1c:fa:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78aa4a83bf663fc1d6d87462b7db352fc41cfa70/; sid:902204441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ba:40:0a:4d:01:60:37:cb:0f:24:4e:a3:ef:0b:04:e2:14:2b:9c:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba400a4d016037cb0f244ea3ef0b04e2142b9c9f/; sid:902204442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:fb:1e:e3:eb:dc:bd:ad:85:99:b9:2e:85:f8:35:3c:68:9f:2d:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9efb1ee3ebdcbdad8599b92e85f8353c689f2d70/; sid:902204443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:be:77:d1:65:9d:1a:ae:a2:8f:21:2b:68:70:2e:33:3e:a2:6b:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfbe77d1659d1aaea28f212b68702e333ea26bb2/; sid:902204444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"fd:aa:2f:ba:83:ec:75:30:43:84:7e:9b:36:a1:a9:17:29:ed:b0:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdaa2fba83ec753043847e9b36a1a91729edb092/; sid:902204445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a5:97:66:bf:ae:64:41:99:0d:72:bc:78:52:68:05:6e:5f:03:ed:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a59766bfae6441990d72bc785268056e5f03ed23/; sid:902204446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f2:4a:1b:37:67:5f:34:52:22:3f:7c:3f:d7:31:09:5c:5d:a0:dc:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f24a1b37675f3452223f7c3fd731095c5da0dc87/; sid:902204447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"c6:e2:3b:a7:0e:45:ce:89:d8:44:0b:15:de:0b:c1:4e:55:c6:81:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6e23ba70e45ce89d8440b15de0bc14e55c6817f/; sid:902204448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:c7:cd:e8:ad:0c:ad:37:b2:eb:00:4d:bf:59:e2:5d:e6:c7:1d:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fc7cde8ad0cad37b2eb004dbf59e25de6c71dc3/; sid:902204449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:8c:ff:5d:7d:e7:62:b5:f1:3b:6d:a3:44:13:bd:82:b5:2e:20:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c58cff5d7de762b5f13b6da34413bd82b52e20ce/; sid:902204450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:e4:b5:03:26:d2:9f:72:de:d5:a4:2c:d1:d0:55:80:de:b2:29:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ce4b50326d29f72ded5a42cd1d05580deb22999/; sid:902204451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:5f:31:e4:9c:03:45:13:79:83:fd:23:54:b9:b3:7e:51:6f:be:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/125f31e49c0345137983fd2354b9b37e516fbe28/; sid:902204452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:25:db:d2:bf:77:23:69:c1:a4:60:6e:4c:c3:4b:aa:bf:fd:64:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f425dbd2bf772369c1a4606e4cc34baabffd6420/; sid:902204453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"28:64:3f:d7:5c:7b:c4:5f:8d:33:74:e1:5f:7a:49:e3:3d:5f:0c:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28643fd75c7bc45f8d3374e15f7a49e33d5f0ca8/; sid:902204454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"eb:73:bb:bb:da:71:d5:0d:1a:25:50:2d:ac:e6:22:74:65:ca:59:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb73bbbbda71d50d1a25502dace6227465ca597d/; sid:902204455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5e:7a:48:ca:36:73:64:03:03:94:e3:4c:81:e9:cb:76:ad:0b:d5:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e7a48ca367364030394e34c81e9cb76ad0bd5c4/; sid:902204456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:53:38:1a:55:1d:e0:bb:db:38:56:2e:3f:f9:16:51:6f:e0:85:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e753381a551de0bbdb38562e3ff916516fe085d3/; sid:902204457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b8:8b:2d:39:92:f2:d4:01:54:8b:bf:f4:a0:67:e4:a8:da:c1:8f:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b88b2d3992f2d401548bbff4a067e4a8dac18f72/; sid:902204458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:37:1f:24:0e:90:a0:19:0a:14:39:7a:5a:da:03:bc:d5:6f:04:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c371f240e90a0190a14397a5ada03bcd56f046e/; sid:902204459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"95:37:db:62:72:04:0e:a5:03:6c:f2:00:62:e8:dc:20:ac:98:cc:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9537db6272040ea5036cf20062e8dc20ac98cc87/; sid:902204460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d4:e2:60:f0:f3:e7:bc:6b:58:52:f3:ad:a0:34:d4:0e:46:93:85:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4e260f0f3e7bc6b5852f3ada034d40e4693850f/; sid:902204461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:a4:21:36:ad:8b:2b:35:17:e4:1d:90:d9:f8:32:90:c0:66:58:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b3a42136ad8b2b3517e41d90d9f83290c06658ab/; sid:902204462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"57:fa:5a:a8:3b:88:8e:92:bf:a4:44:73:ab:4f:95:d7:26:57:82:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57fa5aa83b888e92bfa44473ab4f95d7265782d9/; sid:902204463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:e4:aa:3b:04:78:2d:c6:22:2f:0b:a1:27:5b:1f:5d:e0:95:1b:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51e4aa3b04782dc6222f0ba1275b1f5de0951bf1/; sid:902204464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"09:b1:2a:da:43:36:85:07:71:4b:bb:89:48:f6:3b:2a:d9:f7:0b:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09b12ada43368507714bbb8948f63b2ad9f70b69/; sid:902204465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"53:b2:df:9d:44:f4:eb:56:c2:ac:24:c1:f5:b7:24:f2:7b:66:ef:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/53b2df9d44f4eb56c2ac24c1f5b724f27b66ef1c/; sid:902204466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ea:8c:cb:14:1f:7f:b5:d4:3e:30:41:6c:28:86:fb:09:35:3a:9c:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea8ccb141f7fb5d43e30416c2886fb09353a9c45/; sid:902204467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:07:f7:8f:76:5b:c2:33:46:c9:dd:ad:a2:43:19:a8:c3:a2:d8:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3207f78f765bc23346c9ddada24319a8c3a2d8bb/; sid:902204468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:68:a5:86:da:54:54:b5:8d:89:86:a9:33:93:28:e6:3f:6a:8f:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b68a586da5454b58d8986a9339328e63f6a8f64/; sid:902204469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"6d:40:c2:7d:bc:ac:2d:db:1c:52:53:15:66:78:40:43:38:0c:14:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d40c27dbcac2ddb1c52531566784043380c1404/; sid:902204470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:f7:8a:83:ae:88:37:6c:ee:ae:ef:6e:dd:31:95:d3:9d:73:d8:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ef78a83ae88376ceeaeef6edd3195d39d73d8ad/; sid:902204471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:c0:c2:8f:36:8f:b8:28:1b:04:cb:03:06:d9:16:4a:76:c3:c8:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7c0c28f368fb8281b04cb0306d9164a76c3c8cf/; sid:902204472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dd:58:92:2e:2b:2f:f1:0c:ab:d4:b3:b7:ec:2f:41:55:b9:82:e8:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd58922e2b2ff10cabd4b3b7ec2f4155b982e835/; sid:902204473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cf:5d:04:dd:ec:07:a6:4a:e9:24:54:cb:4e:88:1f:1d:94:b2:30:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf5d04ddec07a64ae92454cb4e881f1d94b23050/; sid:902204474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b4:a3:8c:8e:65:cb:c1:b1:be:24:b8:19:88:37:cc:cd:79:85:5d:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4a38c8e65cbc1b1be24b8198837cccd79855d90/; sid:902204475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"52:a9:18:73:f7:45:b4:49:17:09:b1:d1:66:d1:69:76:90:21:bd:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52a91873f745b4491709b1d166d169769021bd00/; sid:902204476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:35:5c:c7:12:5f:9c:31:62:0b:66:48:d4:2c:3b:c5:c7:1d:3c:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76355cc7125f9c31620b6648d42c3bc5c71d3cfb/; sid:902204477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"65:e5:40:2a:7e:46:e4:41:66:89:52:a1:91:c4:38:3c:dd:bc:1d:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65e5402a7e46e441668952a191c4383cddbc1d85/; sid:902204478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0f:d7:5c:5a:55:72:af:de:73:9c:ef:b1:1f:eb:a1:36:f1:c1:91:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0fd75c5a5572afde739cefb11feba136f1c191f6/; sid:902204479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fc:28:b5:66:b4:a3:3c:db:da:41:5a:6d:83:fd:4e:33:69:f0:98:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc28b566b4a33cdbda415a6d83fd4e3369f098b6/; sid:902204480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:3a:9a:d4:75:44:dc:45:69:8a:d6:c9:b4:26:1f:58:aa:f1:b4:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/223a9ad47544dc45698ad6c9b4261f58aaf1b47e/; sid:902204481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"72:f1:bd:d9:60:82:61:b1:16:43:99:4c:95:0b:70:e6:61:9c:8a:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72f1bdd9608261b11643994c950b70e6619c8ab9/; sid:902204482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"e7:be:e1:40:9d:97:a3:42:04:3e:80:6d:e8:f4:ee:e7:c3:aa:c0:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7bee1409d97a342043e806de8f4eee7c3aac0ce/; sid:902204483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"27:ae:ee:31:05:af:b6:fd:5a:da:06:0d:ea:fa:61:c7:97:bf:4a:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27aeee3105afb6fd5ada060deafa61c797bf4a69/; sid:902204484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0b:4b:65:ba:1a:34:1c:9d:59:40:af:1b:f0:b6:21:8a:91:5f:7d:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b4b65ba1a341c9d5940af1bf0b6218a915f7dbb/; sid:902204485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bd:a2:48:fe:42:69:67:f2:26:a0:cc:b4:44:93:5e:68:a1:e5:75:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bda248fe426967f226a0ccb444935e68a1e575c4/; sid:902204486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f5:df:fb:46:3d:8a:2c:19:6d:64:d3:fe:62:c6:9b:5f:c8:10:4a:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5dffb463d8a2c196d64d3fe62c69b5fc8104adb/; sid:902204487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"be:a6:4b:69:0d:3b:dc:2d:4c:00:59:8b:21:d9:84:1a:83:69:22:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bea64b690d3bdc2d4c00598b21d9841a83692257/; sid:902204488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"48:75:cc:10:37:16:81:8a:00:77:56:36:59:65:dc:13:71:58:b1:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4875cc103716818a007756365965dc137158b1f0/; sid:902204489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"00:32:ab:31:e4:cf:80:e8:f6:6a:3e:55:cc:20:95:21:92:02:79:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0032ab31e4cf80e8f66a3e55cc2095219202796d/; sid:902204490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"16:fd:93:7f:ae:21:1d:1c:05:ee:28:00:ee:40:f5:a2:b6:70:69:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/16fd937fae211d1c05ee2800ee40f5a2b67069d8/; sid:902204491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"3d:78:1b:99:e0:86:0c:93:49:17:dd:47:e8:d2:df:84:75:cc:7f:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d781b99e0860c934917dd47e8d2df8475cc7fc8/; sid:902204492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:8f:d5:b7:53:56:e9:67:76:f6:ff:4a:30:ff:1b:70:10:36:21:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e48fd5b75356e96776f6ff4a30ff1b701036212e/; sid:902204493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e6:10:6d:70:26:5f:3a:8e:e1:4e:f5:0f:08:f5:96:1e:3c:5f:f2:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6106d70265f3a8ee14ef50f08f5961e3c5ff2a1/; sid:902204494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3f:39:19:c4:9f:3e:2a:18:8c:da:da:f9:4b:a8:db:3e:2c:ca:38:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f3919c49f3e2a188cdadaf94ba8db3e2cca3803/; sid:902204495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f3:ef:76:78:1a:ef:62:dc:18:05:bb:dd:bd:f3:8f:57:ee:3f:e1:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3ef76781aef62dc1805bbddbdf38f57ee3fe1bd/; sid:902204496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"32:a4:85:7d:b6:8c:7c:84:d1:80:3e:46:13:a1:f3:e6:1b:e9:5d:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32a4857db68c7c84d1803e4613a1f3e61be95df4/; sid:902204497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:c8:e0:9f:9c:d4:a2:9f:1d:57:fa:dc:70:ca:35:d9:1a:79:e3:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bc8e09f9cd4a29f1d57fadc70ca35d91a79e36e/; sid:902204498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f0:7c:0a:87:46:06:8b:5a:a3:11:95:73:de:52:0a:c3:10:89:93:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f07c0a8746068b5aa3119573de520ac3108993bc/; sid:902204499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f6:b3:7e:5b:cb:5e:86:a4:6d:98:a3:de:6e:6f:11:07:04:42:41:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6b37e5bcb5e86a46d98a3de6e6f1107044241d7/; sid:902204500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"63:8e:83:35:a7:ef:42:6b:a2:c1:a5:36:d2:e0:1b:be:f6:6a:f5:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/638e8335a7ef426ba2c1a536d2e01bbef66af5fc/; sid:902204501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"0d:0f:78:91:bd:61:ae:0c:50:31:75:72:3a:da:78:3c:99:73:f3:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d0f7891bd61ae0c503175723ada783c9973f3b8/; sid:902204502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VoidLogger)"; tls.fingerprint:"0c:77:54:09:65:62:66:cb:47:9f:85:dc:45:09:2f:2b:6d:a5:dd:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c775409656266cb479f85dc45092f2b6da5ddac/; sid:902204503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b6:ca:75:f3:c7:f0:3a:e2:f5:61:0c:fe:72:0f:48:0a:16:52:d8:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6ca75f3c7f03ae2f5610cfe720f480a1652d831/; sid:902204504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:0b:43:60:68:82:f9:b5:81:91:8c:a6:bf:5f:53:79:6a:eb:db:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bc0b43606882f9b581918ca6bf5f53796aebdb86/; sid:902204505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c8:75:88:87:3a:0b:f8:87:e6:ab:d0:26:20:57:e8:d1:b0:74:88:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c87588873a0bf887e6abd0262057e8d1b074889a/; sid:902204506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cc:63:ce:76:02:e3:91:8c:d0:1c:8c:3d:c2:75:08:02:6b:3d:1b:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc63ce7602e3918cd01c8c3dc27508026b3d1bb5/; sid:902204507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:3a:76:f4:19:1c:47:8f:7d:e0:14:91:b4:31:4f:bd:98:b2:e8:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd3a76f4191c478f7de01491b4314fbd98b2e8ce/; sid:902204508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"db:f1:8b:0b:49:1e:d8:6f:e0:05:cd:0c:c3:22:a8:5f:ef:22:6e:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbf18b0b491ed86fe005cd0cc322a85fef226e3a/; sid:902204509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"0a:b6:26:cc:2b:c9:6a:bc:49:c5:87:2b:0e:fc:07:39:ef:67:47:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ab626cc2bc96abc49c5872b0efc0739ef6747a1/; sid:902204510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"af:6e:d0:4f:88:a7:d5:a3:0a:32:5a:6a:f5:b4:a1:6a:45:97:4b:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af6ed04f88a7d5a30a325a6af5b4a16a45974bb0/; sid:902204511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7d:1f:6f:e3:a4:37:2d:9a:5b:5d:da:26:78:e3:08:55:bb:9a:b1:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d1f6fe3a4372d9a5b5dda2678e30855bb9ab1c5/; sid:902204512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"92:b6:2d:d1:bc:7c:c2:e2:b7:eb:31:65:ec:a1:dd:9d:cf:3c:80:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92b62dd1bc7cc2e2b7eb3165eca1dd9dcf3c809b/; sid:902204513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"1c:f9:05:0f:75:c9:31:0e:59:61:fe:cd:a4:20:28:70:d5:e3:ac:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cf9050f75c9310e5961fecda4202870d5e3ace7/; sid:902204514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"18:41:c8:06:3d:7c:6f:b2:7a:74:a5:d5:ae:56:60:38:cd:1c:8b:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1841c8063d7c6fb27a74a5d5ae566038cd1c8bac/; sid:902204515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d4:48:af:e5:af:01:eb:9c:d1:c1:34:3d:46:d2:67:ea:51:3a:e4:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d448afe5af01eb9cd1c1343d46d267ea513ae47c/; sid:902204516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"12:87:c1:0b:c6:3d:f5:c8:d6:f6:41:34:65:2e:82:27:cc:3a:b0:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1287c10bc63df5c8d6f64134652e8227cc3ab007/; sid:902204517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:7e:11:7c:50:12:0f:86:c3:0d:59:8f:4e:c7:5e:83:77:94:74:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/147e117c50120f86c30d598f4ec75e837794748a/; sid:902204518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:54:0c:50:2b:df:5b:61:c9:30:97:25:9a:ee:28:91:b5:f7:27:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94540c502bdf5b61c93097259aee2891b5f72737/; sid:902204519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:0a:61:dc:74:18:2f:e8:21:81:34:df:b2:08:05:cc:26:27:a6:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b10a61dc74182fe8218134dfb20805cc2627a635/; sid:902204520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:3f:8e:05:42:fd:b6:ea:84:c1:5e:ab:d4:d7:ca:c8:b3:47:4e:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/703f8e0542fdb6ea84c15eabd4d7cac8b3474ef1/; sid:902204521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c5:a7:34:4f:b5:0b:dd:8d:71:a7:a3:95:e9:1d:11:0e:42:3d:ed:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5a7344fb50bdd8d71a7a395e91d110e423ded0e/; sid:902204522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"eb:4c:03:3e:dc:a2:7e:b6:86:a6:18:f5:c6:6d:c3:64:3b:c9:8a:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb4c033edca27eb686a618f5c66dc3643bc98a4b/; sid:902204523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"75:dc:b0:f9:8c:1c:c6:c1:23:94:22:89:ed:da:89:1f:54:ee:67:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75dcb0f98c1cc6c123942289edda891f54ee6751/; sid:902204524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"53:7f:cc:1f:d2:e9:9f:a7:58:c6:80:05:a7:32:29:f8:0a:67:66:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/537fcc1fd2e99fa758c68005a73229f80a676606/; sid:902204525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"6c:5b:94:27:c6:d6:3c:06:bd:1d:6e:30:74:8d:cb:94:c3:76:3d:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c5b9427c6d63c06bd1d6e30748dcb94c3763d1c/; sid:902204526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:6a:17:9e:2c:1d:b3:e6:ef:7b:73:b3:0d:af:2c:af:d6:d9:e9:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/926a179e2c1db3e6ef7b73b30daf2cafd6d9e940/; sid:902204527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"24:07:f5:1a:a1:f7:46:91:4c:81:19:ac:30:b6:4b:e3:3f:f5:f3:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2407f51aa1f746914c8119ac30b64be33ff5f323/; sid:902204528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"00:a4:06:11:15:63:8b:15:2b:16:a7:e2:43:10:80:b6:24:4d:0e:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00a4061115638b152b16a7e2431080b6244d0e39/; sid:902204529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"7e:e0:21:16:73:8f:f4:c6:d4:30:cc:5e:9c:a3:ae:e0:79:60:af:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ee02116738ff4c6d430cc5e9ca3aee07960af1b/; sid:902204530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"55:d1:22:4b:ce:61:e0:6d:06:b3:81:92:ae:12:00:4b:07:ad:b7:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55d1224bce61e06d06b38192ae12004b07adb753/; sid:902204531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"98:30:55:6f:4d:8f:99:73:3c:5f:fa:5e:0e:a4:ce:8e:14:a2:0f:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9830556f4d8f99733c5ffa5e0ea4ce8e14a20fe5/; sid:902204532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"bd:c2:6e:f6:62:72:8a:e5:1a:14:ff:28:8c:0f:4b:bc:db:a6:0e:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdc26ef662728ae51a14ff288c0f4bbcdba60e69/; sid:902204533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d9:4b:4b:9d:94:b1:ab:19:79:bb:3d:3b:66:e8:9b:cd:8e:31:59:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d94b4b9d94b1ab1979bb3d3b66e89bcd8e31594c/; sid:902204534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e6:89:be:7c:cf:2b:fe:c6:8c:5f:da:33:99:05:b1:98:3f:b6:c1:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e689be7ccf2bfec68c5fda339905b1983fb6c11a/; sid:902204535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"34:6c:e5:08:bc:44:92:43:2b:00:d0:88:8d:90:d9:c7:ab:d7:77:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/346ce508bc4492432b00d0888d90d9c7abd777b5/; sid:902204536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9d:c8:4b:07:9f:f2:57:f3:9e:0b:81:d6:1c:88:f4:f4:8f:6c:da:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9dc84b079ff257f39e0b81d61c88f4f48f6cdaf7/; sid:902204537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5c:44:bc:16:4d:9a:67:40:45:32:66:42:9b:52:bb:41:36:fd:87:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c44bc164d9a6740453266429b52bb4136fd8742/; sid:902204538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"37:77:10:a8:b0:59:30:36:6e:6f:b2:6c:e2:a7:98:15:c0:47:64:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/377710a8b05930366e6fb26ce2a79815c04764dc/; sid:902204539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RaccoonStealer C&C)"; tls.fingerprint:"98:49:89:0d:6e:4c:db:97:4c:1c:a9:af:43:ff:41:71:27:7f:05:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9849890d6e4cdb974c1ca9af43ff4171277f051a/; sid:902204540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:04:2b:35:3d:16:f5:46:7f:bd:1f:4f:b8:aa:29:10:de:69:0a:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a042b353d16f5467fbd1f4fb8aa2910de690a9d/; sid:902204541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ad:47:20:7d:07:16:e2:c3:72:11:15:bf:8a:32:e3:c8:21:6d:81:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad47207d0716e2c3721115bf8a32e3c8216d81f1/; sid:902204542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"30:5a:d9:e9:5d:c0:28:db:9c:87:ad:73:eb:61:70:38:a7:f2:83:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/305ad9e95dc028db9c87ad73eb617038a7f283c8/; sid:902204543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dc:36:b5:87:d5:3b:01:13:1b:b2:54:20:69:36:5f:43:f1:e9:48:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc36b587d53b01131bb2542069365f43f1e948f9/; sid:902204544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"0f:03:46:bf:4a:bf:28:d3:eb:f7:73:2c:6f:9d:95:62:e1:b2:b0:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f0346bf4abf28d3ebf7732c6f9d9562e1b2b060/; sid:902204545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"af:45:f6:03:5c:17:cd:80:9e:33:c4:6b:11:6e:5a:ed:11:ed:ce:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/af45f6035c17cd809e33c46b116e5aed11edcef0/; sid:902204546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"39:0d:36:81:5d:d2:f7:91:3b:4f:c0:2a:e4:03:46:9d:eb:0d:a0:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/390d36815dd2f7913b4fc02ae403469deb0da09f/; sid:902204547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7d:dc:1d:ad:5c:73:f4:06:b5:6f:48:d7:16:bb:ca:c1:71:b6:93:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ddc1dad5c73f406b56f48d716bbcac171b693e2/; sid:902204548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"58:f7:61:b1:fa:52:40:3a:b8:50:70:9f:13:35:0e:07:e1:29:5b:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58f761b1fa52403ab850709f13350e07e1295b62/; sid:902204549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"91:56:75:c5:5e:2e:bb:e2:b2:f2:6d:da:d2:ff:8a:08:60:41:2b:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/915675c55e2ebbe2b2f26ddad2ff8a0860412b91/; sid:902204550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"09:f6:e5:5d:0a:9c:4d:5e:29:c5:d3:95:2c:12:e5:52:46:cc:93:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09f6e55d0a9c4d5e29c5d3952c12e55246cc9381/; sid:902204551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"24:17:b5:8c:cc:c9:20:98:fd:99:dc:0c:41:54:9f:32:41:0b:f5:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2417b58cccc92098fd99dc0c41549f32410bf562/; sid:902204552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"f2:14:dd:d5:31:9c:aa:66:4a:3e:30:d9:6c:ee:f1:16:cf:d9:5c:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f214ddd5319caa664a3e30d96ceef116cfd95c63/; sid:902204553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"60:02:94:e0:46:0d:d9:47:27:65:b0:6d:aa:03:00:84:7e:03:cc:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/600294e0460dd9472765b06daa0300847e03cc9e/; sid:902204554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"41:a6:2f:a2:e2:d9:58:b6:75:95:c2:64:69:da:07:cd:aa:29:fa:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41a62fa2e2d958b67595c26469da07cdaa29fa5d/; sid:902204555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ArkeiStealer C&C)"; tls.fingerprint:"1d:c5:c4:6e:4d:be:9d:c6:e2:04:c1:08:55:5e:67:c3:de:c9:12:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1dc5c46e4dbe9dc6e204c108555e67c3dec912da/; sid:902204556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ArkeiStealer C&C)"; tls.fingerprint:"65:57:76:7f:90:7e:67:68:e4:e9:71:1c:d2:d4:92:ce:13:b5:20:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6557767f907e6768e4e9711cd2d492ce13b520c8/; sid:902204557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"bf:10:97:41:5b:97:6a:d4:6e:3f:8c:20:f8:85:fc:f4:82:9e:f9:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf1097415b976ad46e3f8c20f885fcf4829ef9fb/; sid:902204558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"7d:06:e7:bd:f3:52:32:57:60:8a:fd:25:6e:c9:f3:23:52:08:dd:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d06e7bdf3523257608afd256ec9f3235208dd8e/; sid:902204559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d3:ba:74:4f:7c:40:9b:46:fd:62:5e:6e:80:6d:4b:86:d6:e3:b2:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3ba744f7c409b46fd625e6e806d4b86d6e3b227/; sid:902204560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fe:51:fb:a9:e3:23:ac:4d:87:9c:38:90:70:11:d8:c5:93:f2:64:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe51fba9e323ac4d879c38907011d8c593f26437/; sid:902204561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8e:1c:10:2b:ae:57:d6:b0:8d:b5:05:7a:05:7a:56:9c:38:37:6c:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e1c102bae57d6b08db5057a057a569c38376c85/; sid:902204562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:bc:31:6b:f5:43:b3:55:50:04:ce:69:d3:b1:bb:c4:3e:0d:d5:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88bc316bf543b3555004ce69d3b1bbc43e0dd53b/; sid:902204563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"3d:e6:fd:47:b3:63:8a:36:86:3c:47:c9:9a:16:84:74:c7:54:53:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3de6fd47b3638a36863c47c99a168474c75453aa/; sid:902204564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"2b:f9:75:f9:c1:ef:c6:e2:83:7c:c5:9e:0b:59:f4:09:bf:ee:6e:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bf975f9c1efc6e2837cc59e0b59f409bfee6e9b/; sid:902204565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"12:3b:70:34:a5:ce:36:8e:46:58:2e:e9:32:89:f0:6d:69:89:b2:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/123b7034a5ce368e46582ee93289f06d6989b2d6/; sid:902204566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"43:73:a5:e6:37:ba:65:50:86:a7:d2:a0:15:3d:f9:6a:60:f5:29:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4373a5e637ba655086a7d2a0153df96a60f52952/; sid:902204567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:1a:8a:5c:4e:e0:91:40:fc:38:d5:7f:dc:3c:38:db:9d:57:15:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/511a8a5c4ee09140fc38d57fdc3c38db9d5715db/; sid:902204568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fd:54:6d:4c:8e:74:59:c3:d1:16:da:83:b7:d6:0a:83:ea:4a:96:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd546d4c8e7459c3d116da83b7d60a83ea4a9636/; sid:902204569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:4d:ef:f7:9f:a8:c1:98:03:66:ea:74:77:46:23:1c:83:68:c9:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/944deff79fa8c1980366ea747746231c8368c9fa/; sid:902204570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1f:d6:26:63:45:a9:d7:c8:23:78:bd:46:c0:89:5a:85:88:31:12:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1fd6266345a9d7c82378bd46c0895a85883112d1/; sid:902204571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3c:38:8c:ad:30:b3:ee:ec:13:94:da:e9:8b:c6:b8:17:04:2e:b6:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c388cad30b3eeec1394dae98bc6b817042eb6f2/; sid:902204572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"57:07:36:de:d5:7f:29:8d:cb:0f:3b:f7:d4:23:a4:eb:72:6e:2b:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/570736ded57f298dcb0f3bf7d423a4eb726e2b72/; sid:902204573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c6:a8:3d:a0:5c:0a:d8:d2:f2:84:98:b0:72:d6:7a:1a:4e:43:9b:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6a83da05c0ad8d2f28498b072d67a1a4e439b0b/; sid:902204574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (ServHelper C&C)"; tls.fingerprint:"00:69:12:0a:0b:94:6b:2d:e0:d8:ce:95:d7:80:c8:68:a3:41:96:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0069120a0b946b2de0d8ce95d780c868a341960a/; sid:902204575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b8:bb:08:f5:01:a5:6a:a7:f0:f2:80:b3:4e:14:17:a0:b0:5d:d5:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8bb08f501a56aa7f0f280b34e1417a0b05dd561/; sid:902204576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Ousaban C&C)"; tls.fingerprint:"73:bb:e1:30:c5:0f:1f:b4:59:e3:9c:15:1a:08:59:cf:b9:7b:94:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73bbe130c50f1fb459e39c151a0859cfb97b9402/; sid:902204577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d5:55:b6:ef:35:d3:57:18:40:4a:8f:d6:63:b7:39:68:b3:58:d9:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d555b6ef35d35718404a8fd663b73968b358d941/; sid:902204578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d1:b0:f9:b5:28:b3:cb:de:d3:8d:93:a0:7b:20:3c:93:2c:70:ff:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d1b0f9b528b3cbded38d93a07b203c932c70ffd6/; sid:902204579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"db:58:ae:f6:8a:e7:d5:05:25:99:8e:3c:7d:ce:76:04:ab:35:d9:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db58aef68ae7d50525998e3c7dce7604ab35d9c6/; sid:902204580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"fa:3a:5c:92:93:dc:2c:d6:de:53:4d:cb:bf:76:0b:29:9f:7a:bd:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa3a5c9293dc2cd6de534dcbbf760b299f7abd72/; sid:902204581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"1c:6c:18:4d:d8:b0:85:59:0a:f5:7f:02:d0:59:2f:cd:f9:b7:c0:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c6c184dd8b085590af57f02d0592fcdf9b7c0ac/; sid:902204582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1b:56:69:cb:e7:b2:c6:ae:bf:8d:30:8e:f1:4e:f2:7d:3e:8b:c1:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b5669cbe7b2c6aebf8d308ef14ef27d3e8bc181/; sid:902204583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"74:48:ea:4e:97:1a:9b:61:ac:3e:c5:76:ed:b4:7b:6a:d3:ec:7e:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7448ea4e971a9b61ac3ec576edb47b6ad3ec7e53/; sid:902204584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:2f:2b:13:64:73:6e:27:60:9f:d4:9c:3d:6f:0f:cc:b9:a8:3f:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e2f2b1364736e27609fd49c3d6f0fccb9a83fb0/; sid:902204585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"a3:85:b6:81:06:91:94:39:72:19:25:a7:eb:0c:3f:3d:02:e8:9c:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a385b68106919439721925a7eb0c3f3d02e89c1d/; sid:902204586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"71:ec:b5:81:a2:91:c2:3e:99:68:b8:8c:58:b0:b9:b0:7b:af:3f:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71ecb581a291c23e9968b88c58b0b9b07baf3f05/; sid:902204587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"33:57:a4:de:44:49:0b:ce:5f:49:5d:27:c2:74:1c:19:fb:56:cc:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3357a4de44490bce5f495d27c2741c19fb56cc0d/; sid:902204588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"06:b0:99:f4:7b:2f:cd:9d:72:97:b7:c4:1f:36:39:b4:33:a8:11:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06b099f47b2fcd9d7297b7c41f3639b433a81125/; sid:902204589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"11:41:c4:12:10:c0:ab:79:1f:3c:8b:51:54:2e:e1:6c:55:33:ec:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1141c41210c0ab791f3c8b51542ee16c5533ec60/; sid:902204590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8a:2a:a2:c8:c9:7a:ad:7a:1b:fe:0c:bf:42:9d:57:0c:10:3e:c1:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a2aa2c8c97aad7a1bfe0cbf429d570c103ec1ac/; sid:902204591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:f1:22:fc:39:83:d5:ae:14:4e:32:48:1e:08:80:63:1e:ed:ae:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29f122fc3983d5ae144e32481e0880631eedaeab/; sid:902204592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:a2:aa:37:63:1e:9e:64:ef:71:1a:48:00:8c:8f:00:e3:3d:26:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6a2aa37631e9e64ef711a48008c8f00e33d26fc/; sid:902204593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b4:01:c0:03:b2:5e:95:2e:63:aa:24:09:86:ff:b7:7f:9f:4f:f1:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b401c003b25e952e63aa240986ffb77f9f4ff17e/; sid:902204594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"a5:e8:12:ef:7e:2a:c5:43:40:12:0a:f8:af:e8:b4:14:ab:fd:5d:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5e812ef7e2ac54340120af8afe8b414abfd5d83/; sid:902204595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:9c:ef:69:c3:26:c6:6a:23:8d:86:73:8c:5d:1d:a1:5e:44:67:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/059cef69c326c66a238d86738c5d1da15e44672a/; sid:902204596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d6:dd:96:6c:1f:69:9c:23:20:d9:85:19:f1:4d:4b:f5:6c:a7:d5:ee"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6dd966c1f699c2320d98519f14d4bf56ca7d5ee/; sid:902204597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e4:f8:15:1c:9d:72:e8:53:80:e4:75:df:0a:ba:e1:1f:98:62:ea:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4f8151c9d72e85380e475df0abae11f9862eac0/; sid:902204598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"94:af:13:ef:54:33:ff:15:65:a1:9a:b8:4e:e2:40:6f:08:f2:41:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94af13ef5433ff1565a19ab84ee2406f08f24159/; sid:902204599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"84:13:14:21:f3:93:04:00:f0:a5:bd:f2:af:99:e1:d0:75:f6:9b:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84131421f3930400f0a5bdf2af99e1d075f69b3a/; sid:902204600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5b:46:cd:45:71:4e:14:58:f8:d4:95:b2:96:68:2c:d9:ec:65:8d:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b46cd45714e1458f8d495b296682cd9ec658dcf/; sid:902204601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"da:b6:73:b1:07:f5:21:84:8a:35:63:ff:25:73:76:48:18:e6:7f:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dab673b107f521848a3563ff2573764818e67f84/; sid:902204602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"13:2a:42:bc:cc:14:c6:8f:08:63:3e:55:3b:66:88:90:2b:55:6a:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/132a42bccc14c68f08633e553b6688902b556ae0/; sid:902204603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d3:f9:23:e9:de:dd:dc:65:f5:28:0a:c9:c0:70:84:ca:82:ac:4c:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3f923e9dedddc65f5280ac9c07084ca82ac4c22/; sid:902204604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"93:60:80:84:d3:86:c5:aa:30:13:9a:d2:16:87:3b:a5:0f:a9:1b:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93608084d386c5aa30139ad216873ba50fa91b59/; sid:902204605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"95:f4:fe:fc:1e:91:d3:aa:f7:76:b2:0d:b2:78:a2:57:47:3b:5e:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/95f4fefc1e91d3aaf776b20db278a257473b5edc/; sid:902204606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bd:98:ed:72:32:7f:6d:3e:ba:4e:e7:3c:d6:bc:52:ab:92:5a:59:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bd98ed72327f6d3eba4ee73cd6bc52ab925a595e/; sid:902204607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5f:bd:2e:36:bb:4f:0e:0e:24:36:02:9e:20:ce:9a:7f:e6:ee:36:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fbd2e36bb4f0e0e2436029e20ce9a7fe6ee36f0/; sid:902204608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d7:9e:fe:af:55:c9:0a:ea:4c:0e:b5:3b:87:a6:6a:49:9b:ad:b7:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d79efeaf55c90aea4c0eb53b87a66a499badb764/; sid:902204609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3d:85:74:f3:30:26:61:85:f8:da:9f:89:81:a7:b3:9b:1d:22:70:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d8574f330266185f8da9f8981a7b39b1d2270d8/; sid:902204610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:5b:04:99:95:62:ea:1c:29:e7:69:d2:c6:bc:f5:d0:78:22:d6:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e75b04999562ea1c29e769d2c6bcf5d07822d646/; sid:902204611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c0:3c:cb:cc:77:bf:65:d0:ed:fc:ad:1f:cb:a2:46:e3:0a:be:52:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c03ccbcc77bf65d0edfcad1fcba246e30abe5298/; sid:902204612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ce:85:d4:f2:81:4f:41:46:8c:99:e4:c4:bf:c7:a1:a8:a9:a4:5d:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce85d4f2814f41468c99e4c4bfc7a1a8a9a45dd1/; sid:902204613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3d:17:4a:0f:d4:94:67:20:13:32:99:2a:1f:72:18:41:4f:3b:fe:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d174a0fd49467201332992a1f7218414f3bfe23/; sid:902204614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:3b:f7:df:eb:12:7b:49:ad:a2:b5:c8:78:0f:3a:e3:b9:9c:c1:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c63bf7dfeb127b49ada2b5c8780f3ae3b99cc18e/; sid:902204615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:00:2b:af:c6:e9:a7:55:60:98:c3:9b:81:c4:a4:8b:4f:42:a2:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75002bafc6e9a7556098c39b81c4a48b4f42a2bf/; sid:902204616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"28:ce:ad:e1:84:97:ae:a4:12:2d:f1:de:38:70:6e:80:53:68:91:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28ceade18497aea4122df1de38706e80536891b6/; sid:902204617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"86:cf:a4:41:4e:48:06:84:de:39:ec:c0:f4:62:af:be:ae:58:c4:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86cfa4414e480684de39ecc0f462afbeae58c471/; sid:902204618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"7d:5e:86:56:5d:82:bd:28:28:f7:e6:ca:9d:bf:fc:1b:5f:e5:c9:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d5e86565d82bd2828f7e6ca9dbffc1b5fe5c940/; sid:902204619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2d:b0:64:e4:cb:e1:bc:5d:4c:8f:34:36:9f:40:8c:09:85:6c:a3:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2db064e4cbe1bc5d4c8f34369f408c09856ca32e/; sid:902204620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:bd:bf:86:76:e3:c4:5e:1a:81:05:77:01:2a:bf:a6:10:2b:16:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c5bdbf8676e3c45e1a810577012abfa6102b169b/; sid:902204621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"e6:8d:e8:08:90:48:93:e7:38:e0:be:4e:b7:a3:40:fd:c8:d2:d8:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e68de808904893e738e0be4eb7a340fdc8d2d8c6/; sid:902204622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9d:3a:ef:40:cf:17:fc:40:18:c0:3b:b6:f2:55:6c:16:22:97:26:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d3aef40cf17fc4018c03bb6f2556c1622972638/; sid:902204623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:bc:4a:24:36:08:ef:3d:02:10:09:2f:e2:9b:d2:7e:03:37:c1:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25bc4a243608ef3d0210092fe29bd27e0337c165/; sid:902204624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"57:37:ba:25:af:59:ef:5e:97:b6:3b:9a:04:ee:86:aa:08:b9:77:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5737ba25af59ef5e97b63b9a04ee86aa08b977ec/; sid:902204625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NanoCore C&C)"; tls.fingerprint:"fb:33:89:b6:1b:0e:38:56:02:57:a0:fd:76:d5:e0:65:4b:5b:7a:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb3389b61b0e38560257a0fd76d5e0654b5b7ab6/; sid:902204626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"08:0d:b6:be:ae:8b:88:3d:41:01:ce:4a:da:d3:36:d3:49:3f:e9:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/080db6beae8b883d4101ce4adad336d3493fe9d9/; sid:902204627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"62:b5:b3:27:ea:fb:32:38:8a:81:e2:65:cf:f1:77:8c:b2:76:16:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62b5b327eafb32388a81e265cff1778cb27616cf/; sid:902204628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:9f:54:bb:51:36:1c:0f:22:5e:6f:85:32:10:55:7d:53:2c:c9:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c99f54bb51361c0f225e6f853210557d532cc909/; sid:902204629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4a:d3:ab:ef:b8:ce:81:93:f5:65:3a:be:3a:d2:d9:2d:ee:62:54:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ad3abefb8ce8193f5653abe3ad2d92dee625492/; sid:902204630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5f:e9:ff:16:82:07:c2:0d:a2:7d:dd:ad:16:c6:ba:12:e2:85:27:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5fe9ff168207c20da27dddad16c6ba12e28527d3/; sid:902204631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"fc:b2:f0:9b:7f:23:54:75:20:bf:3a:e4:43:6d:25:0d:98:02:ec:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcb2f09b7f23547520bf3ae4436d250d9802ecf6/; sid:902204632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"57:81:32:37:d2:95:18:84:5b:9d:3d:b0:85:c2:ea:a2:4d:bf:3c:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57813237d29518845b9d3db085c2eaa24dbf3c85/; sid:902204633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e1:84:e3:1f:5e:2c:d9:fe:44:cd:81:f3:f3:b7:a6:9e:1c:5b:5f:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e184e31f5e2cd9fe44cd81f3f3b7a69e1c5b5ffb/; sid:902204634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:e3:7f:38:74:04:05:4b:ea:6e:cc:ca:1c:3f:b9:33:6f:52:e4:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ee37f387404054bea6eccca1c3fb9336f52e498/; sid:902204635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:02:19:58:63:52:bd:31:93:b3:2e:8d:2c:71:fc:90:ee:6b:e8:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/870219586352bd3193b32e8d2c71fc90ee6be830/; sid:902204636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ed:2b:5b:a7:e1:45:16:e3:9c:02:02:ac:06:26:95:e6:b0:48:4a:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed2b5ba7e14516e39c0202ac062695e6b0484a89/; sid:902204637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d6:94:9f:ac:eb:ae:bc:d5:08:d8:bf:2b:12:07:d9:ab:18:fe:b7:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6949facebaebcd508d8bf2b1207d9ab18feb70e/; sid:902204638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3e:4a:4b:3c:0d:3f:4f:71:a1:4d:db:e9:85:d1:8e:4a:44:5c:93:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e4a4b3c0d3f4f71a14ddbe985d18e4a445c93f2/; sid:902204639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:f1:36:82:e2:46:2c:30:d4:09:e7:f2:8e:27:26:6f:97:6c:d2:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bf13682e2462c30d409e7f28e27266f976cd2d0/; sid:902204640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9d:d8:d8:aa:c9:44:cd:a6:52:14:99:50:36:04:8b:50:42:b6:97:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9dd8d8aac944cda65214995036048b5042b69765/; sid:902204641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"e6:22:1c:21:3b:dc:82:8e:50:98:e8:15:22:46:0c:b4:ea:f2:e3:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e6221c213bdc828e5098e81522460cb4eaf2e383/; sid:902204642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6e:fb:ca:01:b1:4a:61:a1:51:95:43:db:33:fa:e3:8d:22:e9:99:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6efbca01b14a61a1519543db33fae38d22e99941/; sid:902204643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c3:c4:ea:89:1b:58:69:9e:24:1e:ab:46:a9:84:bb:de:b3:ce:70:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3c4ea891b58699e241eab46a984bbdeb3ce7037/; sid:902204644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"23:f6:ed:d8:ef:8c:de:c8:e1:79:17:5d:b7:fc:a4:7b:98:c9:c1:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23f6edd8ef8cdec8e179175db7fca47b98c9c16d/; sid:902204645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"04:f0:19:b2:54:17:52:7f:b4:d8:93:07:17:b1:a2:cc:ba:ba:ff:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/04f019b25417527fb4d8930717b1a2ccbabaff09/; sid:902204646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:fe:e3:b5:ad:ab:ca:9b:08:27:a9:ff:17:59:23:c1:9e:ef:97:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06fee3b5adabca9b0827a9ff175923c19eef9759/; sid:902204647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a4:ee:b4:ae:c0:54:7e:9e:07:e3:14:e5:16:0f:78:73:78:73:e6:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4eeb4aec0547e9e07e314e5160f78737873e6dc/; sid:902204648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"7a:e7:91:ca:bc:e9:14:eb:58:df:74:fa:ea:87:6f:f3:ab:ff:b9:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ae791cabce914eb58df74faea876ff3abffb998/; sid:902204649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"46:77:05:f5:3b:e6:86:0c:ca:86:1e:30:a5:62:99:7d:9b:ad:62:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/467705f53be6860cca861e30a562997d9bad627d/; sid:902204650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:da:7d:0e:93:d8:98:cf:a0:96:5a:11:8f:a6:d7:ec:71:69:a1:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25da7d0e93d898cfa0965a118fa6d7ec7169a122/; sid:902204651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:6b:62:cd:1b:e0:ef:1e:2a:96:75:1b:95:9e:77:3e:27:7b:51:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/876b62cd1be0ef1e2a96751b959e773e277b510a/; sid:902204652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"58:a1:77:ff:b4:0e:14:64:1b:ab:d6:51:f1:30:a9:1a:ab:30:22:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58a177ffb40e14641babd651f130a91aab302234/; sid:902204653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"93:d5:39:ed:ad:8a:aa:04:c7:78:01:ad:93:cf:0d:76:a9:12:cb:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93d539edad8aaa04c77801ad93cf0d76a912cb60/; sid:902204654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0c:90:84:77:69:56:2b:a8:8e:f4:99:f9:f9:f6:59:f1:77:b4:62:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c90847769562ba88ef499f9f9f659f177b462cf/; sid:902204655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f7:71:33:ad:6a:40:14:c9:2a:13:b3:8c:30:6a:73:72:79:e0:74:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f77133ad6a4014c92a13b38c306a737279e074f5/; sid:902204656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"9a:6c:e9:30:a5:49:00:6a:70:4d:76:6a:25:40:df:17:31:e1:57:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a6ce930a549006a704d766a2540df1731e1579c/; sid:902204657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"6c:cc:df:1b:f0:6b:94:bd:bb:ee:4d:e9:cf:09:5d:00:3f:ea:eb:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cccdf1bf06b94bdbbee4de9cf095d003feaebb3/; sid:902204658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c8:a5:8b:f5:6c:23:3b:f1:76:b8:2e:1a:12:e6:76:a9:7e:85:13:3f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8a58bf56c233bf176b82e1a12e676a97e85133f/; sid:902204659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"04:11:d8:b9:b2:35:47:f8:67:33:34:7b:06:34:01:0f:11:2e:15:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0411d8b9b23547f86733347b0634010f112e158f/; sid:902204660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"45:1a:95:ac:e7:f4:8c:d7:62:c4:d2:e3:e4:a0:29:43:97:86:ad:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/451a95ace7f48cd762c4d2e3e4a029439786adce/; sid:902204661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"be:54:f0:00:f8:4c:67:62:d6:30:cb:95:04:86:71:82:00:d1:51:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be54f000f84c6762d630cb950486718200d15186/; sid:902204662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6c:ec:09:bc:b5:75:35:27:85:d3:13:c7:e9:78:f2:6b:fb:d5:28:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cec09bcb575352785d313c7e978f26bfbd528ab/; sid:902204663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"78:bf:bd:93:1d:dd:e8:b1:c2:37:67:e1:16:79:98:3a:3b:97:a4:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78bfbd931ddde8b1c23767e11679983a3b97a42a/; sid:902204664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f2:00:29:6e:05:89:46:93:3f:f5:91:62:25:4c:95:d6:a1:ff:14:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f200296e058946933ff59162254c95d6a1ff1456/; sid:902204665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8a:ce:7e:c9:c8:d6:4c:01:30:55:54:74:66:c8:a5:08:4e:ef:15:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ace7ec9c8d64c013055547466c8a5084eef159a/; sid:902204666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"27:39:48:23:0a:9d:97:23:1e:c5:6f:d8:26:31:16:7d:c8:1a:8e:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/273948230a9d97231ec56fd82631167dc81a8e37/; sid:902204667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:c9:b1:21:08:a7:6a:db:3e:9e:5c:5f:fb:e0:20:60:49:44:37:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27c9b12108a76adb3e9e5c5ffbe02060494437f4/; sid:902204668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"82:88:80:ee:b4:f6:7b:c5:e5:3a:3d:66:b2:18:24:ee:8c:b0:f7:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/828880eeb4f67bc5e53a3d66b21824ee8cb0f74b/; sid:902204669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:c0:32:0a:ca:de:ba:15:53:f8:fd:48:d1:5f:a5:76:12:e8:31:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ffc0320acadeba1553f8fd48d15fa57612e83186/; sid:902204670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f8:68:1b:1d:32:98:74:e6:b9:be:2d:ca:07:20:29:dc:60:80:bd:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8681b1d329874e6b9be2dca072029dc6080bd1b/; sid:902204671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"61:3e:2c:8b:8a:ec:17:71:02:20:83:2d:bf:e3:84:e1:f9:4e:86:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/613e2c8b8aec17710220832dbfe384e1f94e86cf/; sid:902204672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"81:fd:00:66:e7:0f:35:af:af:fc:21:39:1d:79:8b:3b:a5:95:d6:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81fd0066e70f35afaffc21391d798b3ba595d669/; sid:902204673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:e9:1a:b8:b3:1a:13:2d:bc:fb:2b:61:8f:d3:68:a4:fa:aa:e7:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1e91ab8b31a132dbcfb2b618fd368a4faaae721/; sid:902204674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"77:9d:2a:15:02:e4:e7:0a:73:c4:d0:9c:92:50:31:dc:83:e3:5e:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/779d2a1502e4e70a73c4d09c925031dc83e35e41/; sid:902204675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"33:8d:a4:03:dd:d4:fd:9e:2c:ae:23:fe:49:cb:0b:b1:54:00:5a:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/338da403ddd4fd9e2cae23fe49cb0bb154005a18/; sid:902204676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"7e:2a:fd:00:4e:78:56:ab:98:f9:6c:8e:b1:15:8c:1e:5e:87:b6:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e2afd004e7856ab98f96c8eb1158c1e5e87b605/; sid:902204677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"5b:82:e5:eb:98:0f:59:18:6b:a7:df:a8:c9:97:ea:7c:0d:b1:58:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b82e5eb980f59186ba7dfa8c997ea7c0db158e6/; sid:902204678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"da:91:53:f5:1c:f1:f9:93:39:32:9b:11:aa:4f:ee:c8:60:a5:71:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da9153f51cf1f99339329b11aa4feec860a5713b/; sid:902204679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2e:b8:fd:06:a9:6e:d0:b2:27:8a:20:08:97:c9:b4:c1:1b:8e:c2:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2eb8fd06a96ed0b2278a200897c9b4c11b8ec20f/; sid:902204680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5d:8e:43:1e:a5:8e:ba:50:44:d7:d7:2f:0b:9c:be:0b:81:1a:52:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d8e431ea58eba5044d7d72f0b9cbe0b811a5266/; sid:902204681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"10:7c:1a:e3:44:f7:4a:46:f7:d1:e7:8b:c3:78:1e:5b:66:a0:a7:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/107c1ae344f74a46f7d1e78bc3781e5b66a0a7d8/; sid:902204682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"97:a9:ee:9f:0a:07:11:f2:6f:6c:e0:1a:17:2d:6a:c9:24:3b:6e:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97a9ee9f0a0711f26f6ce01a172d6ac9243b6ebe/; sid:902204683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"58:73:9f:ad:9d:e8:5e:90:d0:fa:a1:43:37:c5:35:a3:0f:9c:4f:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58739fad9de85e90d0faa14337c535a30f9c4fb4/; sid:902204684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"96:a6:7a:50:80:f5:be:08:65:b0:ea:80:55:66:46:65:2e:1c:4e:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96a67a5080f5be0865b0ea80556646652e1c4e6f/; sid:902204685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"3b:83:d6:f6:dd:0b:94:1c:47:36:7d:67:50:c9:4b:da:02:90:9d:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b83d6f6dd0b941c47367d6750c94bda02909d84/; sid:902204686; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:d4:da:75:e8:4c:c2:c1:d0:9d:a3:22:42:a6:58:d4:59:61:81:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7d4da75e84cc2c1d09da32242a658d459618143/; sid:902204687; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"34:ee:15:ee:f0:ca:19:74:ba:60:e0:83:bc:6e:d0:69:3c:ca:3c:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34ee15eef0ca1974ba60e083bc6ed0693cca3cc9/; sid:902204688; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"49:fa:f8:5c:97:bb:43:af:1e:64:10:11:d4:8a:b0:eb:c5:8c:47:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49faf85c97bb43af1e641011d48ab0ebc58c478e/; sid:902204689; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:cb:38:fc:f4:9a:17:e0:e5:4a:d2:2c:09:5c:2b:24:e6:f8:5d:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82cb38fcf49a17e0e54ad22c095c2b24e6f85de2/; sid:902204690; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:43:6c:30:b4:27:96:09:31:90:80:61:27:8b:85:ae:d6:7a:7e:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a436c30b427960931908061278b85aed67a7e67/; sid:902204691; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"12:04:58:01:87:84:9e:13:76:f8:f7:78:50:7d:f5:a9:f0:15:69:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1204580187849e1376f8f778507df5a9f01569a6/; sid:902204692; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:52:5a:9c:6d:57:6d:0a:c2:13:94:40:61:9d:29:fc:51:87:4a:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08525a9c6d576d0ac2139440619d29fc51874a77/; sid:902204693; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ac:01:72:a4:15:90:d4:27:4a:12:ee:9c:92:d5:e5:23:ee:6f:d8:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac0172a41590d4274a12ee9c92d5e523ee6fd8e0/; sid:902204694; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6b:2e:a0:5d:5a:ab:7b:06:af:6e:86:28:2e:23:83:7e:02:3d:b0:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b2ea05d5aab7b06af6e86282e23837e023db0b8/; sid:902204695; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ac:b1:31:d0:31:b8:71:cf:13:86:25:71:42:6b:63:53:fa:4a:3f:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acb131d031b871cf13862571426b6353fa4a3fe3/; sid:902204696; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"45:5e:6b:e3:0d:77:86:bc:85:bd:e4:ba:7e:b9:09:a7:5e:88:af:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/455e6be30d7786bc85bde4ba7eb909a75e88af63/; sid:902204697; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:ae:6a:00:8a:30:51:f7:f6:dc:c0:04:0f:02:99:fc:1c:b9:7a:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82ae6a008a3051f7f6dcc0040f0299fc1cb97aa9/; sid:902204698; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PhoenixRAT C&C)"; tls.fingerprint:"2d:e7:a6:1d:40:9e:5f:0f:ec:cf:d5:86:52:ed:1d:5c:f3:99:e7:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2de7a61d409e5f0feccfd58652ed1d5cf399e70c/; sid:902204699; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ca:3f:d5:1c:56:33:ff:7c:54:3f:ab:2f:6f:c3:92:18:b2:e0:2d:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca3fd51c5633ff7c543fab2f6fc39218b2e02db7/; sid:902204700; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6c:3d:1e:f6:0e:f1:4c:b5:48:14:0a:64:d6:c6:0b:af:ea:1a:a9:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c3d1ef60ef14cb548140a64d6c60bafea1aa98a/; sid:902204701; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"04:56:08:f3:96:6c:50:2f:ee:ee:89:31:db:16:9e:08:4d:2b:47:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/045608f3966c502feeee8931db169e084d2b475c/; sid:902204702; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f9:98:c1:9b:07:82:3d:60:d4:1f:dc:e3:40:7c:27:7b:cf:63:e0:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f998c19b07823d60d41fdce3407c277bcf63e0cb/; sid:902204703; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"50:51:27:5d:21:29:7b:ec:da:89:e4:ad:67:e3:6d:34:d5:2c:a1:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5051275d21297becda89e4ad67e36d34d52ca179/; sid:902204704; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1f:2e:05:5d:51:ee:10:fb:8d:65:dc:28:0f:bf:c8:d4:61:5e:fa:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f2e055d51ee10fb8d65dc280fbfc8d4615efa16/; sid:902204705; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5d:5d:9d:e4:a7:87:40:71:c3:61:d9:27:95:07:da:43:2d:55:17:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d5d9de4a7874071c361d9279507da432d55175d/; sid:902204706; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b0:b1:1f:67:59:2a:05:83:c4:bf:28:34:53:fa:31:b4:1c:6b:b8:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0b11f67592a0583c4bf283453fa31b41c6bb8b2/; sid:902204707; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"7f:d9:da:4a:fb:65:56:9f:0f:48:d0:cc:eb:b9:ac:b8:ed:e7:ca:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7fd9da4afb65569f0f48d0ccebb9acb8ede7ca9b/; sid:902204708; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e0:12:78:f6:49:07:36:f0:c6:30:0b:67:98:56:90:94:a9:ca:ed:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e01278f6490736f0c6300b6798569094a9caed9b/; sid:902204709; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:e6:5c:13:61:65:92:a4:99:16:d1:1b:af:4c:76:b8:75:b7:c5:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14e65c13616592a49916d11baf4c76b875b7c5f5/; sid:902204710; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a1:06:36:4d:54:42:ba:17:7d:46:74:f1:0d:b4:b8:8d:75:66:a1:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a106364d5442ba177d4674f10db4b88d7566a131/; sid:902204711; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"40:e6:f0:fd:a8:c8:00:0e:f9:d9:99:52:de:7c:4d:5c:a1:37:19:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40e6f0fda8c8000ef9d99952de7c4d5ca1371983/; sid:902204712; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"81:19:08:5b:4f:7a:8d:86:9e:4b:47:c1:62:fe:3e:cf:1e:e2:78:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8119085b4f7a8d869e4b47c162fe3ecf1ee27837/; sid:902204713; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"07:03:37:03:0e:cb:28:a4:7e:38:25:fd:79:99:f2:55:ae:ee:fb:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/070337030ecb28a47e3825fd7999f255aeeefb49/; sid:902204714; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0b:42:32:52:36:e8:6d:49:52:58:fe:26:25:1e:8b:73:4d:dc:37:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b42325236e86d495258fe26251e8b734ddc37a3/; sid:902204715; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:77:ef:63:0d:82:98:58:9b:19:ce:f5:b6:90:6b:b8:86:8b:91:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b377ef630d8298589b19cef5b6906bb8868b91f8/; sid:902204716; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f0:5c:0f:5b:f6:39:97:cb:29:1e:ab:49:2e:33:6f:eb:87:32:8c:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f05c0f5bf63997cb291eab492e336feb87328c01/; sid:902204717; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:ec:d7:cc:d0:73:25:fe:2f:a0:67:ce:10:bb:99:12:3c:98:ce:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87ecd7ccd07325fe2fa067ce10bb99123c98ce4c/; sid:902204718; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c9:61:35:0e:68:e1:4d:3f:1b:bb:77:83:3c:b8:76:66:9d:3d:7f:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c961350e68e14d3f1bbb77833cb876669d3d7f2a/; sid:902204719; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:85:ec:c6:87:12:9c:2f:10:14:33:4b:36:13:4d:87:8f:dc:1a:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf85ecc687129c2f1014334b36134d878fdc1a18/; sid:902204720; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"10:8c:3a:b5:40:9f:00:43:42:87:5a:2c:82:fd:51:dd:aa:72:74:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/108c3ab5409f004342875a2c82fd51ddaa7274ac/; sid:902204721; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"47:95:eb:97:a0:5a:e5:f4:e6:69:d4:b7:ff:f6:60:8d:94:fc:90:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4795eb97a05ae5f4e669d4b7fff6608d94fc9027/; sid:902204722; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"96:b3:bf:65:a5:f6:cb:de:b1:60:6c:f8:2f:52:0d:64:27:fa:a8:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96b3bf65a5f6cbdeb1606cf82f520d6427faa8fc/; sid:902204723; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"60:59:84:89:eb:06:31:0a:48:ab:6f:5a:a1:9a:09:59:34:d6:09:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60598489eb06310a48ab6f5aa19a095934d609e8/; sid:902204724; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"80:e5:b2:af:6a:e1:3f:f2:23:1b:6e:fc:92:c9:fa:e4:67:41:a9:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80e5b2af6ae13ff2231b6efc92c9fae46741a917/; sid:902204725; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"7d:72:39:8d:29:af:30:c7:79:c5:84:0e:36:ed:b1:06:d4:3d:f6:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d72398d29af30c779c5840e36edb106d43df60a/; sid:902204726; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:e4:09:32:82:5d:ce:dc:54:3a:6a:92:96:56:87:75:7a:70:33:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ee40932825dcedc543a6a92965687757a70338a/; sid:902204727; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:f9:40:d8:5c:05:a9:51:87:67:e2:35:79:b2:14:21:e6:83:8e:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9cf940d85c05a9518767e23579b21421e6838e27/; sid:902204728; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a9:61:70:27:e4:25:4f:d1:98:70:e2:f4:87:7f:39:28:25:2e:3e:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9617027e4254fd19870e2f4877f3928252e3ecf/; sid:902204729; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"9f:cb:39:9a:79:c0:f6:31:6d:90:33:2d:81:05:8b:ec:1b:04:d4:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9fcb399a79c0f6316d90332d81058bec1b04d435/; sid:902204730; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"be:5a:2c:97:67:03:27:29:00:32:f1:20:ed:cd:07:96:29:5b:5e:ac"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be5a2c97670327290032f120edcd0796295b5eac/; sid:902204731; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"84:75:e7:38:0a:3f:0c:b0:6f:59:50:81:69:87:06:a4:77:53:19:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8475e7380a3f0cb06f595081698706a4775319f1/; sid:902204732; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dc:9f:f4:9c:fc:a9:95:e2:66:6e:3f:6d:23:ec:95:a6:aa:82:36:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc9ff49cfca995e2666e3f6d23ec95a6aa823697/; sid:902204733; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"5c:67:e2:d3:e4:88:62:2d:20:0f:bb:8b:f3:41:82:06:df:e0:5a:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c67e2d3e488622d200fbb8bf3418206dfe05a5b/; sid:902204734; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c1:88:e5:23:74:bb:08:9b:9c:dc:ff:20:dd:9f:f2:53:c3:70:ff:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c188e52374bb089b9cdcff20dd9ff253c370ff93/; sid:902204735; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"34:06:ad:b2:0f:28:59:f8:93:d5:a1:70:c5:49:7f:82:3a:b2:12:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3406adb20f2859f893d5a170c5497f823ab2121e/; sid:902204736; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"71:60:71:f3:52:73:a4:cf:f5:f2:26:7b:97:95:ab:e2:39:55:62:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/716071f35273a4cff5f2267b9795abe239556263/; sid:902204737; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:e2:2d:41:30:1d:73:34:c6:46:4d:4a:a3:3f:dc:83:c5:c3:37:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f7e22d41301d7334c6464d4aa33fdc83c5c337f8/; sid:902204738; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"da:46:89:b9:6c:81:1d:32:ab:37:07:e5:88:00:93:19:f9:6e:56:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da4689b96c811d32ab3707e588009319f96e569a/; sid:902204739; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:b0:6e:5d:e3:44:37:8b:5d:aa:75:52:74:67:92:91:3f:ab:c0:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38b06e5de344378b5daa7552746792913fabc095/; sid:902204740; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6c:b5:6a:c7:1f:9a:f3:a9:46:3a:49:de:13:eb:6d:7a:90:24:8f:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cb56ac71f9af3a9463a49de13eb6d7a90248fb8/; sid:902204741; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"5b:92:86:16:5a:84:2e:62:79:8f:27:d4:39:33:15:b8:cd:1b:4f:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5b9286165a842e62798f27d4393315b8cd1b4fe8/; sid:902204742; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bf:80:91:e1:24:22:7c:ca:e7:2f:cf:08:70:6e:31:d6:64:2e:61:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf8091e124227ccae72fcf08706e31d6642e61bb/; sid:902204743; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"40:00:5a:c5:bc:24:78:d6:f5:88:b3:16:1b:b3:e2:59:14:a9:0f:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40005ac5bc2478d6f588b3161bb3e25914a90f83/; sid:902204744; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8c:b0:65:68:b4:cf:b3:0b:8b:25:04:f6:e5:f7:ed:ff:42:04:28:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8cb06568b4cfb30b8b2504f6e5f7edff42042887/; sid:902204745; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:83:73:4f:00:ca:47:9c:4e:78:8d:f7:b7:6e:3d:47:ab:1c:df:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a983734f00ca479c4e788df7b76e3d47ab1cdf28/; sid:902204746; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"dc:e0:61:5a:75:e1:a4:db:9d:a9:22:2b:1f:96:8d:9f:02:f7:58:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dce0615a75e1a4db9da9222b1f968d9f02f75882/; sid:902204747; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"61:a8:61:57:b2:97:0b:2e:b0:9b:7a:0c:3a:2b:8e:43:3a:ac:7c:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61a86157b2970b2eb09b7a0c3a2b8e433aac7cd8/; sid:902204748; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:be:6c:69:1a:96:79:2a:a5:c8:1a:4c:17:40:ea:ce:89:60:94:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9be6c691a96792aa5c81a4c1740eace896094f1/; sid:902204749; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"47:13:9b:bc:3c:52:74:a9:e4:44:43:67:ae:51:ab:22:65:f8:50:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47139bbc3c5274a9e4444367ae51ab2265f850ae/; sid:902204750; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1b:dc:63:17:19:1e:32:0b:3c:26:e8:f6:32:0e:ab:0c:5d:d2:6d:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1bdc6317191e320b3c26e8f6320eab0c5dd26dc8/; sid:902204751; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"3e:18:7a:f7:c1:e6:da:c2:43:44:76:83:9b:57:e4:12:bc:d3:e6:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e187af7c1e6dac2434476839b57e412bcd3e679/; sid:902204752; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ca:99:9c:30:d1:d4:88:a4:c0:f9:cf:50:b2:8d:42:03:d5:be:ef:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca999c30d1d488a4c0f9cf50b28d4203d5beef0c/; sid:902204753; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"9c:15:1e:b9:a0:db:bd:17:72:20:74:a7:48:15:3d:56:bf:64:f7:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c151eb9a0dbbd17722074a748153d56bf64f723/; sid:902204754; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0d:2b:b0:47:0f:a5:b8:fc:63:66:7d:03:c9:a0:90:1d:71:1e:3a:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d2bb0470fa5b8fc63667d03c9a0901d711e3a17/; sid:902204755; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1c:3f:5b:11:b6:8a:da:7a:4c:f5:26:45:2a:7f:cd:69:bb:c9:f5:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c3f5b11b68ada7a4cf526452a7fcd69bbc9f5e2/; sid:902204756; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"90:ed:35:19:af:b1:5b:9d:e6:a0:46:46:f0:ad:f8:fd:7c:ad:4b:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90ed3519afb15b9de6a04646f0adf8fd7cad4bf6/; sid:902204757; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"3b:2d:b8:3c:88:07:3c:59:b0:10:95:1e:be:98:14:00:42:a8:c6:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b2db83c88073c59b010951ebe98140042a8c679/; sid:902204758; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"29:c8:47:8a:7c:47:92:61:46:95:59:82:de:6b:b2:f6:43:61:b8:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29c8478a7c47926146955982de6bb2f64361b82d/; sid:902204759; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f4:69:e0:74:8b:13:28:6e:dc:56:a2:4c:56:b7:e3:4b:d3:76:c3:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f469e0748b13286edc56a24c56b7e34bd376c3b0/; sid:902204760; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"60:83:99:37:9d:28:89:5b:a7:a3:5f:98:34:40:f1:99:fb:66:f9:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/608399379d28895ba7a35f983440f199fb66f9d7/; sid:902204761; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"5d:76:75:0e:8a:e2:9f:a1:bd:c5:1b:9c:bf:18:b4:6d:76:ac:c4:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d76750e8ae29fa1bdc51b9cbf18b46d76acc408/; sid:902204762; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"96:78:e0:ec:2f:09:10:e0:ff:97:7b:57:c6:e0:92:0d:fa:19:82:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9678e0ec2f0910e0ff977b57c6e0920dfa1982e5/; sid:902204763; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"6d:54:a6:4b:57:b9:fd:cf:fd:ab:43:32:3b:17:55:35:6a:13:6d:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d54a64b57b9fdcffdab43323b1755356a136d42/; sid:902204764; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3e:e7:87:4b:d4:dd:b3:f0:d4:50:f9:24:5d:b7:e4:68:dc:05:1e:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ee7874bd4ddb3f0d450f9245db7e468dc051ecd/; sid:902204765; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a7:16:90:ef:b3:cf:8a:ea:17:38:c6:f0:5c:88:db:a8:e7:e7:99:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a71690efb3cf8aea1738c6f05c88dba8e7e799c1/; sid:902204766; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f3:55:d0:c7:8e:9b:f1:87:67:bb:71:56:cc:e8:70:c0:ac:2b:88:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f355d0c78e9bf18767bb7156cce870c0ac2b883d/; sid:902204767; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"61:f6:7c:0f:96:d5:9c:df:95:4e:90:c8:65:09:73:5a:01:1d:e9:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61f67c0f96d59cdf954e90c86509735a011de93c/; sid:902204768; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"57:42:d4:a5:91:48:a3:95:c5:ed:da:e4:1c:46:9f:08:94:a7:f2:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5742d4a59148a395c5eddae41c469f0894a7f277/; sid:902204769; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"39:ec:b0:0b:6e:e8:46:a7:6c:65:09:e0:0c:52:76:82:cc:b3:99:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39ecb00b6ee846a76c6509e00c527682ccb399eb/; sid:902204770; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8a:ca:9c:99:70:52:93:24:59:d2:c2:a1:ec:a5:41:00:47:74:d4:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8aca9c997052932459d2c2a1eca541004774d41e/; sid:902204771; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a5:68:1a:6c:92:f8:06:05:40:ba:ff:e5:18:f6:5c:98:cb:86:cf:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a5681a6c92f8060540baffe518f65c98cb86cff2/; sid:902204772; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b3:70:df:40:44:5b:87:23:ff:2d:ef:9e:76:a3:fc:ef:08:64:19:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b370df40445b8723ff2def9e76a3fcef08641988/; sid:902204773; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"94:aa:3e:63:37:ac:3a:93:82:18:99:bf:38:66:de:6c:0e:bf:ef:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94aa3e6337ac3a93821899bf3866de6c0ebfefc1/; sid:902204774; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f5:e7:26:cc:fd:64:df:a4:81:3f:10:38:fa:54:42:9c:49:50:ff:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5e726ccfd64dfa4813f1038fa54429c4950ffed/; sid:902204775; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"28:4f:59:5f:a5:73:72:c7:2d:2e:18:23:f5:bf:30:ee:8c:f9:fc:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/284f595fa57372c72d2e1823f5bf30ee8cf9fc2c/; sid:902204776; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BlackGuard C&C)"; tls.fingerprint:"d5:a9:58:9a:d3:b3:0d:25:0c:6d:0c:41:ae:72:84:b8:12:ff:45:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5a9589ad3b30d250c6d0c41ae7284b812ff4591/; sid:902204777; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"37:fc:1f:1a:da:cd:74:5a:49:be:53:e9:2c:a1:43:4f:7d:6e:19:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37fc1f1adacd745a49be53e92ca1434f7d6e1908/; sid:902204778; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:07:38:df:da:ed:b0:4c:5a:17:13:b4:f1:f5:0f:fb:f5:ba:ec:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/820738dfdaedb04c5a1713b4f1f50ffbf5baec5c/; sid:902204779; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:a0:e4:63:b7:52:67:2b:04:53:68:cd:0e:5f:4f:2b:90:ba:34:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59a0e463b752672b045368cd0e5f4f2b90ba34f5/; sid:902204780; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"50:2e:4e:70:92:c6:da:fa:75:58:6c:10:d7:cc:2d:5b:d9:ff:ce:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/502e4e7092c6dafa75586c10d7cc2d5bd9ffce8a/; sid:902204781; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a9:51:15:4c:b3:e1:b0:c2:63:da:2f:13:57:33:e2:1f:69:4a:59:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a951154cb3e1b0c263da2f135733e21f694a5980/; sid:902204782; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9f:25:a7:d6:ea:50:63:b3:cc:53:19:21:0e:ed:46:67:58:8f:d6:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f25a7d6ea5063b3cc5319210eed4667588fd6c4/; sid:902204783; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:b4:75:ac:e8:09:b2:dd:4c:57:81:e2:12:d2:71:a1:6f:c8:c8:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcb475ace809b2dd4c5781e212d271a16fc8c881/; sid:902204784; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"50:3e:00:ec:f0:bb:c9:38:9d:72:94:4f:71:a9:48:5a:0d:87:75:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/503e00ecf0bbc9389d72944f71a9485a0d87755d/; sid:902204785; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"6d:9b:de:f3:33:af:6d:f0:3b:c8:53:11:18:1e:98:a0:7b:e6:3f:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d9bdef333af6df03bc85311181e98a07be63f5a/; sid:902204786; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:4c:31:4e:8a:91:3b:a6:9d:8e:40:f0:b4:53:3d:28:77:8f:59:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/444c314e8a913ba69d8e40f0b4533d28778f5909/; sid:902204787; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6d:9e:2c:fe:aa:96:07:0c:8f:54:09:97:e2:67:cc:37:5e:7f:fe:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6d9e2cfeaa96070c8f540997e267cc375e7ffe57/; sid:902204788; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:2a:45:77:9a:26:11:7d:c9:9e:02:1a:a3:19:f7:c4:c4:b2:d7:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/822a45779a26117dc99e021aa319f7c4c4b2d725/; sid:902204789; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:65:4e:b6:5d:bf:b6:e0:52:1b:19:43:ed:be:8f:f4:46:91:6d:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76654eb65dbfb6e0521b1943edbe8ff446916dbc/; sid:902204790; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Neurevt C&C)"; tls.fingerprint:"a7:18:8f:3a:c0:47:85:82:e9:02:a4:0f:1a:a0:99:dd:f4:b1:32:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7188f3ac0478582e902a40f1aa099ddf4b132fc/; sid:902204791; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"65:7a:3d:40:2a:b1:77:51:d6:ad:1b:71:2a:06:f0:fa:d3:30:43:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/657a3d402ab17751d6ad1b712a06f0fad3304380/; sid:902204792; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9a:79:97:4e:66:4d:4c:a4:1a:68:b9:f1:ee:a1:d6:e5:29:26:37:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a79974e664d4ca41a68b9f1eea1d6e529263764/; sid:902204793; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"17:5a:7c:91:0d:0d:06:db:65:77:dc:3f:e0:48:e9:9c:4a:83:3f:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/175a7c910d0d06db6577dc3fe048e99c4a833f4a/; sid:902204794; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f2:3d:33:76:52:f3:55:a4:69:c3:38:8f:c8:8b:a4:b7:7c:6e:50:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f23d337652f355a469c3388fc88ba4b77c6e50e1/; sid:902204795; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"21:34:c5:df:17:72:77:f2:a2:be:c3:7e:b8:83:09:c5:4b:2e:69:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2134c5df177277f2a2bec37eb88309c54b2e69e1/; sid:902204796; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0f:68:f0:b2:33:c8:f9:0e:d1:3e:f5:b4:ed:b6:3b:2a:1a:3b:bc:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f68f0b233c8f90ed13ef5b4edb63b2a1a3bbcd4/; sid:902204797; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"12:a8:79:30:8b:a2:2f:02:a5:5f:ad:62:d5:b0:4b:e6:3a:8d:8a:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12a879308ba22f02a55fad62d5b04be63a8d8a90/; sid:902204798; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"da:e9:e0:2e:5e:04:d5:9d:9a:f2:aa:1d:5e:82:24:8d:59:19:ac:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dae9e02e5e04d59d9af2aa1d5e82248d5919ac6a/; sid:902204799; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"6a:c2:d7:79:ec:46:4a:58:9d:0a:68:6e:08:13:f4:53:c6:9c:85:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ac2d779ec464a589d0a686e0813f453c69c8536/; sid:902204800; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c1:24:20:ba:dc:e5:9d:7a:6f:50:e5:c1:54:87:e1:f7:24:b3:68:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c12420badce59d7a6f50e5c15487e1f724b36845/; sid:902204801; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"72:30:2e:98:86:f9:ec:7e:69:48:f1:15:2a:e7:c2:ce:7b:40:bd:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72302e9886f9ec7e6948f1152ae7c2ce7b40bdec/; sid:902204802; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"a5:71:fb:26:95:2c:9f:6e:ca:d7:c6:ae:c9:28:bd:a8:70:aa:0d:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a571fb26952c9f6ecad7c6aec928bda870aa0d31/; sid:902204803; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"1c:18:6e:8e:d5:a6:f7:ac:91:04:4e:ea:bc:1b:3e:59:7a:a9:ad:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c186e8ed5a6f7ac91044eeabc1b3e597aa9adbc/; sid:902204804; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:24:f7:6b:65:29:57:73:5a:93:54:41:73:b1:83:23:43:dd:46:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d24f76b652957735a93544173b1832343dd46b1/; sid:902204805; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:e8:a1:de:d6:18:3d:23:9a:b1:74:ed:b4:7e:84:19:27:e5:a5:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7e8a1ded6183d239ab174edb47e841927e5a5fe/; sid:902204806; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"1c:36:e9:9a:8f:39:bd:2a:9b:2c:3c:9c:9f:f0:b1:bc:6c:a2:37:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c36e99a8f39bd2a9b2c3c9c9ff0b1bc6ca237c6/; sid:902204807; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:88:19:47:30:a9:b3:8c:da:a2:a5:87:1e:8c:83:c4:d7:e9:bc:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e088194730a9b38cdaa2a5871e8c83c4d7e9bc9a/; sid:902204808; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"64:0e:0e:9a:76:ca:71:0e:ec:c7:92:11:f3:de:6f:9a:f8:cd:e9:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/640e0e9a76ca710eecc79211f3de6f9af8cde92f/; sid:902204809; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"26:e7:ea:e8:09:2e:f6:26:15:3d:b8:e7:55:37:0e:1f:05:39:80:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26e7eae8092ef626153db8e755370e1f0539801c/; sid:902204810; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"11:a2:ca:0d:27:02:43:cd:3e:73:46:c2:77:65:e5:23:c1:55:cc:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11a2ca0d270243cd3e7346c27765e523c155cc96/; sid:902204811; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a0:89:ce:65:0f:e2:05:c0:e0:0d:85:ea:10:ef:bc:5f:09:72:27:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a089ce650fe205c0e00d85ea10efbc5f097227eb/; sid:902204812; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:b7:dd:20:e4:ab:3b:30:e2:b2:19:b6:50:94:7d:87:72:4b:10:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfb7dd20e4ab3b30e2b219b650947d87724b101d/; sid:902204813; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4c:eb:54:9c:9a:cc:18:6e:22:fd:31:4b:1d:de:55:39:9d:7d:53:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ceb549c9acc186e22fd314b1dde55399d7d53c8/; sid:902204814; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"da:02:52:bb:3e:da:ef:c3:7c:c4:9c:e5:4b:40:c1:d7:56:b0:c0:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da0252bb3edaefc37cc49ce54b40c1d756b0c032/; sid:902204815; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"e9:67:51:07:f7:d0:f1:8a:27:16:48:1a:81:bd:93:0b:71:23:af:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9675107f7d0f18a2716481a81bd930b7123af30/; sid:902204816; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d6:fa:47:d0:cf:c9:8f:cc:9d:3c:b5:60:34:72:df:2f:c6:27:22:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6fa47d0cfc98fcc9d3cb5603472df2fc62722c8/; sid:902204817; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3b:49:80:d7:6d:79:ed:58:ef:16:00:46:89:00:ac:3b:13:ed:c2:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b4980d76d79ed58ef1600468900ac3b13edc289/; sid:902204818; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8e:37:e3:3d:de:fe:de:5d:de:d9:4a:52:e6:ed:b1:a8:4a:ed:f1:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e37e33ddefede5dded94a52e6edb1a84aedf14c/; sid:902204819; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a4:c0:25:eb:de:cb:99:8e:ae:3b:62:bc:06:58:70:5a:8e:73:8b:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4c025ebdecb998eae3b62bc0658705a8e738b0f/; sid:902204820; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:c9:41:e2:c8:67:34:9d:ba:ab:78:67:68:fc:82:49:4d:52:75:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eec941e2c867349dbaab786768fc82494d5275e9/; sid:902204821; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"27:58:30:41:26:ac:d2:f8:ae:cb:14:66:23:f9:f5:1d:a3:21:e9:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2758304126acd2f8aecb146623f9f51da321e94d/; sid:902204822; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1f:56:1d:d9:1d:46:b2:4f:14:3c:85:2d:64:ff:c5:43:91:6c:86:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f561dd91d46b24f143c852d64ffc543916c86d1/; sid:902204823; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:42:38:53:59:e5:4f:23:90:dc:d2:f6:8b:7f:dd:09:9c:06:05:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ff42385359e54f2390dcd2f68b7fdd099c06059c/; sid:902204824; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"30:a0:7b:c8:be:b3:37:56:5a:30:c4:c9:37:59:53:a9:09:6a:21:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30a07bc8beb337565a30c4c9375953a9096a216b/; sid:902204825; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"c3:55:1c:59:73:72:24:92:25:c3:6b:69:84:f2:48:bb:a1:cb:e5:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3551c597372249225c36b6984f248bba1cbe513/; sid:902204826; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"85:f3:fa:89:0d:72:94:fa:93:6e:60:60:7a:60:d5:29:87:88:2d:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/85f3fa890d7294fa936e60607a60d52987882d4e/; sid:902204827; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"98:23:e2:d9:19:9a:05:60:2d:8a:e0:5f:fd:2d:3d:c4:52:3a:9e:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9823e2d9199a05602d8ae05ffd2d3dc4523a9ee1/; sid:902204828; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"3d:12:35:2b:d1:e1:05:a7:10:cd:4e:0a:bc:14:49:31:7b:d8:f1:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d12352bd1e105a710cd4e0abc1449317bd8f15c/; sid:902204829; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Matanbuchus C&C)"; tls.fingerprint:"07:7d:c2:79:ee:b1:0e:07:40:76:5a:d9:cd:2a:a2:60:1c:31:46:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/077dc279eeb10e0740765ad9cd2aa2601c31463b/; sid:902204830; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"6f:e1:80:6a:42:15:87:20:a2:36:f3:0c:47:5e:c1:9f:16:cc:c6:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fe1806a42158720a236f30c475ec19f16ccc690/; sid:902204831; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"38:51:0c:8f:0d:40:5e:92:ee:c8:9a:d4:ab:ed:b0:f4:d7:e6:c4:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38510c8f0d405e92eec89ad4abedb0f4d7e6c456/; sid:902204832; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"9c:5a:9c:b1:5b:9c:3f:86:ac:fc:7a:1d:82:0f:1f:8d:e7:16:1f:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c5a9cb15b9c3f86acfc7a1d820f1f8de7161f21/; sid:902204833; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c2:3c:d8:be:62:58:11:44:1c:68:1d:84:dc:70:ea:0f:5c:a7:e4:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c23cd8be625811441c681d84dc70ea0f5ca7e42f/; sid:902204834; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cd:28:72:3c:9b:46:21:e6:1d:4e:fc:60:b3:fe:28:f6:70:d1:cc:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd28723c9b4621e61d4efc60b3fe28f670d1cc4e/; sid:902204835; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4a:9a:97:4d:5c:e5:cd:5a:78:5c:fd:01:ff:26:b5:dc:81:2c:c3:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a9a974d5ce5cd5a785cfd01ff26b5dc812cc371/; sid:902204836; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"6f:5e:c1:21:3f:a0:24:fe:ae:27:0b:65:35:74:0a:39:79:5c:11:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f5ec1213fa024feae270b6535740a39795c1116/; sid:902204837; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ea:41:5e:00:47:20:a1:8e:b6:90:0e:6f:5d:0c:6a:c0:72:59:4e:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea415e004720a18eb6900e6f5d0c6ac072594ef4/; sid:902204838; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"6f:d6:60:3f:04:ba:b7:82:ac:ab:76:0e:02:38:a5:50:a8:73:37:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fd6603f04bab782acab760e0238a550a87337e8/; sid:902204839; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fc:ae:b0:27:b5:88:75:15:1a:8c:97:e1:ad:25:3a:48:36:40:4d:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcaeb027b58875151a8c97e1ad253a4836404de7/; sid:902204840; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:8e:4e:2a:e3:62:12:8a:26:e3:4f:4c:c6:b9:ce:f1:42:08:6f:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/308e4e2ae362128a26e34f4cc6b9cef142086f5a/; sid:902204841; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:d6:05:2e:ef:50:70:7b:34:8a:00:32:f8:dd:63:3a:d1:c6:fe:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fd6052eef50707b348a0032f8dd633ad1c6fe77/; sid:902204842; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c0:74:2f:cf:ac:08:26:95:4d:1f:b6:6f:1e:ab:22:b3:91:b1:75:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c0742fcfac0826954d1fb66f1eab22b391b17590/; sid:902204843; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:f4:fd:c7:0e:5b:91:b8:88:3b:c7:7e:91:33:18:93:80:8f:dd:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79f4fdc70e5b91b8883bc77e91331893808fddaf/; sid:902204844; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:da:bc:30:55:f7:f9:f6:37:ac:86:2d:f4:a6:4b:a5:ae:44:e8:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0dabc3055f7f9f637ac862df4a64ba5ae44e8a6/; sid:902204845; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b8:65:e8:4a:eb:03:8f:f2:d5:8c:6f:f9:0b:9f:38:8c:37:1f:15:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b865e84aeb038ff2d58c6ff90b9f388c371f15de/; sid:902204846; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BumbleBee C&C)"; tls.fingerprint:"3e:ef:3d:73:11:a2:b6:0b:60:0f:ab:18:bd:72:21:85:83:6a:d3:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3eef3d7311a2b60b600fab18bd722185836ad3cc/; sid:902204847; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ab:b2:91:f3:9b:a9:84:4c:c5:f1:34:b4:0c:16:c5:9a:2e:99:70:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abb291f39ba9844cc5f134b40c16c59a2e9970a1/; sid:902204848; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"40:ba:b9:98:f7:5f:01:5f:89:33:de:eb:3c:4d:b1:72:dd:4c:be:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40bab998f75f015f8933deeb3c4db172dd4cbe33/; sid:902204849; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:9b:ca:67:27:1e:e1:00:62:e5:e5:32:d0:d9:b1:18:b6:5a:c8:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f59bca67271ee10062e5e532d0d9b118b65ac880/; sid:902204850; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c8:b9:ef:fa:43:d9:ed:32:5c:7b:2a:2a:24:db:7a:13:14:e4:3b:2d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c8b9effa43d9ed325c7b2a2a24db7a1314e43b2d/; sid:902204851; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"9a:2a:8d:12:11:dd:b7:ee:b0:fd:7e:98:05:94:2d:79:6b:0b:58:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a2a8d1211ddb7eeb0fd7e9805942d796b0b58f1/; sid:902204852; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"86:b2:b1:e9:84:83:a0:b9:6a:92:2a:e7:81:ed:79:79:c1:f7:76:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/86b2b1e98483a0b96a922ae781ed7979c1f77623/; sid:902204853; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"db:39:fb:92:6c:a9:35:50:80:ef:79:83:f1:fe:ac:66:83:05:a0:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db39fb926ca9355080ef7983f1feac668305a0f6/; sid:902204854; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b0:a5:33:c2:6f:d7:3a:2e:92:8f:b1:9b:25:0d:f3:7e:10:4b:08:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0a533c26fd73a2e928fb19b250df37e104b081c/; sid:902204855; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f2:ae:85:46:98:57:27:1d:45:5b:61:48:d9:f5:87:3c:16:a9:f6:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2ae85469857271d455b6148d9f5873c16a9f6fa/; sid:902204856; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8d:0f:ee:ac:c5:7d:be:08:ec:25:a2:72:11:54:d4:7f:94:a6:d8:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d0feeacc57dbe08ec25a2721154d47f94a6d89c/; sid:902204857; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:e5:eb:4d:2b:9b:65:e4:b4:44:1a:0d:39:7e:96:a0:87:33:ab:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44e5eb4d2b9b65e4b4441a0d397e96a08733abad/; sid:902204858; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9d:83:e3:7a:82:37:26:b2:b5:a8:81:91:7a:7c:39:57:c3:69:9e:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d83e37a823726b2b5a881917a7c3957c3699e68/; sid:902204859; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vjw0rm C&C)"; tls.fingerprint:"0c:25:56:9d:92:b7:e8:7e:33:85:2b:ea:51:38:fb:d6:fd:7b:26:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0c25569d92b7e87e33852bea5138fbd6fd7b2610/; sid:902204860; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a1:f3:8c:72:cd:30:3b:e4:69:07:34:61:4c:ad:6b:6e:ec:67:3e:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1f38c72cd303be4690734614cad6b6eec673e7a/; sid:902204861; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:fe:0f:cb:ab:85:4b:c4:59:06:d3:54:ce:be:5a:7c:dd:aa:b7:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/30fe0fcbab854bc45906d354cebe5a7cddaab78e/; sid:902204862; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:55:b0:57:d6:3d:33:5c:3d:e8:a9:c2:67:e2:b4:9d:8e:66:8f:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c55b057d63d335c3de8a9c267e2b49d8e668f56/; sid:902204863; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a8:c9:dc:fe:bc:03:e2:11:ee:55:8f:86:3c:db:f1:76:06:64:01:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8c9dcfebc03e211ee558f863cdbf176066401c6/; sid:902204864; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:07:93:fd:e8:62:2a:e6:1f:79:77:72:e9:a7:22:05:f0:90:67:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/380793fde8622ae61f797772e9a72205f090671e/; sid:902204865; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d8:5b:16:b7:53:44:28:36:c5:e6:c9:c1:7f:68:d1:e4:8c:5e:51:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d85b16b753442836c5e6c9c17f68d1e48c5e51c7/; sid:902204866; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AgentTesla C&C)"; tls.fingerprint:"73:f8:8f:e6:73:eb:ee:b1:ef:4d:6f:c7:92:7b:46:c8:f4:8a:c4:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73f88fe673ebeeb1ef4d6fc7927b46c8f48ac450/; sid:902204867; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4c:31:9e:c8:b5:a6:6a:25:6a:01:37:d7:0c:d0:f9:a7:6b:b2:3f:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4c319ec8b5a66a256a0137d70cd0f9a76bb23fd7/; sid:902204868; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a0:d7:8b:3d:db:27:cd:4f:11:0a:02:92:ca:b8:00:be:ad:af:9b:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0d78b3ddb27cd4f110a0292cab800beadaf9bd2/; sid:902204869; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"37:84:42:2d:67:a6:ae:0c:82:d6:0e:ea:f3:85:09:60:a9:89:6c:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3784422d67a6ae0c82d60eeaf3850960a9896cb2/; sid:902204870; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2c:13:12:48:5a:22:b1:d5:47:83:57:42:b6:90:ee:62:b0:66:8f:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c1312485a22b1d547835742b690ee62b0668fc6/; sid:902204871; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:8e:68:8d:5c:a6:c2:9c:2d:7e:c9:a1:fc:b1:40:15:7e:19:52:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/678e688d5ca6c29c2d7ec9a1fcb140157e19523a/; sid:902204872; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:80:a5:90:11:b8:db:11:a4:9e:4e:fb:8a:5a:73:92:d4:7b:da:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2780a59011b8db11a49e4efb8a5a7392d47bda21/; sid:902204873; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f6:45:26:f0:b8:a4:b2:6f:09:16:a1:fb:e4:bb:3f:57:5b:8e:d2:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f64526f0b8a4b26f0916a1fbe4bb3f575b8ed2a2/; sid:902204874; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ed:ba:78:e2:17:ed:b7:7e:cb:17:d4:6f:62:bf:75:f3:5e:dc:6e:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edba78e217edb77ecb17d46f62bf75f35edc6e69/; sid:902204875; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"37:9e:90:d3:90:1e:e2:87:35:be:ad:d2:5b:54:b9:d0:b3:a5:af:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/379e90d3901ee28735beadd25b54b9d0b3a5af3c/; sid:902204876; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2b:c0:c6:35:dd:a7:e2:0d:09:c4:81:bb:27:da:4e:87:f6:a6:b9:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2bc0c635dda7e20d09c481bb27da4e87f6a6b9a7/; sid:902204877; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:a3:f4:44:14:1f:30:08:99:3e:89:66:b7:e6:dd:33:3c:88:f0:fb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69a3f444141f3008993e8966b7e6dd333c88f0fb/; sid:902204878; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e3:da:ce:16:db:61:68:6d:46:07:3c:d7:b7:18:b4:59:04:43:ff:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3dace16db61686d46073cd7b718b4590443ffeb/; sid:902204879; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:c6:e4:d3:4c:37:e0:31:a2:39:2e:f8:98:1e:14:cb:13:74:ee:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51c6e4d34c37e031a2392ef8981e14cb1374ee89/; sid:902204880; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:c9:cf:94:4b:1a:b2:84:34:75:ab:38:42:3a:21:1a:4d:ab:18:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08c9cf944b1ab2843475ab38423a211a4dab1849/; sid:902204881; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:db:48:1d:5e:2c:f7:35:21:02:2a:6f:78:78:b3:80:00:fa:5e:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eedb481d5e2cf73521022a6f7878b38000fa5e42/; sid:902204882; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"97:11:73:d0:d4:85:fc:e9:35:87:4f:0d:b3:7a:78:40:19:03:38:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/971173d0d485fce935874f0db37a7840190338c5/; sid:902204883; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1f:fd:8b:1b:0e:1c:ae:f8:76:c9:10:1f:80:00:65:1b:c5:69:ad:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ffd8b1b0e1caef876c9101f8000651bc569ad5a/; sid:902204884; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6c:08:a8:51:4a:a4:19:4c:ef:de:7e:1f:8c:cc:10:8b:3e:67:b0:a5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6c08a8514aa4194cefde7e1f8ccc108b3e67b0a5/; sid:902204885; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"32:50:30:2b:ad:47:da:42:cd:0b:8c:c8:c1:14:b5:8a:af:c4:ae:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3250302bad47da42cd0b8cc8c114b58aafc4aedb/; sid:902204886; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"62:ad:46:ba:d4:ed:2a:83:37:16:09:a5:1d:3b:a5:72:e3:ab:70:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62ad46bad4ed2a83371609a51d3ba572e3ab7067/; sid:902204887; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:d8:7e:f0:a0:c2:8d:55:06:67:aa:b3:fc:00:36:15:59:92:3e:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1d87ef0a0c28d550667aab3fc00361559923e64/; sid:902204888; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:02:73:13:0d:14:06:73:52:b2:ca:f9:94:eb:38:f3:86:d3:c2:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/760273130d14067352b2caf994eb38f386d3c213/; sid:902204889; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"66:f4:08:e1:ee:fe:bf:7e:bf:94:0e:90:45:a3:18:f2:46:24:84:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66f408e1eefebf7ebf940e9045a318f2462484b9/; sid:902204890; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"93:39:5a:31:8e:fb:29:9c:0f:b9:28:be:a6:f0:02:9f:54:23:c5:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93395a318efb299c0fb928bea6f0029f5423c532/; sid:902204891; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"3b:a7:6a:8f:58:40:31:ff:3e:f2:89:da:6b:8a:71:23:d2:90:21:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ba76a8f584031ff3ef289da6b8a7123d290218b/; sid:902204892; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"4b:64:ba:e5:ad:72:93:d4:a3:1b:17:6d:99:35:b5:d4:75:71:9d:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b64bae5ad7293d4a31b176d9935b5d475719d73/; sid:902204893; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:58:5d:c9:4d:f4:84:89:12:2d:f9:a2:da:6f:44:e4:3f:d6:69:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78585dc94df48489122df9a2da6f44e43fd6697f/; sid:902204894; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"60:9f:ed:c6:06:73:8c:12:e1:d2:4c:30:2e:c6:4f:41:d5:2d:1b:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/609fedc606738c12e1d24c302ec64f41d52d1b1f/; sid:902204895; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"68:f0:e8:24:d1:7d:04:ab:74:25:c6:50:a0:0c:a3:9e:45:ca:ee:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68f0e824d17d04ab7425c650a00ca39e45caee30/; sid:902204896; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:2a:14:ea:45:eb:b8:46:6f:05:f5:c5:f6:e7:72:6c:93:6f:98:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/702a14ea45ebb8466f05f5c5f6e7726c936f981d/; sid:902204897; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ce:17:fd:b6:20:ce:33:45:14:28:2b:f3:ab:d5:6a:ec:16:82:cb:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce17fdb620ce334514282bf3abd56aec1682cbc0/; sid:902204898; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"62:b0:05:0f:bf:d9:bf:e4:01:4a:a1:d4:9f:ee:c2:c2:15:e9:86:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62b0050fbfd9bfe4014aa1d49feec2c215e986cc/; sid:902204899; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d5:88:2f:43:73:e6:71:a4:bb:e7:f7:14:4c:d7:c5:7d:c6:6b:70:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5882f4373e671a4bbe7f7144cd7c57dc66b70da/; sid:902204900; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b5:3a:df:2d:21:73:e4:b5:91:9d:1b:a2:5f:dd:97:be:5a:e1:d4:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b53adf2d2173e4b5919d1ba25fdd97be5ae1d47b/; sid:902204901; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"79:ee:25:0c:74:1f:4b:69:16:8e:02:cb:41:b5:f4:e9:16:0a:4b:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79ee250c741f4b69168e02cb41b5f4e9160a4bc6/; sid:902204902; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"07:a3:fb:85:65:7a:e7:f6:4d:92:fd:38:62:4e:03:2f:94:0d:8f:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07a3fb85657ae7f64d92fd38624e032f940d8fec/; sid:902204903; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c7:38:43:0d:1f:0c:75:a1:48:1d:4a:8f:28:2c:12:90:54:c0:df:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c738430d1f0c75a1481d4a8f282c129054c0df4f/; sid:902204904; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:f1:a0:d5:c8:37:69:4d:3a:77:61:a5:74:9a:86:b9:21:7b:af:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29f1a0d5c837694d3a7761a5749a86b9217baf15/; sid:902204905; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:f7:c7:ed:46:18:14:f7:0d:38:ce:1e:86:40:ea:d2:e0:b8:53:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88f7c7ed461814f70d38ce1e8640ead2e0b853b9/; sid:902204906; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f9:90:19:82:62:e8:31:a4:18:79:ab:78:3e:b7:35:26:96:ca:ac:b0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f990198262e831a41879ab783eb7352696caacb0/; sid:902204907; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cd:e9:44:a0:0b:de:38:bd:a5:ae:ca:3a:02:6a:3e:f8:48:4b:5c:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cde944a00bde38bda5aeca3a026a3ef8484b5c65/; sid:902204908; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"40:75:0c:80:22:59:6b:02:fc:6a:17:25:99:3a:7f:ff:21:10:0c:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40750c8022596b02fc6a1725993a7fff21100c6d/; sid:902204909; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7e:e1:21:8b:40:e5:5a:31:e8:e5:98:ad:ad:19:12:ba:72:9e:4f:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ee1218b40e55a31e8e598adad1912ba729e4fe0/; sid:902204910; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DarkWatchman C&C)"; tls.fingerprint:"34:ae:ca:22:1f:8e:f6:ab:ca:68:61:95:5f:5d:a2:ca:15:ba:88:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34aeca221f8ef6abca6861955f5da2ca15ba88cb/; sid:902204911; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cf:59:bc:18:48:f3:fc:be:f9:e2:18:56:0a:cc:76:68:34:6c:cc:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf59bc1848f3fcbef9e218560acc7668346ccca9/; sid:902204912; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"65:0e:d8:97:35:f4:1f:23:da:ab:bc:10:63:60:f6:8b:87:4b:6d:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/650ed89735f41f23daabbc106360f68b874b6df8/; sid:902204913; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8e:d5:d7:69:bd:14:6a:02:f9:29:bc:b5:e0:c8:7e:44:4a:dd:60:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ed5d769bd146a02f929bcb5e0c87e444add60d3/; sid:902204914; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"89:da:54:e8:23:be:88:de:8c:f1:76:04:6d:5a:3d:d7:10:1b:fa:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89da54e823be88de8cf176046d5a3dd7101bfabd/; sid:902204915; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"21:a0:44:ee:09:2a:b5:95:5d:d3:35:3c:7d:19:e5:bc:88:a8:81:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21a044ee092ab5955dd3353c7d19e5bc88a8811c/; sid:902204916; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"9f:54:a7:2a:c8:f4:83:9a:19:bc:ef:d1:3c:54:73:64:98:b2:90:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f54a72ac8f4839a19bcefd13c54736498b2903c/; sid:902204917; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"98:c1:6e:81:52:05:ac:92:0b:e9:da:61:d9:d1:39:5f:5b:95:36:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98c16e815205ac920be9da61d9d1395f5b953669/; sid:902204918; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"98:83:7f:a5:f8:e4:0e:04:17:26:18:dd:f2:d3:68:e6:7b:ff:25:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98837fa5f8e40e04172618ddf2d368e67bff2579/; sid:902204919; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:e1:40:c4:51:1c:17:5e:88:e9:e1:61:16:4f:31:4f:2a:68:69:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05e140c4511c175e88e9e161164f314f2a68692b/; sid:902204920; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"40:8e:8b:ae:74:9f:15:a4:65:ab:f4:84:17:34:ee:4f:f6:bb:7f:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/408e8bae749f15a465abf4841734ee4ff6bb7f3b/; sid:902204921; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:af:53:f2:22:80:54:9f:fb:ff:f5:dc:41:d9:d8:1e:4a:26:22:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29af53f22280549ffbfff5dc41d9d81e4a26221b/; sid:902204922; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"69:e3:98:f0:5b:ce:e1:b4:ce:52:66:5d:d1:d3:73:72:38:b9:c3:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69e398f05bcee1b4ce52665dd1d3737238b9c3ab/; sid:902204923; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c3:53:69:c3:18:21:3b:dc:a2:d6:b3:d7:6b:23:51:64:77:54:49:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c35369c318213bdca2d6b3d76b23516477544954/; sid:902204924; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:ad:bb:51:9b:76:37:1a:15:7f:ef:fe:8c:2d:14:60:51:eb:a3:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1dadbb519b76371a157feffe8c2d146051eba3b6/; sid:902204925; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"16:04:b9:33:36:7c:fc:64:30:50:15:8c:7c:df:ca:5b:18:f1:f1:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1604b933367cfc643050158c7cdfca5b18f1f19e/; sid:902204926; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"50:23:e1:72:98:1b:f4:70:8d:82:ce:4b:bd:d5:a6:07:d6:c1:63:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5023e172981bf4708d82ce4bbdd5a607d6c1631c/; sid:902204927; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6a:4a:69:2d:c5:ae:23:0e:25:5b:64:f5:6f:a7:1f:a6:be:c6:4b:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a4a692dc5ae230e255b64f56fa71fa6bec64bc6/; sid:902204928; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b9:86:25:05:0c:50:cd:f7:1b:f2:a0:06:fe:3d:00:5a:13:8c:00:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b98625050c50cdf71bf2a006fe3d005a138c00cf/; sid:902204929; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e0:80:16:a9:07:52:80:83:12:7b:ed:6e:4b:90:2f:41:75:54:a1:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e08016a907528083127bed6e4b902f417554a1b7/; sid:902204930; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"a9:4a:89:40:c9:df:c1:8a:bd:47:0d:e2:e0:73:25:b7:32:f7:d1:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a94a8940c9dfc18abd470de2e07325b732f7d189/; sid:902204931; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:e2:7e:d6:97:9d:b8:91:72:35:28:a8:06:d9:06:91:0e:0b:90:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06e27ed6979db891723528a806d906910e0b9022/; sid:902204932; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fe:64:ad:56:61:4e:66:69:c1:e0:74:be:62:c4:4a:27:31:93:69:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe64ad56614e6669c1e074be62c44a2731936916/; sid:902204933; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"47:3f:f4:24:c0:39:2f:3c:e9:02:87:e3:5e:f1:9c:34:13:11:9e:65"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/473ff424c0392f3ce90287e35ef19c3413119e65/; sid:902204934; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"57:ec:2b:34:c4:c5:74:24:41:ef:fe:d0:5b:54:a3:88:15:a4:e9:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57ec2b34c4c5742441effed05b54a38815a4e940/; sid:902204935; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:b2:e6:e4:1b:38:a3:d6:4a:30:22:ea:17:70:0e:71:37:6c:6c:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fdb2e6e41b38a3d64a3022ea17700e71376c6c17/; sid:902204936; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:07:1d:e2:e1:06:28:fd:a7:0e:00:da:a9:ad:55:2f:3f:fd:f5:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05071de2e10628fda70e00daa9ad552f3ffdf5ec/; sid:902204937; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vjw0rm C&C)"; tls.fingerprint:"2f:ce:7b:d2:f5:a2:28:53:bd:b7:e7:dc:2d:66:03:b7:b2:54:e7:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2fce7bd2f5a22853bdb7e7dc2d6603b7b254e701/; sid:902204938; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"2c:a6:e7:b0:ef:82:68:26:0a:13:2a:e7:6b:73:8e:90:d3:06:ef:19"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ca6e7b0ef8268260a132ae76b738e90d306ef19/; sid:902204939; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:3b:41:3f:99:78:2d:d6:4d:e7:7a:f0:fa:2c:8e:cf:ab:1a:2f:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/783b413f99782dd64de77af0fa2c8ecfab1a2fbd/; sid:902204940; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"19:81:6a:d3:31:69:be:c6:06:a8:39:ca:7d:e0:6f:5d:50:8a:ed:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19816ad33169bec606a839ca7de06f5d508aed35/; sid:902204941; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:1f:77:dd:0e:cc:62:7b:aa:6c:f2:cd:6d:d7:dd:87:f1:6c:81:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/221f77dd0ecc627baa6cf2cd6dd7dd87f16c8125/; sid:902204942; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IceXLoader C&C)"; tls.fingerprint:"9c:a6:ea:cf:82:b6:c3:4f:34:06:34:30:c9:7b:71:d9:c1:f7:fa:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ca6eacf82b6c34f34063430c97b71d9c1f7fa7b/; sid:902204943; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f1:fd:92:d5:e4:89:6e:ee:b9:23:ac:16:6c:4f:65:53:d7:6c:53:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f1fd92d5e4896eeeb923ac166c4f6553d76c539d/; sid:902204944; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"10:40:4f:65:b3:d0:ca:fb:32:77:75:c8:7c:86:ac:e5:6d:6c:70:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10404f65b3d0cafb327775c87c86ace56d6c703a/; sid:902204945; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"2d:87:43:d8:e6:2c:4f:68:d5:c4:86:a0:03:12:20:d0:bc:ca:3e:11"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d8743d8e62c4f68d5c486a0031220d0bcca3e11/; sid:902204946; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b6:7c:5e:03:dd:64:8d:00:fe:ab:75:01:36:4c:3b:50:ff:df:85:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b67c5e03dd648d00feab7501364c3b50ffdf8543/; sid:902204947; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:5d:25:9b:2c:d5:fc:d0:55:b6:63:4e:8c:f5:62:80:95:2c:2e:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee5d259b2cd5fcd055b6634e8cf56280952c2e4a/; sid:902204948; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ff:d2:a7:db:14:1f:14:0d:b5:e3:04:36:ba:7e:21:68:6d:2f:69:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ffd2a7db141f140db5e30436ba7e21686d2f690c/; sid:902204949; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"a5:57:46:f9:c8:10:10:dc:23:42:7c:6a:8a:79:25:d5:de:8c:27:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a55746f9c81010dc23427c6a8a7925d5de8c2727/; sid:902204950; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"11:8e:93:00:fd:76:59:eb:54:c2:8f:0f:b1:b6:1b:c5:cd:02:7c:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/118e9300fd7659eb54c28f0fb1b61bc5cd027c02/; sid:902204951; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b8:0c:a1:c9:cc:aa:12:8f:f8:1f:ec:c1:b9:73:0f:b1:c6:9e:05:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b80ca1c9ccaa128ff81fecc1b9730fb1c69e0560/; sid:902204952; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1e:6c:c2:86:9d:48:5f:1f:64:8c:96:a3:02:5b:6b:3e:e7:68:9b:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e6cc2869d485f1f648c96a3025b6b3ee7689b72/; sid:902204953; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a4:5b:25:48:a5:6c:44:68:7f:b8:7f:2d:fa:4b:7e:23:e2:15:a5:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a45b2548a56c44687fb87f2dfa4b7e23e215a5fa/; sid:902204954; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8f:b9:ef:1a:51:7f:64:99:0e:89:5c:c2:9b:37:4f:52:fc:64:52:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8fb9ef1a517f64990e895cc29b374f52fc645241/; sid:902204955; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:51:4b:d4:0b:fd:60:7c:85:92:6f:d3:30:b7:ce:b4:80:33:fe:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/28514bd40bfd607c85926fd330b7ceb48033fe93/; sid:902204956; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"23:18:86:88:81:bd:92:67:4e:86:85:b4:bb:c2:5f:2e:a2:db:ef:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2318868881bd92674e8685b4bbc25f2ea2dbef55/; sid:902204957; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2f:0d:bd:5a:56:a5:ef:0e:77:9c:1a:c6:1b:e2:4f:d5:b1:76:5c:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2f0dbd5a56a5ef0e779c1ac61be24fd5b1765ca9/; sid:902204958; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9f:6d:40:3e:2b:06:8a:96:b4:10:c3:40:6f:fd:40:6f:3f:56:6d:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9f6d403e2b068a96b410c3406ffd406f3f566d10/; sid:902204959; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"bf:c4:11:8f:f8:21:66:16:3d:5a:5a:5b:7c:dd:7a:b1:39:79:ed:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfc4118ff82166163d5a5a5b7cdd7ab13979ed32/; sid:902204960; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"cb:86:3c:31:28:db:a4:45:f9:58:9d:70:c7:9c:b6:a9:1a:65:88:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb863c3128dba445f9589d70c79cb6a91a65880c/; sid:902204961; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:db:d5:88:31:1a:a3:cb:c7:db:ee:58:ec:41:71:fa:eb:46:80:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/75dbd588311aa3cbc7dbee58ec4171faeb46803b/; sid:902204962; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RM3 C&C)"; tls.fingerprint:"2d:51:17:9e:b5:5c:cc:48:cf:c7:16:4e:3a:93:69:04:a4:0d:7b:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d51179eb55ccc48cfc7164e3a936904a40d7b88/; sid:902204963; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RM3 C&C)"; tls.fingerprint:"60:34:1a:66:47:4e:4d:22:79:db:15:ca:1d:3a:cf:97:5a:32:55:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60341a66474e4d2279db15ca1d3acf975a325594/; sid:902204964; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:d4:ec:b4:ad:e0:81:bc:ee:23:74:2b:49:09:07:2e:30:7a:50:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44d4ecb4ade081bcee23742b4909072e307a5003/; sid:902204965; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:3c:6d:f1:be:3a:9c:41:f3:00:f7:0e:d3:54:ec:a7:a9:ca:5c:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d3c6df1be3a9c41f300f70ed354eca7a9ca5ceb/; sid:902204966; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1c:ab:a6:02:6a:5f:aa:ae:62:f1:ca:2c:5b:34:d9:ea:d5:e1:51:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1caba6026a5faaae62f1ca2c5b34d9ead5e15197/; sid:902204967; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6b:7c:95:dc:3c:fd:5d:1b:1f:82:96:b9:c3:17:49:d8:a5:18:8d:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b7c95dc3cfd5d1b1f8296b9c31749d8a5188d16/; sid:902204968; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8d:ff:fa:cc:fd:16:b0:0d:23:13:a8:5f:89:e1:a0:21:40:d8:fc:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8dfffaccfd16b00d2313a85f89e1a02140d8fc95/; sid:902204969; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:2f:e9:80:30:f0:1e:7c:2f:63:83:d4:8b:03:21:fe:e0:85:97:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/882fe98030f01e7c2f6383d48b0321fee08597a2/; sid:902204970; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d7:f7:a7:ad:8e:0f:18:50:58:83:87:c3:76:17:88:96:6f:94:f0:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d7f7a7ad8e0f1850588387c3761788966f94f0dd/; sid:902204971; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:07:ff:1f:e7:81:3b:14:97:5d:56:77:51:3b:9e:38:ff:7d:61:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b07ff1fe7813b14975d5677513b9e38ff7d61b4/; sid:902204972; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b2:89:04:0e:4b:97:1d:d6:8b:64:80:b6:02:18:66:00:10:e5:94:5c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b289040e4b971dd68b6480b60218660010e5945c/; sid:902204973; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e9:eb:0c:d7:71:b9:ce:cd:27:82:86:9c:1c:b9:b1:59:b6:0d:d6:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e9eb0cd771b9cecd2782869c1cb9b159b60dd6f0/; sid:902204974; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"41:c3:cf:52:ef:ca:98:1f:2a:2c:4b:11:ee:aa:de:ca:b1:e2:dc:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/41c3cf52efca981f2a2c4b11eeaadecab1e2dc49/; sid:902204975; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d0:a9:6c:cc:28:9b:51:b7:c0:65:6e:fe:7d:f9:b8:77:34:d4:5d:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0a96ccc289b51b7c0656efe7df9b87734d45da9/; sid:902204976; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"d8:45:10:b4:a9:e8:3e:5d:26:6d:82:79:8b:97:a4:2a:ba:ed:b2:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d84510b4a9e83e5d266d82798b97a42abaedb29c/; sid:902204977; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"dd:1d:74:bb:b0:b2:6c:09:a9:55:95:6e:22:4f:2a:88:49:d5:fe:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd1d74bbb0b26c09a955956e224f2a8849d5fea1/; sid:902204978; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"98:9c:73:49:42:f4:82:91:75:00:9b:ed:75:3c:9d:4c:1d:29:d7:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/989c734942f4829175009bed753c9d4c1d29d78e/; sid:902204979; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"00:70:78:5e:6e:3d:ee:58:a6:88:2e:6d:23:df:7d:ae:14:94:3c:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0070785e6e3dee58a6882e6d23df7dae14943c1b/; sid:902204980; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1d:cf:5d:55:99:d4:39:00:1b:15:e9:4e:02:6d:13:6b:c0:5e:cb:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1dcf5d5599d439001b15e94e026d136bc05ecb15/; sid:902204981; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"60:43:13:0d:0a:4d:80:4f:1a:48:16:a4:bc:19:75:5f:33:63:95:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6043130d0a4d804f1a4816a4bc19755f33639534/; sid:902204982; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"f9:a6:89:8f:ac:27:e1:39:aa:9a:c3:a4:61:7e:48:f7:15:e9:9b:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9a6898fac27e139aa9ac3a4617e48f715e99b02/; sid:902204983; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"36:1b:b3:09:54:b8:aa:de:81:d8:e5:01:c1:95:78:70:6e:22:87:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/361bb30954b8aade81d8e501c19578706e228754/; sid:902204984; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Adwind C&C)"; tls.fingerprint:"b9:5a:90:c2:b5:ce:07:57:15:9d:36:3b:10:22:f0:40:d4:59:1b:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b95a90c2b5ce0757159d363b1022f040d4591bea/; sid:902204985; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"a0:f5:63:f0:08:34:97:a7:2c:f4:92:b7:d8:e1:c9:cf:9c:31:b2:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a0f563f0083497a72cf492b7d8e1c9cf9c31b252/; sid:902204986; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f9:15:3b:74:10:5d:6c:51:cd:63:47:a3:ea:34:1d:73:7d:ef:43:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9153b74105d6c51cd6347a3ea341d737def43b5/; sid:902204987; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware distribution)"; tls.fingerprint:"24:b6:21:82:41:51:58:5b:03:59:05:51:9a:e7:e2:fe:fc:18:c0:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24b621824151585b035905519ae7e2fefc18c036/; sid:902204988; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a8:be:b8:e0:e3:2f:a3:79:26:93:6a:67:10:61:9f:e7:e5:b5:c7:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8beb8e0e32fa37926936a6710619fe7e5b5c76c/; sid:902204989; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c1:66:44:ae:15:54:53:01:1f:36:dd:3f:4c:45:9c:b3:b2:ee:8c:e7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c16644ae155453011f36dd3f4c459cb3b2ee8ce7/; sid:902204990; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"4b:00:c2:3c:42:00:f2:54:5e:d2:ea:a1:d4:f8:2f:7b:5e:ed:9d:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b00c23c4200f2545ed2eaa1d4f82f7b5eed9df0/; sid:902204991; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e4:08:64:2f:44:0d:4a:df:45:91:dd:cc:2a:26:e6:c4:b1:2c:58:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e408642f440d4adf4591ddcc2a26e6c4b12c5864/; sid:902204992; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"78:57:c5:f2:8c:4f:52:a4:bf:c9:eb:35:af:d7:ee:27:22:9a:40:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7857c5f28c4f52a4bfc9eb35afd7ee27229a40e8/; sid:902204993; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:89:06:a7:0c:04:b9:51:bb:cd:d4:a7:c4:2c:ca:e9:c4:6c:31:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6f8906a70c04b951bbcdd4a7c42ccae9c46c31ea/; sid:902204994; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"58:4f:ee:fc:ec:6b:72:45:bf:82:e4:93:6e:43:3d:2e:d6:ac:3a:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/584feefcec6b7245bf82e4936e433d2ed6ac3a93/; sid:902204995; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a9:bf:88:87:22:55:e1:d7:c1:20:2f:66:8b:b0:8b:ed:e3:89:71:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a9bf88872255e1d7c1202f668bb08bede3897123/; sid:902204996; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:28:ae:72:30:42:d7:9e:76:f3:72:34:de:91:dc:22:8d:88:b5:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b328ae723042d79e76f37234de91dc228d88b57f/; sid:902204997; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:39:af:ae:d1:9c:3c:e0:93:f4:b2:b5:30:d6:2a:1a:a7:af:77:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1239afaed19c3ce093f4b2b530d62a1aa7af771e/; sid:902204998; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"11:52:5e:4b:b2:f5:41:bf:5d:1c:42:5e:df:3b:06:1d:23:80:fb:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11525e4bb2f541bf5d1c425edf3b061d2380fbfa/; sid:902204999; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8b:14:d1:39:9f:c3:cc:42:d5:87:52:97:8f:e0:4c:9a:2e:ec:5c:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b14d1399fc3cc42d58752978fe04c9a2eec5c1e/; sid:902205000; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Meterpreter C&C)"; tls.fingerprint:"68:bc:7e:d7:ea:6b:fd:68:b6:59:c2:0e:1d:11:08:7f:8b:2d:54:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68bc7ed7ea6bfd68b659c20e1d11087f8b2d54a2/; sid:902205001; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bd:ae:ce:cb:12:91:44:85:a4:fb:2e:93:5b:24:a6:09:b9:76:59:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bdaececb12914485a4fb2e935b24a609b97659e9/; sid:902205002; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4e:61:2d:35:2f:e6:00:11:8d:d5:4b:22:e7:79:61:18:1e:08:04:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4e612d352fe600118dd54b22e77961181e0804e9/; sid:902205003; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:aa:58:97:a0:7c:71:b7:7f:64:92:d6:7d:e1:04:07:c5:ed:19:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25aa5897a07c71b77f6492d67de10407c5ed19f8/; sid:902205004; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"45:3d:dc:e5:e7:e5:f6:49:ab:f4:e4:89:e6:c3:e2:52:bc:19:fa:b6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/453ddce5e7e5f649abf4e489e6c3e252bc19fab6/; sid:902205005; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8b:d0:14:e7:4b:cc:c0:14:6f:cb:52:c1:79:51:ed:e8:18:69:b0:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8bd014e74bccc0146fcb52c17951ede81869b012/; sid:902205006; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4e:ee:f5:83:ff:e1:58:ea:51:1e:32:08:d8:2e:03:75:6a:a7:91:32"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4eeef583ffe158ea511e3208d82e03756aa79132/; sid:902205007; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"5e:19:76:14:3d:d1:40:8b:b2:a1:54:a3:7c:2f:0f:23:20:31:6f:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e1976143dd1408bb2a154a37c2f0f2320316fde/; sid:902205008; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c4:5b:95:4b:51:7b:c6:c7:54:4f:01:3d:ef:a5:1d:41:cf:0f:5f:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c45b954b517bc6c7544f013defa51d41cf0f5fb5/; sid:902205009; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:e4:2a:2e:5a:0f:33:a1:85:4e:76:a1:62:0c:85:5e:a4:c5:24:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38e42a2e5a0f33a1854e76a1620c855ea4c52449/; sid:902205010; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b8:55:89:01:48:3d:33:ff:0f:4d:ae:dd:a1:e5:e2:d2:89:93:ef:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8558901483d33ff0f4daedda1e5e2d28993ef6e/; sid:902205011; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:32:91:e6:3e:30:ab:0e:cd:6a:1a:f9:f8:6c:93:eb:3b:a8:9b:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b33291e63e30ab0ecd6a1af9f86c93eb3ba89bea/; sid:902205012; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7d:fe:9c:51:2c:65:a7:20:f7:6f:90:4e:0a:49:40:10:ed:7d:e8:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7dfe9c512c65a720f76f904e0a494010ed7de8fd/; sid:902205013; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"38:f9:57:a7:71:4e:be:6f:c2:7e:56:c6:ea:b8:ba:dc:98:7f:5e:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38f957a7714ebe6fc27e56c6eab8badc987f5e2b/; sid:902205014; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a3:75:c6:65:f1:44:3e:8a:a5:86:0b:58:91:f4:29:74:ed:a3:66:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a375c665f1443e8aa5860b5891f42974eda366d9/; sid:902205015; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"22:6a:76:00:dd:8a:09:c2:e5:9d:c5:0c:42:a5:3b:15:47:c3:1d:31"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/226a7600dd8a09c2e59dc50c42a53b1547c31d31/; sid:902205016; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3e:de:14:28:9a:58:b5:53:9a:69:99:27:e2:29:38:44:7f:c6:bd:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3ede14289a58b5539a699927e22938447fc6bd62/; sid:902205017; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"36:95:c9:01:eb:a6:3b:a3:98:9d:b3:ba:f3:38:e8:78:7a:f7:13:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3695c901eba63ba3989db3baf338e8787af7135b/; sid:902205018; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AveMariaRAT C&C)"; tls.fingerprint:"b8:d4:4c:01:0f:86:fb:6a:a1:2b:0a:93:55:13:f7:67:88:d3:31:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b8d44c010f86fb6aa12b0a935513f76788d331df/; sid:902205019; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"36:35:0b:ea:7d:40:3d:03:cc:c6:1b:0b:b2:a3:2a:18:41:dd:32:0b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36350bea7d403d03ccc61b0bb2a32a1841dd320b/; sid:902205020; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"94:4a:7c:ac:49:c0:0a:c4:69:70:06:c4:f7:27:4c:6b:ff:c4:25:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/944a7cac49c00ac4697006c4f7274c6bffc425c3/; sid:902205021; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4f:7d:62:8b:38:ca:92:2d:6b:b1:90:22:0b:88:5c:be:19:84:e3:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4f7d628b38ca922d6bb190220b885cbe1984e30e/; sid:902205022; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"71:c8:b3:70:75:00:73:3d:d2:8c:05:e5:b8:20:08:e1:74:67:77:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/71c8b3707500733dd28c05e5b82008e174677759/; sid:902205023; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"65:b1:f8:8a:66:99:59:d0:fb:ff:24:58:26:5b:38:41:a3:57:76:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65b1f88a669959d0fbff2458265b3841a357768a/; sid:902205024; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"48:99:8f:33:d0:2e:a1:26:6a:95:f4:6f:37:56:2d:54:00:0b:f6:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/48998f33d02ea1266a95f46f37562d54000bf6d5/; sid:902205025; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b7:74:41:01:d0:7d:d4:3f:c0:d0:62:c4:f4:88:f4:3b:4f:0c:f6:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7744101d07dd43fc0d062c4f488f43b4f0cf6a9/; sid:902205026; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DoNot C&C)"; tls.fingerprint:"85:27:97:3d:c0:6a:76:ea:86:d0:bf:24:14:c5:a0:34:1f:be:7e:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8527973dc06a76ea86d0bf2414c5a0341fbe7e4b/; sid:902205027; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"78:43:6c:6a:86:32:25:0c:2b:59:8d:06:95:b9:26:69:12:6a:bb:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78436c6a8632250c2b598d0695b92669126abb74/; sid:902205028; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f0:4a:75:e6:50:71:73:fa:ee:c2:bb:82:c5:64:03:0a:5e:84:13:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f04a75e6507173faeec2bb82c564030a5e8413ff/; sid:902205029; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:71:9d:77:50:8b:45:fb:c4:22:47:1d:20:59:ef:79:ff:55:8a:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a719d77508b45fbc422471d2059ef79ff558a4d/; sid:902205030; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vjw0rm C&C)"; tls.fingerprint:"a5:6c:ed:67:e4:3b:d6:67:f8:29:16:1a:91:d4:87:01:6f:fb:96:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a56ced67e43bd667f829161a91d487016ffb9672/; sid:902205031; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cc:c1:7a:e2:62:83:54:e5:4e:4f:39:25:b4:83:26:73:f5:35:af:b8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ccc17ae2628354e54e4f3925b4832673f535afb8/; sid:902205032; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5e:59:50:d6:a4:68:ac:40:92:eb:6d:ee:e3:08:ef:27:fa:4a:a8:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5e5950d6a468ac4092eb6deee308ef27fa4aa817/; sid:902205033; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"3a:62:b3:29:54:6a:88:17:80:ad:2c:a9:35:bc:14:49:a2:f2:73:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a62b329546a881780ad2ca935bc1449a2f273dd/; sid:902205034; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:05:97:8a:1b:cd:ba:b4:73:f6:5a:8f:86:20:99:1d:4b:da:f9:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd05978a1bcdbab473f65a8f8620991d4bdaf9fe/; sid:902205035; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"49:f2:7d:39:c4:f9:ed:9f:e3:cc:a0:6b:ff:b9:57:58:32:64:ad:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49f27d39c4f9ed9fe3cca06bffb957583264ad3b/; sid:902205036; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b6:c5:1c:fe:0d:b2:02:3a:4b:8b:9d:37:3e:dd:f0:b3:a3:95:d8:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6c51cfe0db2023a4b8b9d373eddf0b3a395d892/; sid:902205037; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c3:90:e6:28:81:f2:53:47:c3:9c:de:51:02:4a:9c:68:7d:49:67:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c390e62881f25347c39cde51024a9c687d49675f/; sid:902205038; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"07:3a:e3:fa:fe:03:23:f0:0f:08:80:09:56:78:22:c9:9c:2f:30:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/073ae3fafe0323f00f088009567822c99c2f3090/; sid:902205039; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"97:f4:80:af:d1:8b:07:8b:dc:db:af:4c:b1:45:83:95:41:61:15:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97f480afd18b078bdcdbaf4cb14583954161150a/; sid:902205040; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a2:9d:95:a4:ef:e6:24:60:42:0d:ed:10:f8:47:c4:c1:a0:a7:5e:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a29d95a4efe62460420ded10f847c4c1a0a75e0e/; sid:902205041; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7e:19:05:f5:f7:a6:dc:4a:20:93:62:fa:1b:21:c4:2c:63:c8:42:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7e1905f5f7a6dc4a209362fa1b21c42c63c8422b/; sid:902205042; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:06:ec:ac:4e:49:b4:46:55:29:d3:9e:da:ee:e8:f1:6d:01:4d:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c906ecac4e49b4465529d39edaeee8f16d014db9/; sid:902205043; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:02:1e:3c:55:8b:8e:36:26:8f:51:89:18:a0:6a:1c:83:0c:cf:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a021e3c558b8e36268f518918a06a1c830ccff9/; sid:902205044; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"d1:0e:6c:d0:13:94:9c:08:1d:b7:11:7c:bb:b1:69:64:0b:2c:26:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d10e6cd013949c081db7117cbbb169640b2c260a/; sid:902205045; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0e:27:6e:bc:2d:52:a5:8a:4a:31:f1:c9:33:16:53:8b:85:24:af:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e276ebc2d52a58a4a31f1c93316538b8524afa7/; sid:902205046; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:b6:db:23:29:9d:ae:a2:a7:66:af:c6:38:7e:4f:44:78:a8:c2:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67b6db23299daea2a766afc6387e4f4478a8c209/; sid:902205047; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"08:29:d7:66:b7:ad:04:25:84:9c:63:0e:09:c6:74:cd:c0:4c:29:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0829d766b7ad0425849c630e09c674cdc04c29a4/; sid:902205048; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"74:5f:7f:9e:e8:ec:74:a2:00:9f:40:40:d6:44:3a:bf:12:d6:d2:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/745f7f9ee8ec74a2009f4040d6443abf12d6d22a/; sid:902205049; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f8:d6:ee:a1:11:ec:7c:4c:7b:53:02:41:32:ca:ca:86:97:fc:ab:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8d6eea111ec7c4c7b53024132caca8697fcabbd/; sid:902205050; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"db:9a:f5:49:ae:a6:74:0d:59:6c:7d:de:16:4e:83:f5:c2:28:5c:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db9af549aea6740d596c7dde164e83f5c2285c09/; sid:902205051; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:a5:b7:0f:77:45:36:d6:01:ba:60:82:0f:ab:92:fa:60:96:99:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5a5b70f774536d601ba60820fab92fa609699df/; sid:902205052; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"59:a9:20:39:f9:51:e5:06:9c:9f:50:fd:9f:34:0e:75:97:13:b0:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/59a92039f951e5069c9f50fd9f340e759713b058/; sid:902205053; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ab:fa:d1:48:c8:e4:3f:f7:51:68:87:c3:73:3b:22:90:60:23:61:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abfad148c8e43ff7516887c3733b2290602361c9/; sid:902205054; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"96:b4:f2:96:70:af:67:0e:1d:6b:85:2e:6b:54:e6:1d:9c:ef:ec:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/96b4f29670af670e1d6b852e6b54e61d9cefec30/; sid:902205055; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"18:90:b3:a0:cb:98:6f:f4:dd:98:13:76:93:88:76:a6:13:09:b5:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1890b3a0cb986ff4dd981376938876a61309b588/; sid:902205056; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3f:66:24:1b:80:7b:b2:24:a1:25:6b:7b:00:62:6d:a6:54:1b:6d:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f66241b807bb224a1256b7b00626da6541b6d6f/; sid:902205057; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"67:ab:40:f5:7f:a8:43:54:85:9b:a3:ea:df:6a:41:07:d3:5a:8d:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67ab40f57fa84354859ba3eadf6a4107d35a8dba/; sid:902205058; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"02:f6:54:56:66:72:9e:c9:8f:d2:fe:d2:46:3b:b2:e9:59:99:90:e8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02f6545666729ec98fd2fed2463bb2e9599990e8/; sid:902205059; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"62:91:3f:92:e0:0b:74:59:88:e8:a4:60:9a:c7:99:47:76:88:93:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62913f92e00b745988e8a4609ac7994776889317/; sid:902205060; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"70:92:b4:7f:c4:80:b4:20:29:b8:1d:b2:1b:6d:87:53:a3:32:63:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7092b47fc480b42029b81db21b6d8753a3326395/; sid:902205061; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ce:ce:f4:05:ec:05:43:5f:a3:b0:63:7b:47:44:08:49:68:cf:26:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cecef405ec05435fa3b0637b4744084968cf26b4/; sid:902205062; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"99:69:1f:03:4c:74:5e:33:f7:a8:7f:ee:ec:f6:a1:e3:2b:90:04:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/99691f034c745e33f7a87feeecf6a1e32b90045f/; sid:902205063; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"74:f3:29:64:69:06:a5:2a:92:9b:06:4f:86:aa:7c:da:3c:01:5b:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/74f329646906a52a929b064f86aa7cda3c015bf1/; sid:902205064; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"14:ef:a1:0c:23:4b:5c:6d:bb:fb:25:20:e1:44:f9:15:08:ba:4b:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14efa10c234b5c6dbbfb2520e144f91508ba4b7c/; sid:902205065; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"39:f1:6b:69:44:8d:96:11:09:3a:81:88:cc:4a:9b:74:f0:91:27:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39f16b69448d9611093a8188cc4a9b74f09127de/; sid:902205066; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"f8:a4:3f:9e:9e:5c:1b:ea:ee:da:0a:1a:bd:27:08:2a:80:56:c7:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8a43f9e9e5c1beaeeda0a1abd27082a8056c759/; sid:902205067; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:4c:89:b2:28:e9:b2:c6:e5:7c:19:d2:fd:a6:3a:dd:46:47:9c:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/804c89b228e9b2c6e57c19d2fda63add46479c53/; sid:902205068; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"af:f5:0d:82:9b:82:5b:1f:a2:f7:8e:8e:cc:c9:71:20:c6:84:d1:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aff50d829b825b1fa2f78e8eccc97120c684d1cd/; sid:902205069; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"aa:91:72:a6:4e:c2:d4:ef:18:43:c2:08:09:a1:b0:b3:00:db:2b:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa9172a64ec2d4ef1843c20809a1b0b300db2b8e/; sid:902205070; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a2:48:21:29:dc:5f:2f:07:75:06:a3:08:f9:5d:df:7d:8a:4a:fe:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2482129dc5f2f077506a308f95ddf7d8a4afedd/; sid:902205071; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"0b:ee:fb:32:f9:fc:a5:56:2e:e3:bf:9e:c7:e3:51:44:4f:0f:73:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0beefb32f9fca5562ee3bf9ec7e351444f0f7381/; sid:902205072; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bf:3b:15:4d:f2:97:a9:3e:5d:32:25:a5:d8:03:3e:97:f8:79:4b:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf3b154df297a93e5d3225a5d8033e97f8794bbb/; sid:902205073; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"7c:9a:39:67:b2:46:7b:f3:54:72:98:b1:5f:b7:41:92:71:cb:e0:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7c9a3967b2467bf3547298b15fb7419271cbe046/; sid:902205074; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"83:48:7d:17:0e:d9:ba:79:4c:9a:b7:bd:b7:8c:99:c0:0d:e3:74:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83487d170ed9ba794c9ab7bdb78c99c00de37445/; sid:902205075; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"47:de:b6:22:88:45:18:54:5d:a4:f8:00:24:26:38:fa:f9:9d:fc:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47deb622884518545da4f800242638faf99dfc91/; sid:902205076; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"96:0d:5e:ca:a9:53:b8:8e:52:af:a5:d5:4e:6b:2c:61:ac:9a:ed:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/960d5ecaa953b88e52afa5d54e6b2c61ac9aed6b/; sid:902205077; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"d3:3d:ee:92:f0:f5:de:07:11:03:54:ca:ff:48:4f:e1:e6:b5:48:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d33dee92f0f5de07110354caff484fe1e6b54886/; sid:902205078; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"25:95:2b:83:aa:dc:e9:9a:c0:f0:6d:86:74:ad:0b:83:63:54:c4:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/25952b83aadce99ac0f06d8674ad0b836354c407/; sid:902205079; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:e2:ef:7f:7e:bf:62:2a:d3:c6:14:ff:9e:5b:76:70:b5:d1:f2:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92e2ef7f7ebf622ad3c614ff9e5b7670b5d1f218/; sid:902205080; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cd:30:67:c8:b6:6b:09:fe:55:df:19:24:62:29:12:03:fd:87:c9:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cd3067c8b66b09fe55df192462291203fd87c9cd/; sid:902205081; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"20:e8:c5:46:1f:d7:bf:1b:8c:38:aa:8e:2e:4b:da:0e:e1:ef:fb:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20e8c5461fd7bf1b8c38aa8e2e4bda0ee1effb42/; sid:902205082; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e8:80:37:af:bd:4b:78:97:be:96:a3:dd:b8:70:87:78:ea:be:2c:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e88037afbd4b7897be96a3ddb8708778eabe2cde/; sid:902205083; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"4d:16:c3:3b:65:25:c2:d3:d4:82:a3:2b:8c:ca:51:8e:4c:0c:f9:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d16c33b6525c2d3d482a32b8cca518e4c0cf9f7/; sid:902205084; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"53:31:60:b4:fb:cc:b2:1a:34:ca:96:3e:15:47:3d:98:7a:ad:58:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/533160b4fbccb21a34ca963e15473d987aad58f1/; sid:902205085; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:0c:de:5d:03:9e:78:fe:b1:8a:f0:c2:12:fa:01:92:47:03:67:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/290cde5d039e78feb18af0c212fa019247036702/; sid:902205086; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"1c:bb:0d:8a:d6:ad:39:77:ce:31:71:40:26:4f:b7:c5:e7:17:9e:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cbb0d8ad6ad3977ce317140264fb7c5e7179e5f/; sid:902205087; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d3:74:95:70:79:5a:04:1a:5b:9b:7f:71:d1:5c:d5:39:09:6d:c3:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3749570795a041a5b9b7f71d15cd539096dc336/; sid:902205088; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"17:cc:a4:da:0c:0e:54:62:41:8b:65:c7:8b:84:ac:cb:11:37:eb:26"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17cca4da0c0e5462418b65c78b84accb1137eb26/; sid:902205089; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f3:23:23:2b:41:a1:8c:9e:75:bf:57:a1:69:a3:b1:2d:04:19:76:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f323232b41a18c9e75bf57a169a3b12d04197697/; sid:902205090; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"c9:2d:f6:e1:c9:58:8d:d9:67:96:b1:1c:0c:c8:02:79:63:1b:bb:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c92df6e1c9588dd96796b11c0cc80279631bbba8/; sid:902205091; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:8c:12:6d:30:2c:98:7e:4d:48:ad:05:4e:31:7d:59:2c:e8:d4:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/798c126d302c987e4d48ad054e317d592ce8d484/; sid:902205092; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2f:fa:56:4a:f8:3c:ae:ec:70:8c:e1:e9:e8:39:3f:a0:4d:0f:08:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2ffa564af83caeec708ce1e9e8393fa04d0f0864/; sid:902205093; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:0d:2b:3b:35:4c:6e:d1:fc:65:3c:9e:09:01:e0:14:8c:38:93:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/670d2b3b354c6ed1fc653c9e0901e0148c389317/; sid:902205094; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e5:06:7b:a7:fb:1c:cd:3c:81:28:b3:61:db:19:66:4e:f1:dd:0a:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e5067ba7fb1ccd3c8128b361db19664ef1dd0ad8/; sid:902205095; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"9e:9b:35:35:52:39:90:de:10:ea:2e:bc:7b:4a:1f:a5:d2:cb:8f:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e9b3535523990de10ea2ebc7b4a1fa5d2cb8f70/; sid:902205096; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"56:81:9c:67:2f:c1:d9:7e:95:b9:21:5f:f5:91:5c:dc:03:46:31:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/56819c672fc1d97e95b9215ff5915cdc03463102/; sid:902205097; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d5:5b:0c:3e:2b:c6:df:6f:06:a5:c4:1f:bb:dc:15:7c:d3:21:6e:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d55b0c3e2bc6df6f06a5c41fbbdc157cd3216ec0/; sid:902205098; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a5:40:85:62:44:cf:c3:52:f6:bd:b7:d3:63:66:ec:27:3c:d0:af:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a540856244cfc352f6bdb7d36366ec273cd0afe9/; sid:902205099; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:64:21:7c:37:ce:3f:8d:be:e1:4e:93:d0:f9:59:ac:30:73:e7:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b964217c37ce3f8dbee14e93d0f959ac3073e746/; sid:902205100; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"20:d9:6d:b3:27:cf:bb:1a:03:37:0d:12:61:b2:d4:cd:f0:e7:7b:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20d96db327cfbb1a03370d1261b2d4cdf0e77bc0/; sid:902205101; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:8a:16:1d:5c:b6:d7:14:c6:f9:09:56:9c:8d:83:c1:48:25:be:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a8a161d5cb6d714c6f909569c8d83c14825be10/; sid:902205102; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"52:ff:2f:c2:51:9c:ff:d6:1b:48:db:62:15:c4:b1:8e:b0:09:0a:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52ff2fc2519cffd61b48db6215c4b18eb0090a95/; sid:902205103; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"3e:9e:14:1a:d8:3c:5b:d6:ce:91:88:0c:0e:25:6e:15:40:1e:c6:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e9e141ad83c5bd6ce91880c0e256e15401ec674/; sid:902205104; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e5:3d:eb:95:2f:ad:b3:9a:2c:0c:f5:68:1c:d1:28:46:c2:34:80:8f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e53deb952fadb39a2c0cf5681cd12846c234808f/; sid:902205105; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:7b:6a:f3:10:f7:0f:9d:9d:94:34:31:b2:74:29:26:71:4d:0d:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/517b6af310f70f9d9d943431b2742926714d0d0d/; sid:902205106; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"90:ac:75:88:20:db:52:ef:9c:e1:98:d3:59:c5:38:a4:4c:26:ab:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/90ac758820db52ef9ce198d359c538a44c26ab59/; sid:902205107; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"56:66:47:6e:e8:3f:70:a6:ac:21:93:66:d7:aa:67:b6:c1:9c:d9:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5666476ee83f70a6ac219366d7aa67b6c19cd929/; sid:902205108; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"85:7c:a7:37:bd:9f:19:b6:b1:01:52:a8:5f:42:4d:10:74:a4:d8:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/857ca737bd9f19b6b10152a85f424d1074a4d834/; sid:902205109; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7f:4a:db:5e:da:82:72:4c:d6:bd:d1:eb:33:a2:3e:fc:2c:c1:51:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f4adb5eda82724cd6bdd1eb33a23efc2cc15104/; sid:902205110; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"27:4c:4c:b4:53:96:a4:70:39:f9:29:2d:f2:a7:54:dc:52:22:55:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/274c4cb45396a47039f9292df2a754dc52225502/; sid:902205111; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Meterpreter C&C)"; tls.fingerprint:"43:20:d2:35:7d:0a:95:ad:13:b5:83:d1:bd:1e:65:c8:ae:ef:cd:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4320d2357d0a95ad13b583d1bd1e65c8aeefcde3/; sid:902205112; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:da:ef:ab:b9:95:74:13:55:96:33:70:95:3a:6a:ac:97:ef:01:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27daefabb995741355963370953a6aac97ef015d/; sid:902205113; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:36:6f:ef:4f:f8:d5:71:d8:15:a9:f5:a7:35:74:ea:2e:ea:f4:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a366fef4ff8d571d815a9f5a73574ea2eeaf40c/; sid:902205114; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"36:8e:ee:19:0f:7a:3e:36:8f:fc:18:69:97:ba:43:24:e3:29:20:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/368eee190f7a3e368ffc186997ba4324e329200a/; sid:902205115; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f9:ec:de:7d:48:11:2d:23:a7:5b:a9:43:84:d4:89:9d:44:69:86:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9ecde7d48112d23a75ba94384d4899d4469866c/; sid:902205116; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b2:71:ec:2a:83:aa:2a:62:45:85:80:8d:fd:2f:66:51:c0:35:c8:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b271ec2a83aa2a624585808dfd2f6651c035c889/; sid:902205117; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3b:bb:0d:f2:72:f6:e2:08:cf:e5:71:d8:89:e0:c3:98:ea:3b:87:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3bbb0df272f6e208cfe571d889e0c398ea3b87e6/; sid:902205118; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c8:4c:b6:13:47:01:74:1c:51:22:a1:4f:ac:db:67:c8:cf:a9:c0:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c84cb6134701741c5122a14facdb67c8cfa9c0ab/; sid:902205119; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"41:11:eb:4e:34:52:f3:04:6c:6f:5d:fe:90:f8:4f:08:d3:e1:bb:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4111eb4e3452f3046c6f5dfe90f84f08d3e1bb9c/; sid:902205120; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f2:f1:0a:25:f4:d0:d0:54:3f:55:20:c8:c8:ba:c5:00:da:1b:1a:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f2f10a25f4d0d0543f5520c8c8bac500da1b1ac1/; sid:902205121; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c4:bc:ef:f5:5f:71:3b:0e:1a:dd:1d:61:df:69:b0:ea:fb:56:bb:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4bceff55f713b0e1add1d61df69b0eafb56bb93/; sid:902205122; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:19:db:0e:77:8c:00:0f:f5:ea:74:15:85:2c:88:a4:7e:40:64:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b119db0e778c000ff5ea7415852c88a47e4064ab/; sid:902205123; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"33:f9:3f:89:08:66:d7:f4:b9:95:5f:3e:29:a7:85:43:42:41:4a:c5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33f93f890866d7f4b9955f3e29a7854342414ac5/; sid:902205124; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:36:5b:84:ba:c5:d2:e0:e7:db:9f:bf:8b:ea:49:aa:22:40:52:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94365b84bac5d2e0e7db9fbf8bea49aa2240525e/; sid:902205125; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ad:04:51:44:44:aa:97:1b:c8:4c:16:e6:c0:0e:57:5b:e0:58:8d:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad04514444aa971bc84c16e6c00e575be0588d93/; sid:902205126; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"ec:81:57:af:1f:ab:c6:4a:3b:31:e7:e6:84:a1:17:75:b5:b6:08:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ec8157af1fabc64a3b31e7e684a11775b5b60874/; sid:902205127; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"93:25:00:3b:38:39:65:fd:a1:d3:46:95:03:04:bb:f7:68:1b:e8:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9325003b383965fda1d346950304bbf7681be82c/; sid:902205128; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"72:17:b1:22:73:36:15:6c:6b:5e:ae:9d:85:e4:10:7e:2f:74:d8:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7217b1227336156c6b5eae9d85e4107e2f74d8d0/; sid:902205129; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"bc:dd:9d:bd:60:3e:10:d9:79:44:43:e7:36:84:67:ad:d9:21:3f:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcdd9dbd603e10d9794443e7368467add9213f6b/; sid:902205130; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ad:3a:b0:63:e6:de:4e:ee:ae:b6:73:18:c1:05:d8:55:20:94:dd:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad3ab063e6de4eeeaeb67318c105d8552094dd06/; sid:902205131; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"54:7c:2f:b1:1a:13:67:1c:49:51:d6:13:cd:ab:a9:f2:f6:a0:16:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/547c2fb11a13671c4951d613cdaba9f2f6a0161f/; sid:902205132; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"94:0f:b0:c3:a9:89:d7:fa:eb:96:8a:90:a8:6d:9c:6f:3b:db:a8:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/940fb0c3a989d7faeb968a90a86d9c6f3bdba8fd/; sid:902205133; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"1f:40:6e:ed:3f:64:6a:1a:30:cf:e9:56:67:e1:df:a3:88:47:63:e9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1f406eed3f646a1a30cfe95667e1dfa3884763e9/; sid:902205134; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"e4:bb:a1:6c:2a:a6:56:3e:30:a7:ea:fc:cb:cb:5f:43:e4:b7:2f:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4bba16c2aa6563e30a7eafccbcb5f43e4b72f68/; sid:902205135; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"31:3b:7c:c0:78:75:6b:a4:56:56:79:a4:88:77:bc:51:6a:c4:1a:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/313b7cc078756ba4565679a48877bc516ac41af4/; sid:902205136; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3d:af:49:99:76:ab:20:e5:61:70:4c:9e:56:1f:43:f2:6b:f8:c3:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3daf499976ab20e561704c9e561f43f26bf8c394/; sid:902205137; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"3b:93:12:83:29:c3:8c:48:f4:27:d3:1f:51:40:1d:ed:a7:9d:bc:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b93128329c38c48f427d31f51401deda79dbce6/; sid:902205138; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"52:c9:9b:8b:5c:5d:69:34:ee:8c:f8:d1:5c:84:a8:f7:a1:2a:57:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52c99b8b5c5d6934ee8cf8d15c84a8f7a12a57ed/; sid:902205139; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f7:68:99:07:81:e2:a6:d9:b9:03:13:c7:c6:71:4b:ed:d1:ae:16:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f768990781e2a6d9b90313c7c6714bedd1ae162a/; sid:902205140; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"d8:cc:44:6d:ef:18:16:0f:ff:1c:b6:d4:b5:50:0f:91:33:aa:48:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d8cc446def18160fff1cb6d4b5500f9133aa4890/; sid:902205141; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:e6:65:dd:3f:f7:5c:2d:d8:47:4f:e6:2b:bf:30:f4:54:1a:11:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9ee665dd3ff75c2dd8474fe62bbf30f4541a117f/; sid:902205142; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:25:87:36:52:5b:d5:29:53:5a:9b:73:b5:66:d1:f2:c8:f1:44:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14258736525bd529535a9b73b566d1f2c8f14461/; sid:902205143; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"f5:99:9b:ff:a7:0a:09:d8:45:6c:49:e3:f6:fc:6b:fd:68:66:d7:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5999bffa70a09d8456c49e3f6fc6bfd6866d71b/; sid:902205144; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d6:92:3b:a0:6e:28:e7:68:1f:0a:0c:e3:4f:06:71:9d:36:30:bf:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d6923ba06e28e7681f0a0ce34f06719d3630bf4f/; sid:902205145; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"6b:db:30:2e:1d:d3:a6:af:6e:22:f3:19:da:18:98:b4:6e:eb:9c:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6bdb302e1dd3a6af6e22f319da1898b46eeb9c55/; sid:902205146; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6c:d7:a7:27:eb:9f:3a:77:e3:fe:d0:c3:85:67:ef:be:1d:88:15:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cd7a727eb9f3a77e3fed0c38567efbe1d88157a/; sid:902205147; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:3b:19:da:4e:43:76:b2:fb:a6:ae:01:07:c9:69:57:e2:20:b0:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c33b19da4e4376b2fba6ae0107c96957e220b0f2/; sid:902205148; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:35:a1:08:e9:bb:80:f6:cd:3a:28:0a:47:55:ba:d1:a7:bb:eb:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6735a108e9bb80f6cd3a280a4755bad1a7bbeb1a/; sid:902205149; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"5f:3c:be:fd:74:63:d0:cc:d3:dc:59:9e:8a:9d:94:fe:08:30:cc:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5f3cbefd7463d0ccd3dc599e8a9d94fe0830cc06/; sid:902205150; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"93:6c:78:4d:f6:bf:bc:b8:6d:89:ed:f1:da:84:25:e6:d7:0d:cf:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/936c784df6bfbcb86d89edf1da8425e6d70dcfbb/; sid:902205151; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:3e:ce:78:ef:c1:a5:5a:8e:63:ee:09:27:58:c3:af:1a:94:eb:c0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/593ece78efc1a55a8e63ee092758c3af1a94ebc0/; sid:902205152; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"84:fb:d7:2d:1c:9a:08:b5:d6:c2:1d:f8:1a:7e:f2:39:f4:c5:f6:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/84fbd72d1c9a08b5d6c21df81a7ef239f4c5f63a/; sid:902205153; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"69:f4:76:ae:bc:36:cd:cb:23:51:87:23:0c:f3:f9:95:52:bd:17:03"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69f476aebc36cdcb235187230cf3f99552bd1703/; sid:902205154; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"e1:22:46:90:82:c0:9f:12:ff:47:77:fb:52:03:73:9e:6d:9a:8f:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e122469082c09f12ff4777fb5203739e6d9a8fda/; sid:902205155; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ac:8f:6f:9b:65:7e:86:e5:26:31:c7:20:15:78:08:b3:d1:7c:ab:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ac8f6f9b657e86e52631c720157808b3d17cab69/; sid:902205156; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"69:5f:e4:b0:58:17:67:96:7e:6d:9c:75:41:c7:5c:c7:09:2e:c7:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/695fe4b0581767967e6d9c7541c75cc7092ec788/; sid:902205157; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"29:15:93:ff:4d:75:ea:47:cf:97:c5:34:73:e8:9e:72:03:81:6b:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/291593ff4d75ea47cf97c53473e89e7203816b27/; sid:902205158; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"7d:f4:58:e2:6a:20:58:1d:2d:9f:d7:8f:db:f2:b4:50:bd:bb:64:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7df458e26a20581d2d9fd78fdbf2b450bdbb643d/; sid:902205159; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e8:8c:ae:4f:69:0a:f1:12:76:24:21:61:cc:d3:73:d9:14:a1:be:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e88cae4f690af11276242161ccd373d914a1bea7/; sid:902205160; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"9c:7a:da:c0:79:88:a1:f8:77:7e:35:50:fa:e5:de:6a:34:1a:86:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c7adac07988a1f8777e3550fae5de6a341a86d2/; sid:902205161; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d2:bb:3a:cf:c2:bb:4d:21:79:c7:d5:16:5d:f8:e1:d9:fe:44:e1:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d2bb3acfc2bb4d2179c7d5165df8e1d9fe44e150/; sid:902205162; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2d:1a:39:94:d3:c8:e5:c6:07:1e:70:48:58:90:30:f3:e3:89:dd:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d1a3994d3c8e5c6071e7048589030f3e389ddc7/; sid:902205163; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"37:24:bf:2e:a7:7f:f1:3e:a8:36:ee:0f:e8:ec:b7:fd:dc:b8:cd:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3724bf2ea77ff13ea836ee0fe8ecb7fddcb8cd76/; sid:902205164; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:88:2e:31:3d:72:64:3d:cd:a0:40:cb:67:54:cc:c7:ac:79:d9:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee882e313d72643dcda040cb6754ccc7ac79d95b/; sid:902205165; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a8:72:5c:3c:2c:b0:7b:5c:e5:9c:49:93:14:cf:3a:cf:2c:43:c2:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8725c3c2cb07b5ce59c499314cf3acf2c43c217/; sid:902205166; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"79:b3:73:57:b4:15:8e:d8:4f:18:f4:e8:5b:77:13:cf:2d:04:a0:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/79b37357b4158ed84f18f4e85b7713cf2d04a0d9/; sid:902205167; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"bb:ec:7f:09:e2:36:97:eb:0d:5d:77:2f:38:55:b3:58:93:fc:30:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbec7f09e23697eb0d5d772f3855b35893fc307a/; sid:902205168; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"64:72:07:29:26:3e:98:b5:df:0b:ab:c4:33:45:a6:b9:b9:42:10:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64720729263e98b5df0babc43345a6b9b94210be/; sid:902205169; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c9:87:fc:24:73:d3:df:2f:6d:61:09:45:15:65:3b:e8:a5:c7:54:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c987fc2473d3df2f6d61094515653be8a5c75441/; sid:902205170; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"38:a4:29:48:a8:fe:12:e0:c8:e3:6a:40:80:58:62:24:7a:08:21:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/38a42948a8fe12e0c8e36a40805862247a0821bf/; sid:902205171; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"68:0f:48:fb:b8:1b:9f:7c:85:03:b9:07:7b:15:b0:df:b3:cc:8e:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/680f48fbb81b9f7c8503b9077b15b0dfb3cc8e79/; sid:902205172; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"eb:5a:14:fa:b2:23:ec:62:ca:25:06:9e:1e:93:68:c1:ba:de:62:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb5a14fab223ec62ca25069e1e9368c1bade62f9/; sid:902205173; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:14:3a:9c:a9:3c:9b:bd:c9:7f:46:27:75:6f:7a:10:b6:b4:bc:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01143a9ca93c9bbdc97f4627756f7a10b6b4bc66/; sid:902205174; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7f:56:09:19:6f:c5:fa:b9:3b:46:44:2f:41:7a:4c:3b:90:b1:08:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7f5609196fc5fab93b46442f417a4c3b90b108f6/; sid:902205175; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"2c:8e:11:bb:12:62:6d:6b:02:a7:d3:d9:13:fb:a2:4a:dc:2e:4c:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2c8e11bb12626d6b02a7d3d913fba24adc2e4ca3/; sid:902205176; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"bb:b0:5b:54:0b:fd:17:c1:77:e5:2f:7c:d9:7c:ab:7c:83:0b:a9:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbb05b540bfd17c177e52f7cd97cab7c830ba90c/; sid:902205177; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"35:5a:e6:ac:55:f6:51:24:12:32:ea:29:9b:9b:67:fb:6a:d3:88:48"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/355ae6ac55f651241232ea299b9b67fb6ad38848/; sid:902205178; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"83:11:2e:b8:c6:f7:35:ef:54:e6:21:e0:80:e7:46:b7:06:45:81:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83112eb8c6f735ef54e621e080e746b706458129/; sid:902205179; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8a:3e:1e:d7:87:c1:e7:ba:ba:d7:34:4a:e5:51:7f:a9:0a:ec:04:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a3e1ed787c1e7babad7344ae5517fa90aec04d8/; sid:902205180; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"39:d3:db:18:79:2e:fc:d7:8b:b5:0e:ba:92:03:dd:f4:ac:a1:dd:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39d3db18792efcd78bb50eba9203ddf4aca1ddd3/; sid:902205181; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"82:b9:13:ee:d8:83:1b:65:39:3f:24:eb:b0:f4:b3:ec:07:63:51:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82b913eed8831b65393f24ebb0f4b3ec07635123/; sid:902205182; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:eb:de:b6:83:09:7c:d9:4a:c5:3d:e9:7e:15:80:f8:9a:1d:5b:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c3ebdeb683097cd94ac53de97e1580f89a1d5b52/; sid:902205183; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"83:fe:26:aa:d8:44:f1:01:03:67:26:af:cd:7f:28:cf:37:7d:20:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/83fe26aad844f101036726afcd7f28cf377d20af/; sid:902205184; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:a8:2a:72:2a:d7:b5:37:64:94:d7:11:27:85:b3:66:da:6c:f4:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/08a82a722ad7b5376494d7112785b366da6cf449/; sid:902205185; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d5:00:0b:9a:b5:d2:15:e8:eb:b9:36:3d:e2:74:1c:67:94:06:8c:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d5000b9ab5d215e8ebb9363de2741c6794068c7c/; sid:902205186; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"34:ea:a5:05:d1:db:50:ee:02:55:58:a7:2f:9f:26:64:72:08:f0:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34eaa505d1db50ee025558a72f9f26647208f015/; sid:902205187; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"8b:a2:39:a2:9e:e0:e4:35:00:00:eb:ac:93:0b:1d:cf:ef:30:12:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ba239a29ee0e4350000ebac930b1dcfef301254/; sid:902205188; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"7b:5e:ba:eb:d4:8e:20:47:2b:ad:60:dc:c7:1e:98:79:cd:46:1d:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7b5ebaebd48e20472bad60dcc71e9879cd461dde/; sid:902205189; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b0:32:63:95:ac:2d:48:85:6c:ae:22:97:8a:08:7d:f5:dc:f5:81:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b0326395ac2d48856cae22978a087df5dcf5816d/; sid:902205190; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f3:59:9d:7b:0c:05:c0:35:a8:31:db:2d:89:c8:eb:b6:16:fb:40:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f3599d7b0c05c035a831db2d89c8ebb616fb407d/; sid:902205191; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8a:a6:dc:43:4d:d2:90:a6:17:c8:19:fb:8d:73:37:44:35:03:16:59"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8aa6dc434dd290a617c819fb8d73374435031659/; sid:902205192; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:5b:fc:cc:78:06:48:29:e5:e2:f3:60:9e:53:6d:54:68:5b:b8:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd5bfccc78064829e5e2f3609e536d54685bb85a/; sid:902205193; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c9:25:a9:46:d3:b6:0d:09:cc:81:c4:6e:31:e9:e5:dc:00:21:f5:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c925a946d3b60d09cc81c46e31e9e5dc0021f504/; sid:902205194; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:29:ef:ab:82:16:df:19:43:7c:da:44:82:f4:c7:82:bd:5f:65:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8229efab8216df19437cda4482f4c782bd5f6554/; sid:902205195; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bb:db:bc:5c:9c:29:aa:27:4f:48:de:ab:62:cd:97:f8:8a:a0:66:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bbdbbc5c9c29aa274f48deab62cd97f88aa066db/; sid:902205196; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"59:7c:f6:96:f8:e2:b1:8d:01:39:9b:c4:a0:61:1a:cb:55:7b:4d:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/597cf696f8e2b18d01399bc4a0611acb557b4d36/; sid:902205197; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:28:b8:19:80:07:86:44:e7:fa:17:a3:d2:ce:83:d2:4d:e2:c7:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0128b81980078644e7fa17a3d2ce83d24de2c743/; sid:902205198; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"df:c2:33:22:5e:f8:e5:7b:28:e1:98:e5:23:e0:3e:ad:e9:75:73:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dfc233225ef8e57b28e198e523e03eade9757387/; sid:902205199; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:77:b2:28:28:58:a4:e7:55:b1:98:0a:65:7c:d2:cb:d4:af:32:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5177b2282858a4e755b1980a657cd2cbd4af324d/; sid:902205200; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"08:75:f2:8f:e3:af:06:4b:f7:89:f5:60:5c:f8:a3:98:0c:fd:9d:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0875f28fe3af064bf789f5605cf8a3980cfd9d6a/; sid:902205201; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:dd:7c:6c:52:10:fd:2c:8e:c9:52:67:98:b2:df:d4:38:8c:f4:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7dd7c6c5210fd2c8ec9526798b2dfd4388cf4fa/; sid:902205202; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e1:c2:8c:32:fd:4d:57:e9:90:aa:eb:98:11:70:69:d8:6c:7d:ee:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1c28c32fd4d57e990aaeb98117069d86c7deef8/; sid:902205203; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"db:b1:06:22:35:14:dd:44:b1:01:80:f7:2d:14:8a:87:43:14:3d:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbb106223514dd44b10180f72d148a8743143dca/; sid:902205204; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"04:62:d9:44:ec:9f:f4:38:06:f9:6a:e7:e0:7b:47:cb:b4:3b:66:7d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0462d944ec9ff43806f96ae7e07b47cbb43b667d/; sid:902205205; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"a6:31:eb:bf:ab:52:3d:3a:79:86:d7:ed:02:86:f3:9e:94:23:89:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a631ebbfab523d3a7986d7ed0286f39e9423890e/; sid:902205206; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a1:92:75:bc:88:7e:0e:ba:38:43:57:26:43:9b:ca:9e:6a:d4:34:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a19275bc887e0eba38435726439bca9e6ad43452/; sid:902205207; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"93:e2:4a:ce:7f:fa:02:f1:92:7a:56:c6:2c:fe:fa:bc:58:e6:46:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93e24ace7ffa02f1927a56c62cfefabc58e6463e/; sid:902205208; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:56:99:d2:99:76:a3:97:15:a3:cf:fe:58:7e:d6:29:02:80:08:a3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/065699d29976a39715a3cffe587ed629028008a3/; sid:902205209; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f9:8c:64:65:63:eb:13:16:6d:de:4c:92:21:27:a2:f3:46:96:d1:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f98c646563eb13166dde4c922127a2f34696d1ec/; sid:902205210; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"30:6b:b0:84:7c:94:da:f4:38:32:88:61:79:4f:64:df:13:83:0d:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/306bb0847c94daf438328861794f64df13830d8d/; sid:902205211; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"84:0c:7a:75:9f:58:30:23:96:0d:f5:f7:55:cf:28:b5:8f:7c:aa:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/840c7a759f583023960df5f755cf28b58f7caa93/; sid:902205212; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"40:ca:a9:ba:a1:90:76:ef:b7:a0:1b:9a:17:86:77:99:c1:2f:f5:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40caa9baa19076efb7a01b9a17867799c12ff506/; sid:902205213; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b7:23:4f:3a:d1:a5:9c:70:01:a5:8a:9a:2e:42:5f:db:3d:15:ba:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7234f3ad1a59c7001a58a9a2e425fdb3d15baf1/; sid:902205214; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"59:7d:94:ab:68:2f:74:ad:42:21:b6:2e:30:27:40:b2:fb:c8:33:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/597d94ab682f74ad4221b62e302740b2fbc833a8/; sid:902205215; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"0e:56:dc:d8:bf:da:1d:43:c1:7e:02:91:2d:b3:b9:2e:d2:a0:c0:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0e56dcd8bfda1d43c17e02912db3b92ed2a0c088/; sid:902205216; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"11:5c:3b:bd:63:00:a1:3a:85:93:e1:ea:09:04:33:cd:aa:85:39:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/115c3bbd6300a13a8593e1ea090433cdaa8539ca/; sid:902205217; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"78:bc:50:02:13:62:b6:16:52:20:49:81:b1:3f:e1:7e:05:3a:03:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78bc50021362b61652204981b13fe17e053a03f1/; sid:902205218; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:90:b3:4b:fd:da:7c:49:08:52:1f:f6:9f:50:a9:47:cd:1d:80:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6790b34bfdda7c4908521ff69f50a947cd1d8077/; sid:902205219; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"b8:3e:21:10:01:75:bf:a7:95:db:e1:83:7f:a8:22:9d:63:6d:5a:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b83e21100175bfa795dbe1837fa8229d636d5ace/; sid:902205220; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"eb:b7:46:f9:e9:66:d9:52:19:1f:5e:2b:30:0b:98:28:21:37:31:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ebb746f9e966d952191f5e2b300b98282137315f/; sid:902205221; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"9a:15:d8:e1:14:fe:ed:be:52:81:6c:8c:bc:70:08:9b:0d:c1:42:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a15d8e114feedbe52816c8cbc70089b0dc1420d/; sid:902205222; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"49:75:17:a6:79:09:8c:1b:2d:bb:bb:3a:e5:1d:68:e2:9a:9b:d5:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/497517a679098c1b2dbbbb3ae51d68e29a9bd557/; sid:902205223; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"35:6d:a1:8b:b5:3c:57:d5:37:1d:10:c9:e0:be:eb:02:dd:13:6b:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/356da18bb53c57d5371d10c9e0beeb02dd136b7a/; sid:902205224; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b2:d0:87:82:b7:bf:d7:66:1e:28:ea:34:02:75:76:81:9b:82:0a:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2d08782b7bfd7661e28ea34027576819b820ab4/; sid:902205225; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"cc:2a:8e:3f:3f:cf:0d:52:62:f5:fb:0e:f2:47:73:29:c6:38:27:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cc2a8e3f3fcf0d5262f5fb0ef2477329c6382733/; sid:902205226; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"82:37:13:0d:23:10:2b:8e:3c:9e:39:5f:f0:9d:ca:34:ec:7c:d3:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8237130d23102b8e3c9e395ff09dca34ec7cd3d2/; sid:902205227; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"14:d4:3d:6c:4c:31:42:39:42:81:9f:75:86:ed:67:e2:93:51:69:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14d43d6c4c31423942819f7586ed67e293516972/; sid:902205228; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"73:e2:66:78:10:e0:3a:e2:48:c5:7c:d7:79:1e:12:d7:5b:41:39:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73e2667810e03ae248c57cd7791e12d75b413922/; sid:902205229; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f6:ca:1d:ff:44:31:55:6f:5d:77:56:76:a4:00:5d:1b:1a:bd:97:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f6ca1dff4431556f5d775676a4005d1b1abd97f4/; sid:902205230; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"37:23:fc:26:f5:79:61:47:45:4c:ff:20:5b:68:bb:94:08:04:e1:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3723fc26f5796147454cff205b68bb940804e1b1/; sid:902205231; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4b:95:5d:2b:7b:b2:e7:de:b6:68:8b:8e:0c:13:57:85:74:37:c0:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b955d2b7bb2e7deb6688b8e0c1357857437c0b2/; sid:902205232; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fc:81:ca:84:7e:ba:ed:4d:d9:9c:59:66:e0:33:75:0d:01:95:ce:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc81ca847ebaed4dd99c5966e033750d0195ce50/; sid:902205233; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"04:13:69:b4:55:e8:eb:78:31:5e:f7:15:59:2d:37:d4:d2:9b:f7:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/041369b455e8eb78315ef715592d37d4d29bf785/; sid:902205234; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"03:95:38:49:75:48:3f:a1:19:42:e6:cf:d4:07:d8:60:b7:82:2d:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0395384975483fa11942e6cfd407d860b7822d41/; sid:902205235; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:09:97:19:70:99:8c:89:53:f0:ed:5a:c2:31:86:ab:12:6c:ee:68"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b909971970998c8953f0ed5ac23186ab126cee68/; sid:902205236; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"2d:bb:eb:3f:ab:e1:de:e0:d1:bb:93:4f:44:2c:3c:b2:e8:82:1a:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2dbbeb3fabe1dee0d1bb934f442c3cb2e8821a9f/; sid:902205237; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"29:63:64:40:aa:e6:57:9e:3a:17:8f:e2:7f:15:e5:13:3e:62:6d:bc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/29636440aae6579e3a178fe27f15e5133e626dbc/; sid:902205238; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (IcedID C&C)"; tls.fingerprint:"3a:16:54:4d:a6:76:ca:be:c7:38:cc:2c:f4:8d:c4:b5:59:bf:e7:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a16544da676cabec738cc2cf48dc4b559bfe728/; sid:902205239; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"6a:03:50:2e:91:9a:07:c6:96:91:d1:24:6a:c2:4e:2e:d8:03:e4:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a03502e919a07c69691d1246ac24e2ed803e4f1/; sid:902205240; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"9f:d0:5b:2d:9d:79:18:16:08:7b:a4:a1:46:b3:e4:80:80:43:3a:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9fd05b2d9d791816087ba4a146b3e48080433a4f/; sid:902205241; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:fa:ef:89:04:a7:e1:bc:7d:a3:76:c8:2e:4b:ed:8c:15:14:e2:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e4faef8904a7e1bc7da376c82e4bed8c1514e26f/; sid:902205242; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"00:c9:b5:24:71:40:f9:18:ba:3e:22:3e:5d:5f:f6:b2:f1:44:9a:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00c9b5247140f918ba3e223e5d5ff6b2f1449af2/; sid:902205243; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"63:d0:6f:67:6f:4a:3c:47:d7:a7:83:45:c1:d6:8b:84:bb:bd:c1:28"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/63d06f676f4a3c47d7a78345c1d68b84bbbdc128/; sid:902205244; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0b:15:63:b8:45:d0:9c:e8:cc:d9:95:e2:48:ac:a7:e3:3e:a2:69:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0b1563b845d09ce8ccd995e248aca7e33ea26982/; sid:902205245; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DanaBot C&C)"; tls.fingerprint:"92:9b:10:1c:d6:0f:9b:02:b9:e8:b1:1b:89:1c:34:91:8a:cc:fb:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/929b101cd60f9b02b9e8b11b891c34918accfb7a/; sid:902205246; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (CobaltStrike C&C)"; tls.fingerprint:"36:bd:8b:8d:49:ae:51:26:2b:0a:87:48:d9:ac:63:24:0c:64:2b:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/36bd8b8d49ae51262b0a8748d9ac63240c642b60/; sid:902205247; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"3f:68:cd:bf:bd:6e:7f:74:c0:77:97:e7:73:80:ce:dc:05:24:d9:60"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3f68cdbfbd6e7f74c07797e77380cedc0524d960/; sid:902205248; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"a4:eb:14:41:a0:d2:3f:94:6c:95:ea:f8:3f:86:7e:4b:83:be:51:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4eb1441a0d23f946c95eaf83f867e4b83be51e5/; sid:902205249; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"84:03:ac:68:01:0b:33:90:5b:45:a3:b2:ea:6e:90:a8:ba:59:ac:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8403ac68010b33905b45a3b2ea6e90a8ba59ac3e/; sid:902205250; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"15:38:1b:6d:25:11:08:85:b8:cf:e9:e0:e6:67:f0:8a:a7:04:35:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15381b6d25110885b8cfe9e0e667f08aa70435bd/; sid:902205251; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:83:48:c9:b8:7a:05:9c:e6:68:fb:f1:07:3e:fd:83:c3:00:10:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/598348c9b87a059ce668fbf1073efd83c300108e/; sid:902205252; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b7:68:62:13:e9:84:fd:ae:63:1d:10:cc:c9:41:97:e3:24:6f:43:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b7686213e984fdae631d10ccc94197e3246f43c2/; sid:902205253; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"a6:9f:fc:5b:4f:a1:ae:e0:2d:79:5d:91:cf:c1:c0:09:c3:3a:12:94"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a69ffc5b4fa1aee02d795d91cfc1c009c33a1294/; sid:902205254; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fb:42:77:5b:5f:11:7a:0c:94:0c:b7:d5:65:a5:33:69:6c:6a:92:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb42775b5f117a0c940cb7d565a533696c6a925f/; sid:902205255; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"8e:8b:2e:ac:14:f5:5e:75:ef:fa:46:b4:ef:a3:64:a2:ef:ca:12:9f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8e8b2eac14f55e75effa46b4efa364a2efca129f/; sid:902205256; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"a9:75:aa:78:29:6b:bf:e0:c9:b3:19:e7:9f:41:22:83:94:44:79:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a975aa78296bbfe0c9b319e79f4122839444798e/; sid:902205257; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"90:51:ab:9a:a2:00:ac:18:6f:d1:71:f9:ee:e3:42:ae:9d:0f:f7:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9051ab9aa200ac186fd171f9eee342ae9d0ff7bb/; sid:902205258; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:b9:01:19:85:d6:70:12:bf:98:4b:7e:dc:42:fc:a5:cc:e1:54:d4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b2b9011985d67012bf984b7edc42fca5cce154d4/; sid:902205259; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"88:08:cc:bb:cf:3d:f3:10:d4:a4:d8:c6:85:20:9d:c1:68:5e:3b:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8808ccbbcf3df310d4a4d8c685209dc1685e3b42/; sid:902205260; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"22:4f:8c:df:a3:b3:3f:43:96:d3:98:9e:51:50:bb:36:6a:24:15:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/224f8cdfa3b33f4396d3989e5150bb366a24156a/; sid:902205261; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a2:c3:88:3c:cc:d0:35:ae:19:fe:c8:62:36:e3:fd:c1:bd:d0:67:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2c3883cccd035ae19fec86236e3fdc1bdd06772/; sid:902205262; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"77:d6:4a:9e:7d:6f:98:3a:45:04:81:ef:78:d9:9f:3a:6b:8a:59:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77d64a9e7d6f983a450481ef78d99f3a6b8a5925/; sid:902205263; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"13:45:44:46:7c:b4:44:7b:55:c5:cd:08:1e:72:d1:21:5e:5f:c4:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/134544467cb4447b55c5cd081e72d1215e5fc42a/; sid:902205264; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"72:af:2a:37:c9:04:0f:9a:be:a0:29:75:eb:8b:8c:c9:87:6e:c5:62"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/72af2a37c9040f9abea02975eb8b8cc9876ec562/; sid:902205265; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c8:0b:6f:df:a7:cc:45:26:71:3c:df:de:78:c4:fa:c3:85:5a:48:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c80b6fdfa7cc4526713cdfde78c4fac3855a485a/; sid:902205266; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5d:89:a1:aa:03:d8:8c:95:80:38:cc:a6:10:63:8f:2e:bb:f0:47:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5d89a1aa03d88c958038cca610638f2ebbf047a1/; sid:902205267; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e2:51:f2:88:70:7b:a7:e2:1d:3e:56:66:f0:0d:ef:fd:80:4c:ea:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e251f288707ba7e21d3e5666f00deffd804cea56/; sid:902205268; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3b:60:bd:7a:f0:57:7b:d4:2e:28:c5:43:29:d5:fa:a2:12:94:94:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3b60bd7af0577bd42e28c54329d5faa2129494a7/; sid:902205269; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"3d:03:cf:13:a8:57:b6:d2:8f:32:3f:7b:ab:32:e9:2c:e4:76:ff:6b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3d03cf13a857b6d28f323f7bab32e92ce476ff6b/; sid:902205270; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:bd:25:d5:66:19:18:7f:ac:f3:8a:50:14:cd:db:49:66:9a:84:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51bd25d56619187facf38a5014cddb49669a84f6/; sid:902205271; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cb:78:57:c2:fe:d4:3e:6a:8b:b2:48:c0:7f:a0:3d:91:91:ce:44:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb7857c2fed43e6a8bb248c07fa03d9191ce4467/; sid:902205272; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:d8:8c:50:e5:e6:10:f9:b2:1e:ad:a9:89:22:55:df:fc:98:9a:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcd88c50e5e610f9b21eada9892255dffc989a5e/; sid:902205273; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"65:ad:26:c7:41:55:9c:71:7c:42:c5:f3:0a:9f:21:e7:05:51:ed:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65ad26c741559c717c42c5f30a9f21e70551edc2/; sid:902205274; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1e:ba:b6:ee:e5:e7:34:7b:a0:7a:e7:e2:4a:c9:72:10:bb:46:1e:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ebab6eee5e7347ba07ae7e24ac97210bb461eea/; sid:902205275; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c1:bf:18:39:40:86:da:31:af:aa:5a:47:0e:02:f3:62:ac:31:ad:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1bf18394086da31afaa5a470e02f362ac31ade6/; sid:902205276; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (zgRAT C&C)"; tls.fingerprint:"c4:6f:a9:29:a3:40:24:cb:67:49:41:7a:d8:ac:35:40:f3:2d:1a:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c46fa929a34024cb6749417ad8ac3540f32d1aa8/; sid:902205277; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:8f:9b:74:db:9c:21:72:5a:b5:0a:5b:33:d7:35:bd:01:07:35:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b28f9b74db9c21725ab50a5b33d735bd010735be/; sid:902205278; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4b:6c:67:55:90:f8:f3:e1:bf:af:18:e4:2b:f0:37:fe:da:8f:c9:e6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4b6c675590f8f3e1bfaf18e42bf037feda8fc9e6/; sid:902205279; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"1a:e8:1a:fd:9d:d8:88:d8:b5:b6:03:c9:a0:10:de:1b:55:8f:c5:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1ae81afd9dd888d8b5b603c9a010de1b558fc5b1/; sid:902205280; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:cf:4e:65:9f:f1:cc:20:42:e5:7d:f9:6e:2e:18:2d:69:54:bc:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32cf4e659ff1cc2042e57df96e2e182d6954bce3/; sid:902205281; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c0:24:ce:97:c0:46:9e:72:75:fd:0b:a8:5f:66:28:a8:e2:c6:06:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c024ce97c0469e7275fd0ba85f6628a8e2c6064e/; sid:902205282; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"03:be:f9:3d:91:08:fa:36:40:c2:aa:71:29:7a:3f:a2:43:e4:ff:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/03bef93d9108fa3640c2aa71297a3fa243e4ffc8/; sid:902205283; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"0a:a8:e0:28:f1:63:50:55:8f:5e:35:53:73:7b:4c:52:c1:32:47:a7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0aa8e028f16350558f5e3553737b4c52c13247a7/; sid:902205284; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c3:49:30:0f:20:38:a5:32:1f:bd:f5:7a:25:a4:36:1a:af:e8:1e:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c349300f2038a5321fbdf57a25a4361aafe81e42/; sid:902205285; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"6a:3f:b4:1b:1a:05:53:eb:ac:22:3e:24:2d:d1:d3:b9:e4:1c:7a:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6a3fb41b1a0553ebac223e242dd1d3b9e41c7a36/; sid:902205286; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi malware distribution)"; tls.fingerprint:"c3:5a:d0:69:ff:08:72:7c:68:8b:65:87:4e:88:15:09:1d:61:6c:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c35ad069ff08727c688b65874e8815091d616cd9/; sid:902205287; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"47:60:53:47:53:41:61:67:5a:96:f7:fe:d3:f0:5f:85:41:7a:33:9c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/47605347534161675a96f7fed3f05f85417a339c/; sid:902205288; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"2d:f0:09:d9:91:ab:46:54:d2:53:2f:f5:1c:07:67:53:93:09:fa:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2df009d991ab4654d2532ff51c0767539309faf5/; sid:902205289; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:b9:c4:fd:28:34:e4:67:b2:bb:ce:b4:c3:7d:15:92:96:2d:66:1f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69b9c4fd2834e467b2bbceb4c37d1592962d661f/; sid:902205290; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"6d:a0:01:bd:6c:62:76:99:52:40:68:8d:d6:53:2a:41:6f:ad:b8:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6da001bd6c6276995240688dd6532a416fadb825/; sid:902205291; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d4:44:6d:13:63:89:5e:c5:ba:7b:2b:12:ac:84:02:3c:5b:b5:5c:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4446d1363895ec5ba7b2b12ac84023c5bb55c5e/; sid:902205292; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"82:0e:d5:d6:2f:ea:f0:69:5e:e0:4e:3c:cb:7d:c9:be:82:ce:8a:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/820ed5d62feaf0695ee04e3ccb7dc9be82ce8a1e/; sid:902205293; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"55:e0:2c:78:e8:a0:f8:5f:ab:9f:05:82:46:47:ab:a7:12:e7:b0:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/55e02c78e8a0f85fab9f05824647aba712e7b0b7/; sid:902205294; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f4:67:d7:94:b2:e1:08:1b:6a:d1:ea:d5:81:3a:fa:74:f0:53:24:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f467d794b2e1081b6ad1ead5813afa74f053248d/; sid:902205295; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8e:c9:d3:1e:23:c6:88:0e:16:08:17:70:5c:d4:66:c9:3a:7f:2d:16"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8ec9d31e23c6880e160817705cd466c93a7f2d16/; sid:902205296; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"5f:fc:fe:07:00:eb:01:08:51:0d:86:f9:23:11:db:ed:79:1a:fa:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5ffcfe0700eb0108510d86f92311dbed791afa6a/; sid:902205297; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"11:e5:8d:d8:44:a8:a2:e5:92:c4:3c:95:15:b7:f8:6f:30:28:29:41"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11e58dd844a8a2e592c43c9515b7f86f30282941/; sid:902205298; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"d0:ef:f5:31:2a:d4:85:8a:d2:01:e3:5e:55:35:76:49:73:fb:4a:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0eff5312ad4858ad201e35e5535764973fb4a3c/; sid:902205299; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"33:97:a1:9b:37:9a:94:4d:6a:93:c7:16:46:7b:a7:6f:56:e1:59:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3397a19b379a944d6a93c716467ba76f56e1596e/; sid:902205300; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"69:a7:a3:2f:40:f4:7c:45:03:10:c4:40:d6:56:62:19:c8:c1:4f:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/69a7a32f40f47c450310c440d6566219c8c14f13/; sid:902205301; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"15:86:18:c4:3a:83:f3:41:4c:d7:54:86:e3:fa:3c:f2:e7:0b:37:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/158618c43a83f3414cd75486e3fa3cf2e70b3746/; sid:902205302; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fb:74:ba:44:00:a3:89:14:19:0a:1d:21:9f:98:74:1f:67:c1:21:b3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fb74ba4400a38914190a1d219f98741f67c121b3/; sid:902205303; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"52:d9:31:48:bf:a0:68:53:df:15:82:30:1f:ff:21:12:0a:0b:17:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52d93148bfa06853df1582301fff21120a0b1796/; sid:902205304; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"57:00:07:a8:a9:0f:9a:53:7c:ab:39:22:4a:f0:95:6c:fa:bf:ba:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/570007a8a90f9a537cab39224af0956cfabfbace/; sid:902205305; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cb:41:bd:86:24:88:f4:7c:aa:7b:74:d2:02:54:24:2c:65:49:bf:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb41bd862488f47caa7b74d20254242c6549bf29/; sid:902205306; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"33:ca:ec:34:b4:66:16:1b:6e:4d:7a:f2:38:5a:35:d1:e6:40:2d:50"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/33caec34b466161b6e4d7af2385a35d1e6402d50/; sid:902205307; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"29:4f:8c:2d:54:a6:d4:28:87:ea:5b:a2:9a:b0:b0:df:3b:d7:a0:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/294f8c2d54a6d42887ea5ba29ab0b0df3bd7a08e/; sid:902205308; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"4a:13:6f:05:b5:7f:04:42:b7:fc:aa:dd:13:68:d7:48:44:6f:1e:a4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a136f05b57f0442b7fcaadd1368d748446f1ea4/; sid:902205309; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e3:1a:3f:2a:8a:cb:88:60:1f:4a:99:56:9c:20:86:47:37:80:c1:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e31a3f2a8acb88601f4a99569c2086473780c1fd/; sid:902205310; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"32:37:d2:01:6d:90:14:77:c3:f2:d8:fd:f9:4d:04:82:e3:e5:26:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3237d2016d901477c3f2d8fdf94d0482e3e52621/; sid:902205311; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"1b:2f:a0:7c:aa:33:4d:92:fd:41:b7:5a:e0:97:6b:f2:39:b7:eb:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1b2fa07caa334d92fd41b75ae0976bf239b7eb6d/; sid:902205312; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fe:2c:a5:d3:c3:ed:9b:ee:b7:77:fd:68:73:2f:f5:4e:72:f3:74:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe2ca5d3c3ed9beeb777fd68732ff54e72f37490/; sid:902205313; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Nemesis C&C)"; tls.fingerprint:"50:1e:28:0c:05:ae:94:fe:21:d7:b7:4d:b6:08:60:b7:63:6a:93:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/501e280c05ae94fe21d7b74db60860b7636a9306/; sid:902205314; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"17:65:26:81:a4:d9:31:1c:49:d2:74:f1:ee:7a:d6:20:21:1c:e7:dd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/17652681a4d9311c49d274f1ee7ad620211ce7dd/; sid:902205315; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:3d:96:b5:6c:43:62:ce:c7:d2:a2:93:f1:69:f9:df:4b:8f:3f:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e3d96b56c4362cec7d2a293f169f9df4b8f3f22/; sid:902205316; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a8:f8:d4:d4:4e:36:4d:e3:00:0b:f7:7e:0a:9a:be:33:e4:a7:3c:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a8f8d4d44e364de3000bf77e0a9abe33e4a73cb9/; sid:902205317; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"6d:bc:f6:c0:41:c5:51:90:c2:85:dd:d9:6c:21:0d:fe:c7:00:16:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6dbcf6c041c55190c285ddd96c210dfec70016b1/; sid:902205318; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8e:dd:a5:1f:6d:0a:8c:e1:6d:6a:67:5e:c1:4a:70:b7:60:1f:b6:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8edda51f6d0a8ce16d6a675ec14a70b7601fb6cc/; sid:902205319; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4a:23:17:92:49:b1:fa:85:55:97:f4:f8:2e:b9:97:f2:3c:26:b6:14"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a23179249b1fa855597f4f82eb997f23c26b614/; sid:902205320; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"a8:6c:84:2d:62:4f:f7:b0:fa:1b:b2:d5:a1:0a:22:af:6f:2e:75:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a86c842d624ff7b0fa1bb2d5a10a22af6f2e7554/; sid:902205321; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:fe:08:0b:0a:32:e4:66:1a:c5:bc:7e:d6:e3:c1:ef:5d:b3:19:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7fe080b0a32e4661ac5bc7ed6e3c1ef5db3197c/; sid:902205322; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ed:ab:54:3d:ae:20:94:56:7a:5f:48:a2:ca:2d:7d:9d:34:08:41:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/edab543dae2094567a5f48a2ca2d7d9d34084110/; sid:902205323; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"93:32:28:44:d2:04:07:ec:71:81:d7:38:9b:88:d0:30:9d:26:30:2c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/93322844d20407ec7181d7389b88d0309d26302c/; sid:902205324; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"57:f6:67:87:7c:1f:cd:a6:66:3e:2f:da:c6:fb:8c:fd:e3:ce:a9:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57f667877c1fcda6663e2fdac6fb8cfde3cea957/; sid:902205325; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"7e:e2:09:0e:e2:9f:f1:60:f8:c1:b5:f7:1b:0c:f1:2b:e9:b9:f0:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ee2090ee29ff160f8c1b5f71b0cf12be9b9f086/; sid:902205326; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:c3:72:78:d3:42:f8:b4:71:95:23:d3:69:81:b1:22:7a:ca:ea:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80c37278d342f8b4719523d36981b1227acaeaca/; sid:902205327; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"12:d9:d8:92:ee:8c:95:d4:6e:6a:23:50:25:4b:61:1b:d1:05:b5:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/12d9d892ee8c95d46e6a2350254b611bd105b529/; sid:902205328; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"24:c1:22:67:a4:b4:a9:18:20:b1:cf:90:ba:7a:80:11:57:57:f9:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24c12267a4b4a91820b1cf90ba7a80115757f929/; sid:902205329; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"78:61:5e:a1:d4:67:bb:07:6e:09:1f:a9:b1:3c:c3:09:c5:c6:9b:00"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/78615ea1d467bb076e091fa9b13cc309c5c69b00/; sid:902205330; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"f5:ea:2d:cd:ef:5f:82:e6:60:f4:4f:c5:87:1d:d5:07:aa:c7:47:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5ea2dcdef5f82e660f44fc5871dd507aac7478b/; sid:902205331; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"6f:e7:c0:42:81:13:cd:51:38:47:5f:b6:c7:cd:51:e9:57:a8:1d:87"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6fe7c0428113cd5138475fb6c7cd51e957a81d87/; sid:902205332; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b0:63:bc:ea:69:89:32:42:9a:ca:7d:18:5d:7f:6f:cb:08:df:a2:aa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b063bcea698932429aca7d185d7f6fcb08dfa2aa/; sid:902205333; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"10:0f:db:59:2c:9d:b1:ee:e4:34:cf:83:b6:19:2b:77:70:e3:48:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/100fdb592c9db1eee434cf83b6192b7770e3488b/; sid:902205334; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"25:66:b0:bf:fa:8e:b0:c2:49:6c:84:1c:56:c8:25:67:05:8d:74:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2566b0bffa8eb0c2496c841c56c82567058d74b4/; sid:902205335; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"02:39:8a:8c:cf:d4:f6:15:22:ec:d2:2c:00:e9:28:dd:97:fd:89:82"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02398a8ccfd4f61522ecd22c00e928dd97fd8982/; sid:902205336; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d0:a8:e8:e5:34:e6:0c:34:ed:23:41:43:5a:18:23:b1:1c:3b:a6:05"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d0a8e8e534e60c34ed2341435a1823b11c3ba605/; sid:902205337; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"dc:58:63:8f:f0:29:78:a3:1f:8e:48:9e:46:cb:44:65:72:de:5c:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dc58638ff02978a31f8e489e46cb446572de5cf8/; sid:902205338; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"ab:d8:76:ef:7e:c7:4d:fb:d0:04:d3:30:3b:c0:52:75:f4:66:97:15"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/abd876ef7ec74dfbd004d3303bc05275f4669715/; sid:902205339; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"05:ed:ec:05:14:63:6b:e5:e8:ea:9c:4a:27:6d:34:7c:6b:4d:01:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05edec0514636be5e8ea9c4a276d347c6b4d0176/; sid:902205340; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"27:82:43:f6:e9:f1:24:65:50:36:ad:f3:af:54:2e:d5:63:f2:d5:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/278243f6e9f124655036adf3af542ed563f2d59d/; sid:902205341; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (zgRAT C&C)"; tls.fingerprint:"7a:d0:b9:d0:28:79:0d:ff:a8:f7:7b:4b:1b:f8:90:b4:47:0e:df:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7ad0b9d028790dffa8f77b4b1bf890b4470edf96/; sid:902205342; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"77:43:a8:2b:47:2b:c6:fb:26:70:57:6d:2c:30:25:ed:2a:25:66:8d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7743a82b472bc6fb2670576d2c3025ed2a25668d/; sid:902205343; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"4a:ea:81:58:04:d8:92:86:87:5e:b0:54:70:08:67:4b:ba:cf:db:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4aea815804d89286875eb0547008674bbacfdbca/; sid:902205344; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"f6:01:12:b4:9d:8b:ff:fe:b9:ef:60:82:12:2a:6b:88:9c:9a:0a:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f60112b49d8bfffeb9ef6082122a6b889c9a0a71/; sid:902205345; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"49:67:46:fd:bb:98:f4:d8:48:ad:62:b1:4c:b3:80:60:0f:18:4e:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/496746fdbb98f4d848ad62b14cb380600f184ee1/; sid:902205346; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a3:1e:07:8a:7c:c4:5d:36:76:d5:ae:3f:b4:60:c3:e3:65:21:93:97"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a31e078a7cc45d3676d5ae3fb460c3e365219397/; sid:902205347; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"d4:b5:d3:9e:fc:eb:82:66:f1:e6:99:26:a8:51:31:29:f2:8d:49:66"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d4b5d39efceb8266f1e69926a8513129f28d4966/; sid:902205348; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"84:43:08:1e:ef:39:1d:36:0a:c0:1c:59:63:5c:53:b9:ec:bd:6b:54"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8443081eef391d360ac01c59635c53b9ecbd6b54/; sid:902205349; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"40:c7:99:e1:66:d5:d8:9a:82:6f:1a:55:6b:ab:07:00:b2:c0:21:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/40c799e166d5d89a826f1a556bab0700b2c02108/; sid:902205350; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"63:89:bd:d6:84:23:02:01:cb:25:42:5c:60:4e:22:97:8a:b8:3c:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6389bdd684230201cb25425c604e22978ab83c63/; sid:902205351; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e2:95:3d:27:1a:fc:a7:01:70:89:db:e6:42:67:5d:21:38:94:d2:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2953d271afca7017089dbe642675d213894d2fa/; sid:902205352; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Havoc C&C)"; tls.fingerprint:"c2:78:8a:69:8b:49:ce:f3:e0:9a:14:d7:4b:b1:b7:8f:b1:a4:5f:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c2788a698b49cef3e09a14d74bb1b78fb1a45f47/; sid:902205353; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"88:3b:db:d5:33:bd:49:b6:10:c2:50:cf:4c:89:98:a9:3c:7f:8a:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/883bdbd533bd49b610c250cf4c8998a93c7f8ae2/; sid:902205354; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"bb:58:9a:fd:40:ef:eb:28:30:01:1a:ab:ff:54:9a:d7:aa:a4:7c:d8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb589afd40efeb2830011aabff549ad7aaa47cd8/; sid:902205355; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"e0:f7:07:20:57:c5:de:eb:21:c5:98:67:37:40:de:bc:7f:6e:b8:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0f7072057c5deeb21c598673740debc7f6eb8a1/; sid:902205356; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cf:6e:3a:44:ec:f9:d5:31:e6:9e:4a:79:55:d6:d2:84:75:85:c0:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf6e3a44ecf9d531e69e4a7955d6d2847585c001/; sid:902205357; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"f4:87:94:cf:89:8b:b4:c5:b6:22:3d:4f:47:2d:7c:5e:4a:d2:ef:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f48794cf898bb4c5b6223d4f472d7c5e4ad2ef9d/; sid:902205358; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b3:cd:cc:c5:ed:03:a1:bc:14:a2:cc:ba:98:ca:2c:35:9a:27:83:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b3cdccc5ed03a1bc14a2ccba98ca2c359a278346/; sid:902205359; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"68:b4:fc:7d:a8:37:c6:43:32:b9:f0:19:ad:ae:f4:c7:03:8e:c8:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/68b4fc7da837c64332b9f019adaef4c7038ec85d/; sid:902205360; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"64:34:fe:dd:08:ec:89:e2:0a:2f:f7:d9:a1:19:90:21:ed:ae:f8:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6434fedd08ec89e20a2ff7d9a1199021edaef86d/; sid:902205361; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f9:a8:25:38:85:ec:f7:b6:00:3f:e0:e1:37:18:26:93:6c:05:eb:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f9a8253885ecf7b6003fe0e1371826936c05eb69/; sid:902205362; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f8:43:07:de:52:05:2e:eb:50:b7:2a:9f:3b:cb:8d:9d:25:0c:c9:7a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f84307de52052eeb50b72a9f3bcb8d9d250cc97a/; sid:902205363; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c9:50:c1:7e:66:32:16:d5:17:5f:a1:c3:f5:6a:4a:5c:46:c1:01:52"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c950c17e663216d5175fa1c3f56a4a5c46c10152/; sid:902205364; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ad:db:92:d4:3f:97:6c:8e:4f:41:7a:3a:87:cb:1a:77:35:e5:2a:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/addb92d43f976c8e4f417a3a87cb1a7735e52a96/; sid:902205365; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8e:df:97:19:6a:83:15:b1:22:d6:95:20:14:54:19:aa:17:ac:0b:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8edf97196a8315b122d69520145419aa17ac0b2e/; sid:902205366; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:8a:02:3b:40:b2:44:bf:8b:1d:b9:bb:d5:4c:82:f8:92:54:4d:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee8a023b40b244bf8b1db9bbd54c82f892544de3/; sid:902205367; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"e8:f2:67:40:40:48:cc:d9:53:da:ca:3c:06:fa:cd:88:9f:a7:84:04"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8f267404048ccd953daca3c06facd889fa78404/; sid:902205368; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"71:28:e2:ca:36:43:a8:cc:c4:c7:e4:cf:3f:7b:e6:62:02:af:9b:43"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7128e2ca3643a8ccc4c7e4cf3f7be66202af9b43/; sid:902205369; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ce:53:0a:62:a9:e4:3e:89:21:db:13:29:fa:63:da:d1:76:d1:f5:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce530a62a9e43e8921db1329fa63dad176d1f5ff/; sid:902205370; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Gozi C&C)"; tls.fingerprint:"61:d9:91:d7:06:3e:5e:74:70:da:a3:05:93:57:f8:28:2e:68:0b:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/61d991d7063e5e7470daa3059357f8282e680bb7/; sid:902205371; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"22:59:08:8c:bf:fb:54:47:6e:7e:ac:72:61:e8:1c:19:1e:46:08:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2259088cbffb54476e7eac7261e81c191e460837/; sid:902205372; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b7:36:86:7c:d5:16:c8:b6:fb:67:36:5a:df:94:5a:5f:c6:94:30:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b736867cd516c8b6fb67365adf945a5fc6943067/; sid:902205373; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"98:02:5c:f0:5c:d7:8f:7f:f3:53:49:16:6a:be:62:67:bd:43:3a:b1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98025cf05cd78f7ff35349166abe6267bd433ab1/; sid:902205374; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"e3:f7:80:b0:8e:36:1a:ab:ca:36:cb:81:ed:db:ae:22:e4:9d:a8:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3f780b08e361aabca36cb81eddbae22e49da829/; sid:902205375; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e7:2a:60:56:bb:82:f2:67:76:4b:bd:e3:a7:c4:ff:88:48:63:4d:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e72a6056bb82f267764bbde3a7c4ff8848634d13/; sid:902205376; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ce:28:89:24:01:cc:45:17:a5:30:57:17:a7:49:5d:4b:2d:a8:cd:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce28892401cc4517a5305717a7495d4b2da8cdce/; sid:902205377; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"51:08:90:85:e7:dd:7c:30:9d:4c:83:4f:c0:db:84:e5:41:9b:07:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51089085e7dd7c309d4c834fc0db84e5419b07c6/; sid:902205378; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:67:89:00:22:38:26:1e:ca:38:56:bc:9f:81:e2:f7:c6:be:6a:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/446789002238261eca3856bc9f81e2f7c6be6afe/; sid:902205379; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b5:db:73:d9:4e:c0:16:6b:23:30:96:bb:00:ef:8b:11:fe:fe:2b:90"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b5db73d94ec0166b233096bb00ef8b11fefe2b90/; sid:902205380; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"cb:3f:a6:67:9f:3d:ff:63:74:48:0c:12:f0:92:df:67:99:cc:c9:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cb3fa6679f3dff6374480c12f092df6799ccc9cb/; sid:902205381; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e3:ac:42:a2:5d:0f:e0:c9:1e:77:04:9c:86:aa:1c:c0:3d:04:c2:1b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3ac42a25d0fe0c91e77049c86aa1cc03d04c21b/; sid:902205382; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"ef:b9:ac:e8:79:98:a2:1c:c9:36:13:37:2f:38:68:bf:3f:2c:0c:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/efb9ace87998a21cc93613372f3868bf3f2c0c1d/; sid:902205383; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cd:f9:2c:96:bb:32:e9:b1:b7:8b:c5:72:66:62:a1:2a:9b:e6:a9:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cdf92c96bb32e9b1b78bc5726662a12a9be6a9f4/; sid:902205384; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (zgRAT C&C)"; tls.fingerprint:"91:75:9a:e9:b8:1b:d7:9c:f6:fb:48:5d:a2:02:26:4d:5b:37:0a:b2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/91759ae9b81bd79cf6fb485da202264d5b370ab2/; sid:902205385; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"e3:a0:40:03:bd:df:50:47:8d:a4:fb:e2:f7:6a:30:1a:26:22:51:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e3a04003bddf50478da4fbe2f76a301a262251f6/; sid:902205386; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"77:4e:d3:50:32:86:8d:da:3e:7f:36:df:6d:38:0e:c2:45:6f:1e:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/774ed35032868dda3e7f36df6d380ec2456f1e58/; sid:902205387; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"0d:53:80:1a:2d:e8:8d:bd:fb:02:eb:24:72:7b:ca:aa:9c:98:56:8b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d53801a2de88dbdfb02eb24727bcaaa9c98568b/; sid:902205388; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ee:b6:d6:64:1a:df:1d:48:0f:a1:de:96:51:74:97:c3:db:50:78:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eeb6d6641adf1d480fa1de96517497c3db50784f/; sid:902205389; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"10:b9:c5:9b:04:35:94:7c:97:f5:da:8c:3f:4c:7b:57:65:a2:e6:1d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/10b9c59b0435947c97f5da8c3f4c7b5765a2e61d/; sid:902205390; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:67:ee:51:2d:dc:88:b8:c0:ef:c2:4a:25:f3:61:31:97:c5:5a:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f567ee512ddc88b8c0efc24a25f3613197c55a02/; sid:902205391; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"2d:80:15:f6:f7:6c:fc:a5:6a:46:e7:0c:d5:11:d2:fe:16:b5:ee:57"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d8015f6f76cfca56a46e70cd511d2fe16b5ee57/; sid:902205392; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:3a:1e:3c:31:71:05:f8:1c:62:ec:89:9e:91:54:87:59:8f:e6:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f53a1e3c317105f81c62ec899e915487598fe696/; sid:902205393; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"18:6c:b4:3a:a4:84:37:a2:f6:1a:66:2b:e1:9e:3f:27:8c:5d:50:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/186cb43aa48437a2f61a662be19e3f278c5d5099/; sid:902205394; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"11:81:3b:03:b9:12:19:09:50:eb:a3:dd:fe:83:a3:eb:bb:ea:d4:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11813b03b912190950eba3ddfe83a3ebbbead4e1/; sid:902205395; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"1c:c1:0e:04:6c:2f:0d:1c:1b:b8:24:a3:46:58:e6:e7:b9:68:8b:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1cc10e046c2f0d1c1bb824a34658e6e7b9688bfc/; sid:902205396; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ad:14:2e:a9:15:42:75:04:8e:4e:d1:88:21:10:be:8a:d8:f9:98:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad142ea9154275048e4ed1882110be8ad8f998f5/; sid:902205397; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"52:c5:bd:23:48:33:3d:83:2e:d3:4f:8d:9d:76:b4:d8:4c:1e:3a:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/52c5bd2348333d832ed34f8d9d76b4d84c1e3a9e/; sid:902205398; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c6:ca:3a:3e:49:86:b9:d5:d3:fa:36:c1:b8:56:e7:f6:05:d4:05:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c6ca3a3e4986b9d5d3fa36c1b856e7f605d40509/; sid:902205399; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"82:66:ae:61:fc:33:27:1d:f6:33:ab:92:f5:77:b4:eb:ed:60:19:fe"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8266ae61fc33271df633ab92f577b4ebed6019fe/; sid:902205400; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a7:1d:38:39:a8:f3:33:03:4d:76:d6:85:30:fe:7c:f4:1b:c1:ab:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a71d3839a8f333034d76d68530fe7cf41bc1aba1/; sid:902205401; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"8d:71:82:c4:f9:46:f4:f7:a0:df:42:f9:54:86:e7:0c:c9:dc:32:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8d7182c4f946f4f7a0df42f95486e70cc9dc320e/; sid:902205402; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d1:27:d8:b7:a1:51:6f:8c:1f:5f:01:8e:ba:fa:6c:1d:a1:82:11:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d127d8b7a1516f8c1f5f018ebafa6c1da18211f9/; sid:902205403; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"73:ba:25:92:0c:98:59:e8:40:45:fe:00:33:a4:8f:ae:af:62:78:06"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73ba25920c9859e84045fe0033a48faeaf627806/; sid:902205404; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Meterpreter C&C)"; tls.fingerprint:"e1:e8:9a:1e:fe:dd:bb:2f:27:71:f3:df:fb:67:c1:9f:22:d3:c9:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1e89a1efeddbb2f2771f3dffb67c19f22d3c95d/; sid:902205405; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"42:a6:02:6d:e7:af:57:89:3e:8b:91:f0:05:eb:03:22:06:ca:a8:2e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/42a6026de7af57893e8b91f005eb032206caa82e/; sid:902205406; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"26:17:3d:c1:9b:47:14:1e:72:82:df:e5:12:a2:f0:22:19:b5:72:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26173dc19b47141e7282dfe512a2f02219b572bf/; sid:902205407; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:6b:87:7c:66:a6:3b:67:1e:88:41:2f:03:04:7c:13:ca:39:e0:12"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/326b877c66a63b671e88412f03047c13ca39e012/; sid:902205408; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"06:ac:5e:a6:78:f3:d4:14:c6:52:1b:61:83:68:78:37:6b:69:3c:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06ac5ea678f3d414c6521b61836878376b693c5d/; sid:902205409; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a7:fd:82:98:f3:23:8f:51:9d:01:de:46:2d:75:ef:11:1f:3d:9c:10"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a7fd8298f3238f519d01de462d75ef111f3d9c10/; sid:902205410; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:3c:a6:2c:8a:68:e9:36:6a:dd:d9:83:ce:1f:8b:2f:78:49:e5:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/923ca62c8a68e9366addd983ce1f8b2f7849e57c/; sid:902205411; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"8a:2a:7b:58:f2:80:31:15:ff:79:6e:73:3c:73:11:49:39:28:33:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8a2a7b58f2803115ff796e733c7311493928333b/; sid:902205412; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"01:b5:1b:f8:c3:24:f2:eb:d7:f4:60:06:08:61:f3:02:56:d4:ff:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/01b51bf8c324f2ebd7f460060861f30256d4ff07/; sid:902205413; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"d5:60:b1:45:a7:54:c9:83:18:e3:91:5e:cb:09:d7:cb:59:69:2b:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d560b145a754c98318e3915ecb09d7cb59692b09/; sid:902205414; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:ad:8a:3b:fb:52:d1:2f:21:f0:87:5c:76:20:71:47:1b:56:ff:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0ad8a3bfb52d12f21f0875c762071471b56ffc3/; sid:902205415; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"40:9b:75:89:3e:22:f2:2b:72:4a:13:6a:6f:dd:ac:dc:ca:c8:fb:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/409b75893e22f22b724a136a6fddacdccac8fb53/; sid:902205416; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"3e:4f:d8:e8:50:da:0a:9b:14:c0:60:d1:9a:28:75:83:20:b6:d9:e3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e4fd8e850da0a9b14c060d19a28758320b6d9e3/; sid:902205417; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Smoke Loader C&C)"; tls.fingerprint:"67:b0:70:6b:75:bd:7f:c8:5c:39:3c:55:bc:21:fd:c1:75:21:17:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67b0706b75bd7fc85c393c55bc21fdc1752117dc/; sid:902205418; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"c4:c9:e8:08:a5:3b:52:d8:c4:c0:2f:ef:5b:f7:80:33:bd:95:30:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c4c9e808a53b52d8c4c02fef5bf78033bd95301c/; sid:902205419; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5c:80:97:e4:28:22:b0:94:bd:2f:ee:e2:21:9d:fc:7e:5c:02:b0:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5c8097e42822b094bd2feee2219dfc7e5c02b007/; sid:902205420; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NetSupport C&C)"; tls.fingerprint:"94:73:c5:0d:4b:e7:ce:c5:ed:4f:54:4b:1c:6f:dd:04:0c:e2:9c:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9473c50d4be7cec5ed4f544b1c6fdd040ce29c18/; sid:902205421; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (NetSupport C&C)"; tls.fingerprint:"13:8c:72:d1:9a:86:a1:e2:6c:97:fb:78:e4:e4:ef:e6:c0:99:63:1a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/138c72d19a86a1e26c97fb78e4e4efe6c099631a/; sid:902205422; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"28:42:a6:99:9e:16:7f:46:90:bd:28:91:2f:f8:f7:27:51:4f:f1:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2842a6999e167f4690bd28912ff8f727514ff109/; sid:902205423; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:67:11:1a:1c:5c:1e:66:08:49:e9:3f:c0:c1:8e:ce:89:fe:d6:fd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e467111a1c5c1e660849e93fc0c18ece89fed6fd/; sid:902205424; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"6c:c1:86:54:73:ca:53:ec:b7:2f:05:9a:89:7d:cf:5e:64:9c:7f:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cc1865473ca53ecb72f059a897dcf5e649c7f1c/; sid:902205425; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3c:3b:b9:14:07:67:03:7a:0d:1d:6e:92:2b:6f:97:82:35:99:98:17"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3c3bb9140767037a0d1d6e922b6f978235999817/; sid:902205426; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:c6:da:a9:41:1d:fa:6d:aa:21:f1:d1:3f:f3:4f:6a:1a:dc:1b:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0ac6daa9411dfa6daa21f1d13ff34f6a1adc1bc1/; sid:902205427; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Rhadamanthys C&C)"; tls.fingerprint:"41:8b:04:ac:e2:a8:41:e0:38:2a:27:4d:cb:60:07:29:c4:c0:a5:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/418b04ace2a841e0382a274dcb600729c4c0a521/; sid:902205428; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"59:55:89:94:3d:b1:50:72:50:b0:2d:dd:3b:7b:44:24:bb:bf:b6:79"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/595589943db1507250b02ddd3b7b4424bbbfb679/; sid:902205429; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"d2:1b:49:53:9c:3e:a4:94:89:7d:43:cf:75:cb:f5:f9:89:f0:79:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d21b49539c3ea494897d43cf75cbf5f989f0792a/; sid:902205430; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Rhadamanthys C&C)"; tls.fingerprint:"28:01:06:f5:02:8c:00:bf:9f:a8:6e:86:a1:08:6a:7c:12:f8:24:3a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/280106f5028c00bf9fa86e86a1086a7c12f8243a/; sid:902205431; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"55:4f:89:3c:80:d0:67:86:f7:ca:89:69:3e:f8:a5:8e:f2:b4:17:cd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/554f893c80d06786f7ca89693ef8a58ef2b417cd/; sid:902205432; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"95:14:31:e1:8b:12:18:6b:0b:1d:74:3e:bc:8f:d7:78:2f:4e:83:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/951431e18b12186b0b1d743ebc8fd7782f4e83fc/; sid:902205433; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"9e:ed:1b:7d:6e:8f:fa:2c:04:6f:59:57:4d:26:27:77:d3:a1:73:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9eed1b7d6e8ffa2c046f59574d262777d3a1730f/; sid:902205434; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (EmpireRAT C&C)"; tls.fingerprint:"a2:14:fc:15:ee:32:4d:8f:2f:bd:4b:3a:46:73:11:14:57:03:65:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a214fc15ee324d8f2fbd4b3a4673111457036593/; sid:902205435; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"87:0c:a7:4f:a1:b0:58:f9:29:de:ce:4f:a2:16:40:9c:8c:68:db:9e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/870ca74fa1b058f929dece4fa216409c8c68db9e/; sid:902205436; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"6c:ab:78:9e:2a:aa:53:f8:bb:4c:37:ae:0f:f8:78:7f:4e:d4:6b:ce"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6cab789e2aaa53f8bb4c37ae0ff8787f4ed46bce/; sid:902205437; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"92:1a:99:8e:8d:4e:74:fc:dd:bc:f6:c0:80:22:98:f7:d3:80:08:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/921a998e8d4e74fcddbcf6c0802298f7d38008c4/; sid:902205438; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"84:8f:98:5f:d6:91:7e:ed:4c:39:31:8e:75:a9:99:ca:41:c7:26:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/848f985fd6917eed4c39318e75a999ca41c726ff/; sid:902205439; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:b4:60:ce:9e:14:aa:13:d6:4f:6e:28:4a:f7:d0:43:7c:e3:e0:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05b460ce9e14aa13d64f6e284af7d0437ce3e0c6/; sid:902205440; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"53:7c:76:84:2e:a7:41:97:6c:c4:fb:64:5e:cd:47:a5:17:18:36:6f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/537c76842ea741976cc4fb645ecd47a51718366f/; sid:902205441; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"64:62:25:63:12:29:45:dd:98:a7:1e:7c:ec:92:2e:16:61:a1:67:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64622563122945dd98a71e7cec922e1661a167d0/; sid:902205442; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e1:c3:8c:67:67:fb:7d:60:8a:81:17:88:43:98:d4:5b:79:7e:e4:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e1c38c6767fb7d608a8117884398d45b797ee438/; sid:902205443; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3c:b4:3f:ae:55:ea:b4:ae:0a:93:5f:38:88:d0:af:fa:c1:9a:fd:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3cb43fae55eab4ae0a935f3888d0affac19afd4c/; sid:902205444; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e1:2b:88:59:e2:19:5f:69:a0:c4:e8:d7:02:5d:91:c8:44:cb:8b:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e12b8859e2195f69a0c4e8d7025d91c844cb8b49/; sid:902205445; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e0:cf:9d:94:8a:14:07:7a:45:0d:15:d3:29:c1:80:ac:f4:1c:b2:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e0cf9d948a14077a450d15d329c180acf41cb2f5/; sid:902205446; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"00:d8:96:dc:fe:f6:32:65:1a:b0:af:a6:c6:d4:f4:d6:31:b4:64:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/00d896dcfef632651ab0afa6c6d4f4d631b4648c/; sid:902205447; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bf:27:a5:c0:7b:f6:3a:2e:0b:de:90:8f:a6:2f:91:e4:8c:02:19:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf27a5c07bf63a2e0bde908fa62f91e48c0219bf/; sid:902205448; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"bb:76:4a:47:0a:c3:82:1d:3c:f6:65:ee:a3:5a:9e:e9:53:94:8b:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb764a470ac3821d3cf665eea35a9ee953948b81/; sid:902205449; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"cf:08:e3:03:5a:c6:32:43:01:b3:21:1c:e6:2e:87:83:e7:07:55:c1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cf08e3035ac6324301b3211ce62e8783e70755c1/; sid:902205450; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ad:9b:e7:28:99:7e:45:bb:bc:06:a2:a5:91:a6:b4:dd:cc:55:a8:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ad9be728997e45bbbc06a2a591a6b4ddcc55a863/; sid:902205451; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ea:29:82:80:ac:c7:4a:78:d9:0a:4f:63:e1:ec:99:4f:19:0d:a8:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ea298280acc74a78d90a4f63e1ec994f190da8bf/; sid:902205452; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"10:89:af:95:08:3b:7e:36:32:6a:f5:97:53:0c:e8:54:a5:f9:6f:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1089af95083b7e36326af597530ce854a5f96f7f/; sid:902205453; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b9:12:d1:a6:32:32:e8:22:f4:3b:7d:5f:79:b5:bb:6b:e6:a7:d3:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b912d1a63232e822f43b7d5f79b5bb6be6a7d372/; sid:902205454; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9a:7f:a8:b7:10:57:15:94:e5:71:82:aa:ac:8f:d5:c9:07:ab:49:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9a7fa8b710571594e57182aaac8fd5c907ab493d/; sid:902205455; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e6:97:bc:df:3b:f5:dc:e1:cc:c3:a4:a0:59:b3:ed:11:a3:d1:49:61"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e697bcdf3bf5dce1ccc3a4a059b3ed11a3d14961/; sid:902205456; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Fabookie C&C)"; tls.fingerprint:"40:86:96:c2:82:4d:4c:8a:b6:f6:a9:ca:36:80:a1:90:c5:76:16:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/408696c2824d4c8ab6f6a9ca3680a190c5761630/; sid:902205457; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"44:77:0e:57:39:37:dd:93:0e:08:a4:26:65:c8:66:c1:ce:88:27:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/44770e573937dd930e08a42665c866c1ce882788/; sid:902205458; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (BitRAT C&C)"; tls.fingerprint:"c9:d1:dc:29:2a:48:52:cd:b9:9c:e0:2b:3c:b7:53:9d:84:c3:20:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9d1dc292a4852cdb99ce02b3cb7539d84c320e5/; sid:902205459; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ef:fc:70:8c:69:5f:dd:28:da:3e:43:1c:9c:4d:0b:7d:26:6b:f7:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/effc708c695fdd28da3e431c9c4d0b7d266bf7c8/; sid:902205460; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9d:84:87:75:86:54:4f:17:15:8b:83:10:c2:f5:75:97:64:ba:42:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d84877586544f17158b8310c2f5759764ba4234/; sid:902205461; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"20:fd:51:ec:42:d8:84:db:e2:73:66:bb:bc:01:72:7b:9b:2f:a2:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/20fd51ec42d884dbe27366bbbc01727b9b2fa2c8/; sid:902205462; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c5:2b:e0:b1:93:a4:1a:39:50:8b:a9:c1:06:22:2d:79:98:d4:36:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c52be0b193a41a39508ba9c106222d7998d4369d/; sid:902205463; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c9:fd:94:b3:c7:ce:91:57:70:94:bf:0e:46:61:d2:29:69:7c:29:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c9fd94b3c7ce91577094bf0e4661d229697c29e4/; sid:902205464; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8b:60:44:02:e6:70:21:09:87:a7:a2:2d:2c:af:d6:6a:57:f3:9b:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8b604402e670210987a7a22d2cafd66a57f39bae/; sid:902205465; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"76:e2:71:11:6e:03:3a:5f:45:a8:d4:1f:1f:94:db:dd:05:5a:79:a8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/76e271116e033a5f45a8d41f1f94dbdd055a79a8/; sid:902205466; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"73:be:eb:dc:f3:4c:76:01:ad:a4:4e:68:2e:52:1b:e8:96:5b:87:fc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/73beebdcf34c7601ada44e682e521be8965b87fc/; sid:902205467; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ea:b4:03:4d:bb:dd:51:00:51:d9:d3:4d:60:a8:db:17:3c:15:b2:07"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eab4034dbbdd510051d9d34d60a8db173c15b207/; sid:902205468; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"37:c1:d9:55:3c:db:a2:4d:3d:a5:ae:05:05:a0:3e:24:42:ce:52:96"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37c1d9553cdba24d3da5ae0505a03e2442ce5296/; sid:902205469; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"21:07:7c:31:aa:38:8b:81:c6:16:b9:76:1f:50:3b:7e:6d:8a:02:22"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21077c31aa388b81c616b9761f503b7e6d8a0222/; sid:902205470; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9b:0a:d0:32:9f:65:95:8c:bf:b9:46:fb:0d:62:2e:37:c5:6f:88:6e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9b0ad0329f65958cbfb946fb0d622e37c56f886e/; sid:902205471; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:7b:df:c4:c9:ef:68:88:b1:08:2c:c5:bd:5f:85:62:f8:4f:2b:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a7bdfc4c9ef6888b1082cc5bd5f8562f84f2be5/; sid:902205472; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3e:03:57:0f:f4:51:55:d6:20:1d:d6:15:ad:8a:79:b1:e7:09:77:f1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e03570ff45155d6201dd615ad8a79b1e70977f1/; sid:902205473; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"dd:fb:a9:83:d9:1a:8b:d5:a9:bc:b6:84:db:e4:7b:c8:cc:5a:cc:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddfba983d91a8bd5a9bcb684dbe47bc8cc5accaf/; sid:902205474; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"ed:00:e7:06:02:b2:be:af:8e:3f:47:ff:64:5a:be:7e:92:89:7d:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ed00e70602b2beaf8e3f47ff645abe7e92897d3e/; sid:902205475; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"16:40:93:45:43:36:b9:c6:b7:80:bf:2b:a0:e5:99:e5:dc:c1:c1:93"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/164093454336b9c6b780bf2ba0e599e5dcc1c193/; sid:902205476; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1c:1a:4f:a6:fe:bd:e8:2d:9b:63:91:e0:f5:4b:77:6d:ea:c7:b8:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1c1a4fa6febde82d9b6391e0f54b776deac7b81c/; sid:902205477; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4d:dd:49:70:0a:b5:2e:37:c7:8d:01:6f:14:4d:65:72:7c:fb:2b:fa"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ddd49700ab52e37c78d016f144d65727cfb2bfa/; sid:902205478; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"67:7b:a3:ca:93:a1:4e:d2:19:21:e7:6c:df:aa:de:f9:d4:e7:96:29"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/677ba3ca93a14ed21921e76cdfaadef9d4e79629/; sid:902205479; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b1:8c:c2:70:ff:79:9c:56:ea:5e:d1:91:77:52:20:18:91:c2:9c:6c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b18cc270ff799c56ea5ed1917752201891c29c6c/; sid:902205480; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:9d:26:1e:2a:7b:04:63:fc:ea:ad:04:34:42:49:1e:0b:a6:82:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/699d261e2a7b0463fceaad043442491e0ba68247/; sid:902205481; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e8:82:0b:3b:b7:b7:ce:bb:35:72:d3:87:91:5b:9f:fa:08:b8:23:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e8820b3bb7b7cebb3572d387915b9ffa08b823a1/; sid:902205482; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"b1:1d:a2:15:66:06:78:26:d2:ac:17:9e:fe:bb:b1:f1:24:d9:17:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b11da21566067826d2ac179efebbb1f124d917db/; sid:902205483; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"65:50:c5:fd:13:36:83:b3:33:08:70:c7:78:b7:db:73:e9:23:f4:72"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6550c5fd133683b3330870c778b7db73e923f472/; sid:902205484; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b1:de:7f:be:09:39:b5:15:15:ab:10:80:01:12:5c:59:74:fa:24:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b1de7fbe0939b51515ab108001125c5974fa2481/; sid:902205485; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:db:fd:1f:70:87:f9:9f:2a:e1:78:bb:41:e8:b9:b4:7f:e3:fa:25"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/88dbfd1f7087f99f2ae178bb41e8b9b47fe3fa25/; sid:902205486; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f8:6c:17:23:4e:ff:fe:58:8c:ec:44:48:ac:39:03:2a:5e:b6:17:a6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f86c17234efffe588cec4448ac39032a5eb617a6/; sid:902205487; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"7d:08:c9:fd:fe:d1:75:f1:29:15:ed:ed:8a:40:3f:bd:fc:2b:c2:d3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7d08c9fdfed175f12915eded8a403fbdfc2bc2d3/; sid:902205488; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ce:9d:50:68:44:6a:33:72:a7:0a:be:8e:bd:0d:7f:0c:bc:81:4b:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce9d5068446a3372a70abe8ebd0d7f0cbc814b08/; sid:902205489; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"da:3f:0f:31:7f:de:63:65:a7:9b:81:56:06:30:50:74:ce:97:19:ab"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/da3f0f317fde6365a79b815606305074ce9719ab/; sid:902205490; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"4d:7e:e5:47:53:5b:ff:dd:2d:27:03:4f:c7:ea:c1:a3:cf:2a:ca:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4d7ee547535bffdd2d27034fc7eac1a3cf2acadc/; sid:902205491; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:76:7c:58:8f:c8:c8:1d:95:a7:c1:b6:6b:e7:e4:b3:8e:66:37:39"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/14767c588fc8c81d95a7c1b66be7e4b38e663739/; sid:902205492; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:45:78:ae:ae:28:ec:5e:2c:c5:4a:8a:8a:72:f3:36:2a:fa:d9:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a4578aeae28ec5e2cc54a8a8a72f3362afad9df/; sid:902205493; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"3a:40:d6:b9:1d:59:d0:2a:5a:9a:9c:51:ce:26:21:e8:96:f4:52:86"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a40d6b91d59d02a5a9a9c51ce2621e896f45286/; sid:902205494; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9e:33:0c:6d:64:25:72:f6:ce:fb:ac:38:a1:38:c2:3b:8e:7a:ee:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9e330c6d642572f6cefbac38a138c23b8e7aee51/; sid:902205495; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"1d:57:62:f9:dc:f7:27:3d:10:4f:de:de:97:74:de:77:30:90:c5:e4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1d5762f9dcf7273d104fdede9774de773090c5e4/; sid:902205496; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:52:57:0e:ff:94:fb:84:1c:ca:b1:4c:34:43:c3:6e:3f:9f:40:bb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3252570eff94fb841ccab14c3443c36e3f9f40bb/; sid:902205497; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"1e:91:a2:72:2e:50:be:38:a4:6c:42:af:f6:2f:12:50:69:ba:57:2f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1e91a2722e50be38a46c42aff62f125069ba572f/; sid:902205498; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:a7:16:1e:8f:14:29:e0:b9:5d:d1:90:ed:1e:48:2f:01:ca:e0:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80a7161e8f1429e0b95dd190ed1e482f01cae0f2/; sid:902205499; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"14:5d:04:c2:ad:96:e1:fb:32:db:17:18:1e:c9:af:36:80:14:59:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/145d04c2ad96e1fb32db17181ec9af3680145935/; sid:902205500; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"15:ba:d5:20:f0:98:b6:49:15:5b:7d:80:71:d9:a9:ed:92:1e:1d:7c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/15bad520f098b649155b7d8071d9a9ed921e1d7c/; sid:902205501; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e3:07:d3:8b:b1:9d:ec:48:5d:44:59:8e:c6:14:ca:36:c7:7f:ce:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e307d38bb19dec485d44598ec614ca36c77fced9/; sid:902205502; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c1:58:9e:f4:24:f7:70:18:cd:48:8e:83:07:c8:c1:df:19:9c:8a:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c1589ef424f77018cd488e8307c8c1df199c8a42/; sid:902205503; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"69:5c:b5:4d:cd:5b:07:4d:f1:4c:05:16:b0:52:26:89:f2:41:15:47"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/695cb54dcd5b074df14c0516b0522689f2411547/; sid:902205504; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"ca:a6:f0:0a:ab:21:38:22:4c:99:1a:d4:4c:94:10:39:b9:f9:9c:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/caa6f00aab2138224c991ad44c941039b9f99cc8/; sid:902205505; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ab:7e:ca:f8:df:4f:d0:62:74:98:84:c5:fe:1c:92:0e:e9:31:99:ec"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ab7ecaf8df4fd062749884c5fe1c920ee93199ec/; sid:902205506; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"81:25:3a:00:3f:00:03:c9:30:5d:6a:02:c9:85:df:c1:be:0d:ee:51"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/81253a003f0003c9305d6a02c985dfc1be0dee51/; sid:902205507; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f0:0c:4d:01:74:c7:24:bd:69:e4:56:3e:fa:cb:8e:7f:59:a1:2d:08"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f00c4d0174c724bd69e4563efacb8e7f59a12d08/; sid:902205508; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"aa:37:2a:6b:17:6f:2d:90:f2:85:d3:a6:3b:43:30:c0:be:4b:a3:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aa372a6b176f2d90f285d3a63b4330c0be4ba34e/; sid:902205509; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bf:a8:04:a6:55:8d:d1:2b:c2:4c:46:4e:88:e7:b1:8d:a8:38:e4:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bfa804a6558dd12bc24c464e88e7b18da838e42a/; sid:902205510; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"75:04:a0:42:7e:33:a2:03:31:e8:a6:76:a9:92:ab:82:b9:f9:8b:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7504a0427e33a20331e8a676a992ab82b9f98b13/; sid:902205511; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"88:29:16:f3:27:b2:f5:61:80:8c:4d:01:21:67:3f:c7:8c:b0:da:5d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/882916f327b2f561808c4d0121673fc78cb0da5d/; sid:902205512; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"24:cf:04:dd:da:29:82:e7:87:46:25:1f:c4:b6:b7:e6:1b:64:c6:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/24cf04ddda2982e78746251fc4b6b7e61b64c681/; sid:902205513; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"be:32:81:a3:34:e9:e9:55:e7:d4:37:9f:57:98:37:54:bd:54:21:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/be3281a334e9e955e7d4379f57983754bd5421c2/; sid:902205514; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"92:cf:23:48:cd:e2:f4:ee:5a:5a:80:33:1e:62:70:fb:50:97:9a:30"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/92cf2348cde2f4ee5a5a80331e6270fb50979a30/; sid:902205515; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:97:b5:f8:67:30:a8:eb:f9:ed:9c:8e:94:73:f4:64:02:39:e9:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b297b5f86730a8ebf9ed9c8e9473f4640239e981/; sid:902205516; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"dd:b2:42:37:f8:ff:55:ea:54:d1:6d:63:28:03:b9:76:8c:4c:17:e0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ddb24237f8ff55ea54d16d632803b9768c4c17e0/; sid:902205517; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"96:0e:32:f5:29:e3:c6:ce:eb:5c:18:03:ef:47:02:4d:23:ff:19:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/960e32f529e3c6ceeb5c1803ef47024d23ff19a1/; sid:902205518; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d7:47:75:ab:b8:72:f6:11:03:53:22:7e:45:43:88:5d:a0:0c:ea:76"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d74775abb872f6110353227e4543885da00cea76/; sid:902205519; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"11:23:46:47:79:3f:73:cb:de:d8:49:d8:27:af:9f:33:eb:df:28:8a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/11234647793f73cbded849d827af9f33ebdf288a/; sid:902205520; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"2e:35:19:b7:cb:61:a3:cd:61:67:f7:27:df:99:3f:68:31:10:85:ea"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2e3519b7cb61a3cd6167f727df993f68311085ea/; sid:902205521; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Havoc C&C)"; tls.fingerprint:"b4:bc:17:4c:1d:d3:39:72:ed:98:0f:1e:98:ff:70:9a:3e:b4:3f:f2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b4bc174c1dd33972ed980f1e98ff709a3eb43ff2/; sid:902205522; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7a:27:75:c7:1e:27:e3:86:15:3f:bf:3f:f8:b3:cd:c5:2c:78:0a:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7a2775c71e27e386153fbf3ff8b3cdc52c780aa1/; sid:902205523; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4a:58:11:2d:59:18:50:45:0f:d5:39:cd:f8:6f:d1:da:9c:66:e1:70"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a58112d591850450fd539cdf86fd1da9c66e170/; sid:902205524; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"89:ce:ed:02:b5:1d:5d:5f:5f:eb:32:95:a8:62:7b:7f:c0:69:03:d0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89ceed02b51d5d5f5feb3295a8627b7fc06903d0/; sid:902205525; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"07:e8:6e:c2:e7:08:d0:6f:2d:c0:c7:85:c4:32:35:72:fa:9d:3b:9b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/07e86ec2e708d06f2dc0c785c4323572fa9d3b9b/; sid:902205526; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"89:bb:31:11:a0:cd:8c:c5:d8:37:54:fe:3c:98:63:cd:3b:1a:5e:8e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/89bb3111a0cd8cc5d83754fe3c9863cd3b1a5e8e/; sid:902205527; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"ba:15:48:64:e9:63:cd:9b:f9:33:22:e6:8d:98:de:7f:3e:ab:e1:0e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ba154864e963cd9bf93322e68d98de7f3eabe10e/; sid:902205528; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bb:59:15:86:5e:2f:7e:20:74:e9:fc:70:28:4f:99:61:8f:86:b3:1c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bb5915865e2f7e2074e9fc70284f99618f86b31c/; sid:902205529; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"79:6c:40:c5:7d:5e:4b:f2:24:84:ab:54:dc:56:61:9c:17:16:21:d9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/796c40c57d5e4bf22484ab54dc56619c171621d9/; sid:902205530; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"67:64:dd:6c:19:37:fc:4f:bc:33:99:d7:4a:b6:d5:90:96:fa:ae:01"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6764dd6c1937fc4fbc3399d74ab6d59096faae01/; sid:902205531; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0d:8b:23:34:68:0f:42:08:05:cd:d0:3f:c5:c1:da:4c:78:30:6e:5e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d8b2334680f420805cdd03fc5c1da4c78306e5e/; sid:902205532; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"58:19:0d:b5:27:63:9d:7f:de:ea:ab:63:b6:c7:71:21:77:1c:2d:ed"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/58190db527639d7fdeeaab63b6c77121771c2ded/; sid:902205533; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Havoc C&C)"; tls.fingerprint:"6a:e5:aa:53:44:57:e6:c0:d2:26:35:3a:23:4f:84:31:84:92:ca:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6ae5aa534457e6c0d226353a234f84318492ca6a/; sid:902205534; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:00:d6:e4:e6:29:49:8c:f1:ae:f0:d7:44:97:3b:df:09:05:36:74"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee00d6e4e629498cf1aef0d744973bdf09053674/; sid:902205535; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"32:ba:23:fb:75:06:62:29:45:ed:d5:72:3e:8d:af:e7:21:5f:71:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/32ba23fb7506622945edd5723e8dafe7215f71c9/; sid:902205536; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PoshC2 C&C)"; tls.fingerprint:"f5:c3:db:e6:cc:d9:37:78:20:f4:2c:75:00:ab:9b:85:b5:68:d5:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5c3dbe6ccd9377820f42c7500ab9b85b568d55a/; sid:902205537; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fc:0b:26:69:cf:da:6d:3f:2c:77:be:2c:90:5c:32:86:45:6e:2e:c4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fc0b2669cfda6d3f2c77be2c905c3286456e2ec4/; sid:902205538; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b6:d8:5d:96:31:3e:99:a2:8b:c1:e8:ef:b8:17:ac:6f:e3:8c:bb:98"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b6d85d96313e99a28bc1e8efb817ac6fe38cbb98/; sid:902205539; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0a:7c:e7:08:41:da:74:bf:4d:ce:c7:34:b5:c1:12:77:2a:dc:a8:77"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0a7ce70841da74bf4dcec734b5c112772adca877/; sid:902205540; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a2:df:ec:b7:27:e7:6d:ed:3d:f3:10:f8:67:04:e5:cb:74:dc:08:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a2dfecb727e76ded3df310f86704e5cb74dc0871/; sid:902205541; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"9b:b1:0b:12:b9:51:d4:02:06:13:ce:c9:f1:d4:0d:d2:ee:86:1b:d7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9bb10b12b951d4020613cec9f1d40dd2ee861bd7/; sid:902205542; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bf:26:63:26:f5:fc:42:44:d4:5c:14:99:12:df:8e:29:54:c0:94:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bf266326f5fc4244d45c149912df8e2954c094af/; sid:902205543; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:8a:e1:f2:3e:5f:ac:78:03:ef:1a:3f:6f:ee:00:50:5e:ed:8b:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/028ae1f23e5fac7803ef1a3f6fee00505eed8b92/; sid:902205544; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"99:21:ce:1f:4b:a8:82:59:70:ee:2e:47:8d:31:77:8b:95:52:aa:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9921ce1f4ba8825970ee2e478d31778b9552aa23/; sid:902205545; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"62:06:d3:13:85:6c:c7:eb:81:e5:4c:f9:55:ce:05:a1:ee:9e:9d:9a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6206d313856cc7eb81e54cf955ce05a1ee9e9d9a/; sid:902205546; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:e2:ba:f8:57:12:99:9b:72:c8:3d:6e:f2:31:82:7d:fd:68:52:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06e2baf85712999b72c83d6ef231827dfd685264/; sid:902205547; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"42:4c:62:a7:86:38:2c:f4:b2:0a:ec:00:bf:d5:c3:f0:0c:10:3d:de"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/424c62a786382cf4b20aec00bfd5c3f00c103dde/; sid:902205548; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"de:89:50:e9:a7:8a:8e:d5:4c:ac:1b:ce:08:0e:ff:21:d1:5f:83:6d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/de8950e9a78a8ed54cac1bce080eff21d15f836d/; sid:902205549; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"99:55:aa:e5:24:9f:8a:44:f5:f8:69:2b:ea:5b:8f:f2:33:1c:83:5a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9955aae5249f8a44f5f8692bea5b8ff2331c835a/; sid:902205550; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"82:d4:0e:82:a9:cc:cc:da:cd:ec:b8:27:d7:d1:c5:c3:a1:ab:66:a2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82d40e82a9ccccdacdecb827d7d1c5c3a1ab66a2/; sid:902205551; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"79:0b:d6:d1:c1:54:0a:e1:bf:b8:11:f2:dc:1e:01:85:52:5c:5d:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/790bd6d1c1540ae1bfb811f2dc1e0185525c5dcb/; sid:902205552; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"3d:a7:76:da:8f:bb:e7:4c:d4:94:42:59:a8:e9:82:a0:b2:ac:95:81"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3da776da8fbbe74cd4944259a8e982a0b2ac9581/; sid:902205553; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4a:80:cc:50:07:e9:23:82:3e:ff:dc:4f:b7:fa:fa:d0:62:80:26:b4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a80cc5007e923823effdc4fb7fafad0628026b4/; sid:902205554; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fe:6c:99:e1:04:e7:bc:e1:4a:a9:19:cc:af:e5:64:70:6c:10:0d:cf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fe6c99e104e7bce14aa919ccafe564706c100dcf/; sid:902205555; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"f8:ad:61:e5:0c:4e:a7:ea:89:cf:3d:cc:ce:6c:78:b8:92:fc:32:f9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8ad61e50c4ea7ea89cf3dccce6c78b892fc32f9/; sid:902205556; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"09:d6:3e:58:d3:9f:1c:6b:61:ec:26:19:b3:57:b6:d8:ea:7b:31:09"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/09d63e58d39f1c6b61ec2619b357b6d8ea7b3109/; sid:902205557; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"26:fe:54:59:02:1f:27:ee:11:12:ac:41:39:98:18:45:32:a9:87:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/26fe5459021f27ee1112ac413998184532a9877e/; sid:902205558; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"7a:cc:9a:32:44:42:5c:97:d5:32:f4:ae:af:9d:3c:29:29:92:e1:4d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7acc9a3244425c97d532f4aeaf9d3c292992e14d/; sid:902205559; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"ce:bc:a3:90:cd:bc:05:a7:a9:d3:dc:d8:8d:cc:87:1f:3e:97:b8:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cebca390cdbc05a7a9d3dcd88dcc871f3e97b853/; sid:902205560; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"fc:e6:1e:f3:1a:71:ac:4e:ce:f3:1d:08:25:6e:91:02:3d:aa:cf:cc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fce61ef31a71ac4ecef31d08256e91023daacfcc/; sid:902205561; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"77:61:4b:19:10:58:4d:0e:24:17:75:d0:8f:28:fa:96:7c:65:36:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77614b1910584d0e241775d08f28fa967c65360f/; sid:902205562; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"27:c2:d8:e9:f1:1c:1a:83:af:9e:5e:01:c8:47:6b:1e:83:2a:b4:c8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/27c2d8e9f11c1a83af9e5e01c8476b1e832ab4c8/; sid:902205563; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"19:e6:64:f0:94:01:bf:64:8b:6e:a5:77:19:e3:4a:d7:95:f3:b6:cb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/19e664f09401bf648b6ea57719e34ad795f3b6cb/; sid:902205564; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ca:96:52:06:9f:67:6b:14:01:95:38:2d:de:3d:ac:88:51:0b:76:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca9652069f676b140195382dde3dac88510b7623/; sid:902205565; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"bc:e2:80:5b:28:d4:55:73:4a:c9:8a:b7:df:97:91:d2:f2:2a:97:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bce2805b28d455734ac98ab7df9791d2f22a9756/; sid:902205566; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b3:a9:71:5c:0f:99:94:b7:f8:d9:41:2d:4c:df:d4:0e:f3:6c:c1:4b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b3a9715c0f9994b7f8d9412d4cdfd40ef36cc14b/; sid:902205567; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"fc:f3:97:9d:56:5f:eb:03:e2:f8:a3:6f:74:33:79:02:2a:44:a9:23"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fcf3979d565feb03e2f8a36f743379022a44a923/; sid:902205568; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"db:a2:33:fb:04:b2:29:9a:ec:6c:e0:54:10:49:cd:ee:ac:30:62:40"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dba233fb04b2299aec6ce0541049cdeeac306240/; sid:902205569; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:e1:27:49:4b:7a:36:18:21:64:6e:a5:77:e3:de:b5:76:6c:16:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94e127494b7a361821646ea577e3deb5766c16b9/; sid:902205570; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"47:4d:aa:5d:f9:cf:d4:ed:6f:2d:0d:02:4a:e9:4c:92:a7:6a:60:bd"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/474daa5df9cfd4ed6f2d0d024ae94c92a76a60bd/; sid:902205571; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"b1:18:cd:1a:01:0f:9e:09:54:59:9b:37:43:ef:5e:a8:c1:61:ca:5f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b118cd1a010f9e0954599b3743ef5ea8c161ca5f/; sid:902205572; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"23:c4:71:7f:94:73:84:82:d4:66:ab:8c:33:dd:a1:28:ef:6a:6c:8c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/23c4717f94738482d466ab8c33dda128ef6a6c8c/; sid:902205573; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"05:7c:9a:67:b8:f9:15:27:c9:a7:cb:8a:54:97:01:6a:39:4f:65:3e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/057c9a67b8f91527c9a7cb8a5497016a394f653e/; sid:902205574; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"8f:05:03:47:08:e0:64:9f:2e:7a:bd:7c:9c:d4:87:14:aa:0e:a4:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8f05034708e0649f2e7abd7c9cd48714aa0ea44c/; sid:902205575; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"fb:a2:23:14:8f:25:79:3a:ea:78:69:37:81:f3:a9:bb:15:a1:f1:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fba223148f25793aea78693781f3a9bb15a1f1e1/; sid:902205576; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"d9:3c:bc:ee:94:4b:a7:66:f2:f0:24:ad:5a:22:75:b2:58:04:b2:f0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d93cbcee944ba766f2f024ad5a2275b25804b2f0/; sid:902205577; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"2d:17:0b:be:cf:aa:cf:d8:5c:a1:1a:61:07:e5:4f:94:06:2c:77:4a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/2d170bbecfaacfd85ca11a6107e54f94062c774a/; sid:902205578; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"bc:d9:ec:59:15:97:18:fd:3d:69:2b:3a:23:60:db:91:c0:bf:2b:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/bcd9ec59159718fd3d692b3a2360db91c0bf2b38/; sid:902205579; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"64:25:5d:d3:2d:7a:e6:c0:18:8c:6c:b7:2d:52:e4:a3:56:22:aa:c6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/64255dd32d7ae6c0188c6cb72d52e4a35622aac6/; sid:902205580; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vidar C&C)"; tls.fingerprint:"ca:3d:33:ba:e1:76:17:a6:d1:a3:b6:fd:da:fd:36:22:2f:3c:67:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ca3d33bae17617a6d1a3b6fddafd36222f3c67c9/; sid:902205581; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"58:33:ac:02:a5:90:bf:14:e4:6f:8e:bd:7d:e2:71:3c:af:50:7a:f4"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5833ac02a590bf14e46f8ebd7de2713caf507af4/; sid:902205582; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"db:8a:ef:4c:7e:33:fe:c5:c3:cb:23:56:68:fe:8a:53:50:fa:11:ba"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/db8aef4c7e33fec5c3cb235668fe8a5350fa11ba/; sid:902205583; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"34:dd:f4:38:9b:c4:3a:41:63:2f:27:1f:1e:94:af:2e:a3:b5:b7:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/34ddf4389bc43a41632f271f1e94af2ea3b5b7da/; sid:902205584; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4a:03:35:27:3f:26:2e:32:be:75:95:b2:cd:ac:21:3c:2f:79:bd:53"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4a0335273f262e32be7595b2cdac213c2f79bd53/; sid:902205585; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (T34loader C&C)"; tls.fingerprint:"b8:50:ca:99:3a:06:d9:29:f0:d7:6c:96:3f:03:93:b0:6f:25:6a:55"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b850ca993a06d929f0d76c963f0393b06f256a55/; sid:902205586; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (njrat C&C)"; tls.fingerprint:"00:3b:ec:d9:03:71:38:c2:ba:71:85:ab:c0:da:32:67:7c:7e:be:f5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/003becd9037138c2ba7185abc0da32677c7ebef5/; sid:902205587; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Malware C&C)"; tls.fingerprint:"66:be:36:b5:b3:c7:a9:cc:91:d5:14:97:06:bb:5c:d3:b7:b3:05:c7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66be36b5b3c7a9cc91d5149706bb5cd3b7b305c7/; sid:902205588; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"dd:79:af:83:6b:d9:9b:d2:fc:3d:66:a0:61:3f:83:fc:8a:50:a5:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dd79af836bd99bd2fc3d66a0613f83fc8a50a5ca/; sid:902205589; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"60:57:4f:17:41:a0:78:6c:82:7a:f4:9c:65:2a:b3:a7:da:05:33:d1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/60574f1741a0786c827af49c652ab3a7da0533d1/; sid:902205590; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"c0:3d:a4:39:fc:96:1d:3c:84:cc:c1:d0:c4:46:40:a0:f3:07:d0:5b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c03da439fc961d3c84ccc1d0c44640a0f307d05b/; sid:902205591; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"c0:0a:d8:5c:c2:8f:51:33:46:d9:c3:03:10:6e:f9:b0:a0:be:d3:13"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c00ad85cc28f513346d9c303106ef9b0a0bed313/; sid:902205592; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"21:c6:db:5a:b5:fb:41:6a:e9:89:a0:8b:f9:55:f7:15:b6:0b:01:0d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21c6db5ab5fb416ae989a08bf955f715b60b010d/; sid:902205593; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ee:02:f4:3e:da:45:75:43:25:cc:c2:22:77:09:22:8e:ab:df:09:46"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee02f43eda45754325ccc2227709228eabdf0946/; sid:902205594; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"65:c9:82:ba:7d:bb:ac:c5:dc:e7:30:ba:e0:48:63:a6:5e:02:21:dc"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/65c982ba7dbbacc5dce730bae04863a65e0221dc/; sid:902205595; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"0f:68:d8:e8:72:5e:b5:84:c1:66:0d:84:49:54:69:1d:35:75:ae:35"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0f68d8e8725eb584c1660d844954691d3575ae35/; sid:902205596; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b9:0d:9a:43:f7:c3:bf:3b:ba:75:40:34:10:e5:71:b5:f8:0b:a7:e1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b90d9a43f7c3bf3bba75403410e571b5f80ba7e1/; sid:902205597; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"9c:6d:80:bd:52:42:75:aa:ab:7c:35:f9:e1:c8:d1:7a:ca:14:da:56"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c6d80bd524275aaab7c35f9e1c8d17aca14da56/; sid:902205598; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:c6:b6:2f:2a:4a:e2:8b:e5:e0:51:83:00:76:c5:24:0f:5b:38:7e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/02c6b62f2a4ae28be5e051830076c5240f5b387e/; sid:902205599; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"ae:03:87:86:e5:0e:26:e9:9d:03:0a:42:23:b3:28:4a:44:de:8f:f6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ae038786e50e26e99d030a4223b3284a44de8ff6/; sid:902205600; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"98:82:0b:cb:b4:55:a8:22:6e:07:21:66:b1:85:ad:5a:4d:a7:a5:75"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/98820bcbb455a8226e072166b185ad5a4da7a575/; sid:902205601; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"06:da:44:f8:7d:12:bb:ca:ae:57:af:e6:63:b0:52:81:0a:d2:39:3d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/06da44f87d12bbcaae57afe663b052810ad2393d/; sid:902205602; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"57:d5:7e:a6:a2:d7:15:fd:f5:e0:1a:43:a4:64:df:56:fd:9f:a1:ff"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/57d57ea6a2d715fdf5e01a43a464df56fd9fa1ff/; sid:902205603; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fa:c2:ec:25:0d:e2:ba:8f:8c:77:5c:eb:d9:1f:81:49:0f:0a:10:18"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fac2ec250de2ba8f8c775cebd91f81490f0a1018/; sid:902205604; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b2:1e:67:8c:b6:09:64:07:1a:4e:76:80:5a:86:39:cb:83:19:c9:c9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b21e678cb60964071a4e76805a8639cb8319c9c9/; sid:902205605; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e4:33:17:93:71:c4:3c:71:4e:fa:4d:60:78:f7:41:5c:69:e2:19:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e433179371c43c714efa4d6078f7415c69e2190c/; sid:902205606; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"eb:31:e9:09:6e:1a:34:0f:bd:bf:c8:a9:5e:97:fe:21:cc:8d:ae:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/eb31e9096e1a340fbdbfc8a95e97fe21cc8dae0f/; sid:902205607; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fd:77:f1:c0:57:18:7f:06:c0:6a:e8:34:f0:4b:07:d0:4e:39:d7:38"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fd77f1c057187f06c06ae834f04b07d04e39d738/; sid:902205608; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"3a:15:14:75:43:e6:cb:16:c7:9c:54:5a:78:30:d2:66:1a:9c:b6:c3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a15147543e6cb16c79c545a7830d2661a9cb6c3/; sid:902205609; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"83:32:84:3c:84:51:46:72:c1:9e:1c:f1:22:d0:2f:e1:48:a6:a7:3c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8332843c84514672c19e1cf122d02fe148a6a73c/; sid:902205610; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"db:cd:9c:87:fe:c5:21:00:28:3f:b2:f0:e4:0c:e0:f3:5b:5e:5f:02"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/dbcd9c87fec52100283fb2f0e40ce0f35b5e5f02/; sid:902205611; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"5a:ab:ab:54:f6:33:ab:e8:e5:59:b0:a9:4a:af:d6:8a:65:9a:56:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/5aabab54f633abe8e559b0a94aafd68a659a564e/; sid:902205612; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"39:da:64:e9:4d:8f:6a:82:6f:0e:52:88:37:82:02:49:10:34:d2:e2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/39da64e94d8f6a826f0e5288378202491034d2e2/; sid:902205613; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e7:ab:8e:4d:90:3a:37:a3:8e:64:4a:54:27:c9:1a:25:74:bc:11:69"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7ab8e4d903a37a38e644a5427c91a2574bc1169/; sid:902205614; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"d7:4b:24:a0:a4:fb:be:4b:97:fe:85:97:87:9a:bb:6d:b7:6c:61:83"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d74b24a0a4fbbe4b97fe8597879abb6db76c6183/; sid:902205615; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (VenomRAT C&C)"; tls.fingerprint:"61:22:13:8b:36:39:f9:2c:58:df:50:56:cd:a2:9d:e7:e3:9f:74:ad"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6122138b3639f92c58df5056cda29de7e39f74ad/; sid:902205616; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fa:5b:71:0a:9b:a1:0d:17:ec:4c:f0:f9:22:62:ee:5a:fc:91:05:bf"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fa5b710a9ba10d17ec4cf0f92262ee5afc9105bf/; sid:902205617; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"77:e1:ce:64:c9:07:13:d6:93:76:a6:54:f4:c5:6c:1e:02:62:c5:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/77e1ce64c90713d69376a654f4c56c1e0262c545/; sid:902205618; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (RedLineStealer C&C)"; tls.fingerprint:"9c:85:16:27:56:52:a9:fb:b9:c0:f3:83:88:17:37:7e:48:4d:40:92"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9c8516275652a9fbb9c0f3838817377e484d4092/; sid:902205619; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"80:bc:79:95:4a:2f:63:5e:43:01:23:fd:b2:45:60:89:0b:db:77:89"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/80bc79954a2f635e430123fdb24560890bdb7789/; sid:902205620; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"0d:92:b2:8b:f1:d0:db:78:22:a3:7f:47:78:1b:49:ff:26:a7:1e:c2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0d92b28bf1d0db7822a37f47781b49ff26a71ec2/; sid:902205621; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ce:42:9e:13:e7:76:7d:9b:d5:c6:a1:d4:a8:08:16:1c:26:36:f7:20"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ce429e13e7767d9bd5c6a1d4a808161c2636f720/; sid:902205622; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"94:f6:06:fe:c2:76:1b:ae:e1:f5:8f:32:f8:eb:74:43:ca:1e:d4:88"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/94f606fec2761baee1f58f32f8eb7443ca1ed488/; sid:902205623; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"72:9e:1c:86:f4:6b:d5:39:c2:20:4c:b0:22:7e:6d:ec:16:62:12:64"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/729e1c86f46bd539c2204cb0227e6dec16621264/; sid:902205624; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f5:87:8a:d7:86:db:5c:25:2c:13:89:04:e8:a8:32:f5:8c:fe:46:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f5878ad786db5c252c138904e8a832f58cfe46ca/; sid:902205625; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"ee:6d:ef:59:cf:1e:0c:f3:6b:b4:c2:37:56:6a:5c:22:a6:fd:68:1e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/ee6def59cf1e0cf36bb4c237566a5c22a6fd681e/; sid:902205626; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"01:5b:57:3f:b6:23:2b:4a:5d:ce:82:07:c4:1c:51:4c:82:50:20:45"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/015b573fb6232b4a5dce8207c41c514c82502045/; sid:902205627; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"aa:fe:56:94:85:13:f4:6f:19:27:1c:23:50:12:fe:18:e0:64:ea:4c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/aafe56948513f46f19271c235012fe18e064ea4c/; sid:902205628; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a3:cd:b1:18:ca:89:73:48:56:db:94:7b:20:58:49:a1:dc:a8:16:67"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a3cdb118ca89734856db947b205849a1dca81667/; sid:902205629; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"fa:b4:de:47:f9:43:eb:41:17:98:dc:be:93:74:78:dd:76:88:1e:73"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fab4de47f943eb411798dcbe937478dd76881e73/; sid:902205630; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"d3:ca:53:4e:40:cc:bb:a2:1a:97:22:c2:16:53:29:94:76:27:e3:49"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d3ca534e40ccbba21a9722c2165329947627e349/; sid:902205631; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Latrodectus C&C)"; tls.fingerprint:"d9:b5:8c:37:4f:81:30:5f:b5:b5:45:b6:f9:a9:3b:99:bb:81:07:0a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d9b58c374f81305fb5b545b6f9a93b99bb81070a/; sid:902205632; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Latrodectus C&C)"; tls.fingerprint:"62:d0:26:a9:d6:60:d6:e5:33:90:7e:fe:af:e2:3a:fa:22:87:fb:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/62d026a9d660d6e533907efeafe23afa2287fb42/; sid:902205633; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"71:77:24:87:07:fb:fd:c6:35:f4:34:c3:45:e6:25:c7:6f:40:9d:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7177248707fbfdc635f434c345e625c76f409d27/; sid:902205634; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"74:3a:c4:d7:14:f4:af:4f:2c:f7:6d:14:10:19:92:fa:a9:e6:20:db"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/743ac4d714f4af4f2cf76d14101992faa9e620db/; sid:902205635; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a6:d5:e0:5f:8d:c8:55:e1:6c:19:4b:35:78:25:8f:94:2e:1e:55:37"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a6d5e05f8dc855e16c194b3578258f942e1e5537/; sid:902205636; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"54:5f:e2:34:9a:e3:06:45:df:ba:84:61:45:5c:dd:19:08:44:39:a9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/545fe2349ae30645dfba8461455cdd19084439a9/; sid:902205637; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"ac:f5:f3:1e:13:48:1f:44:62:56:f4:14:5d:00:70:35:d8:12:cf:ae"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/acf5f31e13481f446256f4145d007035d812cfae/; sid:902205638; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e8:83:fe:a8:00:a4:7b:3b:85:3a:04:dd:cd:0d:16:2e:78:2b:41:b7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e883fea800a47b3b853a04ddcd0d162e782b41b7/; sid:902205639; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"83:6e:a2:4d:2b:09:48:29:c5:2d:ba:e3:48:50:95:d5:c8:94:24:7b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/836ea24d2b094829c52dbae3485095d5c894247b/; sid:902205640; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"21:f0:eb:5d:4b:32:ba:b8:e2:28:3e:78:36:5f:26:80:47:e8:18:33"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/21f0eb5d4b32bab8e2283e78365f268047e81833/; sid:902205641; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"66:eb:66:a1:97:a4:e6:ec:13:32:fe:ed:82:90:ca:c1:a9:19:b0:85"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/66eb66a197a4e6ec1332feed8290cac1a919b085/; sid:902205642; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e2:ee:25:3a:7b:ef:95:55:8c:c9:2d:ae:92:a7:cf:76:4c:f9:3e:4e"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e2ee253a7bef95558cc92dae92a7cf764cf93e4e/; sid:902205643; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"87:d9:07:25:87:5d:82:5b:d5:fe:c4:6a:2a:0b:3c:e8:e2:71:6e:58"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/87d90725875d825bd5fec46a2a0b3ce8e2716e58/; sid:902205644; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"e7:45:c2:dc:4d:c1:f9:6a:c4:40:86:bd:5a:05:ca:92:34:55:8a:34"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e745c2dc4dc1f96ac44086bd5a05ca9234558a34/; sid:902205645; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"a1:f8:67:22:46:a5:5d:fa:fa:31:7b:fd:c5:f1:4c:91:a5:b3:44:b9"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a1f8672246a55dfafa317bfdc5f14c91a5b344b9/; sid:902205646; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"85:78:74:9c:7e:e0:91:41:05:02:53:13:82:46:46:3f:d7:f8:59:80"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/8578749c7ee09141050253138246463fd7f85980/; sid:902205647; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"44:29:92:b3:e8:27:96:c9:b3:8c:65:68:4c:b1:dc:5e:9a:e5:5d:a1"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/442992b3e82796c9b38c65684cb1dc5e9ae55da1/; sid:902205648; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"22:1f:4b:12:3d:3b:19:e6:2a:94:fc:f5:10:57:95:35:fd:91:fd:4f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/221f4b123d3b19e62a94fcf510579535fd91fd4f/; sid:902205649; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"b0:1c:26:c4:7c:b2:8d:ea:fd:2f:4e:08:0c:5b:6a:4b:29:69:d2:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b01c26c47cb28deafd2f4e080c5b6a4b2969d2be/; sid:902205650; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"e4:29:f2:4e:27:9e:8b:25:74:2d:0f:53:47:15:1b:0f:90:d0:31:ca"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e429f24e279e8b25742d0f5347151b0f90d031ca/; sid:902205651; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"3e:03:4e:54:c9:2a:3a:88:f3:e2:f9:ee:4d:e0:fb:77:42:df:3b:42"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3e034e54c92a3a88f3e2f9ee4de0fb7742df3b42/; sid:902205652; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a4:59:6c:32:c6:a2:60:ff:a4:c5:ed:ee:33:81:4f:73:ff:53:62:0f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4596c32c6a260ffa4c5edee33814f73ff53620f/; sid:902205653; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"51:d9:32:05:1a:79:7e:9c:73:fa:52:09:7f:01:9e:26:69:9f:26:d6"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/51d932051a797e9c73fa52097f019e26699f26d6/; sid:902205654; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"82:05:3c:51:58:eb:d8:8c:5a:e8:55:3b:7e:fe:18:20:0e:c0:30:7f"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/82053c5158ebd88c5ae8553b7efe18200ec0307f/; sid:902205655; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"49:bf:5a:48:97:0d:91:4c:7e:70:f4:94:a8:e1:6b:5e:fa:3a:b6:a0"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/49bf5a48970d914c7e70f494a8e16b5efa3ab6a0/; sid:902205656; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Rhadamanthys C&C)"; tls.fingerprint:"37:e1:06:6c:8e:c7:8d:34:03:fb:17:ae:c2:f3:3d:cd:0f:2d:4a:36"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/37e1066c8ec78d3403fb17aec2f33dcd0f2d4a36/; sid:902205657; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (DCRat C&C)"; tls.fingerprint:"10:31:24:5f:a6:3c:c4:b7:56:7f:70:2b:f6:e8:ee:37:15:92:33:df"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/1031245fa63cc4b7567f702bf6e8ee37159233df/; sid:902205658; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"a4:a7:8c:ad:de:73:17:0c:71:5e:85:94:2c:e1:56:e2:23:ba:5f:f3"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/a4a78cadde73170c715e85942ce156e223ba5ff3/; sid:902205659; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"e9:6b:ef:09:7f:d1:6d:12:6b:93:d1:17:f7:10:8b:1f:46:10:e9:d2"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e96bef097fd16d126b93d117f7108b1f4610e9d2/; sid:902205660; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (OrcusRAT C&C)"; tls.fingerprint:"b9:25:72:0e:95:9b:8d:6f:85:5e:87:b0:bd:3e:ac:fd:eb:88:ce:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b925720e959b8d6f855e87b0bd3eacfdeb88ce2b/; sid:902205661; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"54:8e:e6:e2:cd:52:79:c7:1f:4d:f6:d8:4c:0d:11:b7:f0:36:37:21"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/548ee6e2cd5279c71f4df6d84c0d11b7f0363721/; sid:902205662; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"e7:bb:6c:b5:e7:15:4e:79:4d:10:1c:c3:a4:9d:fd:ef:68:be:b2:99"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e7bb6cb5e7154e794d101cc3a49dfdef68beb299/; sid:902205663; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"6b:0d:9c:df:bf:22:25:1a:89:f5:54:e0:59:b7:46:3c:8c:de:0f:0c"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/6b0d9cdfbf22251a89f554e059b7463c8cde0f0c/; sid:902205664; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"47:85:08:31:78:d8:7e:b2:ad:34:2d:88:49:d0:67:2a:e2:9f:17:44"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4785083178d87eb2ad342d8849d0672ae29f1744/; sid:902205665; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AgentTesla C&C)"; tls.fingerprint:"05:df:91:91:f4:21:f5:70:89:28:1a:00:67:54:2d:95:46:ad:86:eb"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/05df9191f421f57089281a0067542d9546ad86eb/; sid:902205666; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"c6:3e:9e:0a:e6:75:57:77:d4:90:4e:1d:8d:df:14:6c:eb:83:73:f8"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/c63e9e0ae6755777d4904e1d8ddf146ceb8373f8/; sid:902205667; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"67:d8:ac:e7:5a:df:77:9e:6a:2e:d7:99:b8:79:2d:fe:d4:68:ec:af"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/67d8ace75adf779e6a2ed799b8792dfed468ecaf/; sid:902205668; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"e1:3c:f9:c7:2e:ee:40:60:4c:94:9b:be:29:93:5b:19:db:5a:7c:91"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/e13cf9c72eee40604c949bbe29935b19db5a7c91/; sid:902205669; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"7b:d3:29:dc:50:b3:bc:00:84:b0:b7:bb:5e:ad:d2:8c:c5:e1:3b:9d"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/7bd329dc50b3bc0084b0b7bb5eadd28cc5e13b9d/; sid:902205670; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"b0:7a:5a:cb:95:a4:58:5b:18:07:77:93:dc:a9:a6:39:7f:04:da:84"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/b07a5acb95a4585b18077793dca9a6397f04da84/; sid:902205671; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"4e:f1:54:7b:5d:b5:05:8d:cc:eb:6a:60:d4:8a:54:c3:50:26:d8:d5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ef1547b5db5058dcceb6a60d48a54c35026d8d5/; sid:902205672; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"9a:a1:56:60:a0:a0:db:41:5a:7a:08:20:02:1e:d5:d0:d9:c8:91:63"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9aa15660a0a0db415a7a0820021ed5d0d9c89163/; sid:902205673; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (QuasarRAT C&C)"; tls.fingerprint:"cf:b4:f4:ca:02:2c:9b:63:55:a5:63:91:e8:51:51:9d:74:d8:99:6a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/cfb4f4ca022c9b6355a56391e851519d74d8996a/; sid:902205674; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"97:c4:7b:0b:ec:5a:12:c4:2d:c4:82:5f:b2:0d:3e:d9:c8:95:45:b5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/97c47b0bec5a12c42dc4825fb20d3ed9c89545b5/; sid:902205675; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"fe:e8:8c:fc:81:f8:5a:9b:23:32:65:8b:06:2f:34:c9:3b:62:1f:2b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/fee88cfc81f85a9b2332658b062f34c93b621f2b/; sid:902205676; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (MarsStealer C&C)"; tls.fingerprint:"3a:88:43:fc:a6:f4:e2:06:bd:f6:9a:e1:50:cb:65:75:6a:2e:87:95"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/3a8843fca6f4e206bdf69ae150cb65756a2e8795/; sid:902205677; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vidar C&C)"; tls.fingerprint:"16:4a:ae:df:df:70:74:33:c8:a5:0f:1e:55:5a:22:f7:ee:2f:77:e5"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/164aaedfdf707433c8a50f1e555a22f7ee2f77e5/; sid:902205678; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"54:fa:d4:70:8b:c4:f7:a7:e4:c6:08:b1:eb:9d:d2:7a:31:87:26:3b"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/54fad4708bc4f7a7e4c608b1eb9dd27a3187263b/; sid:902205679; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (Vidar C&C)"; tls.fingerprint:"d4:51:76:62:1e:48:75:d8:50:f7:e7:c7:de:5e:ec:c6:57:b6:c6:71"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/d45176621e4875d850f7e7c7de5eecc657b6c671/; sid:902205680; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (PureLogStealer C&C)"; tls.fingerprint:"fa:ff:79:8e:6e:eb:91:92:55:d3:d3:6d:46:1d:46:dd:3f:cc:2c:f7"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/faff798e6eeb919255d3d36d461d46dd3fcc2cf7/; sid:902205681; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"87:7b:5b:d7:e0:e4:b1:40:e5:ef:8f:0a:c6:40:d0:90:41:ec:d1:da"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/877b5bd7e0e4b140e5ef8f0ac640d09041ecd1da/; sid:902205682; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (zgRAT C&C)"; tls.fingerprint:"9d:2e:aa:28:47:77:ce:a1:ce:cd:ba:13:e5:fc:6f:7f:de:5f:bb:24"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/9d2eaa284777cea1cecdba13e5fc6f7fde5fbb24/; sid:902205683; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"4e:d2:b0:4c:25:79:c3:d4:ce:65:5d:70:7e:b2:64:a9:6f:6a:03:27"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/4ed2b04c2579c3d4ce655d707eb264a96f6a0327/; sid:902205684; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"02:75:f0:54:d3:e6:2c:2e:d9:69:e7:cf:76:78:27:56:75:59:04:2a"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/0275f054d3e62c2ed969e7cf767827567559042a/; sid:902205685; rev:1;) alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSLBL: Malicious SSL certificate detected (AsyncRAT C&C)"; tls.fingerprint:"f8:74:3c:52:80:b0:d0:f8:39:09:2c:97:28:74:ca:f3:97:9c:37:be"; reference:url, sslbl.abuse.ch/ssl-certificates/sha1/f8743c5280b0d0f839092c972874caf3979c37be/; sid:902205686; rev:1;) # END (5687) entries