Certificates associated with malware added to SSL Blacklist

Share this article:

Introduced on Tuesday, the SSL Blacklist (SSLBL) is designed to aid in detecting botnet traffic that uses SSL to communicate, including Shylock malware and variants of the infamous Zeus trojan, according to a post on Swiss security blog abuse.ch.

Noting an increase in attackers shifting to SSL in order to evade detection, a researcher with abuse.ch decided to compile and maintain a list of SHA1 fingerprints of SSL certificates associated with malware and botnet activities, according to the post.

As of Wednesday afternoon, 127 SSL certificates have been blacklisted.

The idea for SSLBL came to the researcher while tinkering around with Suricata, an open source intrusion detection and prevention system equipped with a module to fingerprint SSL/TLS certificates, according to the post.

Share this article:

Sign up to our newsletters

More in News

Phishing campaign targeting users of Bitcoin wallet Blockchain.info

More than 12,000 messages have been sent to more than 400 companies as part of a phishing campaign targeting users of Bitcoin wallet Blockchain.info.

AOL announces that it does not follow 'Do Not Track' requests

Eight months after the enactment of a new California privacy law, AOL clarified that it does not respond to web browsers' "Do Not Track" requests.

Experts discover history of malware infections on network of Community Health Systems

Following a major breach at the hospital provider, security experts analyzed its network and discovered malware infections dating back to January.