Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
Abuse SSL (Deprecated) logo

Abuse SSL (Deprecated)

Supported by Filigran
Infrastructure & Attack Surface Visibility

Overview

Imports botnet C&C server IP addresses detected via SSL certificate fingerprints from the Abuse.ch SSLBL blacklist into OpenCTI as STIX 2.1 indicators. ⚠️ Deprecated — source feed no longer updated since January 2025.

The Abuse.ch SSLBL (SSL Blacklist) identifies and lists IP addresses associated with botnet Command & Control (C&C) servers based on SSL certificate fingerprints. SSLBL collects IP addresses running with blacklisted SSL certificates and publishes a CSV blacklist that can be used to detect botnet C2 traffic leaving your network.

⚠️ This connector is deprecated — the source CSV feed has not been updated since 2025-01-03 and will no longer be maintained.

Basic information

Abuse SSL (Deprecated)
Connectors
6.8.13
7

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".