Abuse SSL (Deprecated)
Supported by Filigran
Infrastructure & Attack Surface Visibility
Overview
Imports botnet C&C server IP addresses detected via SSL certificate fingerprints from the Abuse.ch SSLBL blacklist into OpenCTI as STIX 2.1 indicators. ⚠️ Deprecated — source feed no longer updated since January 2025.
The Abuse.ch SSLBL (SSL Blacklist) identifies and lists IP addresses associated with botnet Command & Control (C&C) servers based on SSL certificate fingerprints. SSLBL collects IP addresses running with blacklisted SSL certificates and publishes a CSV blacklist that can be used to detect botnet C2 traffic leaving your network.
⚠️ This connector is deprecated — the source CSV feed has not been updated since 2025-01-03 and will no longer be maintained.