ET-3393
📛 Threat Title
False positive 2035595 - zgRAT / PureRAT confusion
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- False positive 2035595 - zgRAT / PureRAT confusion Emerging Threats Community
Remediations (10)
-
web:community.emergingthreats.net
I see rule 2035595 "ET MALWARE Generic AsyncRAT/ zgRAT Style SSL Cert" getting triggered every now and then, but never for zgRAT traffic. It typically triggers when there's PureRAT C2 traffic.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion techniques. They have named it 'Resolver' due to its heavy reliance on runtime resolution mechanisms and dynamic resource handling, which make static and behavioral analysis significantly more difficult.
-
web:malpedia.caad.fkie.fraunhofer.de
2026-07-27 (Back to Inventory) Propose Change PureLogs, PureRAT and misleading zgRAT Author (s): Erik Hjelmvik Organization: Netresec win.purelogs win. pure_rat win. zgrat Open article directly Open article on Archive.org Show BibTex Entry
-
web:research.checkpoint.com
Further investigation led to the discovery of a PureRAT builder, revealing insights into the RAT's capabilities and highlighting features linked to PureCrypter, another tool developed by PureCoder, the author behind the Pure malware suite.
-
web:www.bleepingcomputer.com
Researchers map a campaign that escalated from a Python infostealer to a full PureRAT backdoor — loaders, evasions, and TLS-pinned C2. Join Huntress Labs' Tradecraft Tuesday for deep technical ...
-
web:www.enigma-global.com
This reduces label fragmentation and downstream confusion when the same label is reused for different malware families. Why zgRAT causes confusion Many zgRAT signatures consistently match PureLogs, while others match PureRAT .
-
web:www.netresec.com
The alert labels merely reflect how the rule author named the suspected malware at creation time. Nevertheless, the fact that the " zgRAT " label is used for PureLogs as well as PureRAT signatures contributes to the confusion regarding what zgRAT actually is. I use FlowCarp to identify PureLogs and PureRAT traffic and to tell them apart.
-
web:www.netresec.com
Many zgRAT signatures consistently match PureLogs, while others match PureRAT . There's also a fairly popular YARA rule called "MALWARE_Win_zgRAT" that matches pretty much any binary protected with .NET Reactor. Taken together, this creates a solid foundation for false positives and misunderstandings stemming from the zgRAT label.
-
web:www.penetrify.cloud
When you reduce false positives vulnerability scanning to this 5% threshold, your security team can spend 95% of their time on actual remediation efforts instead of chasing ghosts in the system. How does Penetrify verify exploitability without crashing my application?
-
web:x.com
zgRAT is a confusing catch-all label: both #PureLogs and # PureRAT commonly trigger " zgRAT " detections. Please don't label malware as # zgRAT . 27 Jul 2026 16:12:00
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.