s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3393

📛 Threat Title

False positive 2035595 - zgRAT / PureRAT confusion

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:community.emergingthreats.net

    I see rule 2035595 "ET MALWARE Generic AsyncRAT/ zgRAT Style SSL Cert" getting triggered every now and then, but never for zgRAT traffic. It typically triggers when there's PureRAT C2 traffic.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion techniques. They have named it 'Resolver' due to its heavy reliance on runtime resolution mechanisms and dynamic resource handling, which make static and behavioral analysis significantly more difficult.

  • web:malpedia.caad.fkie.fraunhofer.de

    2026-07-27 (Back to Inventory) Propose Change PureLogs, PureRAT and misleading zgRAT Author (s): Erik Hjelmvik Organization: Netresec win.purelogs win. pure_rat win. zgrat Open article directly Open article on Archive.org Show BibTex Entry

  • web:research.checkpoint.com

    Further investigation led to the discovery of a PureRAT builder, revealing insights into the RAT's capabilities and highlighting features linked to PureCrypter, another tool developed by PureCoder, the author behind the Pure malware suite.

  • web:www.bleepingcomputer.com

    Researchers map a campaign that escalated from a Python infostealer to a full PureRAT backdoor — loaders, evasions, and TLS-pinned C2. Join Huntress Labs' Tradecraft Tuesday for deep technical ...

  • web:www.enigma-global.com

    This reduces label fragmentation and downstream confusion when the same label is reused for different malware families. Why zgRAT causes confusion Many zgRAT signatures consistently match PureLogs, while others match PureRAT .

  • web:www.netresec.com

    The alert labels merely reflect how the rule author named the suspected malware at creation time. Nevertheless, the fact that the " zgRAT " label is used for PureLogs as well as PureRAT signatures contributes to the confusion regarding what zgRAT actually is. I use FlowCarp to identify PureLogs and PureRAT traffic and to tell them apart.

  • web:www.netresec.com

    Many zgRAT signatures consistently match PureLogs, while others match PureRAT . There's also a fairly popular YARA rule called "MALWARE_Win_zgRAT" that matches pretty much any binary protected with .NET Reactor. Taken together, this creates a solid foundation for false positives and misunderstandings stemming from the zgRAT label.

  • web:www.penetrify.cloud

    When you reduce false positives vulnerability scanning to this 5% threshold, your security team can spend 95% of their time on actual remediation efforts instead of chasing ghosts in the system. How does Penetrify verify exploitability without crashing my application?

  • web:x.com

    zgRAT is a confusing catch-all label: both #PureLogs and # PureRAT commonly trigger " zgRAT " detections. Please don't label malware as # zgRAT . 27 Jul 2026 16:12:00

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.