logo

Have you been haunted by the Gh0st RAT today?

ID: a1936dc7-2fdb-59c4-9733-1f980d4894ca

STIX ID: report--a1936dc7-2fdb-59c4-9733-1f980d4894ca

Feed Name: Volexity Blog

Threat Score
10/100

Date Published: 2017-03-23

Date Updated: 2026-05-01

...
...

Volexity observed Shodan scanning activity that mimics Gh0st RAT C2 traffic, including a zlib-compressed payload and a decoded TOKEN string, which is causing widespread false-positive alerts on network monitoring/security appliances; the advisory explains how to identify these inbound scans (source = Shodan, payload match) and recommends tuning signatures to alert on outbound traffic to avoid misclassification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.