Have you been haunted by the Gh0st RAT today?
ID: a1936dc7-2fdb-59c4-9733-1f980d4894ca
STIX ID: report--a1936dc7-2fdb-59c4-9733-1f980d4894ca
Feed Name: Volexity Blog
Threat Score
Volexity observed Shodan scanning activity that mimics Gh0st RAT C2 traffic, including a zlib-compressed payload and a decoded TOKEN string, which is causing widespread false-positive alerts on network monitoring/security appliances; the advisory explains how to identify these inbound scans (source = Shodan, payload match) and recommends tuning signatures to alert on outbound traffic to avoid misclassification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
