False positive 2035595 - zgRAT / PureRAT confusion

I see rule 2035595 “ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert” getting triggered every now and then, but never for zgRAT traffic. It typically triggers when there’s PureRAT C2 traffic. I think I might have seen it alert on AsyncRAT traffic as well, but I’m not sure.

Would it make sense to rename 2035595 to “ET MALWARE Generic PureRAT/AsyncRAT Style SSL Cert”?

Here are some network indicators that I sometimes use to verify that the C2 traffic is PureRAT:

  • Default TCP port: 56001 / 56002 / 56003 (can use other ports)
  • JA3: fc54e0d16d9764783542f0146a98b300 / 07af4aa9e4d215a5ee63f9a0a277fbe3
  • Self signed X.509 cert often expires 9999-12-31 23:59:59 UTC

Here are some example sandbox executions that trigger 1:2035595:6: