Gh0st.Rat.Botnet

description-logoDescription

This indicates that a system might be infected by the Gh0st Rat Botnet.
Gh0st Rat is a Windows malware that can remotely control a computer to log key strokes, take screenshots, execute arbitrary commands, download and install additional malware.
Please note: this signature sometimes gets triggered by botnet scanning traffics from Shodan scanners. Please check the source IP to verify if it's an actual infection on the network. All botnet signatures from FortiOS 5.6 onwards are under IPS, and have their default action set to "Block".

affected-products-logoAffected Products

Any unprotected Windows system is vulnerable.

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

If required, the signature's action can be set to "Block".
Use Anti-Virus software to scan and clean the system.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-06-12 33.027
Modified
Sig Added
2025-04-08 31.985
Modified
Sig Added
2023-11-21 26.681
Modified
Sig Added
2023-03-28 23.521
Modified
Sig Added