TF-MAL-jar.bluebanana
📛 Threat Title
Malware family: Blue Banana RAT
Description
ThreatFox malware family `jar.bluebanana`. Printable name: Blue Banana RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
jar.bluebanana
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.bluebanana
IOC database
- Type
- domain
- Value
jar.bluebanana- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-jar.bluebanana
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.bluebanana
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
MalwareBazaar Database This page shows some basic information the YARA rule RAT_BlueBanana including corresponding malware samples. Database Entry ... Malware Samples The table below shows all malware samples that matching this particular YARA rule (max 1000).
-
web:blog.sucuri.net
Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .
-
web:github.com
For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots. - BruteQuad/ultimate- rat -collection
-
web:hunt.io
Learn about njRAT (Bladabindi), a remote access trojan enabling attackers to control infected Windows machines. Discover its features, variants, and mitigation strategies.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Blue Banana RAT malware family including references, samples and yara signatures.
-
web:sslinsights.com
Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.
-
web:www.malwarebytes.com
Short bio Backdoor.Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system. Type and source of the infection Backdoor.Remcos is a Remote Administration Tool ( RAT ). Backdoor.Remcos can arrive as a malicious email attachment or be downloaded by other malware . Aftermath Backdoor.Remcos gives the threat actor full ...
-
web:www.microsoft.com
CrashFix crashes browsers to coerce users into executing commands that deploy a Python RAT , abusing finger.exe and portable Python to evade detection and persist on high‑value systems.
-
web:www.redteamnews.com
Arch Linux has removed three compromised packages from its Arch User Repository (AUR) after discovering they contained the Chaos Remote Access Trojan ( RAT ). The malicious packages, which posed as browser patches, were available for download until their removal on July 18, 2025 1.
-
web:www.trendmicro.com
In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.