s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.bluebanana

📛 Threat Title

Malware family: Blue Banana RAT

Category: Blue Banana RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.bluebanana`. Printable name: Blue Banana RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.bluebanana VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.bluebanana

IOC database

Type
domain
Value
jar.bluebanana
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.bluebanana

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.bluebanana

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    MalwareBazaar Database This page shows some basic information the YARA rule RAT_BlueBanana including corresponding malware samples. Database Entry ... Malware Samples The table below shows all malware samples that matching this particular YARA rule (max 1000).

  • web:blog.sucuri.net

    Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .

  • web:github.com

    For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots. - BruteQuad/ultimate- rat -collection

  • web:hunt.io

    Learn about njRAT (Bladabindi), a remote access trojan enabling attackers to control infected Windows machines. Discover its features, variants, and mitigation strategies.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Blue Banana RAT malware family including references, samples and yara signatures.

  • web:sslinsights.com

    Learn about Remote Access Trojan types, security measures to prevent RAT attacks, and effective removal steps to protect your devices.

  • web:www.malwarebytes.com

    Short bio Backdoor.Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system. Type and source of the infection Backdoor.Remcos is a Remote Administration Tool ( RAT ). Backdoor.Remcos can arrive as a malicious email attachment or be downloaded by other malware . Aftermath Backdoor.Remcos gives the threat actor full ...

  • web:www.microsoft.com

    CrashFix crashes browsers to coerce users into executing commands that deploy a Python RAT , abusing finger.exe and portable Python to evade detection and persist on high‑value systems.

  • web:www.redteamnews.com

    Arch Linux has removed three compromised packages from its Arch User Repository (AUR) after discovering they contained the Chaos Remote Access Trojan ( RAT ). The malicious packages, which posed as browser patches, were available for download until their removal on July 18, 2025 1.

  • web:www.trendmicro.com

    In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063's Banana RAT banking malware by analyzing server-side artifacts and victim-side data.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.