ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://162.33.178.68/msedge.txt.

Database Entry


IOC ID:1854537
IOC: http://162.33.178.68/msedge.txt
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (80%)
Is compromised? : True
ASN:AS399629 BLNWX
Country:- NL
First seen:2026-07-21 05:20:22 UTC
Last seen:never
UUID:261020d6-847e-11f1-8973-42010aa4000a
Reporter DENNISAROSS
Reward 5 credits from ThreatFox
Tags:BananaRAT banking-trojan BL-Networks brazil masquerading powershell
Reference: https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/

Avatar
DENNISAROSS
Banana RAT PowerShell client (524K) masquerading as a .txt file and named after msedge.exe for evasion. Staged on BL Networks (AS399629). Contains hardcoded C2: testewin.com (Cloudflare Tunnel) and fallback 149.56.12.51:443. Full RAT: screen capture/streaming, keylogger, clipboard capture, mouse/keyboard control, SYSTEM persistence via scheduled task, bank-branded screen overlays blocking victim during fraud. Targets BB, Bradesco, Itau, Santander, Caixa + Brazilian crypto exchanges.