Joe Sandbox v45 - Green Opal
Published on: 07.09.2026
Today, we are proud to release Joe Sandbox 45 under the code name Green Opal! This release is packed with many new detection signatures and important features to improve Joe Sandbox.
If you wish to upgrade your on-premise Joe Sandbox installation, please follow the instructions in the chapter on "Updating" in the user guide which you find in our customer portal.
625 New Behavior and YARA Signatures
Joe Sandbox v45 comes with a significant number of new detection signatures.
We added 50 new behavior signatures and 575 new custom YARA rules to detect emerging malware families, phishing frameworks, ransomware, stealers, RATs, and other threats.
New detections include: RatonRAT, REMUS Stealer, EtherHiding, Evooo1Bot, Cyb3r Phishing Kit, SilentNet, GehennaLocker, PureLogs Stealer, 0aptLocker, PhantomGate, notnullOSX, Microsoft Device Code Phisher, QuimaRAT, and many more.
55 New Malware Configuration Extractors
We added 55 new malware configuration extractors, further expanding Joe Sandbox’s ability to automatically identify malware families and extract valuable configuration data and indicators of compromise.
New configuration extractors include:
ZigClipper, BlakcSee Stealer, phishingtelegramexfil, CyberPhishingKit, Sirius RAT, OverLordRat, Crown Phishing Kit, CastleRat, WikiKit, PhantomGate, Remus Stealer, SnappyClient, SantaStealer, and GenericBot, to name a few.
These extractors help analysts quickly uncover important malware configuration details without having to manually reverse engineer every sample.
133 New Suricata Rules
Joe Sandbox v45 adds 133 new Suricata rules to improve the detection of malicious and suspicious network activity, including 30 anomaly, 88 malware, and 15 phishing rules.
New detections include CastleRAT, LummaC, LxBase RAT, njRAT, Phoenix Stealer, SilentNet, ErrTraffic v2 ClickFix, EvilTokens, Tycoon2FA, and WikiKit/Sneaky2FA.
Improved DOM Extraction and Phishing Detection
Phishing campaigns continue to become more sophisticated, using dynamic web content, obfuscated scripts, redirects, and other techniques to make automated analysis more difficult.
With Joe Sandbox v45, we have improved DOM extraction and phishing detection to provide better visibility into suspicious websites and phishing pages.
The improvements help Joe Sandbox more accurately analyze web content and identify phishing-related behavior, giving analysts additional context when investigating suspicious URLs and web-based threats.
With Joe Sandbox v45, we have improved DOM extraction and phishing detection to provide better visibility into suspicious websites and phishing pages.
The improvements help Joe Sandbox more accurately analyze web content and identify phishing-related behavior, giving analysts additional context when investigating suspicious URLs and web-based threats.
Improved QR Code Reader
QR codes are increasingly used as part of phishing and social engineering campaigns, particularly to move victims away from traditional email security controls.
Joe Sandbox v45 includes further improvements to the QR code reader, strengthening the analysis of samples and documents containing QR codes.
This helps analysts uncover URLs and other information embedded in QR codes and provides additional visibility into QR-based phishing campaigns.
Joe Sandbox v45 includes further improvements to the QR code reader, strengthening the analysis of samples and documents containing QR codes.
This helps analysts uncover URLs and other information embedded in QR codes and provides additional visibility into QR-based phishing campaigns.
Improved Live Interaction Performance
We also made important improvements to Live Interaction.
Joe Sandbox v45 provides improved responsiveness and performance during Live Interaction, creating a smoother experience when analysts manually interact with an analysis machine.
Live Interaction is especially valuable when investigating samples or websites that require user input, navigation, clicks, or other manual actions before revealing their malicious behavior.
Joe Sandbox v45 provides improved responsiveness and performance during Live Interaction, creating a smoother experience when analysts manually interact with an analysis machine.
Live Interaction is especially valuable when investigating samples or websites that require user input, navigation, clicks, or other manual actions before revealing their malicious behavior.
Final Words
Joe Sandbox v45 significantly expands our detection and analysis capabilities.
With 50 new behavior signatures, 575 new custom YARA rules, 55 new configuration extractors, and 133 new Suricata rules, the release provides substantially broader coverage for malware, phishing, ransomware, stealers, RATs, and emerging threats.
Beyond the new detection content, Joe Sandbox v45 also includes important improvements to:
With 50 new behavior signatures, 575 new custom YARA rules, 55 new configuration extractors, and 133 new Suricata rules, the release provides substantially broader coverage for malware, phishing, ransomware, stealers, RATs, and emerging threats.
Beyond the new detection content, Joe Sandbox v45 also includes important improvements to:
- Improved prevention of various VM and analysis system detections
- Update to Suricata 8
- Large number of bug fixes
- macOS shutdown protection
Would you like to try Joe Sandbox? Register for a free account on Joe Sandbox Cloud Basic or contact us for an in-depth technical demo!