JNLP files can be super-dangerous. These benign looking XML files really can lead to disaster; they have the capability to load JAR files from remote locations and run them cross-platform (anywhere Java is installed). Here we see an example which leads to a malicious Windows Executable which has a VERY interesting technique to evade security controls.
I show you the tools, tactics and methods you need to analyse this malware quickly and effectively.
👇 ⭐ VIDEO SPONSOR ⭐ 👇
=======================
This video is sponsored by Malwarebytes Privacy; a super-quick, super-secure VPN which will protect your privacy and prevent unauthorised tracking. If you care about your privacy you should absolutely be using a VPN.
Malwarebytes Privacy is highly secure, super-fast and extremely cost effective. Also, check out the bundle you can get with Malwarebytes Device Security - where you can protect up to 5 of your devices from phishing, ransomware and malware.
Check out this link to learn more about how you can protect your Privacy online:
https://www.malwarebytes.com/for-home/
LINKS
=====
https://isc.sans.edu/forums/diary/Ano...
https://docs.microsoft.com/en-us/wind...
https://docs.microsoft.com/en-us/wind...
TOOLS
======
pestudio - https://www.winitor.com/
Process Monitor - https://docs.microsoft.com/en-us/sysi...
x64dbg - https://x64dbg.com/#start
unpacme - https://www.unpac.me/
SAMPLE
=======
delivery.jar - https://hybrid-analysis.com/sample/a4...
videodrv.exe https://hybrid-analysis.com/sample/ce...
unpacked.exe - https://www.unpac.me/results/b1185bb2...
FOLLOW
=======
You can join in the conversation by following me at / cybercdh
THANKS
=======
If you LIKED this video, please hit the THUMBS UP.
If you LOVED it, please SUBSCRIBE!
Many thanks for watching, it means a lot.
Peace out.
✌️
@cybercdh