Malware Analysis - Dumping COVID-19.jar with Java Instrumentation

Опубликовано: 27 Март 2026
на канале: MalwareAnalysisForHedgehogs
6,497
192

We dynamically unpack a Java malware that jumps on the COVID-19 bandwagon to trick users into running it.

The dumping method is useful for other packed JAR malware as well. It utilizes Java instrumentation, more specifically Java Agent.

Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

Referenced blog article: https://www.securityinbits.com/malwar...
Source code: https://github.com/Securityinbits/blo...
Sample download (password: "infected"): https://www.dropbox.com/s/d8tbhasrexi...
Java Agents Tutorial: https://stackify.com/what-are-java-ag...
Sample on VT: https://www.virustotal.com/gui/file/6...
Java Development Toolkit: https://www.oracle.com/java/technolog...

Bytecode Viewer: https://github.com/konloch/bytecode-v...
Process Explorer: https://docs.microsoft.com/en-us/sysi...