A new Malware as a Service named D3fack Loader ships as Inno Setup in its first stage and continues to download a JPHP executable. JPHP runs on the Java VM but it cannot be compiled by Java decompilers. How is it possible to reverse engineer this unusual language implementation?
Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Esentire article: https://www.esentire.com/blog/d3f-ck-...
Inno Setup malware: https://bazaar.abuse.ch/sample/740925...
ZIP archive: https://bazaar.abuse.ch/sample/e7cf02...
Recaf: https://www.coley.software/Recaf/
Innounp: https://innounp.sourceforge.net/
Inno Setup Decompiler: https://download.cnet.com/inno-setup-...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
#malware #malwareanalysis #reverseengineering #jphp #innosetup
00:00 Intro
00:50 Triage
02:08 Inno Setup unpacking and decompilation
07:58 Decoding obfuscated strings
12:39 Inno Setup script analysis
19:47 Triage of downloaded archive
22:54 Analysing JPHP
30:25 Project idea?