skilly. Buy ad slot
All skills
Community / AGENT SKILL

analyzing-java-jar-malware

meltedinhex/analyst-ai-pack
0 installs 22 GitHub stars
0

Analyzes Java/JAR malware (such as Adwind/jRAT-class cross-platform RATs) by inventorying the archive, reading the manifest entry point, detecting obfuscators and string encryption, and flagging suspicious runtime, reflection, and networking class usage. Activates for requests to analyze a malicious JAR, inspect Java malware, or identify a Java RAT.

BEFORE YOU INSTALL

Understand the trade-offs.

SECURITY REVIEW

Not yet assessed

Review the original instructions and requested permissions before installing.

No security review is available for this catalog entry yet.

SKILL QUALITY

Not yet assessed

How clearly the skill guides your agent, how complete its workflow is, and how you can check the outcome.

No quality assessment is available for this catalog entry yet.

The full skill.

Original instructions from the publisher’s SKILL.md

# Analyzing Java/JAR Malware

## When to Use

- You have a malicious or suspicious `.jar` (often a cross-platform RAT) and need to map its
  structure, entry point, obfuscation, and capability surface before decompiling.
- You want to triage a Java payload without running the JVM.

**Do not use** `java -jar` to run it — that executes the malware. Treat the JAR as a ZIP and read
its contents statically.

## Prerequisites

- The JAR file, read inertly. Optional: a Java decompiler (CFR, Procyon) for the next stage.

## Safety & Handling

- Read the archive statically; never launch the JVM on the sample. Defang any URLs found.

## Workflow

### Step 1: Inventory the archive and entry point

```bash
python scripts/analyst.py inspect sample.jar
```

Lists `.class` files, embedded resources/payloads (nested JARs, scripts, encrypted blobs), and
reads `META-INF/MANIFEST.MF` for `Main-Class`/`Premain-Class`.

### Step 2: Detect obfuscation and packers

Flags obfuscator fingerprints (Allatori, ProGuard, Zelix), single-character class/package names,
and string-decryption indicators.

### Step 3: Flag capability classes

Surface dangerous API usage in strings/constant pools: `Runtime.exec`/`ProcessBuilder`,
`java.lang.reflect`, `URLClassLoader`, `javax.crypto`, `java.net.Socket`, registry/persistence
helpers.

### Step 4: Route to decompilation

Hand the key classes to a decompiler (CFR/Procyon) for source recovery; record IOCs.

## Validation

- The manifest entry point is read and reported.
- Embedded payloads/nested archives are enumerated.
- Capability flags are backed by concrete class/string evidence.

## Pitfalls

- String-encrypted samples where capability strings appear only after decryption.
- Multi-stage droppers that unpack a second JAR at runtime.
- Benign obfuscated commercial JARs — corroborate with capability and delivery context.

## References

- See [`references/api-reference.md`](references/api-reference.md) for the inspector.
- JVM/JAR format and ATT&CK T1027 references (linked in frontmatter).