May 20, 2024, 6:30 a.m. | MalwareAnalysisForHedgehogs

MalwareAnalysisForHedgehogs www.youtube.com

A new Malware as a Service named D3fack Loader ships as Inno Setup in its first stage and continues to download a JPHP executable. JPHP runs on the Java VM but it cannot be compiled by Java decompilers. How is it possible to reverse engineer this unusual language implementation?

Udemy course: https://www.udemy.com/course/windows-malware-analysis-for-hedgehogs-beginner-training/?couponCode=FDC34C32653EE09B9E57

Esentire article: https://www.esentire.com/blog/d3f-ck-loader-the-new-maas-loader
Inno Setup malware: https://bazaar.abuse.ch/sample/7409250e8be3bdcdaa756faff2150b13677ae066e42cefa52844c87451f6f60d
ZIP archive: https://bazaar.abuse.ch/sample/e7cf02ad880e8ebb37134c5370189bd2620ce1bf60794aa8776db6ccc4d4f0f7/

Recaf: https://www.coley.software/Recaf/
Innounp: https://innounp.sourceforge.net/
Inno Setup Decompiler: https://download.cnet.com/inno-setup-decompiler/3000-2383_4-77452731.html?ex=BER-1275.2

Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: https://twitter.com/struppigel …

analysis download engineer implementation java language loader malware malware analysis reverse reverse engineer service setup ships stage

Information Technology Specialist I: Windows Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, California

Information Technology Specialist I, LACERA: Information Security Engineer

@ Los Angeles County Employees Retirement Association (LACERA) | Pasadena, CA

Account Executive - Secureworks Direct Sales - US Remote Philadelphia

@ Dell Technologies | Remote - Pennsylvania, United States

SATCOM Technician - Shariki, Japan - Secret Clearance (Onsite)

@ RTX | RVA99: RTN Remote, Virginia

Senior Test Engineer

@ Commonwealth Bank | Bengaluru - Manyata Tech Park Road

Lead Developer - Pipeline & Algorithms

@ Arctic Wolf | Waterloo