Analyzing java jar malware
Skill meltedinhex/analyst-ai-pack/skills/analyzing-java-jar-malware
An open agent-skills library for malware analysis, reverse engineering, and threat hunting - 118 curated, runnable skills mapped to MITRE ATT&CK, D3FEND, and CAR.
npx -y skills add meltedinhex/analyst-ai-pack --skill analyzing-java-jar-malwareAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 19 stars19 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Analyzes Java/JAR malware (such as Adwind/jRAT-class cross-platform RATs) by inventorying the archive, reading the manifest entry point, detecting obfuscators and string encryption, and flagging suspicious runtime, reflection, and networking class usage. Activates for requests to analyze a malicious JAR, inspect Java malware, or identify a Java RAT.
The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.9 KB, as published. Nobody here has run it
Analyzing Java/JAR Malware
When to Use
- You have a malicious or suspicious
.jar(often a cross-platform RAT) and need to map its structure, entry point, obfuscation, and capability surface before decompiling. - You want to triage a Java payload without running the JVM.
Do not use java -jar to run it — that executes the malware. Treat the JAR as a ZIP and read
its contents statically.
Prerequisites
- The JAR file, read inertly. Optional: a Java decompiler (CFR, Procyon) for the next stage.
Safety & Handling
- Read the archive statically; never launch the JVM on the sample. Defang any URLs found.
Workflow
Step 1: Inventory the archive and entry point
python scripts/analyst.py inspect sample.jar
Lists .class files, embedded resources/payloads (nested JARs, scripts, encrypted blobs), and
reads META-INF/MANIFEST.MF for Main-Class/Premain-Class.
Step 2: Detect obfuscation and packers
Flags obfuscator fingerprints (Allatori, ProGuard, Zelix), single-character class/package names, and string-decryption indicators.
Step 3: Flag capability classes
Surface dangerous API usage in strings/constant pools: Runtime.exec/ProcessBuilder,
java.lang.reflect, URLClassLoader, javax.crypto, java.net.Socket, registry/persistence
helpers.
Step 4: Route to decompilation
Hand the key classes to a decompiler (CFR/Procyon) for source recovery; record IOCs.
Validation
- The manifest entry point is read and reported.
- Embedded payloads/nested archives are enumerated.
- Capability flags are backed by concrete class/string evidence.
Pitfalls
- String-encrypted samples where capability strings appear only after decryption.
- Multi-stage droppers that unpack a second JAR at runtime.
- Benign obfuscated commercial JARs — corroborate with capability and delivery context.
References
- See
references/api-reference.mdfor the inspector. - JVM/JAR format and ATT&CK T1027 references (linked in frontmatter).