agentsclimarketplace

Analyzing java jar malware

Skill meltedinhex/analyst-ai-pack/skills/analyzing-java-jar-malware

An open agent-skills library for malware analysis, reverse engineering, and threat hunting - 118 curated, runnable skills mapped to MITRE ATT&CK, D3FEND, and CAR.

Install
npx -y skills add meltedinhex/analyst-ai-pack --skill analyzing-java-jar-malware

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 19 stars19 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Analyzes Java/JAR malware (such as Adwind/jRAT-class cross-platform RATs) by inventorying the archive, reading the manifest entry point, detecting obfuscators and string encryption, and flagging suspicious runtime, reflection, and networking class usage. Activates for requests to analyze a malicious JAR, inspect Java malware, or identify a Java RAT.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

2.9 KB, as published. Nobody here has run it

Analyzing Java/JAR Malware

When to Use

  • You have a malicious or suspicious .jar (often a cross-platform RAT) and need to map its structure, entry point, obfuscation, and capability surface before decompiling.
  • You want to triage a Java payload without running the JVM.

Do not use java -jar to run it — that executes the malware. Treat the JAR as a ZIP and read its contents statically.

Prerequisites

  • The JAR file, read inertly. Optional: a Java decompiler (CFR, Procyon) for the next stage.

Safety & Handling

  • Read the archive statically; never launch the JVM on the sample. Defang any URLs found.

Workflow

Step 1: Inventory the archive and entry point

python scripts/analyst.py inspect sample.jar

Lists .class files, embedded resources/payloads (nested JARs, scripts, encrypted blobs), and reads META-INF/MANIFEST.MF for Main-Class/Premain-Class.

Step 2: Detect obfuscation and packers

Flags obfuscator fingerprints (Allatori, ProGuard, Zelix), single-character class/package names, and string-decryption indicators.

Step 3: Flag capability classes

Surface dangerous API usage in strings/constant pools: Runtime.exec/ProcessBuilder, java.lang.reflect, URLClassLoader, javax.crypto, java.net.Socket, registry/persistence helpers.

Step 4: Route to decompilation

Hand the key classes to a decompiler (CFR/Procyon) for source recovery; record IOCs.

Validation

  • The manifest entry point is read and reported.
  • Embedded payloads/nested archives are enumerated.
  • Capability flags are backed by concrete class/string evidence.

Pitfalls

  • String-encrypted samples where capability strings appear only after decryption.
  • Multi-stage droppers that unpack a second JAR at runtime.
  • Benign obfuscated commercial JARs — corroborate with capability and delivery context.

References

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.