3 ms·
Do you have any way of capturing the actual JAR? Our Sophos security friend wants to analyze it, but we don't know how to get it.
by jonmwords 15y ago
Do you have any way of capturing the actual JAR? Our Sophos security friend wants to analyze it, but we don't know how to get it.
- citricsquid 15y agoedit: http://pastie.org/private/jun6syyaoe2uynjbrla4a http://pastie.org/private/jun6syyaoe2uynjbrla4a
- verroq 15y agoNot a professional reverse engineer. But the jar is not obfuscated and is fairly easy to understand. The jar loads a "model" which is a serialised version of a class containing keywords from a url constructed from the applet params "codebase" and "getmodelurl". It looks into 1. Chrome, firefox, and IE histories Matches history with sites in the "model" 2. Main filesystem It enumerates all the files in the file system, checking if it is either a picture, or a movie, then checks if the filename matches the list of keywords obtained from the "model". >".bmp"".gif"".jpeg"".jpg"".png"".tif"".tiff"".3g2"".3gp"".aaf"".asf"".asx"".avi"".flv"".mkv"".mov"".mp4"".mpeg"".mpg"".rm"".vob"".wmv" The only filetypes it'll match. I didn't see anything malicious.