Upgraded JasperLoader Malware Adds Anti-Analysis Mechanisms

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
New anti-analysis capabilities
Even though overall JasperLoader's structure has not changed very much since April, its maintainers have been hard at work adding quite a few new modules and features to improve its evasion skills and ability to stay in touch with its masters.

The latest version has added sandbox and virtual machine detection which allows it to stay one step ahead of malware analysts and anti-malware solutions which would try to dissect it by automatically terminating itself when it's executed in a virtual environment.

The previously observed JasperLoader variant used several obfuscation techniques to make analysis more difficult leveraging "character replacement mechanisms and perform mathematical calculations at runtime to reconstruct the PowerShell instructions that will be executed on infected systems."
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top