WiryJMPer Dropper
WiryJMPer is a newly observed dropper trojan that uses a novel obfuscation method to disguise its operations on affected systems.
Summary
WiryJMPer is a newly observed dropper trojan that uses a novel obfuscation method to disguise its operations on affected systems.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, WiryJMPer is distributed as a binary file disguised as the legitimate application ABBC Coin Wallet (specifically version 3.9.1). It is presently unclear how this application is delivered, although there are unconfirmed reports indicating it is downloaded from third-party hosting sites. This file contains a sizeable amount of content from the WinBin2Iso (version 3.16) file converter, and uses multiple JMP loop-handling instructions to prevent static analysis and security tools from detecting it's presence.
When executed, WiryJMPer will create a bespoke virtual machine (VM) in memory to decrypt and combine several separate code sections contained within its binary to produce the intended payloads. Once these are installed, the VM is used to initiate a connection to a command and control server. WiryJMPer will also attempt to install legitimate versions of both ABBC Coin Wallet and WinBin2Iso.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:54 pm