| name | reverse-engineering-dotnet-malware-with-dnspy |
| description | Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis. . Use when working with reverse engineering dotnet malware with dnspy. |
| domain | cybersecurity |
| tags | ["malware","dotnet","reverse-engineering","dnSpy","decompilation"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Reverse Engineering Dotnet Malware With Dnspy
Overview
Cybersecurity skill for reverse engineering dotnet malware with dnspy. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"reverse engineering dotnet malware with dnspy"
-
"reverseing engineering dotnet malware with dnspy"
-
"Reverse engineers "
-
A malware sample is identified as a .NET assembly (C#, VB.NET, F#) requiring decompilation
-
Analyzing .NET-based malware families (AgentTesla, AsyncRAT, RedLine Stealer, Quasar RAT)
-
Deobfuscating .NET code protected by ConfuserEx, SmartAssembly, or custom obfuscators
-
Extracting hardcoded C2 configurations, encryption keys, and credentials from managed assemblies
-
Debugging .NET malware at runtime to observe decryption routines and dynamic behavior
Do not use for native (unmanaged) PE binaries; use Ghidra or IDA for native code analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- dnSpy or dnSpyEx installed (https://github.com/dnSpyEx/dnSpy - community maintained fork)
- de4dot for automated .NET deobfuscation (
https://github.com/de4dot/de4dot)
- ILSpy as an alternative decompiler for cross-validation
- .NET SDK installed for recompiling modified assemblies during analysis
- Isolated Windows VM for running dnSpy debugger on live malware
- Detect It Easy (DIE) for identifying the .NET obfuscator used
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}