Reverse Engineering Dotnet Malware With Dnspy
Overview
Cybersecurity skill for reverse engineering dotnet malware with dnspy. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"reverse engineering dotnet malware with dnspy"
"reverseing engineering dotnet malware with dnspy"
"Reverse engineers "
A malware sample is identified as a .NET assembly (C#, VB.NET, F#) requiring decompilation
Analyzing .NET-based malware families (AgentTesla, AsyncRAT, RedLine Stealer, Quasar RAT)
Deobfuscating .NET code protected by ConfuserEx, SmartAssembly, or custom obfuscators
Extracting hardcoded C2 configurations, encryption keys, and credentials from managed assemblies
Debugging .NET malware at runtime to observe decryption routines and dynamic behavior
Do not use for native (unmanaged) PE binaries; use Ghidra or IDA for native code analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- dnSpy or dnSpyEx installed (https://github.com/dnSpyEx/dnSpy - community maintained fork)
- de4dot for automated .NET deobfuscation (
https://github.com/de4dot/de4dot)
- ILSpy as an alternative decompiler for cross-validation
- .NET SDK installed for recompiling modified assemblies during analysis
- Isolated Windows VM for running dnSpy debugger on live malware
- Detect It Easy (DIE) for identifying the .NET obfuscator used
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for engineering dotnet malware.
- Gather Resources — Collect tools, data, and access needed for engineering dotnet malware.
- Execute Process — Carry out engineering dotnet malware operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- dnspy — Primary tool for this skill
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: reverse-engineering-dotnet-malware-with-dnspy3description: Use when reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify obfuscation techniques, extract configurations, and understand malicious functionality including stealers, RATs, and loaders. Activates for requests involving .NET malware analysis, C# malware decompilation, managed code reverse engineering, or .NET obfuscation analysis. . Use when working with reverse engineering dotnet malware with dnspy.4license: Apache-2.05---67# Reverse Engineering Dotnet Malware With Dnspy89## Overview1011Cybersecurity skill for reverse engineering dotnet malware with dnspy. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "reverse engineering dotnet malware with dnspy"16- "reverseing engineering dotnet malware with dnspy"17- "Reverse engineers "181920- A malware sample is identified as a .NET assembly (C#, VB.NET, F#) requiring decompilation21- Analyzing .NET-based malware families (AgentTesla, AsyncRAT, RedLine Stealer, Quasar RAT)22- Deobfuscating .NET code protected by ConfuserEx, SmartAssembly, or custom obfuscators23- Extracting hardcoded C2 configurations, encryption keys, and credentials from managed assemblies24- Debugging .NET malware at runtime to observe decryption routines and dynamic behavior2526**Do not use** for native (unmanaged) PE binaries; use Ghidra or IDA for native code analysis.272829## When NOT to Use3031- When you lack proper authorization for testing32- For production systems without change management33- When the task requires legal or compliance expertise beyond technical scope343536## Prerequisites3738- dnSpy or dnSpyEx installed (https://github.com/dnSpyEx/dnSpy - community maintained fork)39- de4dot for automated .NET deobfuscation (`https://github.com/de4dot/de4dot`)40- ILSpy as an alternative decompiler for cross-validation41- .NET SDK installed for recompiling modified assemblies during analysis42- Isolated Windows VM for running dnSpy debugger on live malware43- Detect It Easy (DIE) for identifying the .NET obfuscator used4445## Workflow4647```python48# Example: IOC detection49import re5051IOC_PATTERNS = {52 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",53 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",54 "hash_md5": r"\b[a-f0-9]{32}\b",55 "hash_sha256": r"\b[a-f0-9]{64}\b",56}5758def extract_iocs(text: str) -> dict:59 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}60```61621. **Define Objectives** — Clarify the goals and scope for engineering dotnet malware.632. **Gather Resources** — Collect tools, data, and access needed for engineering dotnet malware.643. **Execute Process** — Carry out engineering dotnet malware operations methodically.654. **Verify Quality** — Check results against acceptance criteria.665. **Document Outcomes** — Record findings, decisions, and next steps.6768## Tools6970- **dnspy** — Primary tool for this skill71- **Analysis Platform** — Data processing and visualization72- **Collaboration Tools** — Team coordination and knowledge sharing737475## Process76771. **Reconnaissance** — Gather target information, identify attack surface, enumerate services781. **Analysis/Exploitation** — Execute the technique, analyze results, document findings791. **Reporting** — Document IOCs, write findings, provide remediation recommendations8081## Verification8283- [ ] All engineering dotnet malware procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |