本文へ移動
cccskills
無料GitHub で公開

analyzing-dotnet-malware-internals

Reverses .NET/managed malware: decompiling MSIL back to C#, defeating common .NET protectors and string encryptors, and tracing reflection-based loaders to recover the real payload. Activates for requests to analyze a .NET sample, decompile MSIL, or unpack a managed loader.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.1 KB
  • LICENSE340 B
  • references/api-reference.md1.1 KB
  • scripts/analyst.py2.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Analyzing .NET Malware Internals

When to Use

  • A sample is a managed (.NET) assembly — confirmed by a CLR header / mscoree import or BSJB metadata signature.
  • You need readable C# from MSIL and want to defeat .NET-specific obfuscation.
  • A loader uses reflection (Assembly.Load) to run an in-memory payload you must recover.

Do not use native disassembly workflows (Ghidra for x86) as the primary tool — managed code decompiles far more cleanly with a .NET decompiler.

Prerequisites

  • ILSpy / dnSpyEx for decompilation and (with dnSpyEx) managed debugging.
  • de4dot or equivalent for known protectors; familiarity with common .NET obfuscators.

Workflow

Step 1: Confirm it is managed

Check for the CLR runtime header and the BSJB metadata magic:

python scripts/analyst.py identify sample.exe

Step 2: Decompile

Open in ILSpy/dnSpyEx and review the entry point, Main, and module initializer (<Module>.cctor), which protectors often abuse.

Step 3: Handle obfuscation

Recognize and undo common schemes:

  • String encryption — a decryptor method called everywhere; run/trace it to recover plaintext (de4dot can often static-decrypt).
  • Control-flow flattening — follow the dispatcher state machine.
  • Proxy methods / renaming — rely on decompiler analysis rather than names.

Step 4: Trace reflection loaders

Find Assembly.Load(byte[]) / Activator.CreateInstance; dump the byte array argument at runtime (managed debugger breakpoint) to recover the real second-stage assembly, then recurse.

Step 5: Analyze the payload

Decompile the recovered stage; extract C2, configuration, and capabilities for the report.

Validation

  • Decompiled C# is coherent (named or recovered) and the entry path is traced.
  • Encrypted strings are recovered to plaintext.
  • The reflection-loaded stage is dumped and itself decompiles.

Pitfalls

  • Treating the loader as the payload — managed malware is frequently multi-stage.
  • Ignoring the module initializer where protectors install hooks.
  • Static-decrypting strings when the scheme is runtime-keyed; debug and dump instead.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する