Fast malware analysis

10 August 2016

.NET Decompiler

  1. Identifying PE

    asdf

  2. deasemble

    if .net: http://ilspy.net/ or https://github.com/0xd4d/dnSpy
    if is packed by ConfuserEx us https://www.youtube.com/watch?v=WTpUBnXfJ2c use deobfuscator

  3.  

  4. asdf