logo

.NET Malware 101: Analyzing the .NET Executable File Structure

ID: 8ed5d4a4-4810-5c70-8cbc-360007547274

STIX ID: report--8ed5d4a4-4810-5c70-8cbc-360007547274

Feed Name: Intezer Blog

Threat Score
20/100

Date Published: 2024-03-13

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

This document is a hands‑on technical guide to reverse-engineering .NET malware: it explains .NET compilation and runtime (CLR/JIT), assembly and metadata structures, metadata tokens, method body formats (Tiny/Fat), and the use of tools like dnSpy, ILSpy, and PEStudio, illustrating concepts with real malware examples (e.g., a SolarWinds/Sunburst sample hash) to teach analysts how to inspect and interpret .NET executables.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.