[ << ALL_FEED ]

.NET Reactor: evolution of protection from 6.7 to 7.0 and methods for removing obfuscation

More in Phishing & sandbox

.NET Reactor: The Evolution of Protection from 6.7 to 7.0 and Methods for Removing Obfuscation 🔄

.NET Reactor is a powerful tool for protecting executables written in C# from decompilation and reverse engineering. It provides various methods of obfuscation and licensing, ensuring the security of developers’ intellectual property.

But, as is usually the case, it is not only used for good purposes: experts at the PT ESC antivirus laboratory often encounter malicious files protected from analysis by .Net Reactor.

🔓 How is it protected?

.NET Reactor uses several layers of protection to prevent decompilation and code analysis:

• NecroBit IL Code Protection: replaces the CIL code of methods with encrypted code, making decompilation and recovery of the source code impossible.

• Code virtualization: transforms the source code into a set of instructions different from .NET IL, which are interpreted at runtime by a virtual machine, complicating analysis and recovery of the original code.

• Control Flow Obfuscation: transforms the code of methods into a tangled structure, complicating understanding of the program’s logic and hindering the work of decompilers (example — in screenshot 1).

• String Encryption: encrypts strings in the code, preventing their reading and analysis, which complicates understanding of the application’s functionality, as shown in screenshot 2.

• Anti-Debug mechanisms (Anti Debug): injects checks for the presence of debuggers, terminating the process when they are detected, which impedes dynamic analysis of the application.

🆕 What’s new?

• .NET 6.0 support: provides protection for the latest applications on this platform.

• Improvements in code virtualization and Control Flow Obfuscation provide a further increase in the reliability and complexity of obfuscation.

• Hiding the contents of merged .NET Core, 5.0, 6.0 applications prevents viewing the contents using tools such as ILSpy / dnSpy.

🧐 How to analyze?

Despite the complexity of the protection, there are tools that make life easier for reverse engineers.
NETReactorSlayer — a powerful tool for reversing applications obfuscated with .NET Reactor. Its main features:

• NecroBit decryption — restores CIL code from encrypted methods;

• removal of proxies and wrappers — cleans the code of garbage added by the obfuscator (see screenshot 3);

• decoding of strings and resources — returns readable strings encrypted in the application;

• bypassing anti-debug and code tamper protection.

However, starting with version 6.9, the original version of Net Reactor Slayer stopped coping with deobfuscating the protection even with basic parameters. Thanks to the open source code and a fairly large community, in pull requests you can find fixed code that works perfectly even on the very latest version of the obfuscator.

But things are not so smooth with virtualized code: Net Reactor Slayer cannot handle it. If you are lucky and the file was protected with version 6.9.0.0, then you can avoid wasting time on manual analysis of the virtual machine and use VMAttack — a tool for devirtualizing .NET applications, which supports this version of .NET Reactor. And if you are not lucky — the easiest way is to analyze the file by its behavior, for example using PT Sandbox.

☝️ Conclusion

.NET Reactor remains one of the most popular obfuscators for .NET. With each version, the protection becomes more complex, especially through virtualization. If you are going to analyze it — stock up on patience and good tools.

#avlab #sandboxteam #dotnet #obfuscation
@ptescalator

More from global_author

More from global_author

More in Phishing & sandbox