radare2 - UNIX-like reverse engineering framework and command-line toolset.

NET based malware does have a lot of similarity to Thanos which had its builder leaked. de4dot is a wonderful tool for deobfuscating known and unknown.



Confuser.

It is also Open Source.

de4dot is an open source (GPLv3).

blocks. It is open source, actively developed, and it claims to support the following obfuscators: Babel.

Dealing with known and supported protections is easy - drag&drop executable on de4dot and it will create deobfuscated assembly.

de4dot is an open source (GPLv3).

Updated on: 2022-Aug-05.

Restore the types of method parameters and fields.

Requires de4dot to be present on your system.

string encryption), but symbol renaming is impossible to restore since the original names aren't (usually) part.