mal_unpack

PE unpacker

A tool to unpack malicious code from packed executables using the PE-sieve technique.

Dynamic unpacker based on PE-sieve

GitHub

668 stars
29 watching
69 forks
Language: C
last commit: over 2 years ago
Linked from 1 awesome list

libpeconvmalware-analysismalware-unpackermemory-forensicspe-sieve

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
hasherezade/libpeconvA C++ library that provides a set of helper functions for loading, manipulating, and dumping PE files.1,129
hasherezade/bearparserA C++ library for parsing Portable Executable files647
hasherezade/pe-bear-releasesAn open-source tool for analyzing and editing PE file formats772
malwaremusings/unpackerAutomated malware analysis tool118
packing-box/pypackerdetectDetects whether an executable is packed using various methods and signatures.21
yurisizuku/win-simpledpackA tool for packaging Windows executable files into a compressed format using LZMA compression and relocating shell code to an external DLL.110
strazzere/android-unpackerA tool designed to reverse-engineer and analyze Android malware by unpacking and disassembling APK files1,129
phra/pezorA tool for obfuscating and packing executable files to evade antivirus detection and security measures1,869
hasherezade/transacted_hollowingAn implementation of a memory-based PE injection technique for executing payloads in a target process521
samlarenn/pepackerA tool for encrypting and obfuscating .text sections of executable files.49
czs108/windows-pe-packerA tool that packs Windows executable files to make them harder to reverse-engineer330
crackinglandia/fuuA GUI tool with plugins to unpack and decrypt software protected by various compression and encryption algorithms.46
phat3/pindemoniumAn unpacker tool that uses the PIN technology to analyze and dissect Windows executables.229
egebalci/amberCreates reflective PE files that can be executed in memory without being written to disk1,208
kevoreilly/capev2A tool to extract configuration and payload from malware by analyzing its behavior in a sandboxed environment.2,043