evbunpack mos9527
Use this command to install evbunpack:
winget install --id=mos9527.evbunpack -e Enigma Virtual Box unpacker.
winget install --id=mos9527.evbunpack -e Enigma Virtual Box unpacker.
Enigma Virtual Box unpacker
-pe [variant]| Packer Version | Notes | Unpack with Flags |
|---|---|---|
| 11.00 | Automatically tested in CI for x86/x64 binaries. | -pe 10_70 |
| 10.70 | Automatically tested in CI for x86/x64 binaries. | -pe 10_70 |
| 9.70 | Automatically tested in CI for x86/x64 binaries. | -pe 9_70 |
| 7.80 | Automatically tested in CI for x86/x64 binaries | -pe 7_80 --legacy-fs |
For Windows Users : Builds are available here
Or get the latest version from PyPi:
pip install evbunpack
usage: evbunpack [-h] [--log-level {DEBUG,INFO,WARNING,ERROR,CRITICAL}] [-l] [--ignore-fs] [--ignore-pe] [--legacy-fs] [-pe {10_70,9_70,7_80}] [--out-pe OUT_PE] file output
Enigma Virtual Box Unpacker
options:
-h, --help show this help message and exit
--log-level {DEBUG,INFO,WARNING,ERROR,CRITICAL}
Set log level
Flags:
-l, --list Don't extract the files and print the table of content to stderr only
--ignore-fs Don't extract virtual filesystem
--ignore-pe Don't restore the executable
--legacy-fs Use legacy mode for filesystem extraction
-pe {10_70,9_70,7_80}, --pe-variant {10_70,9_70,7_80}
Unpacker variant to use when unpacking EXEs. default=9_70
Overrides:
--out-pe OUT_PE (If the executable is to be recovered) Where the unpacked EXE is saved. Leave as-is to save it in the output folder.
Input:
file File to be unpacked
output Output folder
Input:
evbunpack x64_PackerTestApp_packed_20240522.exe output
Output:
INFO: Enigma Virtual Box Unpacker v0.2.1
INFO: Extracting virtual filesystem
Filesystem:
└─── output
└─── output/README.txt
Writing File [size=0x11, offset=0x3465]: total= 11h read= 0h
INFO: Extraction complete
INFO: Restoring executable
INFO: Using default executable save path: output\x64_PackerTestApp_packed_20240522.exe
Saving PE: total= 3211h read= 0h
INFO: Unpacked PE saved: output\x64_PackerTestApp_packed_20240522.exe
Apache 2.0 License