pe_unmapper
Small tool to convert a PE from a virtual format into a raw format
(useful in recovering executables dumped from the memory).
Usage:
pe_unmapper.exe [input_file] [load base: in hex] [*output_file]
* - optional
Example:
pe_unmapper.exe _02660000.mem 02660000 payload.dll
source twitter @hasherezade
github https://github.com/hasherezade/malware_analysis/tree/master/pe_unmapper
Small tool to convert a PE from a virtual format into a raw format
(useful in recovering executables dumped from the memory).
Usage:
pe_unmapper.exe [input_file] [load base: in hex] [*output_file]
* - optional
Example:
pe_unmapper.exe _02660000.mem 02660000 payload.dll
source twitter @hasherezade
github https://github.com/hasherezade/malware_analysis/tree/master/pe_unmapper