Skip to main content

dearmor

Deobfuscate pyarmor encryption.

It is best to use it with the pyc files extracted from the exe file, but exe file should work. Working only on windows.

It was not checked with custom pyarmor modes, only with the default configuration.

Method

Dearmor injects a dll into the running process, which calls a python function to run custom code. Using the custom code dearmor calls each function the exists in the file and deobfuscate it.

  • Run dearmor -i {file_path} The files will be created in a folder called "dump" in the same directory

To change the files from pyc to py, use docompyle++

installation

pip install dearmor

Contribute

Just ask away or make a pull request. If something is unclear open an issue

Desclaimer

This repo is for educational purposes only. I take no responsibility for its usage.

Tested versions:

  • 3.6
  • 3.7
  • 3.8
  • 3.9

Metadata

Release files for dearmor 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dearmor 0.3.1
File Size Uploaded
dearmor-0.3.1.tar.gz 16.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dearmor 0.3.1
File Interpreter ABI Platform
dearmor-0.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 32.1 kB

Release files / dearmor-0.3.1.tar.gz

Download URL dearmor-0.3.1.tar.gz
Size 16.9 kB
Tags Source
SHA-256 checksum
How to use checksums
cfdd4efbda3728168038b0c629125b2874fb1e3c828b836d7c75188747a3ab5c
BLAKE2b-256 checksum
How to use checksums
7de260e99356687e6605687a82c3e5c3e4598ead8379b91615b23201869c56f2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.9.13

Release files / dearmor-0.3.1-py3-none-any.whl

Download URL dearmor-0.3.1-py3-none-any.whl
Size 15.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7b2382427b63ad2cc33b5f982e4e7cd338c8844073878e148fd8567449d7ec2b
BLAKE2b-256 checksum
How to use checksums
528fc360ced3fff971df0f45e72b781fe4558478ceb09356c273d30b5c1d13ee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.9.13

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 release files

0.3

2 release files

0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page