What?
pydumpck is a multi-threads tool for decompile exe,elf,pyz,pyc packed by python which is base on pycdc and uncompyle6.sometimes its py-file result not exactly right ,maybe could use uncompyle6.
Install
pip install pydumpck
Usage
usage: pydumpck [-h] [-o OUTPUT_DIRECTORY] [-w THREAD] [-t TIMEOUT] [--session-timeout TIMEOUT_SESSION]
[-y TARGET_FILE_TYPE] [-d [DECOMPILE_FILE ...]] [--header [STRUCT_HEADERS ...]] [-v [SHOW_VERSION]]
[-p [PLUGIN ...]]
[target_file]
pydumpck is a multi-threads tool for decompile exe,elf,pyz,pyc packed by python which is base on pycdc and
uncompyle6.sometimes its py-file result not exactly right ,maybe could use uncompyle6.
positional arguments:
target_file file to extract or decompiler,combine with -y for type select.
options:
-h, --help show this help message and exit
-o OUTPUT_DIRECTORY, --output OUTPUT_DIRECTORY
output archive file to (default: output_2938294).
-w THREAD, --thread THREAD
thread count for running (default: 0) cpu-count * 8.
-t TIMEOUT, --timeout TIMEOUT
timeout running single decompiler (default: 10).
--session-timeout TIMEOUT_SESSION
timeout running total task (default: 10).
-y TARGET_FILE_TYPE, --type TARGET_FILE_TYPE
file-type of input file,can use pe,exe,elf,pyc,pyz (default: None : auto guess).
-d [DECOMPILE_FILE ...], --decompile_file [DECOMPILE_FILE ...]
only decompile referred file for quick complete (default: None).
--header [STRUCT_HEADERS ...]
specify pyc header hex-string (default: None).if not set , pydumpck will use struct.pyc's
header(if possible) and default header.eg:6f0d0d0a 00000000 00000000 ffffffff
-v [SHOW_VERSION], --version [SHOW_VERSION]
show version of package
-p [PLUGIN ...], --plugin [PLUGIN ...]
enable decompiler plugins,split by space .example: `--plugin pycdc uncompyle6` (default:
['pycdc']).available:pycdc,uncompyle6
Quick Start
pydumpck xxx.exe
pydumpck xxx.elf
pydumpck xxx.pyc
pydumpck xxx.pyz
pydumpck xxx.exe --output ./output --thread 8 --timeout 10
Example
-p/--pluginspecified which plugin to use for decompile (pycdc|uncompyle6)
pydumpck xxx.exe -p uncompyle6
pydumpck xxx.exe -p pycdc uncompyle6
-d/--decompile_filespecified which file(s) to decompile for a faster run
pydumpck xxx.exe -d main for only target main.py
pydumpck xxx.exe -d main lib_base64 secert for targets main.py and lib_base64.py and secert.py
Demo
- pyc with header been tampered with
- (Warning:gif with size 5MB)
- (Warning:gif with size 5MB)
Notice
pycdcspeed is more than 10 times faster thanuncompyle6, anduncompyle6is not support for python that version above 3.8.however
pycdcsometimes return a not precisely right result.in pydumpck , you can use
--plugin uncompyle6for single-use or--plugin pycdc uncompyle6for both-use.
Status
Release files for pydumpck 1.20.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pydumpck-1.20.1.tar.gz | 682.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pydumpck-1.20.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:1.4 MB
Release files / pydumpck-1.20.1.tar.gz
| Download URL | pydumpck-1.20.1.tar.gz |
|---|---|
| Size | 682.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b68b403000e487d9a676dac39e5e6d780383009a7658e90002b2292678f0e34f
|
|
BLAKE2b-256 checksum How to use checksums |
117265a4395d86ca61123392e4be2cf3fa81618de17a2fb9998144e878dbab5c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.0.0 CPython/3.12.3
|
Release files / pydumpck-1.20.1-py3-none-any.whl
| Download URL | pydumpck-1.20.1-py3-none-any.whl |
|---|---|
| Size | 686.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1dd493f348a2721a118c00c6739b0cf14746274b55a3bc78b495a02eaf343160
|
|
BLAKE2b-256 checksum How to use checksums |
13676f2aaf897be677ce75665a560df0cad4031566cc4ebfe2fe4cac2fcf5e29
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.0.0 CPython/3.12.3
|