PE_unmapper is a small tool that can be used as a helper in malware analysis.
Various malware types unpack their core modules in memory, load them and run.
In order to unpack them fast, we can let the malware do all the operations and then just dump the result. However, the dumps are in virtual format – so, we may have problems running them independently and viewing by typical tools.
PE_unmapper allows to convert those dumps into their raw format. The tool is totally independent, so it is up to you by which way you prefer to make dumps. You only need to know the base where the module was loaded in order to relocate it properly.
The tool is open-source, available on my github:
See it in action on YouTube:
*TURN ON SUBTITLES FOR MORE INFO*