themida-dumper logo

themida-dumper

Malware-Analysis Open Source

Generic Themida/WinLicense payload extractor. Launches protected PE as suspended process, detects section decryption, dumps unpacked binary with fixed headers, and scans process memory for IOCs. Supp

★ 34 Stars ⑂ 8 Forks License: MIT License