Extract Embedded RAR Archives from EXE Using Unrar

The unrar command-line utility can extract files from an archive embedded within an executable file. These files, commonly known as self-extracting (SFX) archives, package an executable stub together with compressed RAR data so users can extract them on systems without archiving software. Because unrar identifies archive headers by looking for internal signature markers rather than relying solely on file extensions or starting offsets, it treats compatible .exe files identically to standard .rar archives.

How Unrar Handles Embedded Archives

When a RAR archive is packaged into an executable, the resulting .exe file begins with standard executable headers (such as Windows PE headers) followed by the actual RAR payload. When unrar opens a target file, it parses the binary structure to locate the RAR marker block (Rar!). Once this signature is detected, unrar skips the executable wrapper and reads the archive catalog, allowing full extraction and inspection capabilities.

Extracting Files with the Command Line

To extract files from an embedded executable, pass the .exe file directly to unrar using standard arguments.

To view the archive contents without extracting:

unrar l installer.exe

To extract the files into the current working directory while preserving the original folder structure:

unrar x installer.exe

To extract all files directly into the destination folder without preserving their internal subdirectories:

unrar e installer.exe

You can also specify a destination directory by adding it to the end of the command:

unrar x installer.exe /path/to/destination/

Limitations and Caveats

While unrar natively handles genuine RAR SFX archives, extraction will fail under the following circumstances:

  • Non-RAR Installers: Many .exe setup files are generated using tools such as Inno Setup, NSIS (Nullsoft Scriptable Install System), or InstallShield. These do not use the RAR compression format and cannot be unpacked using unrar. Tools like 7z (7-Zip) or specialized unpackers are required for those formats.
  • Encrypted Headers: If the SFX archive uses encrypted file headers, you must supply the decryption password using the -p flag (e.g., unrar x -p<password> installer.exe) before unrar can list or extract the embedded contents.
  • Modified Executable Payloads: If an executable embeds a RAR archive as a non-standard resource or encrypts the RAR signature block, unrar will be unable to locate the start of the archive stream automatically. In such scenarios, extracting the raw payload using a binary editor or resource hacker prior to running unrar is necessary.