
Search and extract blob files on the Ethereum Blockchain network
Search and extract blob files on the Ethereum network using Etherscan.io API.

EtherBlob Explorer is a tool intended for researchers, analysts, CTF players or anyone curious enough wanting to search for different kinds of files or any meaningful human-supplied data on the Ethereum Blockchain Network. It searches over a user-supplied range of block IDs or UNIX timestamps on any of the 5 available networks: MainNet, Görli, Kovan, Rinkeby and Ropsten.
For a real-life case you can read this experiment made on 2017. The immutability of the blockchain can truly be a double-edged sword.
Run the following command:
$ pip install git+https://github.com/litneet64/etherblob-explorer.git
Now it's ready to use from your CLI, you can find some common usage examples below!
Search on any of the five Ethereum Networks:
This tool can search on the following locations, either separately or combining any of these on the same run:
[*] Storing data on 'to' addresses is possible on the Ethereum network as there's no verification if sending to an address that has no associated account keys. Meaning you can make transactions to arbitrary addresses to craft a payload over several 20-byte sized transactions (it's very rare but so are some CTF challenges).
All of these methods can be used either separately or in any combination:
binwalk.file (default method).IMPORTANT: The order showed here is used under-the-hood for discarding searches with other methods (e.g. if file is found via embedded files then it won't attempt to search using file headers, ascii string dump nor entropy) as it's not likely to find anything meaningful if previous methods were already successful.
-h)!.api-key) and between these two block IDs (inclusive):$ etherblob 4081599 4081600
$ etherblob -K api.key 3134050 3145570 -M -H --network goerli
$ etherblob 4081599 4081600 --blocks --transactions -D extracted/
Jan 25 2021 19:00:00 and Jan 26 2021 19:00:00:$ etherblob -t 1611601200 1611687600 --addresses
$ etherblob 3911697 3912697 -S --contracts -C 4
$ etherblob 4081599 4081600 --encrypted
$ etherblob 3911697 3912697 -E 4.0 5.0 -s
$ etherblob -t 1608836400 1608922800 --blocks --transactions --strings
$ etherblob 4081599 4081600 -U -S -M -H --blocks --transactions --addresses --contracts
There are more explanations for advanced usage cases and the things found with them on the wiki!
usage: etherblob [-h] [--transactions] [--blocks] [--addresses] [--contracts]
[--network {main,goerli,kovan,rinkeby,ropsten}] [-H] [-M] [-U] [-E CUSTOM_ENTROPY CUSTOM_ENTROPY]
[--encrypted] [-S] [-C CONTRACT_POSITION] [-t] [-K API_KEY_PATH] [-k API_KEY] [-D OUTPUT_DIR]
[-o OUT_LOG] [-s] [-i [IGNORED_FMT [IGNORED_FMT ...]]] [--version]
start_block end_block
Tool to search and extract blob files on the Ethereum Network.
positional arguments:
start_block Start of block id range.
end_block End of block id range.