PDFly Variant Uses Custom PyInstaller Tweaks to Obfuscate Payload, Thwarting Analysis
ID: a4d81908-7eb9-560f-94d3-3f7554ee7f5e
STIX ID: report--a4d81908-7eb9-560f-94d3-3f7554ee7f5e
Feed Name: GBHackers
A researcher dissected two related PyInstaller-packaged droppers—PDFly and PDFClick—that deliberately alter the PyInstaller stub (changing the overlay "cookie") and apply a custom two-stage XOR + zlib encryption to hide embedded Python bytecode. Standard extractors failed, so the analyst patched pyinstxtractor-ng, removed nonessential assertions, incorporated the custom decryption sequence, and developed a generic scanner to recover custom cookies and XOR keys, enabling payload recovery and deeper behavioral analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
