Obfuscated Malicious Python Scripts with PyArmor, (Wed, Apr 9th)
ID: b8f2e86f-9bb1-5db2-b4e9-eadb42371758
STIX ID: report--b8f2e86f-9bb1-5db2-b4e9-eadb42371758
Feed Name: SANS ISC Diary
Threat Score
This report examines PyArmor-obfuscated malicious Python scripts delivered by a PowerShell one-liner that downloads a bundled Python runtime (python3.zip) containing an obfuscated exec.py; the analyst uses Frida to hook PyMarshal_ReadObjectFromString and memory-dump the process to recover strings and confirm stealer behavior (browser/process targeting, credit card and wallet artifact searches), and provides associated IOAs/IOCs and analysis techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
