typeanalysisfamilyxlabb-grabberconfidencehighcreated2026-07-25
SHA-256: 24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a

XLABB Grabber — PyInstaller-Packed Python Infostealer

Build / RE

Outer binary: PE32+ executable (GUI) x86-64, MSVC 14.41 linker (VS 2022), timestamp Mon Nov 11 12:30:00 2024 UTC ^[pefile.txt:42] ^[rabin2-info.txt:11]. Signed: no ^[rabin2-info.txt:27]. Dynamic-base, NX, Guard-CF, high-entropy VA enabled ^[pefile.txt:80]. No .NET COM descriptor ^[pefile.txt:249].

Packing: PyInstaller 2.1+ one-file build ^[strings.txt:394] ^[strings.txt:494]. CArchive overlay at raw offset 0x50000 ^[binwalk.txt:11]; overlay size ~25.9 MB. Pyinstxtractor extracted 217 embedded files including PYZ-00.pyz, runtime hooks, python311.dll, libssl-3.dll, libcrypto-3.dll, Crypto/ and Cryptodome/ directories.

Entry module: xlabbgrabber.pyc (Python 3.11). Unmarshalled at offset 16; all IOCs and logic exposed via plaintext co_consts ^[xlabbgrabber.pyc:marshal]. No Python-layer obfuscation — strings are naked constants.

Anti-analysis: None observed. No anti-VM, anti-debug, sandbox gates, or import hash manipulation. Outer PE imports only USER32, KERNEL32, ADVAPI32, GDI32, COMCTL32 — standard PyInstaller bootloader surface ^[pefile.txt:256].

Code quality: Script-kiddie grade. Hardcoded Discord emoji IDs, copy-paste webhook URL, naive exception passthrough (Error occurred in chrome_logger: ...).

Deploy / ATT&CK

Static-inferred only — CAPE skipped (no Windows guest) ^[dynamic-analysis.md:1].

Technique ID Evidence
Account Discovery T1087 Queries COMPUTERNAME, USERNAME, wmic csproduct get uuid ^[xlabbgrabber.pyc:marshal]
Browser Credential Dumping T1555.003 Targets Chrome, Edge, Firefox, Opera, OperaGX, Brave, Chromium, Yandex Login Data SQLite via browser_cookie3; embeds SELECT action_url, username_value, password_value FROM logins ^[xlabbgrabber.pyc:marshal]
Cryptocurrency Wallet Theft T1659 Targets Atomic Wallet, Exodus, Binance, Coinbase, MetaMask (multi-browser extension IDs) ^[xlabbgrabber.pyc:marshal]
Data from Local System T1005 Harvests Local Storage/leveldb, Cookies, browser extension data, Telegram tdata, Riot Games client data ^[xlabbgrabber.pyc:marshal]
Exfiltration Over Web Service T1567.002 Discord webhook POST with file attachments (BLXPasswords.txt, BLXCookies.txt) ^[xlabbgrabber.pyc:marshal]
System Information Discovery T1082 Collects CPU, RAM, OS, GPU (REG QUERY driver desc), MAC, IP, HWID ^[xlabbgrabber.pyc:marshal]
Token Impersonation / Theft T1528 Discord token theft from discord_desktop_core levels 0/1; Roblox .ROBLOSECURITY ^[xlabbgrabber.pyc:marshal]
Application Layer Protocol T1071.001 HTTPS to Discord API (api/v6/users/@me, /billing/payment-sources) for token validation and payment-source enumeration ^[xlabbgrabber.pyc:marshal]

C2 / Exfil: Single hardcoded Discord webhook URL ^[xlabbgrabber.pyc:marshal]. Data posted as Discord embed fields; full files uploaded via webhook attachment. Secondary file host: https://file.io ^[xlabbgrabber.pyc:marshal]. IP geolocation via https://ipinfo.io/ and https://api.ipify.org ^[xlabbgrabber.pyc:marshal].

Secondary payload: Fetches inject.js from https://raw.githubusercontent.com/blxsi/asdasdas/main/inject.js — likely a browser-injection script for session hijacking or wallet draining ^[xlabbgrabber.pyc:marshal].

Persistence: Not observed statically. No registry Run keys, scheduled tasks, or startup-folder references in recovered constants.

Attribution: Self-branded "XLABB Grabber" with Telegram promo t.me/blxstealer ^[xlabbgrabber.pyc:marshal]. GitHub username blxsi in secondary payload URL. Discord guild avatar (cdn.discordapp.com/attachments/...Picsart_24-06-04...) dates builder to at least June 2024.

IOCs

Type Value Note
SHA-256 24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a Outer PE
Filename transfer.whalebone.io_7BlhQsgOfX_Payload.exe Delivery name ^[metadata.json:4]
Discord Webhook [REDACTED] Hardcoded in co_consts
GitHub Raw URL https://raw.githubusercontent.com/blxsi/asdasdas/main/inject.js inject.js delivery
Browser targets Chrome, Edge, Firefox, Opera, OperaGX, Brave, Chromium, Yandex Credential + cookie theft
Crypto extension IDs nkbihfbeogaeaoehlefnkodbefgpgknn, ejbalbakoplchlghecdalmeeeajnimhm, fhbohimaelbohpjbbldcngcnapndodjp, egjidjbpglichdcondbcbdnbeeppgdph, bfnaelmomeimhlpmgjnjophhpkkoljpa, djclckkglechooblngghdinmeemkbgci MetaMask, Atomic, etc.
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0 Hardcoded
File exfil names BLXPasswords.txt, BLXCookies.txt Discord webhook attachments

Capability Chain

  • browser-credential-harvesting
  • discord-token-theft
  • cryptocurrency-wallet-extension-theft
  • discord-webhook-c2-exfil
  • system-information-enumeration
  • telegram-tdata-harvest
  • roblox-cookie-theft
  • browser-injection-script-fetch