24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9aXLABB Grabber — PyInstaller-Packed Python Infostealer
Build / RE
Outer binary: PE32+ executable (GUI) x86-64, MSVC 14.41 linker (VS 2022), timestamp Mon Nov 11 12:30:00 2024 UTC ^[pefile.txt:42] ^[rabin2-info.txt:11]. Signed: no ^[rabin2-info.txt:27]. Dynamic-base, NX, Guard-CF, high-entropy VA enabled ^[pefile.txt:80]. No .NET COM descriptor ^[pefile.txt:249].
Packing: PyInstaller 2.1+ one-file build ^[strings.txt:394] ^[strings.txt:494]. CArchive overlay at raw offset 0x50000 ^[binwalk.txt:11]; overlay size ~25.9 MB. Pyinstxtractor extracted 217 embedded files including PYZ-00.pyz, runtime hooks, python311.dll, libssl-3.dll, libcrypto-3.dll, Crypto/ and Cryptodome/ directories.
Entry module: xlabbgrabber.pyc (Python 3.11). Unmarshalled at offset 16; all IOCs and logic exposed via plaintext co_consts ^[xlabbgrabber.pyc:marshal]. No Python-layer obfuscation — strings are naked constants.
Anti-analysis: None observed. No anti-VM, anti-debug, sandbox gates, or import hash manipulation. Outer PE imports only USER32, KERNEL32, ADVAPI32, GDI32, COMCTL32 — standard PyInstaller bootloader surface ^[pefile.txt:256].
Code quality: Script-kiddie grade. Hardcoded Discord emoji IDs, copy-paste webhook URL, naive exception passthrough (Error occurred in chrome_logger: ...).
Deploy / ATT&CK
Static-inferred only — CAPE skipped (no Windows guest) ^[dynamic-analysis.md:1].
| Technique | ID | Evidence |
|---|---|---|
| Account Discovery | T1087 | Queries COMPUTERNAME, USERNAME, wmic csproduct get uuid ^[xlabbgrabber.pyc:marshal] |
| Browser Credential Dumping | T1555.003 | Targets Chrome, Edge, Firefox, Opera, OperaGX, Brave, Chromium, Yandex Login Data SQLite via browser_cookie3; embeds SELECT action_url, username_value, password_value FROM logins ^[xlabbgrabber.pyc:marshal] |
| Cryptocurrency Wallet Theft | T1659 | Targets Atomic Wallet, Exodus, Binance, Coinbase, MetaMask (multi-browser extension IDs) ^[xlabbgrabber.pyc:marshal] |
| Data from Local System | T1005 | Harvests Local Storage/leveldb, Cookies, browser extension data, Telegram tdata, Riot Games client data ^[xlabbgrabber.pyc:marshal] |
| Exfiltration Over Web Service | T1567.002 | Discord webhook POST with file attachments (BLXPasswords.txt, BLXCookies.txt) ^[xlabbgrabber.pyc:marshal] |
| System Information Discovery | T1082 | Collects CPU, RAM, OS, GPU (REG QUERY driver desc), MAC, IP, HWID ^[xlabbgrabber.pyc:marshal] |
| Token Impersonation / Theft | T1528 | Discord token theft from discord_desktop_core levels 0/1; Roblox .ROBLOSECURITY ^[xlabbgrabber.pyc:marshal] |
| Application Layer Protocol | T1071.001 | HTTPS to Discord API (api/v6/users/@me, /billing/payment-sources) for token validation and payment-source enumeration ^[xlabbgrabber.pyc:marshal] |
C2 / Exfil: Single hardcoded Discord webhook URL ^[xlabbgrabber.pyc:marshal]. Data posted as Discord embed fields; full files uploaded via webhook attachment. Secondary file host: https://file.io ^[xlabbgrabber.pyc:marshal]. IP geolocation via https://ipinfo.io/ and https://api.ipify.org ^[xlabbgrabber.pyc:marshal].
Secondary payload: Fetches inject.js from https://raw.githubusercontent.com/blxsi/asdasdas/main/inject.js — likely a browser-injection script for session hijacking or wallet draining ^[xlabbgrabber.pyc:marshal].
Persistence: Not observed statically. No registry Run keys, scheduled tasks, or startup-folder references in recovered constants.
Attribution: Self-branded "XLABB Grabber" with Telegram promo t.me/blxstealer ^[xlabbgrabber.pyc:marshal]. GitHub username blxsi in secondary payload URL. Discord guild avatar (cdn.discordapp.com/attachments/...Picsart_24-06-04...) dates builder to at least June 2024.
IOCs
| Type | Value | Note |
|---|---|---|
| SHA-256 | 24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a |
Outer PE |
| Filename | transfer.whalebone.io_7BlhQsgOfX_Payload.exe |
Delivery name ^[metadata.json:4] |
| Discord Webhook | [REDACTED] |
Hardcoded in co_consts |
| GitHub Raw URL | https://raw.githubusercontent.com/blxsi/asdasdas/main/inject.js |
inject.js delivery |
| Browser targets | Chrome, Edge, Firefox, Opera, OperaGX, Brave, Chromium, Yandex | Credential + cookie theft |
| Crypto extension IDs | nkbihfbeogaeaoehlefnkodbefgpgknn, ejbalbakoplchlghecdalmeeeajnimhm, fhbohimaelbohpjbbldcngcnapndodjp, egjidjbpglichdcondbcbdnbeeppgdph, bfnaelmomeimhlpmgjnjophhpkkoljpa, djclckkglechooblngghdinmeemkbgci |
MetaMask, Atomic, etc. |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0 |
Hardcoded |
| File exfil names | BLXPasswords.txt, BLXCookies.txt |
Discord webhook attachments |
Capability Chain
browser-credential-harvestingdiscord-token-theftcryptocurrency-wallet-extension-theftdiscord-webhook-c2-exfilsystem-information-enumerationtelegram-tdata-harvestroblox-cookie-theftbrowser-injection-script-fetch