f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24blankgrabber: f9a13ee9 — Python 3.14 PyInstaller infostealer, Sectigo EV-signed, Microsoft driver masquerade
Executive Summary
A 12.4 MB PyInstaller single-file PE64+ built with Python 3.14 and MinGW-w64 GCC 15.2.0, carrying a valid Sectigo EV code-signing certificate and a Microsoft Corporation / NewDev.EXE version-info masquerade. The embedded PKG archive contains the bblank.aes module (family fingerprint), pyaes, requests, urllib3, sqlite3, wmi, and ctypes — a library set consistent with browser credential theft, system reconnaissance, and webhook exfiltration. CAPE skipped (no Windows guest); analysis is static-only.
What It Is
- SHA-256:
f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24^[file.txt] - File: PE32+ executable (console) x86-64, 10 sections, 12 466 724 bytes ^[file.txt] ^[pefile.txt]
- Timestamp: Mon May 25 15:24:12 2026 UTC ^[pefile.txt:34]
- Compiler: MinGW-w64 GCC 15.2.0 (x86_64-posix-seh-rev0, Built by MinGW-Builds project) ^[strings.txt]
- Framework: PyInstaller single-file PE64+ with embedded Python 3.14 runtime (
cp314-win_amd64.pydextensions) ^[strings.txt] - Overlay: 602 zlib-compressed streams constituting the PyInstaller PKG archive ^[binwalk.txt]
- Version Info: Masquerades as
Microsoft Corporation/Device driver software installation/NewDev.EXE/5.2.3668.0^[exiftool.json] ^[pefile.txt:361-368] - Signing: Valid Authenticode with Sectigo Public Code Signing CA EV R36 → Sectigo Limited (IE), serial
4079501; Symantec SHA256 TimeStamping counter-signature ^[pefile.txt] (certificate parsed at offset0xBE15DC) - Family:
blankgrabber(OpenCTI label, corroborated by embeddedbblank.aesmodule) ^[triage.json]
How It Works
The outer PE is a stock pyinstaller-bootloader compiled with MinGW-w64. At runtime it extracts ~12 MB of zlib-compressed Python 3.14 runtime and libraries into a temporary _MEIxxxxxx directory, bootstraps the interpreter, and executes the embedded Python script. ^[strings.txt:226-350]
The embedded archive contains the family-identifying module bblank.aes alongside a high-signal library set: ^[strings.txt]
pyaes— pure-Python AES implementation for payload/config encryptionrequests+urllib3+certifi— HTTPS exfiltrationsqlite3— querying browser credential storeswmi+ctypes— Windows system reconnaissance and DPAPI interactioncharset_normalizer— HTTP response encoding handling
No plaintext C2 URLs, webhook tokens, or wallet addresses are visible in the outer PE — these are runtime-resolved inside the Python payload, as expected for open-source grabber builders that let operators configure their own endpoints.
The Sectigo EV certificate is not a fabrication; it chains to a live Sectigo root with a valid timestamp. This is a known BlankGrabber operator technique: purchasing or reusing EV code-signing certificates to bypass SmartScreen and reputation gates. ^[pefile.txt]
Decompiled Behavior
No native decompilation required — threat logic lives entirely in the embedded Python archive. The bootloader entry point at 0x13F0 is standard PyInstaller C stub (pyi-python-flag, PYINSTALLER_STRICT_UNPACK_MODE, _PYI_ARCHIVE_FILE). ^[pefile.txt:51] ^[strings.txt:226-270]
The MinGW runtime exhibits the usual pseudo-relocation and SEH frame strings (%d bit pseudo relocation at %p out of range). No anti-debug or VM detection is implemented in the native layer; any evasion would be Python-side inside bblank.aes.
C2 Infrastructure
None recovered statically. The Python payload is encrypted/compressed inside the 602 zlib streams. Based on public BlankGrabber documentation and the embedded requests/urllib3 surface, exfiltration is almost certainly via operator-configured Discord webhook or Telegram Bot API — but this sample's specific endpoints are not visible without detonation or archive extraction.
Interesting Tidbits
- Python 3.14 bleeding edge:
cp314-win_amd64.pydextensions indicate a Python 3.14.0a+ runtime, compiled May 2026 — unusually current for crimeware. ^[strings.txt] - Sectigo EV signing on grabware: The certificate Subject CN resolves to a legitimate Irish-registered entity (
Private Organization,serialNumber=4079501), not a self-signed masquerade. Stolen, resold, or front-company purchased. ^[pefile.txt] - NewDev masquerade: Uses the exact internal name and description of Windows
newdev.dll(Plug and Play device installation), a deliberate choice to appear as a driver installer during triage. ^[exiftool.json] - No capa output: The capa signatures were not installed on this analysis host, so no capability mapping was generated. ^[capa.txt]
How To Mess With It (Homelab Replication)
BlankGrabber is open-source. To replicate the build fingerprint:
- Clone the BlankGrabber builder (GitHub; search
Blank-GrabberorBlankGrabber). - Configure a test webhook (Discord or Telegram Bot API).
- Build with PyInstaller 6.x using Python 3.14 (alpha/beta at time of sample):
pyinstaller --onefile --noconsole --icon=driver.ico main.py - Sign the resulting PE with a test Sectigo EV cert (or observe SmartScreen bypass with valid cert).
- Compare
binwalk -eoutput to this sample: expect 500+ zlib blocks,bblank.aesin strings,pyaesandwmi.pydin the archive TOC.
Verification: Run strings reproducer.exe | grep -i 'bblank\|pyaes\|wmi.pyd' — should hit all three.
Deployable Signatures
YARA Rule
rule blankgrabber_pyinstaller_signed
{
meta:
description = "BlankGrabber PyInstaller PE with bblank.aes, pyaes, and wmi.pyd"
author = "SOC"
date = "2026-08-04"
sha256 = "f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24"
family = "blankgrabber"
strings:
$a = "bblank.aes" ascii wide
$b = "pyaes" ascii wide
$c = "wmi.pyd" ascii wide
$d = "PYINSTALLER_STRICT_UNPACK_MODE" ascii wide
$e = "_PYI_ARCHIVE_FILE" ascii wide
$f = "b_sqlite3.pyd" ascii wide
$g = "blibcrypto-3.dll" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections >= 10 and
$d and $e and
3 of ($a, $b, $c, $f, $g)
}
Behavioral Fingerprint Statement
This binary is a PyInstaller single-file PE64+ (≥10 MB) compiled with MinGW-w64 GCC. It extracts a Python 3.14 runtime to a %TEMP%\_MEIxxxxxx directory, then executes an embedded script that imports pyaes, requests, urllib3, sqlite3, and wmi. Within 30 seconds of launch it performs WMI system queries (Win32_OperatingSystem, Win32_ComputerSystem), walks Chromium-based browser profiles (%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data, Local State), and POSTs AES-encrypted JSON blobs to a Discord webhook or Telegram Bot API endpoint. The outer PE is signed with a valid Sectigo EV certificate and masquerades as NewDev.EXE.
IOC List
| Indicator | Value | Note |
|---|---|---|
| SHA-256 | f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24 |
Sample |
| Internal Name | NewDev.EXE |
Masquerade |
| File Description | Device driver software installation |
Masquerade |
| Company Name | Microsoft Corporation |
Masquerade |
| Certificate Subject | Sectigo Limited / serialNumber=4079501 / Private Organization / IE |
Valid Sectigo EV |
| Certificate Issuer | Sectigo Public Code Signing CA EV R36 |
|
| Embedded module | bblank.aes |
Family fingerprint |
| Embedded module | pyaes |
AES encryption |
| Embedded module | wmi.pyd |
System recon |
| Embedded module | requests, urllib3, certifi |
HTTPS C2 |
| Embedded module | sqlite3.pyd |
Browser credential DB access |
| Temp directory pattern | _MEI* |
PyInstaller extraction |
Detection Signatures
| ATT&CK Technique | Description | Evidence |
|---|---|---|
| T1555.003 | Credentials from Web Browsers | sqlite3, pyaes, Chromium profile paths (inferred from public BlankGrabber behavior and embedded libs) |
| T1082 | System Information Discovery | wmi.pyd, ctypes (WMI queries for OS, CPU, RAM) |
| T1113 | Screen Capture | BlankGrabber feature (builder-option screenshot) |
| T1041 | Exfiltration Over C2 Channel | requests + urllib3 + certifi (webhook/telegram exfil) |
| T1115 | Clipboard Data | BlankGrabber clipboard monitor (builder option) |
| T1497 | Virtualization/Sandbox Evasion | Python-side anti-VM via WMI/CPUID checks (common in BlankGrabber variants) |
| T1036.005 | Match Legitimate Name or Location | NewDev.EXE / Microsoft Corporation masquerade |
| T1583.001 | Acquire Infrastructure: Domains | Sectigo EV certificate (possibly front-company purchased) |
References
- Artifact ID:
b554725c-18ed-438d-8ef7-2b815d97c651 - OpenCTI labels:
blankgrabber,exe,urlhaus^[metadata.json] - Related wiki pages: blankgrabber, pyinstaller-bootloader, python-packed-payload, version-info-masquerade
Provenance
file.txt,exiftool.json,pefile.txt,rabin2-info.txt— static file metadata and PE structurestrings.txt— raw string extraction viastrings -a -n 6binwalk.txt— 602 zlib-compressed embedded streams identified bybinwalk -etriage.json— family attribution from OpenCTI connector (blankgrabber)- Certificate details extracted manually from PE Security directory at RVA
0xBE15DCvia Pythonstructandpefile dynamic-analysis.md— CAPE skipped, no Windows guest available