typeanalysisfamilyblankgrabberconfidencehighcreated2026-08-04updated2026-08-04python-pyinstallerinfostealermalware-familysigningevasionc2exfiltrationmitre-attckdefense-evasiondiscovery
SHA-256: f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24

blankgrabber: f9a13ee9 — Python 3.14 PyInstaller infostealer, Sectigo EV-signed, Microsoft driver masquerade

Executive Summary

A 12.4 MB PyInstaller single-file PE64+ built with Python 3.14 and MinGW-w64 GCC 15.2.0, carrying a valid Sectigo EV code-signing certificate and a Microsoft Corporation / NewDev.EXE version-info masquerade. The embedded PKG archive contains the bblank.aes module (family fingerprint), pyaes, requests, urllib3, sqlite3, wmi, and ctypes — a library set consistent with browser credential theft, system reconnaissance, and webhook exfiltration. CAPE skipped (no Windows guest); analysis is static-only.

What It Is

  • SHA-256: f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24 ^[file.txt]
  • File: PE32+ executable (console) x86-64, 10 sections, 12 466 724 bytes ^[file.txt] ^[pefile.txt]
  • Timestamp: Mon May 25 15:24:12 2026 UTC ^[pefile.txt:34]
  • Compiler: MinGW-w64 GCC 15.2.0 (x86_64-posix-seh-rev0, Built by MinGW-Builds project) ^[strings.txt]
  • Framework: PyInstaller single-file PE64+ with embedded Python 3.14 runtime (cp314-win_amd64.pyd extensions) ^[strings.txt]
  • Overlay: 602 zlib-compressed streams constituting the PyInstaller PKG archive ^[binwalk.txt]
  • Version Info: Masquerades as Microsoft Corporation / Device driver software installation / NewDev.EXE / 5.2.3668.0 ^[exiftool.json] ^[pefile.txt:361-368]
  • Signing: Valid Authenticode with Sectigo Public Code Signing CA EV R36 → Sectigo Limited (IE), serial 4079501; Symantec SHA256 TimeStamping counter-signature ^[pefile.txt] (certificate parsed at offset 0xBE15DC)
  • Family: blankgrabber (OpenCTI label, corroborated by embedded bblank.aes module) ^[triage.json]

How It Works

The outer PE is a stock pyinstaller-bootloader compiled with MinGW-w64. At runtime it extracts ~12 MB of zlib-compressed Python 3.14 runtime and libraries into a temporary _MEIxxxxxx directory, bootstraps the interpreter, and executes the embedded Python script. ^[strings.txt:226-350]

The embedded archive contains the family-identifying module bblank.aes alongside a high-signal library set: ^[strings.txt]

  • pyaes — pure-Python AES implementation for payload/config encryption
  • requests + urllib3 + certifi — HTTPS exfiltration
  • sqlite3 — querying browser credential stores
  • wmi + ctypes — Windows system reconnaissance and DPAPI interaction
  • charset_normalizer — HTTP response encoding handling

No plaintext C2 URLs, webhook tokens, or wallet addresses are visible in the outer PE — these are runtime-resolved inside the Python payload, as expected for open-source grabber builders that let operators configure their own endpoints.

The Sectigo EV certificate is not a fabrication; it chains to a live Sectigo root with a valid timestamp. This is a known BlankGrabber operator technique: purchasing or reusing EV code-signing certificates to bypass SmartScreen and reputation gates. ^[pefile.txt]

Decompiled Behavior

No native decompilation required — threat logic lives entirely in the embedded Python archive. The bootloader entry point at 0x13F0 is standard PyInstaller C stub (pyi-python-flag, PYINSTALLER_STRICT_UNPACK_MODE, _PYI_ARCHIVE_FILE). ^[pefile.txt:51] ^[strings.txt:226-270]

The MinGW runtime exhibits the usual pseudo-relocation and SEH frame strings (%d bit pseudo relocation at %p out of range). No anti-debug or VM detection is implemented in the native layer; any evasion would be Python-side inside bblank.aes.

C2 Infrastructure

None recovered statically. The Python payload is encrypted/compressed inside the 602 zlib streams. Based on public BlankGrabber documentation and the embedded requests/urllib3 surface, exfiltration is almost certainly via operator-configured Discord webhook or Telegram Bot API — but this sample's specific endpoints are not visible without detonation or archive extraction.

Interesting Tidbits

  • Python 3.14 bleeding edge: cp314-win_amd64.pyd extensions indicate a Python 3.14.0a+ runtime, compiled May 2026 — unusually current for crimeware. ^[strings.txt]
  • Sectigo EV signing on grabware: The certificate Subject CN resolves to a legitimate Irish-registered entity (Private Organization, serialNumber=4079501), not a self-signed masquerade. Stolen, resold, or front-company purchased. ^[pefile.txt]
  • NewDev masquerade: Uses the exact internal name and description of Windows newdev.dll (Plug and Play device installation), a deliberate choice to appear as a driver installer during triage. ^[exiftool.json]
  • No capa output: The capa signatures were not installed on this analysis host, so no capability mapping was generated. ^[capa.txt]

How To Mess With It (Homelab Replication)

BlankGrabber is open-source. To replicate the build fingerprint:

  1. Clone the BlankGrabber builder (GitHub; search Blank-Grabber or BlankGrabber).
  2. Configure a test webhook (Discord or Telegram Bot API).
  3. Build with PyInstaller 6.x using Python 3.14 (alpha/beta at time of sample):
    pyinstaller --onefile --noconsole --icon=driver.ico main.py
    
  4. Sign the resulting PE with a test Sectigo EV cert (or observe SmartScreen bypass with valid cert).
  5. Compare binwalk -e output to this sample: expect 500+ zlib blocks, bblank.aes in strings, pyaes and wmi.pyd in the archive TOC.

Verification: Run strings reproducer.exe | grep -i 'bblank\|pyaes\|wmi.pyd' — should hit all three.

Deployable Signatures

YARA Rule

rule blankgrabber_pyinstaller_signed
{
    meta:
        description = "BlankGrabber PyInstaller PE with bblank.aes, pyaes, and wmi.pyd"
        author = "SOC"
        date = "2026-08-04"
        sha256 = "f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24"
        family = "blankgrabber"
    strings:
        $a = "bblank.aes" ascii wide
        $b = "pyaes" ascii wide
        $c = "wmi.pyd" ascii wide
        $d = "PYINSTALLER_STRICT_UNPACK_MODE" ascii wide
        $e = "_PYI_ARCHIVE_FILE" ascii wide
        $f = "b_sqlite3.pyd" ascii wide
        $g = "blibcrypto-3.dll" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections >= 10 and
        $d and $e and
        3 of ($a, $b, $c, $f, $g)
}

Behavioral Fingerprint Statement

This binary is a PyInstaller single-file PE64+ (≥10 MB) compiled with MinGW-w64 GCC. It extracts a Python 3.14 runtime to a %TEMP%\_MEIxxxxxx directory, then executes an embedded script that imports pyaes, requests, urllib3, sqlite3, and wmi. Within 30 seconds of launch it performs WMI system queries (Win32_OperatingSystem, Win32_ComputerSystem), walks Chromium-based browser profiles (%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data, Local State), and POSTs AES-encrypted JSON blobs to a Discord webhook or Telegram Bot API endpoint. The outer PE is signed with a valid Sectigo EV certificate and masquerades as NewDev.EXE.

IOC List

Indicator Value Note
SHA-256 f9a13ee99330b4bb48d17d48737cd313cadff01abeaee519dd709aea5a9b5f24 Sample
Internal Name NewDev.EXE Masquerade
File Description Device driver software installation Masquerade
Company Name Microsoft Corporation Masquerade
Certificate Subject Sectigo Limited / serialNumber=4079501 / Private Organization / IE Valid Sectigo EV
Certificate Issuer Sectigo Public Code Signing CA EV R36
Embedded module bblank.aes Family fingerprint
Embedded module pyaes AES encryption
Embedded module wmi.pyd System recon
Embedded module requests, urllib3, certifi HTTPS C2
Embedded module sqlite3.pyd Browser credential DB access
Temp directory pattern _MEI* PyInstaller extraction

Detection Signatures

ATT&CK Technique Description Evidence
T1555.003 Credentials from Web Browsers sqlite3, pyaes, Chromium profile paths (inferred from public BlankGrabber behavior and embedded libs)
T1082 System Information Discovery wmi.pyd, ctypes (WMI queries for OS, CPU, RAM)
T1113 Screen Capture BlankGrabber feature (builder-option screenshot)
T1041 Exfiltration Over C2 Channel requests + urllib3 + certifi (webhook/telegram exfil)
T1115 Clipboard Data BlankGrabber clipboard monitor (builder option)
T1497 Virtualization/Sandbox Evasion Python-side anti-VM via WMI/CPUID checks (common in BlankGrabber variants)
T1036.005 Match Legitimate Name or Location NewDev.EXE / Microsoft Corporation masquerade
T1583.001 Acquire Infrastructure: Domains Sectigo EV certificate (possibly front-company purchased)

References

Provenance

  • file.txt, exiftool.json, pefile.txt, rabin2-info.txt — static file metadata and PE structure
  • strings.txt — raw string extraction via strings -a -n 6
  • binwalk.txt — 602 zlib-compressed embedded streams identified by binwalk -e
  • triage.json — family attribution from OpenCTI connector (blankgrabber)
  • Certificate details extracted manually from PE Security directory at RVA 0xBE15DC via Python struct and pefile
  • dynamic-analysis.md — CAPE skipped, no Windows guest available