Live Steam VOD: PyInstaller Malware Triage - Creal Stealer (Patreon)
Content
In this live stream we triage Creal Stealer, a Python stealer which has been packed with PyInstaller. We cover the differences between Python byte code disassembly and decompiling as well as provide a few tips for decompiling newer versions of Python.
Shout out to Karsten for his YouTube short which covered the same topic in 30 sections instead of an hour... go sub you you aren't already! Reversing PyInstaller in 6 Steps
Sample
21a9b4859121afcf6690c2c15b795094986c0a20c36a356c3915f107ec41f67a UnpacMe
Notes
Python Malware Triage: Creal Stealer - A Few Tips To Help With PyInstaller And Friends