agentsclimarketplace

Analyzing compiled python malware

Skill meltedinhex/analyst-ai-pack/skills/analyzing-compiled-python-malware

An open agent-skills library for malware analysis, reverse engineering, and threat hunting - 118 curated, runnable skills mapped to MITRE ATT&CK, D3FEND, and CAR.

Install
npx -y skills add meltedinhex/analyst-ai-pack --skill analyzing-compiled-python-malware

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 19 stars19 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

2.9 KB, as published. Nobody here has run it

Analyzing Compiled Python Malware

When to Use

  • You have an executable that is actually a frozen Python app (PyInstaller, py2exe, cx_Freeze) and need to identify the packer and locate the embedded Python modules.
  • You want to extract .pyc files for decompilation.

Do not use this to run the executable — it identifies and locates the embedded archive statically. Decompile extracted .pyc in an isolated environment.

Prerequisites

  • The frozen executable (read inertly).

Safety & Handling

  • Read bytes statically; treat extracted modules as malicious until reviewed.

Workflow

Step 1: Detect the packer

python scripts/analyst.py detect sample.exe

Looks for PyInstaller markers (pyi-, PYZ-00.pyz, the MEI CArchive cookie MEI\014\013\012\013\016), py2exe (PYTHONSCRIPT, zipfile.zip), and embedded python3x.dll references.

Step 2: Locate the embedded archive

Find the CArchive cookie near the end of the file and report the offset and the embedded Python version string (python3.x).

Step 3: Extract and decompile

Use a PyInstaller extractor to dump the archive, then decompile .pyc (matching the detected Python version) for source recovery.

Step 4: Analyze the source

Review the recovered Python for C2, persistence, and capability; map to ATT&CK.

Validation

  • The packer is identified by its specific marker, not just the presence of Python strings.
  • The CArchive cookie offset and Python version are reported when PyInstaller is present.
  • Findings distinguish the bootloader stub from the embedded Python payload.

Pitfalls

  • .pyc version mismatch breaking decompilation — match the interpreter version.
  • Stripped/obfuscated bytecode (e.g., custom magic) needing header repair before decompiling.
  • Encrypted PYZ archives (PyInstaller --key) requiring the key.

References

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.