[ << ALL_FEED ]

Tools for working with Python

More in General

Tools for Working with Python 😦

Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in ShadowPad, and modules for Pupy RAT are proof of that. Additionally, tasks involving unpacking packers for further analysis are encountered at capture the flag competitions.

The Supply Chain Security team has compiled a cheat sheet on working with the PyInstaller, py2exe tools and compiled .pyc files.

PyInstaller

One of the most popular tools for packaging a project into an executable file for Windows, Linux, and macOS. Libraries related to the project are additionally serialized using the standard marshal library into a PYZ file.

To work with PyInstaller, you can use one of the first projects — pyinstxtractor. Marshal does not implement backward compatibility between its versions, so to unpack a PYZ file, pyinstxtractor requires running on the same Python version that was used to package PyInstaller.

pyinstxtractor-ng solves this issue: it uses the xdis library, which implements a (de)serializer for Python 2.4–3.13, meaning a specific Python version is no longer required for full unpacking. The author of pyinstxtractor-ng has released a web version, rewritten in Go, which runs locally in the browser. Both projects are actively updated and handle the latest versions of PyInstaller.

py2exe

A solution aimed at packaging a project into an executable file for Windows. It lags slightly behind trends and currently does not support Python 3.12 and 3.13. unpy2exe was supposed to be the “killer” of this packer, but the last commit to master seven years ago leaves a feeling of sadness. The author of this solution, like the author of pyinstxtractor, warns that the versions (at least major) of the installed Python and the final payload must match.

.pyc Files

At the Python level, they are used to speed up code execution and optimize module imports. There are several projects for converting them back to source code, and if possible, it is worth comparing the decompiled code obtained from one project with the decompiled code from another.

1️⃣ Uncompyle6 and decompyle3 — two utilities from the author of the aforementioned xdis. Uncompyle6 covers Python versions up to 3.8, decompyle3 covers from 3.7 to, partially, 3.9. The author is asking for help with the project.

2️⃣ The unpyc family (unpyc3, unpyc37, unpyc37-3.10) — supports specific versions 3.3, 3.7, 3.10.

3️⃣ Pycdc — a promising decompiler written in C++, also regularly updated and striving to support all versions of Python bytecode. It sometimes has difficulties parsing constructs, so…

4️⃣ Pycdas — a disassembler from the pycdc project, helps to try and analyze a .pyc file when decompilers are powerless 🐱🐱🐱

Existing online projects for .pyc files (caution: they send files to a server):

• Decompiler.com — multifunctional, “under the hood” uses uncompyle6.

• PyLingual.io — a promising solution currently in beta. It opens files from versions 3.11, 3.12, 3.13 without any issues.

Happy hacking!

#ti #python #tools #scs
@ptescalator

More from ti_author

More from ti_author

More in General