PyInstaller malware family
PyInstaller is a malware family tracked by MalwareAnalyzer by Cyble across 26 publicly analyzed samples. First seen 2026-07-28, most recently 2026-07-29. Observed ATT&CK techniques include T1071.001, T1112.
Corpus statistics
- Publicly analyzed samples: 26
- First seen: 2026-07-28
- Last seen: 2026-07-29
- Verdicts: malicious 22, suspicious 4
- File types: pe 26
ATT&CK techniques used by PyInstaller
Recent PyInstaller samples
- 21fa2933a5f8ecc157747f190d86762317d8b64f800f67287fbecf0169764b46.exe - suspicious (2026-07-29)
- 17c4da4a81155d233e6eaf6ef7cd2590d6fda76a46bacede4881ab3cd1bf88d3.exe - suspicious (2026-07-29)
- 15d34471d464ff576aa1c6fdbed6821c3b38f811916770a7db2422c5a90d01c8.exe - suspicious (2026-07-29)
- dde2616ab4c9f2972ce9116f5d03a225520242b96211107f5a68e3f69f0ac7f1.exe - malicious (2026-07-28)
- d7be04c19b1d908e4d33edfdcf3fbcb15812763edb905ce1fa46233368181086.exe - malicious (2026-07-28)
- d09ecddb706b55f3b2980ee9aec109326ab7bacb33bc7ab46c27ada51ff646c6.exe - suspicious (2026-07-28)
- c51cdb75acfe918b90165cbeb4b1acc466b3514b9adaac055556987c61939821.exe - malicious (2026-07-28)
- bed759e549a932e839a6fc57ae831105cc17bdd8ec86b5ba54d018f92f5d9795.exe - malicious (2026-07-28)
- b319d03f4eb9120cb7a4584b6c75be04dab781e541ffc74e252945e8522d7504.exe - malicious (2026-07-28)
- aa8e03cadb21e3939196e2658707563e7d6f1259b9d69f973b22ba494d1e49b4.exe - malicious (2026-07-28)
- virussign.com_21d8ee54358aeb6bd4b80e048c318980.vir - malicious (2026-07-28)
- 8fbbea30016a3c3b2763ff274bf511508f3df99c0d33f518b9a0067e7aedd8fc.exe - malicious (2026-07-28)
- 8e885a5a91a3657d47ca23d52659ea56b7010ffb24a4ae3eb184f8783b4223e3.exe - malicious (2026-07-28)
- virussign.com_92fce420015db9108aa2684f9c89e8e0.vir - malicious (2026-07-28)
- 7805b06ffc78058b2dd8f41155c9fc353c1267629aeaf3ee8f8e587fd11f013e.exe - malicious (2026-07-28)
- 732b8cf362f486b7569eaa85d9e39f71fe1438ba68214300a9b33c204c447264.exe - malicious (2026-07-28)
- 6543a1888c58d583be80f8f2749c4a0631c6f3d82a9b64a42b657d874f5d2b90.exe - malicious (2026-07-28)
- 64a385b2bfaef289318908ebf361dfeaac374897753abc7994c4e048120e688f.exe - malicious (2026-07-28)
- 5a6f57b0f7404d70c29e5c39b3bdd95064df4c4885f0fbbdcee41e438ff8444c.exe - malicious (2026-07-28)
- 57cefbb075b766c47392d9a85ccc88ba95c6727b12828046a7e81b20f085fc6a.exe - malicious (2026-07-28)
- 55cd158c88d5e7cd6aadafc8eaf64ab4a1a633691f52951f8b82e2fb5226bbdb.exe - malicious (2026-07-28)
- 3a0ecd128bddb650c684af39de612fb50953c76e1be4677afff1b0a3ae7e01f8.exe - malicious (2026-07-28)
- 373cd79b66b23f65fd93e10807b5217897e603c268ea14f8d8f3fc7806c66322.exe - malicious (2026-07-28)
- 35bcc443025f622df0e121a32b7949f8ed2dd5936cb0b1673b249116b79cbe3a.exe - malicious (2026-07-28)
Frequently asked about PyInstaller
- What is PyInstaller?
- PyInstaller is a malware family tracked by MalwareAnalyzer by Cyble across 26 publicly analyzed samples. First seen 2026-07-28, most recently 2026-07-29. Observed ATT&CK techniques include T1071.001, T1112.
- How many PyInstaller samples have been analyzed?
- MalwareAnalyzer by Cyble holds 26 publicly analyzed samples attributed to PyInstaller, first seen 2026-07-28 and most recently 2026-07-29. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does PyInstaller use?
- Across our PyInstaller samples the most frequently observed techniques are T1071.001 (26), T1112 (17). Counts are the number of analyzed samples in which each technique was observed.
- What file types does PyInstaller use?
- PyInstaller samples in this corpus are distributed as pe (26).
- Is PyInstaller malicious?
- 22 of 26 analyzed PyInstaller samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends