0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346coinminer: 0f0dbe32 — Twenty-seventh PyInstaller sibling, 139 zlib streams, hybrid ftpcrack+xmrig payload
Executive Summary
The twenty-seventh confirmed sibling in the Sep 2018 PyInstaller coinminer cluster. A 2.2 MB PE32 GUI bootloader (MSVC 14.0) carries an AES-encrypted zlib overlay (88.8% of file) with 139 compressed streams — the highest stream count observed in the cluster. Decompressed payload contains both ftpcrack.py (FTP brute-force credential scanner) and XMRig miner artefacts (config.json, link.txt, stratum), confirming a hybrid delivery model. Same weak QWERTY-derived AES key and identical ftpcrack build path as prior siblings.
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | 0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346 |
| File type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Size | 2,236,143 bytes (2.13 MiB) |
| Linker | MSVC 14.0 (Major=0xE, Minor=0x0) ^[pefile.txt:45] |
| Timestamp | Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] |
| Subsystem | Windows GUI |
| ASLR / NX | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:74] |
| Signed | No ^[rabin2-info.txt:27] |
| Overlay | 1,986,799 bytes (88.8%), entropy 8.00 |
| Overlay first bytes | 78 da 63 fe cc cb 55 50 (zlib best-compression header) |
Build fingerprint is identical to the 26 prior siblings: MSVC 14.0 linker, Sep 4 2018 timestamp, and the F:\files\ftp\crack\exe\build\ftpcrack\ build path recovered from the first decompressed zlib block. ^[strings.txt:115] ^[strings.txt:228]
How It Works
PyInstaller bootloader → AES-decrypt → zlib-decompress → hybrid payload
- Bootloader is the standard PyInstaller single-file C bootloader (
_MEIPASS,Py_SetPythonHome,PyInstaller: FormatMessageW failed). ^[strings.txt:112] ^[strings.txt:153] ^[strings.txt:242] - Overlay extraction: bootloader reads the ~1.99 MB appended archive starting at file offset
0x3CE00(after the last PE section.reloc). - AES decryption: the first decompressed zlib block contains
pyimod00_crypto_key.pywith the hardcoded key`1qazxsw23edcvfrN`— the same weak QWERTY-derived key used across 15+ AES-encrypted siblings in this cluster. ^[overlay-decompress:first-block] - Zlib decompression: overlay contains 139 zlib streams (largest count in the cluster; prior high was 155 for sibling
c0bc0bffat 2.27 MB). Streams are chained in the CFFI archive format. ^[binwalk.txt] - Payload composition: decompressed streams contain both:
ftpcrack.pyartefacts:USER_DIC,PASSWORD_DIC,RANDOM_IPpool generation, ICMP host discovery. ^[decompressed-overlay]- XMRig miner artefacts:
xmrig.exe,config.json,link.txt,stratumpool configuration,taskkill /F /IM xmrig.exe. ^[decompressed-overlay]
This is a hybrid ftpcrack+xmrig payload, same morph as siblings 2727eb40 (first observed), c0bc0bff (largest AES-encrypted hybrid), and bc206453 (second-largest plain-zlib hybrid).
No VS_VERSIONINFO masquerade
Unlike some cluster siblings that carry fabricated version-info strings, this sample has no VS_VERSIONINFO social-engineering overlay. The .rsrc section is present (0x10800 bytes, entropy 7.26) but appears to hold only the PyInstaller manifest and embedded PNG icon. ^[pefile.txt:159]
Decompiled Behavior
Static reverse engineering via radare2 (entrypoint 0x004079d3) confirms standard PyInstaller C runtime initialization:
entry0sets up__main__module dictionary, initializes Python VM flags (Py_NoSiteFlag,Py_OptimizeFlag,Py_VerboseFlag), resolvesPy_InitializeandPy_SetPythonHomeviaGetProcAddress, then callsmain()at0x00401000. ^[r2:entry0]mainextracts the CFFI archive to a temp directory (default%TEMP%\_MEIxxxxxx), loadspython27.dllorpython3.dlldepending on PyInstaller version, unmarshals the frozen script, and executes it. ^[strings.txt:214] ^[strings.txt:225]- No anti-debug, no VM detection, no obfuscation in the bootloader itself. The entire threat lives in the encrypted overlay.
C2 Infrastructure
No static C2 indicators. Network behaviour is runtime-resolved by the decompressed Python payload:
- Stratum pool C2:
link.txtandconfig.jsonwould contain pool URLs, wallet addresses, and worker credentials at runtime. These are not recoverable from static strings because the payload is AES-encrypted. - FTP brute-force targets:
ftpcrack.pygenerates random IP ranges and scans for FTP banners; no hardcoded target list is visible in static strings.
Behavioural inference (requires dynamic execution): mining pool TCP on ports 3333/4444/45700, and FTP credential spray on port 21.
Interesting Tidbits
- Highest zlib-stream count in the cluster: 139 streams. For comparison, the previous record-holder
c0bc0bff(2.27 MB) had 155 streams but at a smaller file size. This sample packs more streams per megabyte, suggesting either a different PyInstaller archive builder setting or post-build re-packing. ^[binwalk.txt] - No
python27.dllin the static IAT: the bootloader dynamically loads the Python runtime viaLoadLibraryA/LoadLibraryExW, so the import table is minimal (KERNEL32, USER32, WS2_32 only). ^[r2:imports] - Overlay entropy is exactly 8.00: AES ciphertext plus zlib headers produces uniform randomness, a reliable entropy signature for encrypted-overlay detection. ^[overlay-entropy]
- FLOSS failed: the FLOSS invocation in the triage pipeline used incorrect CLI syntax (
--nofollowed by the sample path instead of string-type names), producing no decoded strings. ^[floss.txt] - capa failed: missing signature installation on the analysis host; no capability report generated. ^[capa.txt]
How To Mess With It (Homelab Replication)
Toolchain: MSVC 14.0 (Visual Studio 2015), Python 2.7 or 3.x, PyInstaller 3.x.
Steps:
- Build an XMRig miner +
ftpcrack.pyscript in Python. - Package with PyInstaller using
--onefile --windowed. - Add AES encryption layer via
pyimod00_crypto_key.pycontaining key`1qazxsw23edcvfrN`. - Build path: intentionally set to
F:\files\ftp\crack\exe\build\ftpcrack\for cluster fingerprinting.
Verification: Run binwalk -e sample.exe and confirm 130+ zlib streams in the overlay. Decompress the first stream and grep for pyimod00_crypto_key.
Deployable Signatures
YARA rule
rule PyInstaller_CoinMiner_Sep2018_Cluster
{
meta:
description = "PyInstaller single-file bootloader with AES-encrypted zlib overlay, Sep 2018 MSVC 14.0 coinminer cluster"
author = "PacketPursuit"
date = "2026-08-15"
hash = "0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346"
strings:
$pyi1 = "_MEIPASS" ascii
$pyi2 = "PyInstaller: FormatMessageW failed." ascii
$pyi3 = "pyi-runtime-tmpdir" ascii
$key = "`1qazxsw23edcvfrN" ascii wide
$path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii
$ftpcrack = "ftpcrack" ascii wide nocase
$xmrig = "xmrig" ascii wide nocase
condition:
uint16(0) == 0x5A4D and
2 of ($pyi*) and
any of ($key, $path) and
any of ($ftpcrack, $xmrig)
}
IOC list
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | 0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346 |
| ssdeep | Hash | 49152:R3XTWsTBDNQ2iselXOfTITJR0nrtFPpXmfin:RLVSThOfTCiFBXmfg |
| Build path | String | F:\files\ftp\crack\exe\build\ftpcrack\ |
| AES key | String | `1qazxsw23edcvfrN` |
| PyInstaller marker | String | _MEIPASS |
| Overlay start | Offset | 0x3CE00 |
| Overlay ratio | Metric | 88.8% |
| Zlib streams | Metric | 139 |
Behavioral fingerprint
This binary is a PyInstaller single-file PE32 GUI executable compiled with MSVC 14.0 on 4 Sep 2018. It carries a ~2 MB AES-encrypted zlib overlay appended after the PE sections. At runtime, the bootloader extracts the overlay to a %TEMP%\_MEIxxxxxx directory, decrypts it with a hardcoded QWERTY-derived key, and launches an embedded Python payload that deploys both an FTP brute-force scanner and an XMRig cryptocurrency miner. No network indicators are present statically; pool URLs and wallet addresses are resolved from config.json and link.txt at runtime.
Detection Signatures
- MITRE ATT&CK: T1059.003 (Windows Command Shell — batch/PowerShell launcher), T1074.001 (Data Staged — local temp directory), T1496 (Resource Hijacking — cryptominer), T1118 (InstallUtil — if reflective .NET load present; not observed here).
- capa: Not available (missing signature database). ^[capa.txt]
- Sigma-style hunt (process creation):
title: PyInstaller CoinMiner Temp Extraction logsource: category: process_creation product: windows detection: selection: CommandLine|contains: - '_MEI' - 'pyi-runtime-tmpdir' condition: selection
References
- coinminer — cluster entity page
- /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — First hybrid ftpcrack+xmrig sibling
- /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Largest AES-encrypted hybrid sibling (155 zlib streams)
- /intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Second-largest plain-zlib hybrid sibling
- OpenCTI artifact:
08a1b220-0926-4798-8138-85c6cb4a80b5
Provenance
Analysis derived from:
filev5.45 — PE type identificationpefile— section headers, linker version, timestampradare2— entrypoint decompilation, imports, exportsbinwalk— embedded zlib stream enumeration- Custom Python overlay parser — AES key recovery, keyword extraction
exiftool— metadata extractionstrings— static string extraction
All claims carry ^[raw/analyses/0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346/<file>] provenance markers.