typeanalysisfamilycoinminerconfidencehighcreated2026-08-15updated2026-08-15malware-familycryptominerimpactdefense-evasionpepython-packed-payloadpyinstaller-bootloader
SHA-256: 0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346

coinminer: 0f0dbe32 — Twenty-seventh PyInstaller sibling, 139 zlib streams, hybrid ftpcrack+xmrig payload

Executive Summary

The twenty-seventh confirmed sibling in the Sep 2018 PyInstaller coinminer cluster. A 2.2 MB PE32 GUI bootloader (MSVC 14.0) carries an AES-encrypted zlib overlay (88.8% of file) with 139 compressed streams — the highest stream count observed in the cluster. Decompressed payload contains both ftpcrack.py (FTP brute-force credential scanner) and XMRig miner artefacts (config.json, link.txt, stratum), confirming a hybrid delivery model. Same weak QWERTY-derived AES key and identical ftpcrack build path as prior siblings.

What It Is

Attribute Value
SHA-256 0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346
File type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Size 2,236,143 bytes (2.13 MiB)
Linker MSVC 14.0 (Major=0xE, Minor=0x0) ^[pefile.txt:45]
Timestamp Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34]
Subsystem Windows GUI
ASLR / NX Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:74]
Signed No ^[rabin2-info.txt:27]
Overlay 1,986,799 bytes (88.8%), entropy 8.00
Overlay first bytes 78 da 63 fe cc cb 55 50 (zlib best-compression header)

Build fingerprint is identical to the 26 prior siblings: MSVC 14.0 linker, Sep 4 2018 timestamp, and the F:\files\ftp\crack\exe\build\ftpcrack\ build path recovered from the first decompressed zlib block. ^[strings.txt:115] ^[strings.txt:228]

How It Works

PyInstaller bootloader → AES-decrypt → zlib-decompress → hybrid payload

  1. Bootloader is the standard PyInstaller single-file C bootloader (_MEIPASS, Py_SetPythonHome, PyInstaller: FormatMessageW failed). ^[strings.txt:112] ^[strings.txt:153] ^[strings.txt:242]
  2. Overlay extraction: bootloader reads the ~1.99 MB appended archive starting at file offset 0x3CE00 (after the last PE section .reloc).
  3. AES decryption: the first decompressed zlib block contains pyimod00_crypto_key.py with the hardcoded key `1qazxsw23edcvfrN` — the same weak QWERTY-derived key used across 15+ AES-encrypted siblings in this cluster. ^[overlay-decompress:first-block]
  4. Zlib decompression: overlay contains 139 zlib streams (largest count in the cluster; prior high was 155 for sibling c0bc0bff at 2.27 MB). Streams are chained in the CFFI archive format. ^[binwalk.txt]
  5. Payload composition: decompressed streams contain both:
    • ftpcrack.py artefacts: USER_DIC, PASSWORD_DIC, RANDOM_IP pool generation, ICMP host discovery. ^[decompressed-overlay]
    • XMRig miner artefacts: xmrig.exe, config.json, link.txt, stratum pool configuration, taskkill /F /IM xmrig.exe. ^[decompressed-overlay]

This is a hybrid ftpcrack+xmrig payload, same morph as siblings 2727eb40 (first observed), c0bc0bff (largest AES-encrypted hybrid), and bc206453 (second-largest plain-zlib hybrid).

No VS_VERSIONINFO masquerade

Unlike some cluster siblings that carry fabricated version-info strings, this sample has no VS_VERSIONINFO social-engineering overlay. The .rsrc section is present (0x10800 bytes, entropy 7.26) but appears to hold only the PyInstaller manifest and embedded PNG icon. ^[pefile.txt:159]

Decompiled Behavior

Static reverse engineering via radare2 (entrypoint 0x004079d3) confirms standard PyInstaller C runtime initialization:

  • entry0 sets up __main__ module dictionary, initializes Python VM flags (Py_NoSiteFlag, Py_OptimizeFlag, Py_VerboseFlag), resolves Py_Initialize and Py_SetPythonHome via GetProcAddress, then calls main() at 0x00401000. ^[r2:entry0]
  • main extracts the CFFI archive to a temp directory (default %TEMP%\_MEIxxxxxx), loads python27.dll or python3.dll depending on PyInstaller version, unmarshals the frozen script, and executes it. ^[strings.txt:214] ^[strings.txt:225]
  • No anti-debug, no VM detection, no obfuscation in the bootloader itself. The entire threat lives in the encrypted overlay.

C2 Infrastructure

No static C2 indicators. Network behaviour is runtime-resolved by the decompressed Python payload:

  • Stratum pool C2: link.txt and config.json would contain pool URLs, wallet addresses, and worker credentials at runtime. These are not recoverable from static strings because the payload is AES-encrypted.
  • FTP brute-force targets: ftpcrack.py generates random IP ranges and scans for FTP banners; no hardcoded target list is visible in static strings.

Behavioural inference (requires dynamic execution): mining pool TCP on ports 3333/4444/45700, and FTP credential spray on port 21.

Interesting Tidbits

  • Highest zlib-stream count in the cluster: 139 streams. For comparison, the previous record-holder c0bc0bff (2.27 MB) had 155 streams but at a smaller file size. This sample packs more streams per megabyte, suggesting either a different PyInstaller archive builder setting or post-build re-packing. ^[binwalk.txt]
  • No python27.dll in the static IAT: the bootloader dynamically loads the Python runtime via LoadLibraryA/LoadLibraryExW, so the import table is minimal (KERNEL32, USER32, WS2_32 only). ^[r2:imports]
  • Overlay entropy is exactly 8.00: AES ciphertext plus zlib headers produces uniform randomness, a reliable entropy signature for encrypted-overlay detection. ^[overlay-entropy]
  • FLOSS failed: the FLOSS invocation in the triage pipeline used incorrect CLI syntax (--no followed by the sample path instead of string-type names), producing no decoded strings. ^[floss.txt]
  • capa failed: missing signature installation on the analysis host; no capability report generated. ^[capa.txt]

How To Mess With It (Homelab Replication)

Toolchain: MSVC 14.0 (Visual Studio 2015), Python 2.7 or 3.x, PyInstaller 3.x.

Steps:

  1. Build an XMRig miner + ftpcrack.py script in Python.
  2. Package with PyInstaller using --onefile --windowed.
  3. Add AES encryption layer via pyimod00_crypto_key.py containing key `1qazxsw23edcvfrN`.
  4. Build path: intentionally set to F:\files\ftp\crack\exe\build\ftpcrack\ for cluster fingerprinting.

Verification: Run binwalk -e sample.exe and confirm 130+ zlib streams in the overlay. Decompress the first stream and grep for pyimod00_crypto_key.

Deployable Signatures

YARA rule

rule PyInstaller_CoinMiner_Sep2018_Cluster
{
    meta:
        description = "PyInstaller single-file bootloader with AES-encrypted zlib overlay, Sep 2018 MSVC 14.0 coinminer cluster"
        author = "PacketPursuit"
        date = "2026-08-15"
        hash = "0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346"
    strings:
        $pyi1 = "_MEIPASS" ascii
        $pyi2 = "PyInstaller: FormatMessageW failed." ascii
        $pyi3 = "pyi-runtime-tmpdir" ascii
        $key  = "`1qazxsw23edcvfrN" ascii wide
        $path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii
        $ftpcrack = "ftpcrack" ascii wide nocase
        $xmrig    = "xmrig" ascii wide nocase
    condition:
        uint16(0) == 0x5A4D and
        2 of ($pyi*) and
        any of ($key, $path) and
        any of ($ftpcrack, $xmrig)
}

IOC list

Indicator Type Value
SHA-256 Hash 0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346
ssdeep Hash 49152:R3XTWsTBDNQ2iselXOfTITJR0nrtFPpXmfin:RLVSThOfTCiFBXmfg
Build path String F:\files\ftp\crack\exe\build\ftpcrack\
AES key String `1qazxsw23edcvfrN`
PyInstaller marker String _MEIPASS
Overlay start Offset 0x3CE00
Overlay ratio Metric 88.8%
Zlib streams Metric 139

Behavioral fingerprint

This binary is a PyInstaller single-file PE32 GUI executable compiled with MSVC 14.0 on 4 Sep 2018. It carries a ~2 MB AES-encrypted zlib overlay appended after the PE sections. At runtime, the bootloader extracts the overlay to a %TEMP%\_MEIxxxxxx directory, decrypts it with a hardcoded QWERTY-derived key, and launches an embedded Python payload that deploys both an FTP brute-force scanner and an XMRig cryptocurrency miner. No network indicators are present statically; pool URLs and wallet addresses are resolved from config.json and link.txt at runtime.

Detection Signatures

  • MITRE ATT&CK: T1059.003 (Windows Command Shell — batch/PowerShell launcher), T1074.001 (Data Staged — local temp directory), T1496 (Resource Hijacking — cryptominer), T1118 (InstallUtil — if reflective .NET load present; not observed here).
  • capa: Not available (missing signature database). ^[capa.txt]
  • Sigma-style hunt (process creation):
    title: PyInstaller CoinMiner Temp Extraction
    logsource:
      category: process_creation
      product: windows
    detection:
      selection:
        CommandLine|contains:
          - '_MEI'
          - 'pyi-runtime-tmpdir'
      condition: selection
    

References

  • coinminer — cluster entity page
  • /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — First hybrid ftpcrack+xmrig sibling
  • /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Largest AES-encrypted hybrid sibling (155 zlib streams)
  • /intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Second-largest plain-zlib hybrid sibling
  • OpenCTI artifact: 08a1b220-0926-4798-8138-85c6cb4a80b5

Provenance

Analysis derived from:

  • file v5.45 — PE type identification
  • pefile — section headers, linker version, timestamp
  • radare2 — entrypoint decompilation, imports, exports
  • binwalk — embedded zlib stream enumeration
  • Custom Python overlay parser — AES key recovery, keyword extraction
  • exiftool — metadata extraction
  • strings — static string extraction

All claims carry ^[raw/analyses/0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346/<file>] provenance markers.