1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4coinminer: 1fed143e — PyInstaller bootloader sibling, 4.14 MB plain-zlib overlay, Sep 2018 cluster
Executive Summary
Large PyInstaller single-file PE32 from the Sep 2018 MSVC 14.0 coinminer cluster. At 4.14 MB it is the second-largest plain-zlib sibling observed in this corpus (surpassed only by the 6.1 MB f284c9aa). Same compilation timestamp and bootloader as sixteen confirmed cluster siblings; no AES encryption layer (no pyimod00_crypto_key.pyc recovered), no appended secondary PE, and no ftpcrack.py misattribution. The ~3.87 MB overlay contains the actual coinminer payload in zlib-compressed Python bytecode, not recoverable without extraction. Static-only — CAPE skipped for lack of a Windows guest.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4 |
| File type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Size | 4,342,176 bytes (4.14 MB) ^[triage.json] |
| Linker | MSVC 14.0 (Visual Studio 2015 RTM) ^[exiftool.json] ^[pefile.txt:45-46] |
| PE timestamp | Tue Sep 4 14:43:33 2018 UTC ^[rabin2-info.txt:11] ^[pefile.txt:34] |
| Signed | No ^[rabin2-info.txt:27] |
| ASLR / DEP | Enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74] |
| Entry point | 0x004079d3 (PyInstaller bootloader) ^[pefile.txt:50] |
| Overlay | ~3.87 MB starting at raw offset 0x3CE00, zlib-compressed ^[binwalk.txt] |
| Sections | .text, .rdata, .data, .gfids, .rsrc, .reloc ^[pefile.txt:78-196] |
The outer binary is a stock PyInstaller C bootloader circa 2018. No mining pool URLs, wallet addresses, or Stratum protocol strings are visible in the PE sections or imports; the coinminer logic is assumed to live inside the compressed overlay.
How It Works
Standard PyInstaller single-file C bootloader flow, identical to siblings 801fbba1, 640ed5b5, and 39b67a79:
- CRT initialisation —
entry0at0x004079d3sets up security cookie and SEH, then callsmain()^[r2:entry0] - Archive resolution —
mainat0x00401000resolves the executable path and hands control to the PyInstaller bootstrap core ^[r2:main] - Extraction — Decompresses the CFFI archive from the overlay to
%TEMP%\_MEI<XXXX>using zlib/inflate 1.2.8 ^[strings.txt:79] ^[binwalk.txt] - Python runtime bootstrap — Loads embedded
python*.dll, resolves CPython C-API functions (Py_Initialize,PyMarshal_ReadObjectFromString,PyEval_EvalCode, etc.) viaGetProcAddress^[strings.txt:119-212] - Script execution — Unmarshals and runs the embedded
__main__.pybytecode ^[strings.txt:104-111] - Cleanup — Removes the
_MEItemp directory on exit unless_MEIPASS2env var is set ^[strings.txt:115]
Cluster fingerprinting:
- Same compilation second as the entire cluster:
2018-09-04 14:43:33 UTC^[rabin2-info.txt:11] - No
pyimod00_crypto_key.pycor hardcoded AES key1qazxsw23edcvfrNfound in overlay (unlike AES-encrypted siblings359fcf01,058ab625,983d2606, etc.) - No appended secondary PE (unlike sibling
5047235c) - No
ftpcrack.pypayload (unlike mislabelled sibling551d2b0e) - Plain zlib compression: 44 zlib blocks identified by binwalk ^[binwalk.txt]
Decompiled Behavior
entry0(0x004079d3): MSVC CRT entry, 103 instructions, 21 basic blocks, cyclomatic complexity 11. Sets up SEH chain and security cookie, then jumps tomain(). ^[r2:entry0]main(0x00401000): Archive status resolution viaGetModuleFileNameW, UTF-8 conversion of argv/envp viaWideCharToMultiByte, then calls the PyInstaller bootstrap. ^[r2:main]- Import surface is entirely benign Win32 + Python CRT APIs:
KERNEL32.dll(file ops, process creation, environment),USER32.dll(MessageBoxA/W),WS2_32.dll(ntohlonly — used by the bootloader, not direct C2). ^[r2:imports]
No anti-debug checks, no VM detection, no API hashing, no sandbox evasion — pure stock PyInstaller behaviour.
C2 Infrastructure
Not statically observable. The outer binary contains only generic PyInstaller and MSVC CRT strings. Mining pool URLs, wallet addresses, and Stratum configuration are assumed to reside inside the zlib-compressed Python payload in the overlay. No hardcoded IPs, domains, or mutex names were recovered. ^[strings.txt]
Interesting Tidbits
floss.txtis a tool-usage error (triage script passed sample path to--noinstead of positional arg), yielding no decoded strings. ^[floss.txt]capa.txtfailed with missing default signature path — signatures not installed on this station. ^[capa.txt]binwalk.txtidentifies 44 zlib-compressed blocks in the overlay plus a PNG icon (256×256) in.rsrc— standard PyInstaller default icon inheritance. ^[binwalk.txt]- Overlay entropy is ~7.999 (near-random), confirming compressed/encrypted payload. No
base_library.ziporstruct.pycstrings recovered from overlay without decompression. - The
.rsrcsection contains standard PyInstaller icon groups; no custom version info masquerade. ^[pefile.txt:159-492] - This sample's size (4.14 MB) places it between the 4.07 MB sibling
fa98331dand the 5.34 MB sibling6b2591e4in the cluster size distribution, suggesting the same build pipeline with variable payload sizes.
How To Mess With It (Homelab Replication)
Follow the recipe at pyinstaller-bootloader and python-packed-payload:
- Install PyInstaller 3.4 on a Windows research VM with Python 2.7 or 3.6.
pyinstaller --onefile --windowed --name=miner_stub your_script.py- The resulting EXE will match this cluster's MSVC 14.0 linker fingerprint,
_MEIPASSstrings, and zlib overlay structure. - Extract the embedded payload with
pyinstxtractor.py(orpyinstxtractor-ngfor Python 3.x archives) to inspect.pycmodules and mining configuration. - Verification:
stringson the output EXE should show_MEIPASS2,PyInstaller,Py_Initialize, and zlib blocks in the overlay. Compare entropy and section layout to this sample. - Learning outcome: Recognising that the outer binary is benign infrastructure and the actual threat lives in the overlay prevents triage teams from stopping analysis after a benign-looking import table.
Deployable Signatures
YARA rule
rule PyInstallerBootloader_Coinminer_2018_1fed143e {
meta:
description = "PyInstaller single-file bootloader (2018 MSVC 14.0 cluster) with large plain-zlib embedded coinminer payload"
author = "Titus"
date = "2026-08-01"
sha256 = "1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4"
strings:
$pyi1 = "PyInstaller: FormatMessageW failed." ascii wide
$pyi2 = "_MEIPASS2" ascii wide
$pyi3 = "pyi-runtime-tmpdir" ascii wide
$pyi4 = "Installing PYZ: Could not get sys.path" ascii wide
$pyi5 = "Failed to execute script %s" ascii wide
$pyi6 = "base_library.zip" ascii wide
$inflate = "inflate 1.2.8 Copyright 1995-2013 Mark Adler" ascii wide
condition:
uint16(0) == 0x5a4d and
4 of ($pyi*) and
$inflate and
filesize > 3MB and
filesize < 7MB
}
Sigma rule
title: PyInstaller Coinminer Child Process Spawned from _MEI Temp Directory
logsource:
product: windows
category: process_creation
detection:
selection:
Image|startswith:
- '%TEMP%\_MEI'
ParentImage|endswith:
- '.exe'
condition: selection
falsepositives:
- Legitimate PyInstaller-built applications
level: medium
IOC list
- SHA-256:
1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4 - Temp path pattern:
%TEMP%\_MEI*\*(PyInstaller extraction directory) - Compilation timestamp:
2018-09-04 14:43:33 UTC(cluster indicator shared with siblings)
Behavioral fingerprint
PE32 GUI executable compiled with MSVC 2015, containing a ~3.87 MB zlib-compressed overlay (93% of file size). At runtime extracts its payload to a _MEI-prefixed temp directory, loads python*.dll from that directory, and executes embedded marshalled Python bytecode. No suspicious imports in the parent process; threat behaviour manifests in spawned Python/miner child processes. Same build fingerprint as confirmed coinminer siblings 801fbba1, 39b67a79, 5047235c, 640ed5b5, and others.
Detection Signatures
- MITRE ATT&CK
- T1059.006 (Python) — execution via embedded Python interpreter
- T1074.001 (Data Staged: Local Data Staging) — extraction to temp directory
- T1055 (Process Injection) — possible process hollowing or injection by the embedded Python payload; not confirmed statically
References
- Artifact ID:
6740d6c5-82cf-4975-84c8-d1c88750fff3 - Source: OpenCTI via abuse.ch URLhaus connector
- OpenCTI labels:
coinminer,exe,urlhaus^[triage.json] - Related wiki pages: coinminer, pyinstaller-bootloader, python-packed-payload
Provenance
Analysis derived from:
file.txt— file(1) type identificationpefile.txt— PE structure and section analysis via pefile (Python)rabin2-info.txt— radare2 binary header summarystrings.txt— ASCII string extraction via GNU stringsbinwalk.txt— embedded artefact identification via binwalkexiftool.json— EXIF/metadata extraction via ExifTooldynamic-analysis.md— CAPE sandbox status (skipped)triage.json— triage pipeline metadatar2:entry0,r2:main,r2:imports— radare2 static disassembly and import analysisfloss.txt,capa.txt— non-functional during analysis (tool errors)
Overlay byte-level analysis performed with custom Python scripts; no mining pool URLs, wallet addresses, or ftpcrack.py strings were recovered from the outer PE or overlay without decompression.