2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3coinminer: 2727eb40 — Hybrid ftpcrack+xmrig sibling, 387 KB, plain-zlib overlay
Executive Summary
Confirmed sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second, same bootloader — but unique in combining FTP brute-force credential scanning (built-in dictionaries, random IP generation) with embedded XMRig miner deployment (xmrig.exe, config.json, link.txt). Plain-zlib overlay (no AES). Static-only analysis; CAPE skipped — no Windows guest.
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 387,488 bytes (378.4 KB) ^[triage.json]
- Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
- Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
- ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[rabin2-info.txt:32]
- Overlay: ~138 KB starting at raw offset 0x3CE00, zlib-compressed (header
78 da) PyInstaller CFFI archive, 10 zlib streams, 35.7% overlay ratio ^[binwalk.txt:11-22] - No AES encryption: no
pyimod00_crypto_keymarker anywhere in overlay or strings ^[strings.txt] - Cluster: identical compilation timestamp to 22+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]
- Hybrid payload: decompressed overlay contains both
ftpcrack.pymodule strings (FTP credential dictionaries,RANDOM_IP_POOL, ICMP socket crafting) andxmrig.exedeployment artefacts (taskkill /F /IM xmrig.exe,config.json,link.txt,stratum,miner) — see How It Works section for recovered strings.
How It Works
Standard PyInstaller single-file C bootloader flow ^[r2:entry0] ^[r2:main] ^[r2:fcn.00402520]:
- CRT initialisation —
entry0(0x004079d3) sets up security cookie and SEH, then callsmain()^[r2:entry0] - Archive resolution —
main(0x00401000) resolves the executable path, then hands control to the extraction routine ^[r2:main] - Extraction — allocates an
ARCHIVE_STATUSstruct, checks the_MEIPASS2environment variable, opens its own image as an archive, and decompresses the CFFI overlay to%TEMP%\_MEI<XXXX>using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115] ^[strings.txt:292] - Python runtime bootstrap — calls
SetDllDirectoryWto the_MEIfolder, loadspython*.dll(overlay containspython27.dllandMSVCR90.dllliterals confirming Python 2.7 runtime), resolves CPython C-API functions viaGetProcAddress, then unmarshals and executes__main__.py(module name in overlay isftpcrack.py) ^[strings.txt:119-212] - Payload behaviour — The embedded Python payload is a dual-function crimeware module:
- FTP brute-force scanner: built-in credential dictionaries (
USER_DIC/PASSWORD_DIC) with hundreds of entries including{user},{user}123,admin,root,test,www-data,password,123456,123123,qwerty,1qaz2wsx,P@ssw0rd!!, etc. Random IP generation viaRANDOM_IP_POOLand ICMP packet crafting for host discovery. Multi-threadedqueue_taskdispatch. - XMRig miner deployment: batch-script fragments recovered from overlay show
taskkill /F /IM xmrig.exe(kills existing miner),copy /y xmrig.exe(stages miner from_MEIPASSto%TMP%),config.json,\link.txt, and stratum pool configuration strings (tcp://,stratum,miner,pool). Thelink.txtfile likely contains runtime-fetched pool URLs or wallet addresses.
- FTP brute-force scanner: built-in credential dictionaries (
No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie, callsmain(). ^[r2:entry0]main(0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]- PyInstaller bootstrap core: allocates
ARCHIVE_STATUS, checks_MEIPASS2, opens self as archive, iterates TOC, extracts to_MEItemp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]
C2 Infrastructure
Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]
Static recovery from decompressed overlay reveals:
stratum,tcp://,miner,pool— confirms Stratum protocol mining127.0.0.1— local interface reference for miner bind or testlink.txt— external C2/pool config file reference- No hardcoded attacker IP addresses or domains recovered from overlay.
Interesting Tidbits
- Hybrid nature: This is the first confirmed sibling in the cluster to contain both FTP brute-force (
ftpcrack.py) AND XMRig miner deployment artefacts in the same overlay. Prior siblings were either pure ftpcrack (551d2b0e,135b3b8d,6b881268) or pure coinminer (801fbba1,39b67a79,5d9fe273). ^[raw/analyses/d90f5359/report.md] python27.dllandMSVCR90.dllliterals in overlay confirm Python 2.7.15 runtime — same as other ftpcrack siblings. ^[overlay-decompress]floss.txtandcapa.txtare both non-functional (tool argument error and missing signatures respectively) — same as prior siblings. ^[floss.txt] ^[capa.txt]- No YARA matches beyond generic
PE_File_Generic^[yara.txt]. - Import table is minimal:
USER32.dll(MessageBoxA/W),KERNEL32.dll(process/thread/file APIs),WS2_32.dll(ntohlby ordinal) ^[pefile.txt:249-300]. .rsrcsection contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely the PyInstaller default icon or a reused icon from the build pipeline ^[binwalk.txt:9] ^[pefile.txt:159-177].
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15
- Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
- Write a Python script (
ftpcrack.py) that combinesftplib.FTPbrute-force scanning withsubprocess.Popento deployxmrig.exeand aconfig.json. - Build:
pyinstaller --onefile --windowed ftpcrack.py - Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with
78 daheaders. - Decompress overlay with
python -m zliborbinwalk -eto recover the embedded.pycandpython27.dll.
Deployable Signatures
YARA rule
rule pyinstaller_sep2018_hybrid_ftpcrack_xmrig
{
meta:
description = "PyInstaller Sep 2018 cluster sibling with hybrid ftpcrack+xmrig payload"
author = "Demetrian Titus"
date = "2026-08-10"
sha256 = "2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3"
strings:
$pyi1 = "PyInstaller: " ascii
$pyi2 = "_MEIPASS" ascii
$pyi3 = "Failed to get address for Py_Initialize" ascii
$zlib = { 78 da }
$ftpcrack = "ftpcrack.py" ascii
$xmrig = "xmrig.exe" ascii
$stratum = "stratum" ascii
$linktxt = "link.txt" ascii
$config = "config.json" ascii
$userdic = "USER_DIC" ascii
$passdic = "PASSWORD_DIC" ascii
condition:
uint16(0) == 0x5A4D and
3 of ($pyi*) and
$zlib and
$ftpcrack and
$xmrig and
any of ($stratum, $linktxt, $config) and
any of ($userdic, $passdic)
}
Sigma rule
title: PyInstaller Hybrid FTPCrack+XMRig Execution
status: experimental
description: Detects execution of Sep 2018 PyInstaller cluster binaries that deploy both FTP brute-force and XMRig miner payloads
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- '_MEI'
- 'xmrig.exe'
- 'config.json'
selection2:
CommandLine|contains:
- 'ftpcrack.py'
- 'link.txt'
condition: selection or selection2
falsepositives:
- None expected; xmrig.exe in _MEI temp path is highly suspicious
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3 | Hash |
| Module name | ftpcrack.py |
String |
| Embedded binary | xmrig.exe |
Filename |
| Config file | config.json |
Filename |
| Pool config | link.txt |
Filename |
| Temp path | %TEMP%\_MEI<XXXX> |
Path |
| Runtime DLL | python27.dll |
Filename |
| Compile timestamp | 2018-09-04 14:43:33 UTC |
Timestamp |
Behavioural fingerprint
This binary is a PyInstaller single-file PE (MSVC 14.0, Sep 2018) that extracts a Python 2.7 runtime and payload to %TEMP%\_MEI<XXXX>. The payload module is ftpcrack.py and performs two distinct malicious behaviours: (1) multi-threaded FTP credential spraying against randomly-generated IP addresses using built-in dictionaries (USER_DIC / PASSWORD_DIC), and (2) XMRig cryptocurrency miner deployment via taskkill /F /IM xmrig.exe followed by copy /y xmrig.exe and config.json staging. Network surface includes ICMP host discovery, FTP banner detection, and Stratum/TCP mining pool communication.
Detection Signatures
PE_File_Generic(YARA) ^[yara.txt]- capa signatures unavailable (missing installation) ^[capa.txt]
- floss decoding unavailable (argument error) ^[floss.txt]
References
- coinminer — entity page for the broader PyInstaller cluster
- ftpcrack — entity page for the FTP brute-force sub-cluster
- /intel/analyses/801fbba19b4d4828191e87e7311480deaf81e84482dab70adf38d61afd01c1fa.html — First confirmed PyInstaller coinminer sibling
- /intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — ftpcrack sibling with AES-encrypted overlay
- /intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html — Largest plain-zlib coinminer sibling (5.98 MB)
Provenance
Analysis derived from static artefacts in wiki/wiki/raw/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3/:
file.txt, exiftool.json, pefile.txt, rabin2-info.txt, strings.txt, binwalk.txt, yara.txt, triage.json, metadata.json, floss.txt (tool error), capa.txt (tool error). Overlay decompression performed via Python zlib against raw offset 0x3CE00. Radare2 analysis (level 2, 930 functions) on entry0, main, and fcn.00402520. CAPE sandbox unavailable — no Windows guest. Report written 2026-08-10.