typeanalysisfamilycoinminerconfidencemediumcreated2026-08-10updated2026-08-10compilerpemalware-familycryptominerdefense-evasionpython-pyinstallerimpact
SHA-256: 2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3

coinminer: 2727eb40 — Hybrid ftpcrack+xmrig sibling, 387 KB, plain-zlib overlay

Executive Summary

Confirmed sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second, same bootloader — but unique in combining FTP brute-force credential scanning (built-in dictionaries, random IP generation) with embedded XMRig miner deployment (xmrig.exe, config.json, link.txt). Plain-zlib overlay (no AES). Static-only analysis; CAPE skipped — no Windows guest.

What It Is

  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 387,488 bytes (378.4 KB) ^[triage.json]
  • Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
  • Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
  • ASLR / DEP: enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74]
  • Subsystem: Windows GUI ^[rabin2-info.txt:32]
  • Overlay: ~138 KB starting at raw offset 0x3CE00, zlib-compressed (header 78 da) PyInstaller CFFI archive, 10 zlib streams, 35.7% overlay ratio ^[binwalk.txt:11-22]
  • No AES encryption: no pyimod00_crypto_key marker anywhere in overlay or strings ^[strings.txt]
  • Cluster: identical compilation timestamp to 22+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]
  • Hybrid payload: decompressed overlay contains both ftpcrack.py module strings (FTP credential dictionaries, RANDOM_IP_POOL, ICMP socket crafting) and xmrig.exe deployment artefacts (taskkill /F /IM xmrig.exe, config.json, link.txt, stratum, miner) — see How It Works section for recovered strings.

How It Works

Standard PyInstaller single-file C bootloader flow ^[r2:entry0] ^[r2:main] ^[r2:fcn.00402520]:

  1. CRT initialisation — entry0 (0x004079d3) sets up security cookie and SEH, then calls main() ^[r2:entry0]
  2. Archive resolution — main (0x00401000) resolves the executable path, then hands control to the extraction routine ^[r2:main]
  3. Extraction — allocates an ARCHIVE_STATUS struct, checks the _MEIPASS2 environment variable, opens its own image as an archive, and decompresses the CFFI overlay to %TEMP%\_MEI<XXXX> using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115] ^[strings.txt:292]
  4. Python runtime bootstrap — calls SetDllDirectoryW to the _MEI folder, loads python*.dll (overlay contains python27.dll and MSVCR90.dll literals confirming Python 2.7 runtime), resolves CPython C-API functions via GetProcAddress, then unmarshals and executes __main__.py (module name in overlay is ftpcrack.py) ^[strings.txt:119-212]
  5. Payload behaviour — The embedded Python payload is a dual-function crimeware module:
    • FTP brute-force scanner: built-in credential dictionaries (USER_DIC / PASSWORD_DIC) with hundreds of entries including {user}, {user}123, admin, root, test, www-data, password, 123456, 123123, qwerty, 1qaz2wsx, P@ssw0rd!!, etc. Random IP generation via RANDOM_IP_POOL and ICMP packet crafting for host discovery. Multi-threaded queue_task dispatch.
    • XMRig miner deployment: batch-script fragments recovered from overlay show taskkill /F /IM xmrig.exe (kills existing miner), copy /y xmrig.exe (stages miner from _MEIPASS to %TMP%), config.json, \link.txt, and stratum pool configuration strings (tcp://, stratum, miner, pool). The link.txt file likely contains runtime-fetched pool URLs or wallet addresses.

No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.

Decompiled Behaviour

  • entry0 (0x004079d3): MSVC CRT entry. Initialises security cookie, calls main(). ^[r2:entry0]
  • main (0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]
  • PyInstaller bootstrap core: allocates ARCHIVE_STATUS, checks _MEIPASS2, opens self as archive, iterates TOC, extracts to _MEI temp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]

C2 Infrastructure

Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]

Static recovery from decompressed overlay reveals:

  • stratum, tcp://, miner, pool — confirms Stratum protocol mining
  • 127.0.0.1 — local interface reference for miner bind or test
  • link.txt — external C2/pool config file reference
  • No hardcoded attacker IP addresses or domains recovered from overlay.

Interesting Tidbits

  • Hybrid nature: This is the first confirmed sibling in the cluster to contain both FTP brute-force (ftpcrack.py) AND XMRig miner deployment artefacts in the same overlay. Prior siblings were either pure ftpcrack (551d2b0e, 135b3b8d, 6b881268) or pure coinminer (801fbba1, 39b67a79, 5d9fe273). ^[raw/analyses/d90f5359/report.md]
  • python27.dll and MSVCR90.dll literals in overlay confirm Python 2.7.15 runtime — same as other ftpcrack siblings. ^[overlay-decompress]
  • floss.txt and capa.txt are both non-functional (tool argument error and missing signatures respectively) — same as prior siblings. ^[floss.txt] ^[capa.txt]
  • No YARA matches beyond generic PE_File_Generic ^[yara.txt].
  • Import table is minimal: USER32.dll (MessageBoxA/W), KERNEL32.dll (process/thread/file APIs), WS2_32.dll (ntohl by ordinal) ^[pefile.txt:249-300].
  • .rsrc section contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely the PyInstaller default icon or a reused icon from the build pipeline ^[binwalk.txt:9] ^[pefile.txt:159-177].

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15

  1. Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
  2. Write a Python script (ftpcrack.py) that combines ftplib.FTP brute-force scanning with subprocess.Popen to deploy xmrig.exe and a config.json.
  3. Build: pyinstaller --onefile --windowed ftpcrack.py
  4. Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with 78 da headers.
  5. Decompress overlay with python -m zlib or binwalk -e to recover the embedded .pyc and python27.dll.

Deployable Signatures

YARA rule

rule pyinstaller_sep2018_hybrid_ftpcrack_xmrig
{
    meta:
        description = "PyInstaller Sep 2018 cluster sibling with hybrid ftpcrack+xmrig payload"
        author = "Demetrian Titus"
        date = "2026-08-10"
        sha256 = "2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3"
    strings:
        $pyi1 = "PyInstaller: " ascii
        $pyi2 = "_MEIPASS" ascii
        $pyi3 = "Failed to get address for Py_Initialize" ascii
        $zlib = { 78 da }
        $ftpcrack = "ftpcrack.py" ascii
        $xmrig = "xmrig.exe" ascii
        $stratum = "stratum" ascii
        $linktxt = "link.txt" ascii
        $config = "config.json" ascii
        $userdic = "USER_DIC" ascii
        $passdic = "PASSWORD_DIC" ascii
    condition:
        uint16(0) == 0x5A4D and
        3 of ($pyi*) and
        $zlib and
        $ftpcrack and
        $xmrig and
        any of ($stratum, $linktxt, $config) and
        any of ($userdic, $passdic)
}

Sigma rule

title: PyInstaller Hybrid FTPCrack+XMRig Execution
status: experimental
description: Detects execution of Sep 2018 PyInstaller cluster binaries that deploy both FTP brute-force and XMRig miner payloads
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - '_MEI'
            - 'xmrig.exe'
            - 'config.json'
    selection2:
        CommandLine|contains:
            - 'ftpcrack.py'
            - 'link.txt'
    condition: selection or selection2
falsepositives:
    - None expected; xmrig.exe in _MEI temp path is highly suspicious
level: high

IOC list

Indicator Value Type
SHA-256 2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3 Hash
Module name ftpcrack.py String
Embedded binary xmrig.exe Filename
Config file config.json Filename
Pool config link.txt Filename
Temp path %TEMP%\_MEI<XXXX> Path
Runtime DLL python27.dll Filename
Compile timestamp 2018-09-04 14:43:33 UTC Timestamp

Behavioural fingerprint

This binary is a PyInstaller single-file PE (MSVC 14.0, Sep 2018) that extracts a Python 2.7 runtime and payload to %TEMP%\_MEI<XXXX>. The payload module is ftpcrack.py and performs two distinct malicious behaviours: (1) multi-threaded FTP credential spraying against randomly-generated IP addresses using built-in dictionaries (USER_DIC / PASSWORD_DIC), and (2) XMRig cryptocurrency miner deployment via taskkill /F /IM xmrig.exe followed by copy /y xmrig.exe and config.json staging. Network surface includes ICMP host discovery, FTP banner detection, and Stratum/TCP mining pool communication.

Detection Signatures

  • PE_File_Generic (YARA) ^[yara.txt]
  • capa signatures unavailable (missing installation) ^[capa.txt]
  • floss decoding unavailable (argument error) ^[floss.txt]

References

  • coinminer — entity page for the broader PyInstaller cluster
  • ftpcrack — entity page for the FTP brute-force sub-cluster
  • /intel/analyses/801fbba19b4d4828191e87e7311480deaf81e84482dab70adf38d61afd01c1fa.html — First confirmed PyInstaller coinminer sibling
  • /intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — ftpcrack sibling with AES-encrypted overlay
  • /intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html — Largest plain-zlib coinminer sibling (5.98 MB)

Provenance

Analysis derived from static artefacts in wiki/wiki/raw/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3/: file.txt, exiftool.json, pefile.txt, rabin2-info.txt, strings.txt, binwalk.txt, yara.txt, triage.json, metadata.json, floss.txt (tool error), capa.txt (tool error). Overlay decompression performed via Python zlib against raw offset 0x3CE00. Radare2 analysis (level 2, 930 functions) on entry0, main, and fcn.00402520. CAPE sandbox unavailable — no Windows guest. Report written 2026-08-10.