6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6acoinminer: 6b2591e40fbb — PyInstaller bootloader thirteenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (5.34 MB)
Executive Summary
Thirteenth confirmed sibling in the September 2018 PyInstaller coinminer cluster. At 5.34 MB it sits between the eleventh (fa98331d, 4.07 MB) and twelfth (f284c9aa, 6.1 MB) siblings. Shares the identical compilation timestamp (Tue Sep 4 14:43:33 2018), MSVC 14.0 linker, AES key 1qazxsw23edcvfrN, and ftpcrack build path with encrypted siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, and f284c9aa. Threat logic lives entirely inside the AES-encrypted PyInstaller CFFI archive; no mining indicators are visible in the outer binary. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 5,594,453 bytes (5.34 MB) ^[rabin2-info.txt]
- SHA-256:
6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a^[metadata.json] - Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt]
- Linker: MSVC 14.0 (Visual Studio 2015 RTM). Rich header not recovered in rabin2 output but compilation timestamp and linker version match cluster fingerprint. ^[exiftool.json]
- Signed: false; checksum
0x00000000^[rabin2-info.txt] - ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[file.txt]
- Overlay: 5,345,109 bytes starting at raw offset
0x3CE00, zlib-compressed CFFI archive with AES-encrypted entries ^[binwalk.txt] ^[manual_overlay_analysis] - Family: coinminer (OpenCTI label) ^[triage.json]
How It Works
Standard PyInstaller single-file C bootloader. Runtime sequence is identical to the cluster documentation at pyinstaller-bootloader and coinminer:
- CRT initialisation — MSVC
entry0→main()→ PyInstaller bootstrap core ^[r2:entry0] - Archive resolution — locates CFFI archive appended past PE sections (overlay at
0x3CE00, same offset as all cluster siblings) ^[binwalk.txt] - Extraction — decompresses zlib blocks and decrypts AES-encrypted entries to
%TEMP%\_MEI<XXXX>^[manual_overlay_analysis] - Python runtime bootstrap — loads Python DLL, resolves CPython API procs (
Py_Initialize,PyMarshal_ReadObjectFromString,PyEval_EvalCode, etc.) ^[strings.txt:119-212] - Script execution — unmarshals embedded code object and runs
__main__.py^[strings.txt:104-111] - Cleanup — deletes temp directory on exit unless
_MEIPASS2is set ^[strings.txt:115]
AES encryption
The first zlib chunk decompresses to a pyimod00_crypto_key module containing the hardcoded AES key: ^[manual_overlay_analysis]
`1qazxsw23edcvfrN
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.py
<module>
The key 1qazxsw23edcvfrN is a left-hand QWERTY diagonal walking pattern, identical to encrypted siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, and f284c9aa. The build path F:\files\ftp\crack\exe\build\ftpcrack\ is also identical, confirming a shared build pipeline. All remaining overlay entries are AES-encrypted and cannot be decompressed without the key.
Cluster delta
| Sibling | Size | Overlay | Encryption | Key visible? | Build path |
|---|---|---|---|---|---|
| 801fbba1 | 799 KB | ~570 KB | None | N/A | Not recovered |
| 39b67a79 | 4.3 MB | ~4.2 MB | None | N/A | Not recovered |
| 5047235c | 1.75 MB | ~1.6 MB | None | N/A | Not recovered |
| 640ed5b5 | 735 KB | ~555 KB | None | N/A | Not recovered |
| 359fcf01 | 4.35 MB | ~4.3 MB | AES | Yes (QWERTY) | F:\files\ftp\crack\exe\build\ftpcrack\ |
| b4cc27e3 | 630 KB | ~540 KB | None | N/A | Not recovered |
| fbfd2d94 | 2.37 MB | ~2.2 MB | None | N/A | Not recovered |
| 058ab625 | 2.76 MB | ~2.6 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
| 983d2606 | 2.43 MB | ~2.18 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
| f7abdaf8 | 1.96 MB | ~1.72 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
| fa98331d | 4.07 MB | ~3.74 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
| f284c9aa | 6.1 MB | ~5.84 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
| 6b2591e40fbb | 5.34 MB | ~5.10 MB | AES | Yes (same QWERTY) | Same ftpcrack path |
Compilation timestamp, linker version, and bootloader strings are identical across all thirteen siblings. The only variable is payload size and the encryption toggle (eight encrypted, five plaintext).
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie, callsmain(), then CRT terminators. No anti-debug or VM checks. ^[r2:entry0]main(0x00401000): Three calls — archive status resolution, UTF-8 argv conversion, then PyInstaller bootstrap core. ^[r2:main]- PyInstaller bootstrap core (
fcn.00402520region): AllocatesARCHIVE_STATUSstruct, checks_MEIPASS2, opens self as archive, iterates TOC, extracts to_MEItemp directory, sets DLL directory, launches Python VM. ^[r2:fcn.00402520] - Imports are limited to standard Win32 +
WS2_32.dll.ntohl(pulled in by CRT, not actively used by the thin bootloader). ^[pefile.txt:249-373] .rsrcsection contains icon groups (PyInstaller default icon inheritance). ^[pefile.txt:159-492]
C2 Infrastructure
Not statically observable. The outer binary contains only generic PyInstaller error strings and MSVC CRT locale strings. No hardcoded IPs, domains, pool URLs, or wallet addresses are present in the PE sections or imports. Pool/C2 configuration is assumed to reside inside the AES-encrypted Python payload in the overlay. ^[strings.txt]
Interesting Tidbits
- At 5.34 MB, this sample is the second-largest sibling in the cluster, between
fa98331d(4.07 MB) andf284c9aa(6.1 MB). ^[manual_overlay_analysis] - The overlay-to-file ratio is 95.5% (5.10 MB of 5.34 MB), nearly identical to
f284c9aa(95.9%). ^[manual_overlay_analysis] floss.txtandcapa.txtwere non-functional during triage (argument error and missing signatures, respectively), yielding no decoded strings or capability hits. ^[floss.txt] ^[capa.txt]- The
_MEIPASS/_MEIPASS2strings are PyInstaller environment variables used for temp-directory lifecycle management. ^[strings.txt] dynamic-analysis.mdnotes CAPE was skipped due to no Windows guest; runtime behaviour is inferred from static analysis of the PyInstaller bootloader code. ^[dynamic-analysis.md]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2015 (MSVC 14.0) or compatible. PyInstaller 3.x with --onefile --windowed. Use pyi-archive_viewer to inspect the CFFI archive structure.
Build recipe to replicate the cluster fingerprint:
# On a Windows VM with Python 2.7 and PyInstaller 3.2.1
pip install pyinstaller==3.2.1 pycrypto
# Create a minimal Python script (e.g., a print statement)
pyinstaller --onefile --windowed --key="1qazxsw23edcvfrN" hello.py
# The resulting PE will have:
# - MSVC 14.0 linker (if built with VS2015 toolchain)
# - Overlay at 0x3CE00
# - PyInstaller bootloader strings
# - AES-encrypted zlib blocks if --key is used
Verification: Run strings on the output PE and confirm Py_Initialize, _MEIPASS, pyi-windows-manifest-filename, inflate 1.2.8 are present. Run binwalk -e to enumerate zlib blocks. Compare overlay start offset and entropy.
What you'll learn: How PyInstaller's --key option generates AES-encrypted CFFI archives and why the bootloader's thin C stub makes outer-binary static analysis nearly useless for threat-intent attribution.
Deployable Signatures
YARA rule
rule PyInstaller_Coinminer_2018_Cluster {
meta:
description = "PyInstaller coinminer cluster, Sep 2018 MSVC 14.0 build, AES-encrypted overlay"
author = "PacketPursuit"
date = "2026-07-31"
sha256 = "6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a"
strings:
$pyi1 = "PyInstaller: FormatMessageW failed." ascii
$pyi2 = "PyInstaller: pyi_win32_utils_to_utf8 failed." ascii
$pyi3 = "_MEIPASS2" ascii
$pyi4 = "pyi-windows-manifest-filename" ascii
$pyi5 = "Error detected starting Python VM." ascii
$pyi6 = "Installing PYZ: Could not get sys.path" ascii
$inflate = "inflate 1.2.8 Copyright 1995-2013 Mark Adler " ascii
$crypto_key = "pyimod00_crypto_key" ascii
$qwerty_key = "1qazxsw23edcvfrN" ascii
$ftpcrack = "ftpcrack" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 500KB and
5 of ($pyi*) and
$inflate and
(
$crypto_key or
($qwerty_key and $ftpcrack)
)
}
IOC list
| Type | Value | Note |
|---|---|---|
| SHA-256 | 6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a |
This sample (thirteenth sibling) |
| SHA-256 | 359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c |
AES sibling, same key |
| SHA-256 | 058ab6252975132460f88bca500c298352643888767b81ec73afe355ec593a34 |
AES sibling, same key |
| SHA-256 | 983d2606de9089f78df7903daf6aa53eff6d87c2216d67fb840b637d053045e1 |
AES sibling, same key |
| SHA-256 | f7abdaf88b8f90e6672e19641a40f88c91f17140c4973c8ff7dd2be52bbdde64 |
AES sibling, same key |
| SHA-256 | fa98331d055828f59834eda383865ba1870c0c47d9de8617c1b22862c252d582 |
AES sibling, same key |
| SHA-256 | f284c9aa10c186c297c5da17ee08d3b1c44be26b0623e305bb6826c9ebf9a40e |
AES sibling, same key |
| AES Key | 1qazxsw23edcvfrN |
Hardcoded in pyimod00_crypto_key |
| Build path | F:\files\ftp\crack\exe\build\ftpcrack\ |
Identical across AES siblings |
| File | %TEMP%\_MEI<XXXX>\* |
PyInstaller extraction target |
| Temp dir | _MEIPASS2 |
Env var to preserve temp dir |
Behavioral fingerprint statement
This binary is a PyInstaller single-file PE with a thin MSVC 14.0 C bootloader. On execution it resolves its own path, opens itself as a CFFI archive starting at raw offset 0x3CE00, iterates zlib-compressed entries, decrypts AES-encrypted payloads using a hardcoded pyimod00_crypto_key module, extracts them to a _MEI-prefixed temp directory under %TEMP%, bootstraps an embedded Python runtime via LoadLibrary("python27.dll"), resolves CPython API entrypoints dynamically via GetProcAddress, unmarshals the embedded __main__.py code object, and transfers control to the Python VM. The outer PE has no network imports and no mining indicators; threat logic is entirely opaque without decrypting the overlay. Temp directory cleanup is conditional on the absence of the _MEIPASS2 environment variable.
Detection Signatures
- MITRE ATT&CK: T1059.003 (Windows Command Shell via batch), T1059.006 (Python), T1074.001 (Data Staged: Local Data Staging), T1106 (Execution through API), T1027.002 (Software Packing: PyInstaller), T1027 (Obfuscated Files or Information: AES encryption)
- No capa hits available (tool failure). ^[capa.txt]
- No floss hits available (tool failure). ^[floss.txt]
References
- Artifact ID:
b94ec746-7e41-4b2e-b69f-d8dfe7cb6025^[metadata.json] - OpenCTI labels:
coinminer,exe,urlhaus^[metadata.json] - Cluster entity page: coinminer
- Technique pages: pyinstaller-bootloader, python-packed-payload
Provenance
Analysis derived from file.txt, strings.txt, pefile.txt, rabin2-info.txt, binwalk.txt, metadata.json, triage.json, floss.txt, capa.txt, dynamic-analysis.md, and manual Python overlay inspection (zlib decompression, entropy calculation, block enumeration). Tools: python3 (zlib, struct, math), binwalk, grep, strings. Static-only; CAPE skipped due to no Windows guest. Report written 2026-07-31.