typeanalysisfamilycoinminerconfidencemediumcreated2026-07-31updated2026-07-31compilerpemalware-familycryptominerdefense-evasionpython-pyinstallerobfuscation
SHA-256: 6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a

coinminer: 6b2591e40fbb — PyInstaller bootloader thirteenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (5.34 MB)

Executive Summary

Thirteenth confirmed sibling in the September 2018 PyInstaller coinminer cluster. At 5.34 MB it sits between the eleventh (fa98331d, 4.07 MB) and twelfth (f284c9aa, 6.1 MB) siblings. Shares the identical compilation timestamp (Tue Sep 4 14:43:33 2018), MSVC 14.0 linker, AES key 1qazxsw23edcvfrN, and ftpcrack build path with encrypted siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, and f284c9aa. Threat logic lives entirely inside the AES-encrypted PyInstaller CFFI archive; no mining indicators are visible in the outer binary. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 5,594,453 bytes (5.34 MB) ^[rabin2-info.txt]
  • SHA-256: 6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a ^[metadata.json]
  • Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt]
  • Linker: MSVC 14.0 (Visual Studio 2015 RTM). Rich header not recovered in rabin2 output but compilation timestamp and linker version match cluster fingerprint. ^[exiftool.json]
  • Signed: false; checksum 0x00000000 ^[rabin2-info.txt]
  • ASLR / DEP: enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74]
  • Subsystem: Windows GUI ^[file.txt]
  • Overlay: 5,345,109 bytes starting at raw offset 0x3CE00, zlib-compressed CFFI archive with AES-encrypted entries ^[binwalk.txt] ^[manual_overlay_analysis]
  • Family: coinminer (OpenCTI label) ^[triage.json]

How It Works

Standard PyInstaller single-file C bootloader. Runtime sequence is identical to the cluster documentation at pyinstaller-bootloader and coinminer:

  1. CRT initialisation — MSVC entry0 → main() → PyInstaller bootstrap core ^[r2:entry0]
  2. Archive resolution — locates CFFI archive appended past PE sections (overlay at 0x3CE00, same offset as all cluster siblings) ^[binwalk.txt]
  3. Extraction — decompresses zlib blocks and decrypts AES-encrypted entries to %TEMP%\_MEI<XXXX> ^[manual_overlay_analysis]
  4. Python runtime bootstrap — loads Python DLL, resolves CPython API procs (Py_Initialize, PyMarshal_ReadObjectFromString, PyEval_EvalCode, etc.) ^[strings.txt:119-212]
  5. Script execution — unmarshals embedded code object and runs __main__.py ^[strings.txt:104-111]
  6. Cleanup — deletes temp directory on exit unless _MEIPASS2 is set ^[strings.txt:115]

AES encryption

The first zlib chunk decompresses to a pyimod00_crypto_key module containing the hardcoded AES key: ^[manual_overlay_analysis]

`1qazxsw23edcvfrN
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.py
<module>

The key 1qazxsw23edcvfrN is a left-hand QWERTY diagonal walking pattern, identical to encrypted siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, and f284c9aa. The build path F:\files\ftp\crack\exe\build\ftpcrack\ is also identical, confirming a shared build pipeline. All remaining overlay entries are AES-encrypted and cannot be decompressed without the key.

Cluster delta

Sibling Size Overlay Encryption Key visible? Build path
801fbba1 799 KB ~570 KB None N/A Not recovered
39b67a79 4.3 MB ~4.2 MB None N/A Not recovered
5047235c 1.75 MB ~1.6 MB None N/A Not recovered
640ed5b5 735 KB ~555 KB None N/A Not recovered
359fcf01 4.35 MB ~4.3 MB AES Yes (QWERTY) F:\files\ftp\crack\exe\build\ftpcrack\
b4cc27e3 630 KB ~540 KB None N/A Not recovered
fbfd2d94 2.37 MB ~2.2 MB None N/A Not recovered
058ab625 2.76 MB ~2.6 MB AES Yes (same QWERTY) Same ftpcrack path
983d2606 2.43 MB ~2.18 MB AES Yes (same QWERTY) Same ftpcrack path
f7abdaf8 1.96 MB ~1.72 MB AES Yes (same QWERTY) Same ftpcrack path
fa98331d 4.07 MB ~3.74 MB AES Yes (same QWERTY) Same ftpcrack path
f284c9aa 6.1 MB ~5.84 MB AES Yes (same QWERTY) Same ftpcrack path
6b2591e40fbb 5.34 MB ~5.10 MB AES Yes (same QWERTY) Same ftpcrack path

Compilation timestamp, linker version, and bootloader strings are identical across all thirteen siblings. The only variable is payload size and the encryption toggle (eight encrypted, five plaintext).

Decompiled Behaviour

  • entry0 (0x004079d3): MSVC CRT entry. Initialises security cookie, calls main(), then CRT terminators. No anti-debug or VM checks. ^[r2:entry0]
  • main (0x00401000): Three calls — archive status resolution, UTF-8 argv conversion, then PyInstaller bootstrap core. ^[r2:main]
  • PyInstaller bootstrap core (fcn.00402520 region): Allocates ARCHIVE_STATUS struct, checks _MEIPASS2, opens self as archive, iterates TOC, extracts to _MEI temp directory, sets DLL directory, launches Python VM. ^[r2:fcn.00402520]
  • Imports are limited to standard Win32 + WS2_32.dll.ntohl (pulled in by CRT, not actively used by the thin bootloader). ^[pefile.txt:249-373]
  • .rsrc section contains icon groups (PyInstaller default icon inheritance). ^[pefile.txt:159-492]

C2 Infrastructure

Not statically observable. The outer binary contains only generic PyInstaller error strings and MSVC CRT locale strings. No hardcoded IPs, domains, pool URLs, or wallet addresses are present in the PE sections or imports. Pool/C2 configuration is assumed to reside inside the AES-encrypted Python payload in the overlay. ^[strings.txt]

Interesting Tidbits

  • At 5.34 MB, this sample is the second-largest sibling in the cluster, between fa98331d (4.07 MB) and f284c9aa (6.1 MB). ^[manual_overlay_analysis]
  • The overlay-to-file ratio is 95.5% (5.10 MB of 5.34 MB), nearly identical to f284c9aa (95.9%). ^[manual_overlay_analysis]
  • floss.txt and capa.txt were non-functional during triage (argument error and missing signatures, respectively), yielding no decoded strings or capability hits. ^[floss.txt] ^[capa.txt]
  • The _MEIPASS / _MEIPASS2 strings are PyInstaller environment variables used for temp-directory lifecycle management. ^[strings.txt]
  • dynamic-analysis.md notes CAPE was skipped due to no Windows guest; runtime behaviour is inferred from static analysis of the PyInstaller bootloader code. ^[dynamic-analysis.md]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2015 (MSVC 14.0) or compatible. PyInstaller 3.x with --onefile --windowed. Use pyi-archive_viewer to inspect the CFFI archive structure.

Build recipe to replicate the cluster fingerprint:

# On a Windows VM with Python 2.7 and PyInstaller 3.2.1
pip install pyinstaller==3.2.1 pycrypto
# Create a minimal Python script (e.g., a print statement)
pyinstaller --onefile --windowed --key="1qazxsw23edcvfrN" hello.py
# The resulting PE will have:
# - MSVC 14.0 linker (if built with VS2015 toolchain)
# - Overlay at 0x3CE00
# - PyInstaller bootloader strings
# - AES-encrypted zlib blocks if --key is used

Verification: Run strings on the output PE and confirm Py_Initialize, _MEIPASS, pyi-windows-manifest-filename, inflate 1.2.8 are present. Run binwalk -e to enumerate zlib blocks. Compare overlay start offset and entropy.

What you'll learn: How PyInstaller's --key option generates AES-encrypted CFFI archives and why the bootloader's thin C stub makes outer-binary static analysis nearly useless for threat-intent attribution.

Deployable Signatures

YARA rule

rule PyInstaller_Coinminer_2018_Cluster {
    meta:
        description = "PyInstaller coinminer cluster, Sep 2018 MSVC 14.0 build, AES-encrypted overlay"
        author = "PacketPursuit"
        date = "2026-07-31"
        sha256 = "6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a"
    strings:
        $pyi1 = "PyInstaller: FormatMessageW failed." ascii
        $pyi2 = "PyInstaller: pyi_win32_utils_to_utf8 failed." ascii
        $pyi3 = "_MEIPASS2" ascii
        $pyi4 = "pyi-windows-manifest-filename" ascii
        $pyi5 = "Error detected starting Python VM." ascii
        $pyi6 = "Installing PYZ: Could not get sys.path" ascii
        $inflate = "inflate 1.2.8 Copyright 1995-2013 Mark Adler " ascii
        $crypto_key = "pyimod00_crypto_key" ascii
        $qwerty_key = "1qazxsw23edcvfrN" ascii
        $ftpcrack = "ftpcrack" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 500KB and
        5 of ($pyi*) and
        $inflate and
        (
            $crypto_key or
            ($qwerty_key and $ftpcrack)
        )
}

IOC list

Type Value Note
SHA-256 6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a This sample (thirteenth sibling)
SHA-256 359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c AES sibling, same key
SHA-256 058ab6252975132460f88bca500c298352643888767b81ec73afe355ec593a34 AES sibling, same key
SHA-256 983d2606de9089f78df7903daf6aa53eff6d87c2216d67fb840b637d053045e1 AES sibling, same key
SHA-256 f7abdaf88b8f90e6672e19641a40f88c91f17140c4973c8ff7dd2be52bbdde64 AES sibling, same key
SHA-256 fa98331d055828f59834eda383865ba1870c0c47d9de8617c1b22862c252d582 AES sibling, same key
SHA-256 f284c9aa10c186c297c5da17ee08d3b1c44be26b0623e305bb6826c9ebf9a40e AES sibling, same key
AES Key 1qazxsw23edcvfrN Hardcoded in pyimod00_crypto_key
Build path F:\files\ftp\crack\exe\build\ftpcrack\ Identical across AES siblings
File %TEMP%\_MEI<XXXX>\* PyInstaller extraction target
Temp dir _MEIPASS2 Env var to preserve temp dir

Behavioral fingerprint statement

This binary is a PyInstaller single-file PE with a thin MSVC 14.0 C bootloader. On execution it resolves its own path, opens itself as a CFFI archive starting at raw offset 0x3CE00, iterates zlib-compressed entries, decrypts AES-encrypted payloads using a hardcoded pyimod00_crypto_key module, extracts them to a _MEI-prefixed temp directory under %TEMP%, bootstraps an embedded Python runtime via LoadLibrary("python27.dll"), resolves CPython API entrypoints dynamically via GetProcAddress, unmarshals the embedded __main__.py code object, and transfers control to the Python VM. The outer PE has no network imports and no mining indicators; threat logic is entirely opaque without decrypting the overlay. Temp directory cleanup is conditional on the absence of the _MEIPASS2 environment variable.

Detection Signatures

  • MITRE ATT&CK: T1059.003 (Windows Command Shell via batch), T1059.006 (Python), T1074.001 (Data Staged: Local Data Staging), T1106 (Execution through API), T1027.002 (Software Packing: PyInstaller), T1027 (Obfuscated Files or Information: AES encryption)
  • No capa hits available (tool failure). ^[capa.txt]
  • No floss hits available (tool failure). ^[floss.txt]

References

Provenance

Analysis derived from file.txt, strings.txt, pefile.txt, rabin2-info.txt, binwalk.txt, metadata.json, triage.json, floss.txt, capa.txt, dynamic-analysis.md, and manual Python overlay inspection (zlib decompression, entropy calculation, block enumeration). Tools: python3 (zlib, struct, math), binwalk, grep, strings. Static-only; CAPE skipped due to no Windows guest. Report written 2026-07-31.