typeanalysisfamilycoinminerconfidencehighcreated2026-09-05updated2026-09-05malware-familycryptominerimpactdefense-evasionpepython-pyinstallercompiler
SHA-256: 727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7

coinminer: 727e89ed — Twenty-ninth PyInstaller sibling, 15 zlib streams, AES-encrypted hybrid ftpcrack+xmrig payload

Executive Summary

The twenty-ninth confirmed sibling in the Sep 2018 PyInstaller coinminer cluster. A 1.2 MB PE32 GUI bootloader (MSVC 14.0) carries an AES-encrypted zlib overlay (79.7% of file) with 15 compressed streams — among the lowest stream counts in the cluster. Decompressed payload contains both ftpcrack.py FTP brute-force credential dictionaries and XMRig miner deployment artefacts (config.json, link.txt, stratum pool config), confirming the hybrid delivery model. Same weak QWERTY-derived AES key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path as all prior siblings.

What It Is

Field Value
SHA-256 727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7
Size 1,228,650 bytes (1.17 MB) ^[file.txt]
Type PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections ^[file.txt]
Compiler MSVC 14.0 (Visual Studio 2015), LinkerVersion 14.0 ^[pefile.txt:45]
Timestamp Tue Sep 4 14:43:33 2018 UTC (0x5B8E9A15) ^[pefile.txt:34]
Subsystem Windows GUI ^[pefile.txt:67]
ASLR / DEP Enabled (DllCharacteristics: DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:74]
Signed No ^[rabin2-info.txt:27]
Overlay 979,306 bytes starting at 0x3CE00 (79.7% of file) ^[manual:overlay-analysis]
Overlay encryption AES (PyInstaller pyimod00_crypto_key) ^[decompressed-overlay:stream_00]
AES key 1qazxsw23edcvfrN (QWERTY-derived) ^[decompressed-overlay:stream_00]
Build path F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt ^[decompressed-overlay:stream_00]
Zlib streams 15 ^[manual:overlay-analysis]

Family attribution: high-confidence coinminer via OpenCTI label and cluster membership. This sample is a confirmed hybrid ftpcrack+xmrig payload, same morph as siblings 2727eb40, c0bc0bff, bc206453, 6c321d46, 0f0dbe32, and e2b273fa. See coinminer for cluster overview.

How It Works

1. PyInstaller bootloader extraction (static-only inference)

The outer PE is a PyInstaller single-file C bootloader ^[strings.txt:111-245]. On execution it would:

  1. Extract the AES-encrypted CFFI archive from the overlay to a _MEI* temp directory ^[strings.txt:115]
  2. Decrypt each zlib-compressed stream with the embedded AES key 1qazxsw23edcvfrN ^[decompressed-overlay:stream_00]
  3. Decompress and stage Python runtime DLLs (python27.dll, _ctypes.pyd, etc.) and the payload scripts ^[decompressed-overlay:streams_08-14]
  4. Launch the embedded Python interpreter to execute ftpcrack.py and the XMRig miner staging logic ^[decompressed-overlay:stream_06]

2. Hybrid payload — ftpcrack + xmrig

Decompressed stream 6 (ftpcrack.py compiled module) contains both FTP brute-force logic and XMRig miner deployment strings:

  • FTP brute-force: USER_DIC, PASSWORD_DIC, RANDOM_IP_POOL, ICMP host discovery, GET / HTTP/1.1 banner grab, multi-threaded credential spray ^[decompressed-overlay:stream_06]
  • Built-in password dictionary: 123456, password, admin123, P@ssw0rd, {user}123, 1qaz2wsx, etc. ^[decompressed-overlay:stream_06]
  • XMRig deployment: xmrig.exe, config.json, link.txt, stratum pool config, taskkill /F /IM xmrig.exe (self-update / restart logic) ^[decompressed-overlay:stream_06]
  • Upgrade bat script: @echo off\nif not exist [...]\ntaskkill /F /IM xmrig.exe\nping -n 3 127.0.0.1>nul\ncopy /y [...]\ndel upgrade.bat ^[decompressed-overlay:stream_06]

3. Embedded Windows service masquerade

Stream 6 also contains Application Support State ftp Service and Application State ftp Services strings — a Windows service wrapper name used for persistence / background execution masquerade ^[decompressed-overlay:stream_06].

Decompiled Behavior

No Ghidra/radare2 deep disassembly required — the threat logic is entirely in the Python payload within the overlay. The C bootloader is the standard PyInstaller runtime stub (see pyinstaller-bootloader). Static analysis of the overlay streams is sufficient.

C2 Infrastructure

No hardcoded C2 IPs or domains recoverable from static strings. The mining pool configuration is stored in config.json and link.txt inside the AES-encrypted overlay, which we decrypt but whose full runtime pool URLs are not visible in the outer binary. The stratum protocol and tcp:// scheme are referenced in the decompressed payload ^[decompressed-overlay:stream_06], but specific pool addresses are runtime-resolved from the embedded config files.

Interesting Tidbits

  1. Lowest zlib-stream count in the AES-encrypted hybrid sub-cluster: Only 15 streams versus 176 in sibling e2b273fa, 139 in 0f0dbe32, and 155 in c0bc0bff. This suggests a leaner payload bundle or a different PyInstaller build configuration. ^[manual:overlay-analysis]

  2. Smallest AES-encrypted hybrid sibling by file count: At 1.2 MB it is smaller than e019096c (1.18 MB, 8 streams, also AES) but with nearly double the stream count, indicating smaller per-stream compression blocks. ^[manual:overlay-analysis]

  3. Same QWERTY key, same build path: The pyimod00_crypto_key.pyt module in stream 0 carries the identical weak key 1qazxsw23edcvfrN and the F:\files\ftp\crack\exe\build\ftpcrack\ path seen in every AES-encrypted sibling since 359fcf01. The operator has not rotated this key in eight years. ^[decompressed-overlay:stream_00]

  4. No python27.dll in outer strings.txt: Unlike some older siblings, this binary does not leak the Python runtime DLL name in the outer PE strings — the runtime is entirely inside the AES-encrypted overlay. Minor opsec improvement. ^[strings.txt:grep]

  5. Overlay ratio anomaly: At 79.7% overlay this is lower than most cluster siblings (typically 88-96%). The smaller ratio is consistent with a leaner payload or fewer embedded dependencies. ^[manual:overlay-analysis]

How To Mess With It (Homelab Replication)

  1. Build an XMRig miner + ftpcrack.py brute-force scanner in Python 2.7.
  2. Package with PyInstaller 3.x on Windows: pyinstaller --onefile --key 1qazxsw23edcvfrN ftpcrack.py
  3. The --key flag enables AES encryption of the CFFI archive with the specified password.
  4. Observe the resulting PE carries the same MSVC 14.0 timestamp pattern and zlib-overlay structure.
  5. Verify: extract overlay, attempt zlib decompression — it should fail without AES decryption. Use the known key to decrypt each block, then zlib-decompress.

Deployable Signatures

YARA rule

rule PyInstallerBootloader_AESCoinminer_2018_QwertyKey {
    meta:
        description = "PyInstaller single-file bootloader with AES-encrypted coinminer payload (2018 cluster, weak QWERTY-derived key)"
        author = "PacketPursuit"
        date = "2026-09-05"
        hash = "727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7"
    strings:
        $pyi1 = "PyInstaller: FormatMessageW failed." ascii
        $pyi2 = "PyInstaller: pyi_win32_utils_to_utf8 failed." ascii
        $pyi3 = "_MEIPASS2" ascii
        $pyi4 = "pyi-windows-manifest-filename" ascii
        $aes_key = "1qazxsw23edcvfrN" ascii
        $build_path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii wide
        $xmrig = "xmrig.exe" ascii
        $taskkill = "taskkill /F /IM xmrig.exe" ascii
        $stratum = "stratum" ascii
        $config = "config.json" ascii
        $link = "link.txt" ascii
        $upgrade_bat = "upgrade.bat" ascii
        $ftp_userdic = "USER_DIC" ascii
        $ftp_passdic = "PASSWORD_DIC" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 2MB and
        3 of ($pyi*) and
        ($aes_key or $build_path) and
        (2 of ($xmrig, $taskkill, $stratum, $config, $link, $upgrade_bat, $ftp_userdic, $ftp_passdic))
}

Sigma rule

title: PyInstaller AES Coinminer Execution — XMRig Self-Update
description: Detects XMRig miner process kill-and-restart pattern typical of the 2018 PyInstaller coinminer cluster
logsource:
    category: process_creation
    product: windows
detection:
    selection_taskkill:
        CommandLine|contains:
            - 'taskkill /F /IM xmrig.exe'
    selection_copy:
        CommandLine|contains:
            - 'copy /y'
            - 'xmrig.exe'
    selection_ping:
        CommandLine|contains:
            - 'ping -n 3 127.0.0.1>nul'
    selection_bat:
        CommandLine|endswith:
            - 'upgrade.bat'
    condition: selection_taskkill or (selection_copy and selection_ping) or selection_bat
falsepositives:
    - Legitimate cryptocurrency miners with poor update hygiene
level: high

IOC list

Indicator Value Type
SHA-256 727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7 Hash
AES key 1qazxsw23edcvfrN Encryption key
Build path F:\files\ftp\crack\exe\build\ftpcrack\ Build artefact
Embedded exe xmrig.exe Payload binary
Config file config.json Runtime config
Pool config link.txt Pool URL staging
Upgrade script upgrade.bat Self-update batch
Service name Application Support State ftp Service Persistence masquerade
Temp prefix _MEI* PyInstaller extraction directory
Mutex / pipe None observed statically —
Registry keys None observed statically —

Behavioral fingerprint

This binary is a PyInstaller single-file PE32 GUI executable (MSVC 14.0, Sep 2018 timestamp) that extracts an AES-encrypted zlib-compressed CFFI archive to a _MEI* temporary directory using a weak QWERTY-derived AES key. The archive contains both an FTP brute-force credential scanner (ftpcrack.py) and XMRig cryptocurrency miner deployment logic. At runtime it creates config.json and link.txt pool configuration files, launches xmrig.exe, and uses a self-updating batch script (upgrade.bat) that kills the miner process, copies a new binary, and restarts. The operator has reused the same AES key and build path across at least 29 siblings spanning eight years.

Detection Signatures

ATT&CK Technique Evidence Source
T1059.006 (Python) PyInstaller bootloader + embedded Python 2.7 runtime ^[strings.txt:118-245]
T1074.001 (Data Staged: Local Data Staging) Extraction to _MEI temp directory ^[strings.txt:115]
T1105 (Ingress Tool Transfer) Self-contained payload delivery in overlay ^[manual:overlay-analysis]
T1496 (Resource Hijacking) XMRig miner deployment (xmrig.exe, stratum, config.json) ^[decompressed-overlay:stream_06]
T1110.001 (Brute Force: Password Guessing) FTP credential spraying from embedded dictionaries ^[decompressed-overlay:stream_06]
T1046 (Network Service Scanning) Random IP generation and FTP banner detection ^[decompressed-overlay:stream_06]
T1574.002 (DLL Side-Loading) Loading Python DLL from _MEI path ^[decompressed-overlay:streams_08-14]
T1543.003 (Create or Modify System Process: Windows Service) Application Support State ftp Service masquerade ^[decompressed-overlay:stream_06]

References

Provenance

Analysis derived from:

  • file.txt (file(1) output)
  • pefile.txt (pefile library dump)
  • strings.txt (strings extraction)
  • rabin2-info.txt (radare2 header summary)
  • Manual overlay analysis: Python zlib decompression of AES-decrypted PyInstaller CFFI archive streams extracted at offset 0x3CE00
  • Tool versions: Python 3.12, pefile 2023.x, radare2 5.x, pyinstxtractor (git HEAD 2026-09-05)