727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7coinminer: 727e89ed — Twenty-ninth PyInstaller sibling, 15 zlib streams, AES-encrypted hybrid ftpcrack+xmrig payload
Executive Summary
The twenty-ninth confirmed sibling in the Sep 2018 PyInstaller coinminer cluster. A 1.2 MB PE32 GUI bootloader (MSVC 14.0) carries an AES-encrypted zlib overlay (79.7% of file) with 15 compressed streams — among the lowest stream counts in the cluster. Decompressed payload contains both ftpcrack.py FTP brute-force credential dictionaries and XMRig miner deployment artefacts (config.json, link.txt, stratum pool config), confirming the hybrid delivery model. Same weak QWERTY-derived AES key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path as all prior siblings.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7 |
| Size | 1,228,650 bytes (1.17 MB) ^[file.txt] |
| Type | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections ^[file.txt] |
| Compiler | MSVC 14.0 (Visual Studio 2015), LinkerVersion 14.0 ^[pefile.txt:45] |
| Timestamp | Tue Sep 4 14:43:33 2018 UTC (0x5B8E9A15) ^[pefile.txt:34] |
| Subsystem | Windows GUI ^[pefile.txt:67] |
| ASLR / DEP | Enabled (DllCharacteristics: DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:74] |
| Signed | No ^[rabin2-info.txt:27] |
| Overlay | 979,306 bytes starting at 0x3CE00 (79.7% of file) ^[manual:overlay-analysis] |
| Overlay encryption | AES (PyInstaller pyimod00_crypto_key) ^[decompressed-overlay:stream_00] |
| AES key | 1qazxsw23edcvfrN (QWERTY-derived) ^[decompressed-overlay:stream_00] |
| Build path | F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt ^[decompressed-overlay:stream_00] |
| Zlib streams | 15 ^[manual:overlay-analysis] |
Family attribution: high-confidence coinminer via OpenCTI label and cluster membership. This sample is a confirmed hybrid ftpcrack+xmrig payload, same morph as siblings 2727eb40, c0bc0bff, bc206453, 6c321d46, 0f0dbe32, and e2b273fa. See coinminer for cluster overview.
How It Works
1. PyInstaller bootloader extraction (static-only inference)
The outer PE is a PyInstaller single-file C bootloader ^[strings.txt:111-245]. On execution it would:
- Extract the AES-encrypted CFFI archive from the overlay to a
_MEI*temp directory ^[strings.txt:115] - Decrypt each zlib-compressed stream with the embedded AES key
1qazxsw23edcvfrN^[decompressed-overlay:stream_00] - Decompress and stage Python runtime DLLs (
python27.dll,_ctypes.pyd, etc.) and the payload scripts ^[decompressed-overlay:streams_08-14] - Launch the embedded Python interpreter to execute
ftpcrack.pyand the XMRig miner staging logic ^[decompressed-overlay:stream_06]
2. Hybrid payload — ftpcrack + xmrig
Decompressed stream 6 (ftpcrack.py compiled module) contains both FTP brute-force logic and XMRig miner deployment strings:
- FTP brute-force:
USER_DIC,PASSWORD_DIC,RANDOM_IP_POOL, ICMP host discovery,GET / HTTP/1.1banner grab, multi-threaded credential spray ^[decompressed-overlay:stream_06] - Built-in password dictionary:
123456,password,admin123,P@ssw0rd,{user}123,1qaz2wsx, etc. ^[decompressed-overlay:stream_06] - XMRig deployment:
xmrig.exe,config.json,link.txt,stratumpool config,taskkill /F /IM xmrig.exe(self-update / restart logic) ^[decompressed-overlay:stream_06] - Upgrade bat script:
@echo off\nif not exist [...]\ntaskkill /F /IM xmrig.exe\nping -n 3 127.0.0.1>nul\ncopy /y [...]\ndel upgrade.bat^[decompressed-overlay:stream_06]
3. Embedded Windows service masquerade
Stream 6 also contains Application Support State ftp Service and Application State ftp Services strings — a Windows service wrapper name used for persistence / background execution masquerade ^[decompressed-overlay:stream_06].
Decompiled Behavior
No Ghidra/radare2 deep disassembly required — the threat logic is entirely in the Python payload within the overlay. The C bootloader is the standard PyInstaller runtime stub (see pyinstaller-bootloader). Static analysis of the overlay streams is sufficient.
C2 Infrastructure
No hardcoded C2 IPs or domains recoverable from static strings. The mining pool configuration is stored in config.json and link.txt inside the AES-encrypted overlay, which we decrypt but whose full runtime pool URLs are not visible in the outer binary. The stratum protocol and tcp:// scheme are referenced in the decompressed payload ^[decompressed-overlay:stream_06], but specific pool addresses are runtime-resolved from the embedded config files.
Interesting Tidbits
-
Lowest zlib-stream count in the AES-encrypted hybrid sub-cluster: Only 15 streams versus 176 in sibling
e2b273fa, 139 in0f0dbe32, and 155 inc0bc0bff. This suggests a leaner payload bundle or a different PyInstaller build configuration. ^[manual:overlay-analysis] -
Smallest AES-encrypted hybrid sibling by file count: At 1.2 MB it is smaller than
e019096c(1.18 MB, 8 streams, also AES) but with nearly double the stream count, indicating smaller per-stream compression blocks. ^[manual:overlay-analysis] -
Same QWERTY key, same build path: The
pyimod00_crypto_key.pytmodule in stream 0 carries the identical weak key1qazxsw23edcvfrNand theF:\files\ftp\crack\exe\build\ftpcrack\path seen in every AES-encrypted sibling since359fcf01. The operator has not rotated this key in eight years. ^[decompressed-overlay:stream_00] -
No
python27.dllin outer strings.txt: Unlike some older siblings, this binary does not leak the Python runtime DLL name in the outer PE strings — the runtime is entirely inside the AES-encrypted overlay. Minor opsec improvement. ^[strings.txt:grep] -
Overlay ratio anomaly: At 79.7% overlay this is lower than most cluster siblings (typically 88-96%). The smaller ratio is consistent with a leaner payload or fewer embedded dependencies. ^[manual:overlay-analysis]
How To Mess With It (Homelab Replication)
- Build an XMRig miner +
ftpcrack.pybrute-force scanner in Python 2.7. - Package with PyInstaller 3.x on Windows:
pyinstaller --onefile --key 1qazxsw23edcvfrN ftpcrack.py - The
--keyflag enables AES encryption of the CFFI archive with the specified password. - Observe the resulting PE carries the same MSVC 14.0 timestamp pattern and zlib-overlay structure.
- Verify: extract overlay, attempt zlib decompression — it should fail without AES decryption. Use the known key to decrypt each block, then zlib-decompress.
Deployable Signatures
YARA rule
rule PyInstallerBootloader_AESCoinminer_2018_QwertyKey {
meta:
description = "PyInstaller single-file bootloader with AES-encrypted coinminer payload (2018 cluster, weak QWERTY-derived key)"
author = "PacketPursuit"
date = "2026-09-05"
hash = "727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7"
strings:
$pyi1 = "PyInstaller: FormatMessageW failed." ascii
$pyi2 = "PyInstaller: pyi_win32_utils_to_utf8 failed." ascii
$pyi3 = "_MEIPASS2" ascii
$pyi4 = "pyi-windows-manifest-filename" ascii
$aes_key = "1qazxsw23edcvfrN" ascii
$build_path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii wide
$xmrig = "xmrig.exe" ascii
$taskkill = "taskkill /F /IM xmrig.exe" ascii
$stratum = "stratum" ascii
$config = "config.json" ascii
$link = "link.txt" ascii
$upgrade_bat = "upgrade.bat" ascii
$ftp_userdic = "USER_DIC" ascii
$ftp_passdic = "PASSWORD_DIC" ascii
condition:
uint16(0) == 0x5A4D and
filesize < 2MB and
3 of ($pyi*) and
($aes_key or $build_path) and
(2 of ($xmrig, $taskkill, $stratum, $config, $link, $upgrade_bat, $ftp_userdic, $ftp_passdic))
}
Sigma rule
title: PyInstaller AES Coinminer Execution — XMRig Self-Update
description: Detects XMRig miner process kill-and-restart pattern typical of the 2018 PyInstaller coinminer cluster
logsource:
category: process_creation
product: windows
detection:
selection_taskkill:
CommandLine|contains:
- 'taskkill /F /IM xmrig.exe'
selection_copy:
CommandLine|contains:
- 'copy /y'
- 'xmrig.exe'
selection_ping:
CommandLine|contains:
- 'ping -n 3 127.0.0.1>nul'
selection_bat:
CommandLine|endswith:
- 'upgrade.bat'
condition: selection_taskkill or (selection_copy and selection_ping) or selection_bat
falsepositives:
- Legitimate cryptocurrency miners with poor update hygiene
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7 |
Hash |
| AES key | 1qazxsw23edcvfrN |
Encryption key |
| Build path | F:\files\ftp\crack\exe\build\ftpcrack\ |
Build artefact |
| Embedded exe | xmrig.exe |
Payload binary |
| Config file | config.json |
Runtime config |
| Pool config | link.txt |
Pool URL staging |
| Upgrade script | upgrade.bat |
Self-update batch |
| Service name | Application Support State ftp Service |
Persistence masquerade |
| Temp prefix | _MEI* |
PyInstaller extraction directory |
| Mutex / pipe | None observed statically | — |
| Registry keys | None observed statically | — |
Behavioral fingerprint
This binary is a PyInstaller single-file PE32 GUI executable (MSVC 14.0, Sep 2018 timestamp) that extracts an AES-encrypted zlib-compressed CFFI archive to a _MEI* temporary directory using a weak QWERTY-derived AES key. The archive contains both an FTP brute-force credential scanner (ftpcrack.py) and XMRig cryptocurrency miner deployment logic. At runtime it creates config.json and link.txt pool configuration files, launches xmrig.exe, and uses a self-updating batch script (upgrade.bat) that kills the miner process, copies a new binary, and restarts. The operator has reused the same AES key and build path across at least 29 siblings spanning eight years.
Detection Signatures
| ATT&CK Technique | Evidence | Source |
|---|---|---|
| T1059.006 (Python) | PyInstaller bootloader + embedded Python 2.7 runtime | ^[strings.txt:118-245] |
| T1074.001 (Data Staged: Local Data Staging) | Extraction to _MEI temp directory |
^[strings.txt:115] |
| T1105 (Ingress Tool Transfer) | Self-contained payload delivery in overlay | ^[manual:overlay-analysis] |
| T1496 (Resource Hijacking) | XMRig miner deployment (xmrig.exe, stratum, config.json) |
^[decompressed-overlay:stream_06] |
| T1110.001 (Brute Force: Password Guessing) | FTP credential spraying from embedded dictionaries | ^[decompressed-overlay:stream_06] |
| T1046 (Network Service Scanning) | Random IP generation and FTP banner detection | ^[decompressed-overlay:stream_06] |
| T1574.002 (DLL Side-Loading) | Loading Python DLL from _MEI path |
^[decompressed-overlay:streams_08-14] |
| T1543.003 (Create or Modify System Process: Windows Service) | Application Support State ftp Service masquerade |
^[decompressed-overlay:stream_06] |
References
- coinminer — Cluster overview and sibling catalogue
- ftpcrack — FTP brute-force scanner entity page
- pyinstaller-bootloader — PyInstaller C bootloader concept page
- python-packed-payload — Python-in-PE packaging concept page
- OpenCTI artifact ID:
c6bc74f8-61c7-4dd2-b784-354d2c32e561
Provenance
Analysis derived from:
file.txt(file(1) output)pefile.txt(pefile library dump)strings.txt(strings extraction)rabin2-info.txt(radare2 header summary)- Manual overlay analysis: Python zlib decompression of AES-decrypted PyInstaller CFFI archive streams extracted at offset 0x3CE00
- Tool versions: Python 3.12, pefile 2023.x, radare2 5.x, pyinstxtractor (git HEAD 2026-09-05)