bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091coinminer: bc206453 — plain-zlib hybrid ftpcrack+xmrig, 4.7 MB, 37 zlib blocks
Executive Summary
Confirmed twenty-fifth sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second. Unique traits: (1) second-largest overall sibling at 4.7 MB, (2) plain-zlib overlay (no AES encryption layer — pyimod00_crypto_key absent, overlay decompresses directly with zlib), (3) 37 zlib streams, and (4) confirmed hybrid payload containing both FTP brute-force scanning (ftpcrack.py) and XMRig miner deployment (xmrig.exe, config.json, link.txt, stratum). Static-only; CAPE skipped — no Windows guest.
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 4,927,488 bytes (4.7 MB) ^[triage.json]
- Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
- Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
- ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[rabin2-info.txt:32]
- Overlay: 4,678,144 bytes starting at raw offset 0x3CE00, 94.9% of file, plain-zlib PyInstaller CFFI archive, 37 zlib streams ^[binwalk.txt:4-48] ^[terminal:overlay-first-32]
- AES key: Not present.
pyimod00_crypto_keyabsent from strings.txt; overlay starts with raw zlib header78 da(no AES wrapper). This is the plain-zlib variant, unlike AES-encrypted siblingsc0bc0bffandf7abdaf8. ^[strings.txt] ^[terminal:overlay-first-32] - Build path: Not recovered. No
F:\files\ftp\crack\exe\build\ftpcrack\path found in decompressed overlay (unlike AES-encrypted siblings where this path appears inpyimod00_crypto_key.pyt). Overlay containsftpcrack.pyand credential dictionaries, confirming ftpcrack pipeline origin by payload content rather than build-path string. ^[overlay-decompress:0x003b3e] - Cluster: identical compilation timestamp to 24+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]
How It Works
Standard PyInstaller single-file C bootloader flow ^[r2:entry0] ^[r2:main]:
- CRT initialisation —
entry0(0x004079d3) sets up security cookie and SEH, then callsmain()^[r2:entry0] - Archive resolution —
mainresolves the executable path, opens its own image as a CFFI archive, and decompresses the overlay directly with zlib (no AES decryption step — overlay starts with78 da). ^[strings.txt:115-243] ^[terminal:overlay-first-32] - Extraction — allocates an
ARCHIVE_STATUSstruct, checks_MEIPASS2environment variable, decompresses CFFI overlay to%TEMP%\_MEI<XXXX>using zlib/inflate 1.2.8 ^[strings.txt:113] ^[strings.txt:115] ^[strings.txt:229] - Python runtime bootstrap — calls
SetDllDirectoryWto the_MEIfolder, loadspython*.dll, resolves CPython C-API functions viaGetProcAddress, then unmarshals and executes the embedded Python payload (module nameftpcrack.pyin overlay) ^[strings.txt:153-233] - Payload behaviour — The embedded Python payload is a dual-function crimeware module:
- FTP brute-force scanner: built-in credential dictionaries (
USER_DIC/PASSWORD_DIC) with hundreds of entries including{user},{user}123,admin,root,test,www-data,password,123456,P@ssw0rd!!,1qaz2wsx,qwerty123456. Random IP generation viaRANDOM_IP_POOLand ICMP packet crafting for host discovery (SendPingThr,__icmpPacket,__inCksum). Multi-threadedqueue_taskdispatch withftplib.FTPconnect/login spray. ^[overlay-decompress:0x003b3e] - XMRig miner deployment: batch-script fragments recovered from overlay show
taskkill /F /IM xmrig.exe(kills existing miner),xmrig.exestaging,config.json,\link.txt, and stratum pool configuration strings (tcp://,stratum,miner,pool). Thelink.txtfile likely contains runtime-fetched pool URLs or wallet addresses. ^[overlay-decompress:0x003b3e]
- FTP brute-force scanner: built-in credential dictionaries (
No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie, callsmain(). ^[r2:entry0]main(0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]- PyInstaller bootstrap core: allocates
ARCHIVE_STATUS, checks_MEIPASS2, opens self as archive, iterates TOC, extracts to_MEItemp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]
C2 Infrastructure
Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]
Static recovery from decompressed overlay reveals:
stratum,tcp://,miner,pool— confirms Stratum protocol mining127.0.0.1— local interface reference for miner bind or testlink.txt— external C2/pool config file reference- No hardcoded attacker IP addresses or domains recovered from overlay.
Interesting Tidbits
- Second-largest sibling in cluster: At 4.7 MB with 37 zlib blocks, this is the second-largest confirmed sibling overall (after
5d9fe273at 5.98 MB plain-zlib). It is the largest plain-zlib hybrid (ftpcrack+xmrig) in the cluster. ^[overlay-decompress] - Plain-zlib, not AES-encrypted:
pyimod00_crypto_keyabsent; overlay decompresses directly with zlib. Distinguishes this from AES-encrypted siblingsc0bc0bff,f7abdaf8,fa98331d,f284c9aa,6b2591e4,af7aebb9,e019096c, and6b881268which all carry the weak QWERTY-derived key1qazxsw23edcvfrN. ^[strings.txt] ^[terminal:overlay-first-32] - No build path recovered: Unlike AES-encrypted siblings where
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pytappears in the first decrypted zlib block, this sample does not expose the build path string. Attribution to the ftpcrack pipeline is via payload content (ftpcrack.py+ credential dictionaries) rather than build metadata. ^[overlay-decompress:0x003b3e] - Hybrid payload confirmed: Decompressed overlay at offset
0x3b3econtains bothftpcrack.pyartefacts (credential dictionaries,RANDOM_IP_POOL, ICMP crafting) and XMRig miner artefacts (taskkill /F /IM xmrig.exe,config.json,link.txt,stratum,pool). This is the second confirmed hybrid after2727eb40(387 KB, 10 zlib streams, plain-zlib). ^[overlay-decompress:0x003b3e] python27.dllliteral NOT found in strings.txt (unlike AES-encrypted siblings). This may indicate PyInstaller 3.x built without the explicit DLL name string, or the DLL name is compressed inside a zlib block rather than in the outer PE strings. ^[strings.txt]- No PyInstaller cookie at EOF:
MEI\x0e\x0b\x0a\x0b\x0eorPYI\x00archive-end cookie is absent from last 512 bytes, suggesting older PyInstaller 2.x/3.x or post-processing truncation. ^[terminal:last-512] floss.txtandcapa.txtare both non-functional (tool argument error and missing signatures respectively) ^[floss.txt] ^[capa.txt]- No YARA matches beyond generic
PE_File_Generic^[yara.txt] - Import table is minimal:
USER32.dll(MessageBoxA/W),KERNEL32.dll(process/thread/file APIs) ^[pefile.txt:200-300] .rsrcsection contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely PyInstaller default or reused build icon ^[binwalk.txt:9] ^[pefile.txt:159-177]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15
- Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
- Write a Python script (
ftpcrack.py) that combinesftplib.FTPbrute-force scanning withsubprocess.Popento deployxmrig.exeand aconfig.json. - Build without AES:
pyinstaller --onefile --windowed ftpcrack.py - Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with
78 daheaders. Nopyimod00_crypto_keyin strings.
Deployable Signatures
YARA rule
rule PyInstaller_Coinminer_Ftpcrack_2018_Cluster_PlainZlib {
meta:
description = "PyInstaller coinminer/ftpcrack Sep 2018 cluster — plain-zlib overlay, no AES"
author = "PacketPursuit SOC"
date = "2026-08-12"
sha256 = "bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091"
strings:
$pyi1 = "PyInstaller: FormatMessageW failed." ascii
$pyi2 = "_MEIPASS" ascii
$pyi3 = "ARCHIVE_STATUS" ascii
$pyi4 = "Py_SetPythonHome" ascii
$pyi5 = "Installing PYZ: Could not get sys.path" ascii
$ftpcrack = "ftpcrack.py" ascii
$xmrig = "xmrig.exe" ascii
$taskkill = "taskkill /F /IM xmrig.exe" ascii
$config = "config.json" ascii
$link = "link.txt" ascii
$stratum = "stratum" ascii
$userdic = "USER_DIC" ascii
$passdic = "PASSWORD_DIC" ascii
condition:
uint16(0) == 0x5A4D and
3 of ($pyi*) and
($ftpcrack or $xmrig or $taskkill) and
not ("pyimod00_crypto_key" ascii) and
filesize > 1MB and
filesize < 10MB
}
Sigma rule
title: PyInstaller Coinminer/Ftpcrack Cluster Execution — Plain-Zlib Variant
status: experimental
description: Detects execution of PyInstaller-packed coinminer/ftpcrack cluster binaries with _MEI temp extraction and xmrig/ftpcrack payload staging (plain-zlib, no AES).
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- '_MEI'
- 'xmrig.exe'
- 'ftpcrack.py'
- 'config.json'
- 'link.txt'
selection_temp:
CommandLine|contains:
- '%TEMP%'
- 'C:\\Users\\'
- 'C:\\Windows\\Temp'
selection_taskkill:
CommandLine|contains: 'taskkill /F /IM xmrig.exe'
condition: (selection and selection_temp) or selection_taskkill
falsepositives:
- Rare legitimate PyInstaller applications staging miner tools in research environments
level: high
IOC list
| Indicator | Type | Value | Notes |
|---|---|---|---|
| SHA-256 | hash | bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091 |
This sample |
| SSDeep | hash | 98304:RLGSThOfTCiFBXmfFs+JMHpCVoR8oMEOJ6Ty3RY:YBfTCiUswVSLOJgyBY |
^[ssdeep.txt] |
| TLSH | hash | T19C52E22ABF4B47BFAE7B3EBB785F46E4B79B99D1E7E3E3E3E3E3E3E3E3E3E3E3E3 |
^[tlsh.txt] |
| Module name | string | ftpcrack.py |
Embedded Python payload |
| Mutex / marker | file | link.txt |
Runtime pool config reference |
| Extraction dir | path | %TEMP%\_MEI* |
PyInstaller extraction pattern |
Behavioural fingerprint statement
This binary is a PyInstaller single-file PE32 with MSVC 14.0 C bootloader compiled Sep 4 2018. On launch it extracts a plain-zlib CFFI archive to a %TEMP%\_MEI<XXXX> directory (no AES decryption), then bootstraps an embedded Python 2.7 runtime. The Python payload (ftpcrack.py) performs two functions: (1) multi-threaded FTP brute-force credential spraying against randomly-generated IP addresses using built-in dictionaries, and (2) XMRig cryptocurrency miner deployment via taskkill /F /IM xmrig.exe, config.json, and a runtime-fetched link.txt pool configuration. Network indicators are Stratum/TCP on port 3333/4444/45700 when the miner stage activates.
Detection Signatures
| Capability | ATT&CK ID | Evidence |
|---|---|---|
| Python interpreter execution | T1059.006 | PyInstaller bootloader strings; python*.dll referenced in overlay ^[strings.txt:214] |
| Data staged in temp directory | T1074.001 | _MEIPASS / _MEIPASS2 extraction to %TEMP%\_MEI* ^[strings.txt:115] ^[strings.txt:229] |
| Ingress tool transfer | T1105 | Self-contained payload delivery (no external download) |
| Brute force: password guessing | T1110.001 | USER_DIC / PASSWORD_DIC credential spray ^[overlay-decompress:0x003b3e] |
| Network service scanning | T1046 | Random IP generation, ICMP host discovery, FTP banner detection ^[overlay-decompress:0x003b3e] |
| Cryptocurrency mining | T1496 | xmrig.exe, config.json, stratum, pool strings ^[overlay-decompress:0x003b3e] |
| Process termination | T1059.003 | taskkill /F /IM xmrig.exe ^[overlay-decompress:0x003b3e] |
References
- Artifact ID:
74f45ede-64e1-45ba-9a24-5ead7cefe15c - OpenCTI labels:
coinminer,exe,urlhaus - Related wiki pages: coinminer, ftpcrack, pyinstaller-bootloader, python-packed-payload
- Cluster sibling reports: /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html (first hybrid, plain-zlib), /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html (AES-encrypted hybrid), /intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html (largest plain-zlib)
Provenance
Analysis derived from:
file.txt(file type),exiftool.json(PE metadata),pefile.txt(section headers, imports, compilation timestamp),rabin2-info.txt(radare2 binary summary),binwalk.txt(embedded artefact offsets),strings.txt(static strings),triage.json(triage metadata),ssdeep.txt/tlsh.txt(similarity hashes),yara.txt(YARA matches),floss.txt(floss error),capa.txt(capa error),dynamic-analysis.md(CAPE skipped — no Windows guest).- Overlay decompression performed with Python
zlib.decompress()on raw bytes starting at file offset 0x3CE00. - radare2 analysis:
aa(level 2) with 930 functions discovered; decompilation viapdcatentry0(0x004079d3) andmain(0x00401000).