typeanalysisfamilycoinminerconfidencemediumcreated2026-08-12updated2026-08-12compilerpemalware-familycryptominerdefense-evasionpython-pyinstallerimpact
SHA-256: bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091

coinminer: bc206453 — plain-zlib hybrid ftpcrack+xmrig, 4.7 MB, 37 zlib blocks

Executive Summary

Confirmed twenty-fifth sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second. Unique traits: (1) second-largest overall sibling at 4.7 MB, (2) plain-zlib overlay (no AES encryption layer — pyimod00_crypto_key absent, overlay decompresses directly with zlib), (3) 37 zlib streams, and (4) confirmed hybrid payload containing both FTP brute-force scanning (ftpcrack.py) and XMRig miner deployment (xmrig.exe, config.json, link.txt, stratum). Static-only; CAPE skipped — no Windows guest.

What It Is

  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 4,927,488 bytes (4.7 MB) ^[triage.json]
  • Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
  • Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
  • ASLR / DEP: enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74]
  • Subsystem: Windows GUI ^[rabin2-info.txt:32]
  • Overlay: 4,678,144 bytes starting at raw offset 0x3CE00, 94.9% of file, plain-zlib PyInstaller CFFI archive, 37 zlib streams ^[binwalk.txt:4-48] ^[terminal:overlay-first-32]
  • AES key: Not present. pyimod00_crypto_key absent from strings.txt; overlay starts with raw zlib header 78 da (no AES wrapper). This is the plain-zlib variant, unlike AES-encrypted siblings c0bc0bff and f7abdaf8. ^[strings.txt] ^[terminal:overlay-first-32]
  • Build path: Not recovered. No F:\files\ftp\crack\exe\build\ftpcrack\ path found in decompressed overlay (unlike AES-encrypted siblings where this path appears in pyimod00_crypto_key.pyt). Overlay contains ftpcrack.py and credential dictionaries, confirming ftpcrack pipeline origin by payload content rather than build-path string. ^[overlay-decompress:0x003b3e]
  • Cluster: identical compilation timestamp to 24+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]

How It Works

Standard PyInstaller single-file C bootloader flow ^[r2:entry0] ^[r2:main]:

  1. CRT initialisation — entry0 (0x004079d3) sets up security cookie and SEH, then calls main() ^[r2:entry0]
  2. Archive resolution — main resolves the executable path, opens its own image as a CFFI archive, and decompresses the overlay directly with zlib (no AES decryption step — overlay starts with 78 da). ^[strings.txt:115-243] ^[terminal:overlay-first-32]
  3. Extraction — allocates an ARCHIVE_STATUS struct, checks _MEIPASS2 environment variable, decompresses CFFI overlay to %TEMP%\_MEI<XXXX> using zlib/inflate 1.2.8 ^[strings.txt:113] ^[strings.txt:115] ^[strings.txt:229]
  4. Python runtime bootstrap — calls SetDllDirectoryW to the _MEI folder, loads python*.dll, resolves CPython C-API functions via GetProcAddress, then unmarshals and executes the embedded Python payload (module name ftpcrack.py in overlay) ^[strings.txt:153-233]
  5. Payload behaviour — The embedded Python payload is a dual-function crimeware module:
    • FTP brute-force scanner: built-in credential dictionaries (USER_DIC / PASSWORD_DIC) with hundreds of entries including {user}, {user}123, admin, root, test, www-data, password, 123456, P@ssw0rd!!, 1qaz2wsx, qwerty123456. Random IP generation via RANDOM_IP_POOL and ICMP packet crafting for host discovery (SendPingThr, __icmpPacket, __inCksum). Multi-threaded queue_task dispatch with ftplib.FTP connect/login spray. ^[overlay-decompress:0x003b3e]
    • XMRig miner deployment: batch-script fragments recovered from overlay show taskkill /F /IM xmrig.exe (kills existing miner), xmrig.exe staging, config.json, \link.txt, and stratum pool configuration strings (tcp://, stratum, miner, pool). The link.txt file likely contains runtime-fetched pool URLs or wallet addresses. ^[overlay-decompress:0x003b3e]

No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.

Decompiled Behaviour

  • entry0 (0x004079d3): MSVC CRT entry. Initialises security cookie, calls main(). ^[r2:entry0]
  • main (0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]
  • PyInstaller bootstrap core: allocates ARCHIVE_STATUS, checks _MEIPASS2, opens self as archive, iterates TOC, extracts to _MEI temp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]

C2 Infrastructure

Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]

Static recovery from decompressed overlay reveals:

  • stratum, tcp://, miner, pool — confirms Stratum protocol mining
  • 127.0.0.1 — local interface reference for miner bind or test
  • link.txt — external C2/pool config file reference
  • No hardcoded attacker IP addresses or domains recovered from overlay.

Interesting Tidbits

  • Second-largest sibling in cluster: At 4.7 MB with 37 zlib blocks, this is the second-largest confirmed sibling overall (after 5d9fe273 at 5.98 MB plain-zlib). It is the largest plain-zlib hybrid (ftpcrack+xmrig) in the cluster. ^[overlay-decompress]
  • Plain-zlib, not AES-encrypted: pyimod00_crypto_key absent; overlay decompresses directly with zlib. Distinguishes this from AES-encrypted siblings c0bc0bff, f7abdaf8, fa98331d, f284c9aa, 6b2591e4, af7aebb9, e019096c, and 6b881268 which all carry the weak QWERTY-derived key 1qazxsw23edcvfrN. ^[strings.txt] ^[terminal:overlay-first-32]
  • No build path recovered: Unlike AES-encrypted siblings where F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt appears in the first decrypted zlib block, this sample does not expose the build path string. Attribution to the ftpcrack pipeline is via payload content (ftpcrack.py + credential dictionaries) rather than build metadata. ^[overlay-decompress:0x003b3e]
  • Hybrid payload confirmed: Decompressed overlay at offset 0x3b3e contains both ftpcrack.py artefacts (credential dictionaries, RANDOM_IP_POOL, ICMP crafting) and XMRig miner artefacts (taskkill /F /IM xmrig.exe, config.json, link.txt, stratum, pool). This is the second confirmed hybrid after 2727eb40 (387 KB, 10 zlib streams, plain-zlib). ^[overlay-decompress:0x003b3e]
  • python27.dll literal NOT found in strings.txt (unlike AES-encrypted siblings). This may indicate PyInstaller 3.x built without the explicit DLL name string, or the DLL name is compressed inside a zlib block rather than in the outer PE strings. ^[strings.txt]
  • No PyInstaller cookie at EOF: MEI\x0e\x0b\x0a\x0b\x0e or PYI\x00 archive-end cookie is absent from last 512 bytes, suggesting older PyInstaller 2.x/3.x or post-processing truncation. ^[terminal:last-512]
  • floss.txt and capa.txt are both non-functional (tool argument error and missing signatures respectively) ^[floss.txt] ^[capa.txt]
  • No YARA matches beyond generic PE_File_Generic ^[yara.txt]
  • Import table is minimal: USER32.dll (MessageBoxA/W), KERNEL32.dll (process/thread/file APIs) ^[pefile.txt:200-300]
  • .rsrc section contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely PyInstaller default or reused build icon ^[binwalk.txt:9] ^[pefile.txt:159-177]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15

  1. Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
  2. Write a Python script (ftpcrack.py) that combines ftplib.FTP brute-force scanning with subprocess.Popen to deploy xmrig.exe and a config.json.
  3. Build without AES: pyinstaller --onefile --windowed ftpcrack.py
  4. Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with 78 da headers. No pyimod00_crypto_key in strings.

Deployable Signatures

YARA rule

rule PyInstaller_Coinminer_Ftpcrack_2018_Cluster_PlainZlib {
    meta:
        description = "PyInstaller coinminer/ftpcrack Sep 2018 cluster — plain-zlib overlay, no AES"
        author = "PacketPursuit SOC"
        date = "2026-08-12"
        sha256 = "bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091"
    strings:
        $pyi1 = "PyInstaller: FormatMessageW failed." ascii
        $pyi2 = "_MEIPASS" ascii
        $pyi3 = "ARCHIVE_STATUS" ascii
        $pyi4 = "Py_SetPythonHome" ascii
        $pyi5 = "Installing PYZ: Could not get sys.path" ascii
        $ftpcrack = "ftpcrack.py" ascii
        $xmrig = "xmrig.exe" ascii
        $taskkill = "taskkill /F /IM xmrig.exe" ascii
        $config = "config.json" ascii
        $link = "link.txt" ascii
        $stratum = "stratum" ascii
        $userdic = "USER_DIC" ascii
        $passdic = "PASSWORD_DIC" ascii
    condition:
        uint16(0) == 0x5A4D and
        3 of ($pyi*) and
        ($ftpcrack or $xmrig or $taskkill) and
        not ("pyimod00_crypto_key" ascii) and
        filesize > 1MB and
        filesize < 10MB
}

Sigma rule

title: PyInstaller Coinminer/Ftpcrack Cluster Execution — Plain-Zlib Variant
status: experimental
description: Detects execution of PyInstaller-packed coinminer/ftpcrack cluster binaries with _MEI temp extraction and xmrig/ftpcrack payload staging (plain-zlib, no AES).
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - '_MEI'
            - 'xmrig.exe'
            - 'ftpcrack.py'
            - 'config.json'
            - 'link.txt'
    selection_temp:
        CommandLine|contains:
            - '%TEMP%'
            - 'C:\\Users\\'
            - 'C:\\Windows\\Temp'
    selection_taskkill:
        CommandLine|contains: 'taskkill /F /IM xmrig.exe'
    condition: (selection and selection_temp) or selection_taskkill
falsepositives:
    - Rare legitimate PyInstaller applications staging miner tools in research environments
level: high

IOC list

Indicator Type Value Notes
SHA-256 hash bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091 This sample
SSDeep hash 98304:RLGSThOfTCiFBXmfFs+JMHpCVoR8oMEOJ6Ty3RY:YBfTCiUswVSLOJgyBY ^[ssdeep.txt]
TLSH hash T19C52E22ABF4B47BFAE7B3EBB785F46E4B79B99D1E7E3E3E3E3E3E3E3E3E3E3E3E3 ^[tlsh.txt]
Module name string ftpcrack.py Embedded Python payload
Mutex / marker file link.txt Runtime pool config reference
Extraction dir path %TEMP%\_MEI* PyInstaller extraction pattern

Behavioural fingerprint statement

This binary is a PyInstaller single-file PE32 with MSVC 14.0 C bootloader compiled Sep 4 2018. On launch it extracts a plain-zlib CFFI archive to a %TEMP%\_MEI<XXXX> directory (no AES decryption), then bootstraps an embedded Python 2.7 runtime. The Python payload (ftpcrack.py) performs two functions: (1) multi-threaded FTP brute-force credential spraying against randomly-generated IP addresses using built-in dictionaries, and (2) XMRig cryptocurrency miner deployment via taskkill /F /IM xmrig.exe, config.json, and a runtime-fetched link.txt pool configuration. Network indicators are Stratum/TCP on port 3333/4444/45700 when the miner stage activates.

Detection Signatures

Capability ATT&CK ID Evidence
Python interpreter execution T1059.006 PyInstaller bootloader strings; python*.dll referenced in overlay ^[strings.txt:214]
Data staged in temp directory T1074.001 _MEIPASS / _MEIPASS2 extraction to %TEMP%\_MEI* ^[strings.txt:115] ^[strings.txt:229]
Ingress tool transfer T1105 Self-contained payload delivery (no external download)
Brute force: password guessing T1110.001 USER_DIC / PASSWORD_DIC credential spray ^[overlay-decompress:0x003b3e]
Network service scanning T1046 Random IP generation, ICMP host discovery, FTP banner detection ^[overlay-decompress:0x003b3e]
Cryptocurrency mining T1496 xmrig.exe, config.json, stratum, pool strings ^[overlay-decompress:0x003b3e]
Process termination T1059.003 taskkill /F /IM xmrig.exe ^[overlay-decompress:0x003b3e]

References

  • Artifact ID: 74f45ede-64e1-45ba-9a24-5ead7cefe15c
  • OpenCTI labels: coinminer, exe, urlhaus
  • Related wiki pages: coinminer, ftpcrack, pyinstaller-bootloader, python-packed-payload
  • Cluster sibling reports: /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html (first hybrid, plain-zlib), /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html (AES-encrypted hybrid), /intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html (largest plain-zlib)

Provenance

Analysis derived from:

  • file.txt (file type), exiftool.json (PE metadata), pefile.txt (section headers, imports, compilation timestamp), rabin2-info.txt (radare2 binary summary), binwalk.txt (embedded artefact offsets), strings.txt (static strings), triage.json (triage metadata), ssdeep.txt/tlsh.txt (similarity hashes), yara.txt (YARA matches), floss.txt (floss error), capa.txt (capa error), dynamic-analysis.md (CAPE skipped — no Windows guest).
  • Overlay decompression performed with Python zlib.decompress() on raw bytes starting at file offset 0x3CE00.
  • radare2 analysis: aa (level 2) with 930 functions discovered; decompilation via pdc at entry0 (0x004079d3) and main (0x00401000).