typeanalysisfamilycoinminerconfidencemediumcreated2026-08-10updated2026-08-10compilerpemalware-familycryptominerdefense-evasionpython-pyinstallerimpact
SHA-256: c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853

coinminer: c0bc0bff — AES-encrypted hybrid ftpcrack+xmrig, 2.27 MB, 155 zlib blocks

Executive Summary

Confirmed sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second, same ftpcrack build path — but unique in three ways: (1) AES-encrypted overlay with the weak QWERTY-derived key 1qazxsw23edcvfrN (not plain-zlib), (2) largest hybrid payload in the cluster at 2.27 MB with 155 zlib blocks, and (3) the decompressed overlay confirms both FTP brute-force credential scanning (ftpcrack.py) and XMRig miner deployment (xmrig.exe, config.json, link.txt, stratum) in the same binary. Static-only analysis; CAPE skipped — no Windows guest.

What It Is

  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 2,383,581 bytes (2.27 MB) ^[triage.json]
  • Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
  • Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
  • ASLR / DEP: enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74]
  • Subsystem: Windows GUI ^[rabin2-info.txt:32]
  • Overlay: 2,134,237 bytes starting at raw offset 0x3CE00, AES-encrypted PyInstaller CFFI archive inside zlib-compressed blocks, 155 zlib streams, 89.5% overlay ratio ^[binwalk.txt:4-49]
  • AES encryption: pyimod00_crypto_key module present in overlay with hardcoded key 1qazxsw23edcvfrN ^[overlay-decompress:0]
  • Build path: F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt ^[overlay-decompress]
  • Cluster: identical compilation timestamp to 24+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]

How It Works

Standard PyInstaller single-file C bootloader flow with an AES decryption layer ^[r2:entry0] ^[r2:main]:

  1. CRT initialisation — entry0 (0x004079d3) sets up security cookie and SEH, then calls main() ^[r2:entry0]
  2. Archive resolution — main resolves the executable path, opens its own image as a CFFI archive, and decrypts the overlay using PyCrypto AES (key 1qazxsw23edcvfrN) before zlib decompression ^[strings.txt:119-212] ^[overlay-decompress]
  3. Extraction — allocates an ARCHIVE_STATUS struct, checks _MEIPASS2 environment variable, decompresses decrypted CFFI overlay to %TEMP%\_MEI<XXXX> using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115] ^[strings.txt:292]
  4. Python runtime bootstrap — calls SetDllDirectoryW to the _MEI folder, loads python*.dll (overlay contains python27.dll and MSVCR90.dll literals confirming Python 2.7 runtime), resolves CPython C-API functions via GetProcAddress, then unmarshals and executes __main__.py (module name in overlay is ftpcrack.py) ^[strings.txt:119-212]
  5. Payload behaviour — The embedded Python payload is a dual-function crimeware module:
    • FTP brute-force scanner: built-in credential dictionaries (USER_DIC / PASSWORD_DIC) with hundreds of entries including {user}, {user}123, admin, root, test, www-data, password, 123456, 123123, qwerty, 1qaz2wsx, P@ssw0rd!!, etc. Random IP generation via RANDOM_IP_POOL and ICMP packet crafting for host discovery. Multi-threaded queue_task dispatch.
    • XMRig miner deployment: batch-script fragments recovered from overlay show taskkill /F /IM xmrig.exe (kills existing miner), copy /y xmrig.exe (stages miner from _MEIPASS to %TMP%), config.json, \link.txt, and stratum pool configuration strings (tcp://, stratum, miner, pool). The link.txt file likely contains runtime-fetched pool URLs or wallet addresses.

No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.

Decompiled Behaviour

  • entry0 (0x004079d3): MSVC CRT entry. Initialises security cookie, calls main(). ^[r2:entry0]
  • main (0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]
  • PyInstaller bootstrap core: allocates ARCHIVE_STATUS, checks _MEIPASS2, opens self as archive, iterates TOC, extracts to _MEI temp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]

C2 Infrastructure

Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]

Static recovery from decompressed overlay reveals:

  • stratum, tcp://, miner, pool — confirms Stratum protocol mining
  • 127.0.0.1 — local interface reference for miner bind or test
  • link.txt — external C2/pool config file reference
  • No hardcoded attacker IP addresses or domains recovered from overlay.

Interesting Tidbits

  • Largest hybrid payload in cluster: At 2.27 MB with 155 zlib blocks, this is the largest confirmed sibling containing both ftpcrack.py and xmrig.exe artefacts. Prior hybrid sibling 2727eb40 was 387 KB with 10 zlib blocks and plain-zlib (no AES) ^[raw/analyses/2727eb40/report.md]
  • AES encryption layer present: Unlike 2727eb40, this sibling carries the pyimod00_crypto_key module with the same weak QWERTY-derived key 1qazxsw23edcvfrN seen in AES-encrypted coinminer siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, f284c9aa, 6b2591e4, af7aebb9, and e019096c ^[overlay-decompress]
  • Build path ties it to ftpcrack pipeline: The recovered path F:\files\ftp\crack\exe\build\ftpcrack\ matches the ftpcrack mislabel sub-cluster (551d2b0e, 135b3b8d, 6b881268) and AES-encrypted coinminer siblings with the same weak key, confirming a single build environment produced both ftpcrack-only and coinminer payloads ^[overlay-decompress]
  • python27.dll and MSVCR90.dll literals in overlay confirm Python 2.7.15 runtime — same as other ftpcrack siblings ^[overlay-decompress]
  • floss.txt and capa.txt are both non-functional (tool argument error and missing signatures respectively) ^[floss.txt] ^[capa.txt]
  • No YARA matches beyond generic PE_File_Generic ^[yara.txt]
  • Import table is minimal: USER32.dll (MessageBoxA/W), KERNEL32.dll (process/thread/file APIs), WS2_32.dll (ntohl by ordinal) ^[pefile.txt:249-300]
  • .rsrc section contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely the PyInstaller default icon or a reused icon from the build pipeline ^[binwalk.txt:9] ^[pefile.txt:159-177]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15 + PyCrypto 2.6

  1. Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM. Install PyCrypto 2.6 (pip install pycrypto).
  2. Write a Python script (ftpcrack.py) that combines ftplib.FTP brute-force scanning with subprocess.Popen to deploy xmrig.exe and a config.json.
  3. Build with AES encryption: pyinstaller --onefile --windowed --key=1qazxsw23edcvfrN ftpcrack.py
  4. Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with 78 da headers inside AES-encrypted blocks.
  5. Decompress overlay with pyinstxtractor-ng or manual AES decrypt + zlib decompress to recover the embedded .pyc and python27.dll.

Deployable Signatures

YARA rule

rule pyinstaller_sep2018_aes_hybrid_ftpcrack_xmrig
{
    meta:
        description = "PyInstaller Sep 2018 cluster: AES-encrypted overlay with hybrid ftpcrack+xmrig payload"
        author = "Demetrian Titus"
        date = "2026-08-10"
        sha256 = "c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853"
    strings:
        $pyi1 = "PyInstaller: " ascii
        $pyi2 = "_MEIPASS" ascii
        $pyi3 = "Failed to get address for Py_Initialize" ascii
        $zlib = { 78 da }
        $crypto_key = "pyimod00_crypto_key" ascii
        $aes_key = "1qazxsw23edcvfrN" ascii
        $ftpcrack = "ftpcrack.py" ascii
        $xmrig = "xmrig.exe" ascii
        $taskkill = "taskkill /F /IM xmrig.exe" ascii
        $link = "link.txt" ascii
        $config = "config.json" ascii
        $stratum = "stratum" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 6 and
        pe.linker_version.major == 14 and
        pe.timestamp == 0x5B8E9A15 and
        $pyi1 and $pyi2 and $pyi3 and
        $crypto_key and $aes_key and
        any of ($ftpcrack, $xmrig, $taskkill, $link, $config, $stratum)
}

Sigma rule

title: PyInstaller Sep 2018 Hybrid FTPCrack+XMRig Execution
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'taskkill /F /IM xmrig.exe'
            - 'copy /y xmrig.exe'
            - '_MEI'
            - 'python27.dll'
        ParentImage|endswith:
            - '\ftpcrack.exe'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC list

Indicator Type Value
SHA-256 Hash c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853
ssdeep Hash 49152:R3XTWsOBDNQ2iselXOfTITJR0nr43XTWsTBDNQ2iselu:RLGSThOfTC/LVSTg
Build timestamp Timestamp 2018-09-04 14:43:33 UTC
AES key Crypto 1qazxsw23edcvfrN
Embedded module File ftpcrack.py
Staged miner File xmrig.exe
Miner config File config.json
Pool config File link.txt
Temp extract Path %TEMP%\_MEI<XXXX>
Runtime DLL File python27.dll
Runtime DLL File MSVCR90.dll

Behavioral fingerprint

This binary is a PyInstaller single-file PE (MSVC 14.0, Sep 2018 timestamp) that extracts an AES-encrypted zlib-compressed Python 2.7 payload to a _MEI<XXXX> temp directory on launch. Within 5 seconds of execution, it spawns python27.dll-backed bytecode that stages xmrig.exe and a config.json into the same temp directory, then issues taskkill /F /IM xmrig.exe to terminate any existing miner before launching the newly staged one. Simultaneously, the embedded ftpcrack.py module performs multi-threaded FTP credential scanning against randomly generated IP addresses using ICMP host discovery and built-in username/password dictionaries. Network telemetry will show Stratum/TCP traffic to mining pools and outbound FTP connection attempts on port 21 from the same process tree.

Detection Signatures

Capability Evidence ATT&CK Mapping
PyInstaller single-file packing MSVC 14.0 PE with _MEIPASS strings and zlib overlay T1027.002
AES-encrypted payload overlay pyimod00_crypto_key module with hardcoded 1qazxsw23edcvfrN T1027
Temp-directory payload staging _MEIPASS2 env var → %TEMP%\_MEI<XXXX> extraction T1074.001
Process execution CreateProcessW bootstrap to Python VM T1106
Command shell taskkill /F /IM xmrig.exe recovered from overlay T1059.003
Cryptocurrency mining xmrig.exe, config.json, stratum, pool, miner strings T1496
Network communication WS2_32.dll:ntohl import; Stratum/TCP pool traffic inferred T1071, T1048
FTP brute-force ftplib.FTP, RANDOM_IP_POOL, ICMP socket crafting T1110
Resource abuse Dual-function crimeware: compute theft (mining) + credential theft (FTP) T1496

References

  • Artifact ID: 528087d0-3262-4c1a-b39b-f1ff9f94c4cb
  • OpenCTI labels: coinminer, exe, urlhaus
  • Related wiki pages: coinminer, ftpcrack, pyinstaller-bootloader, python-packed-payload
  • Prior sibling reports: /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html (plain-zlib hybrid, 387 KB), /intel/analyses/359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c.html (AES-encrypted ftpcrack-only, 4.35 MB)

Provenance

This report draws on file.txt, pefile.txt, exiftool.json, rabin2-info.txt, strings.txt, binwalk.txt, triage.json, metadata.json, dynamic-analysis.md, yara.txt, floss.txt, capa.txt, and radare2 static analysis (entry0, main). Overlay content was recovered via custom Python zlib decompression of the post-PE overlay starting at raw offset 0x3CE00. AES key and module names were extracted from decompressed PyInstaller CFFI archive blocks. Capa signatures were unavailable due to missing capa rule installation. FLOSS failed due to incorrect command-line argument parsing.