c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853coinminer: c0bc0bff — AES-encrypted hybrid ftpcrack+xmrig, 2.27 MB, 155 zlib blocks
Executive Summary
Confirmed sibling in the Sep 2018 PyInstaller cluster (see coinminer and ftpcrack entity pages). Same MSVC 14.0 build fingerprint, same compilation second, same ftpcrack build path — but unique in three ways: (1) AES-encrypted overlay with the weak QWERTY-derived key 1qazxsw23edcvfrN (not plain-zlib), (2) largest hybrid payload in the cluster at 2.27 MB with 155 zlib blocks, and (3) the decompressed overlay confirms both FTP brute-force credential scanning (ftpcrack.py) and XMRig miner deployment (xmrig.exe, config.json, link.txt, stratum) in the same binary. Static-only analysis; CAPE skipped — no Windows guest.
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 2,383,581 bytes (2.27 MB) ^[triage.json]
- Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Linker: MSVC 14.0 (MajorLinkerVersion 0xE, MinorLinkerVersion 0x0) ^[pefile.txt:45-46] ^[exiftool.json:18]
- Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
- ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[rabin2-info.txt:32]
- Overlay: 2,134,237 bytes starting at raw offset 0x3CE00, AES-encrypted PyInstaller CFFI archive inside zlib-compressed blocks, 155 zlib streams, 89.5% overlay ratio ^[binwalk.txt:4-49]
- AES encryption:
pyimod00_crypto_keymodule present in overlay with hardcoded key1qazxsw23edcvfrN^[overlay-decompress:0] - Build path:
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt^[overlay-decompress] - Cluster: identical compilation timestamp to 24+ confirmed PyInstaller siblings in the coinminer/ftpcrack cluster ^[pefile.txt:34]
How It Works
Standard PyInstaller single-file C bootloader flow with an AES decryption layer ^[r2:entry0] ^[r2:main]:
- CRT initialisation —
entry0(0x004079d3) sets up security cookie and SEH, then callsmain()^[r2:entry0] - Archive resolution —
mainresolves the executable path, opens its own image as a CFFI archive, and decrypts the overlay using PyCrypto AES (key1qazxsw23edcvfrN) before zlib decompression ^[strings.txt:119-212] ^[overlay-decompress] - Extraction — allocates an
ARCHIVE_STATUSstruct, checks_MEIPASS2environment variable, decompresses decrypted CFFI overlay to%TEMP%\_MEI<XXXX>using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115] ^[strings.txt:292] - Python runtime bootstrap — calls
SetDllDirectoryWto the_MEIfolder, loadspython*.dll(overlay containspython27.dllandMSVCR90.dllliterals confirming Python 2.7 runtime), resolves CPython C-API functions viaGetProcAddress, then unmarshals and executes__main__.py(module name in overlay isftpcrack.py) ^[strings.txt:119-212] - Payload behaviour — The embedded Python payload is a dual-function crimeware module:
- FTP brute-force scanner: built-in credential dictionaries (
USER_DIC/PASSWORD_DIC) with hundreds of entries including{user},{user}123,admin,root,test,www-data,password,123456,123123,qwerty,1qaz2wsx,P@ssw0rd!!, etc. Random IP generation viaRANDOM_IP_POOLand ICMP packet crafting for host discovery. Multi-threadedqueue_taskdispatch. - XMRig miner deployment: batch-script fragments recovered from overlay show
taskkill /F /IM xmrig.exe(kills existing miner),copy /y xmrig.exe(stages miner from_MEIPASSto%TMP%),config.json,\link.txt, and stratum pool configuration strings (tcp://,stratum,miner,pool). Thelink.txtfile likely contains runtime-fetched pool URLs or wallet addresses.
- FTP brute-force scanner: built-in credential dictionaries (
No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie, callsmain(). ^[r2:entry0]main(0x00401000): Resolves archive status struct and argv, then calls extraction routine. ^[r2:main]- PyInstaller bootstrap core: allocates
ARCHIVE_STATUS, checks_MEIPASS2, opens self as archive, iterates TOC, extracts to_MEItemp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]
C2 Infrastructure
Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only PyInstaller bootloader strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the embedded Python payload. ^[strings.txt]
Static recovery from decompressed overlay reveals:
stratum,tcp://,miner,pool— confirms Stratum protocol mining127.0.0.1— local interface reference for miner bind or testlink.txt— external C2/pool config file reference- No hardcoded attacker IP addresses or domains recovered from overlay.
Interesting Tidbits
- Largest hybrid payload in cluster: At 2.27 MB with 155 zlib blocks, this is the largest confirmed sibling containing both
ftpcrack.pyandxmrig.exeartefacts. Prior hybrid sibling2727eb40was 387 KB with 10 zlib blocks and plain-zlib (no AES) ^[raw/analyses/2727eb40/report.md] - AES encryption layer present: Unlike
2727eb40, this sibling carries thepyimod00_crypto_keymodule with the same weak QWERTY-derived key1qazxsw23edcvfrNseen in AES-encrypted coinminer siblings359fcf01,058ab625,983d2606,f7abdaf8,fa98331d,f284c9aa,6b2591e4,af7aebb9, ande019096c^[overlay-decompress] - Build path ties it to ftpcrack pipeline: The recovered path
F:\files\ftp\crack\exe\build\ftpcrack\matches the ftpcrack mislabel sub-cluster (551d2b0e,135b3b8d,6b881268) and AES-encrypted coinminer siblings with the same weak key, confirming a single build environment produced both ftpcrack-only and coinminer payloads ^[overlay-decompress] python27.dllandMSVCR90.dllliterals in overlay confirm Python 2.7.15 runtime — same as other ftpcrack siblings ^[overlay-decompress]floss.txtandcapa.txtare both non-functional (tool argument error and missing signatures respectively) ^[floss.txt] ^[capa.txt]- No YARA matches beyond generic
PE_File_Generic^[yara.txt] - Import table is minimal:
USER32.dll(MessageBoxA/W),KERNEL32.dll(process/thread/file APIs),WS2_32.dll(ntohlby ordinal) ^[pefile.txt:249-300] .rsrcsection contains a 256×256 PNG icon (189 KB, entropy 7.26) — likely the PyInstaller default icon or a reused icon from the build pipeline ^[binwalk.txt:9] ^[pefile.txt:159-177]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15 + PyCrypto 2.6
- Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM. Install PyCrypto 2.6 (
pip install pycrypto). - Write a Python script (
ftpcrack.py) that combinesftplib.FTPbrute-force scanning withsubprocess.Popento deployxmrig.exeand aconfig.json. - Build with AES encryption:
pyinstaller --onefile --windowed --key=1qazxsw23edcvfrN ftpcrack.py - Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed overlay starting at 0x3CE00 with
78 daheaders inside AES-encrypted blocks. - Decompress overlay with
pyinstxtractor-ngor manual AES decrypt + zlib decompress to recover the embedded.pycandpython27.dll.
Deployable Signatures
YARA rule
rule pyinstaller_sep2018_aes_hybrid_ftpcrack_xmrig
{
meta:
description = "PyInstaller Sep 2018 cluster: AES-encrypted overlay with hybrid ftpcrack+xmrig payload"
author = "Demetrian Titus"
date = "2026-08-10"
sha256 = "c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853"
strings:
$pyi1 = "PyInstaller: " ascii
$pyi2 = "_MEIPASS" ascii
$pyi3 = "Failed to get address for Py_Initialize" ascii
$zlib = { 78 da }
$crypto_key = "pyimod00_crypto_key" ascii
$aes_key = "1qazxsw23edcvfrN" ascii
$ftpcrack = "ftpcrack.py" ascii
$xmrig = "xmrig.exe" ascii
$taskkill = "taskkill /F /IM xmrig.exe" ascii
$link = "link.txt" ascii
$config = "config.json" ascii
$stratum = "stratum" ascii
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 6 and
pe.linker_version.major == 14 and
pe.timestamp == 0x5B8E9A15 and
$pyi1 and $pyi2 and $pyi3 and
$crypto_key and $aes_key and
any of ($ftpcrack, $xmrig, $taskkill, $link, $config, $stratum)
}
Sigma rule
title: PyInstaller Sep 2018 Hybrid FTPCrack+XMRig Execution
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'taskkill /F /IM xmrig.exe'
- 'copy /y xmrig.exe'
- '_MEI'
- 'python27.dll'
ParentImage|endswith:
- '\ftpcrack.exe'
condition: selection
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Type | Value |
|---|---|---|
| SHA-256 | Hash | c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853 |
| ssdeep | Hash | 49152:R3XTWsOBDNQ2iselXOfTITJR0nr43XTWsTBDNQ2iselu:RLGSThOfTC/LVSTg |
| Build timestamp | Timestamp | 2018-09-04 14:43:33 UTC |
| AES key | Crypto | 1qazxsw23edcvfrN |
| Embedded module | File | ftpcrack.py |
| Staged miner | File | xmrig.exe |
| Miner config | File | config.json |
| Pool config | File | link.txt |
| Temp extract | Path | %TEMP%\_MEI<XXXX> |
| Runtime DLL | File | python27.dll |
| Runtime DLL | File | MSVCR90.dll |
Behavioral fingerprint
This binary is a PyInstaller single-file PE (MSVC 14.0, Sep 2018 timestamp) that extracts an AES-encrypted zlib-compressed Python 2.7 payload to a _MEI<XXXX> temp directory on launch. Within 5 seconds of execution, it spawns python27.dll-backed bytecode that stages xmrig.exe and a config.json into the same temp directory, then issues taskkill /F /IM xmrig.exe to terminate any existing miner before launching the newly staged one. Simultaneously, the embedded ftpcrack.py module performs multi-threaded FTP credential scanning against randomly generated IP addresses using ICMP host discovery and built-in username/password dictionaries. Network telemetry will show Stratum/TCP traffic to mining pools and outbound FTP connection attempts on port 21 from the same process tree.
Detection Signatures
| Capability | Evidence | ATT&CK Mapping |
|---|---|---|
| PyInstaller single-file packing | MSVC 14.0 PE with _MEIPASS strings and zlib overlay |
T1027.002 |
| AES-encrypted payload overlay | pyimod00_crypto_key module with hardcoded 1qazxsw23edcvfrN |
T1027 |
| Temp-directory payload staging | _MEIPASS2 env var → %TEMP%\_MEI<XXXX> extraction |
T1074.001 |
| Process execution | CreateProcessW bootstrap to Python VM |
T1106 |
| Command shell | taskkill /F /IM xmrig.exe recovered from overlay |
T1059.003 |
| Cryptocurrency mining | xmrig.exe, config.json, stratum, pool, miner strings |
T1496 |
| Network communication | WS2_32.dll:ntohl import; Stratum/TCP pool traffic inferred |
T1071, T1048 |
| FTP brute-force | ftplib.FTP, RANDOM_IP_POOL, ICMP socket crafting |
T1110 |
| Resource abuse | Dual-function crimeware: compute theft (mining) + credential theft (FTP) | T1496 |
References
- Artifact ID:
528087d0-3262-4c1a-b39b-f1ff9f94c4cb - OpenCTI labels:
coinminer,exe,urlhaus - Related wiki pages: coinminer, ftpcrack, pyinstaller-bootloader, python-packed-payload
- Prior sibling reports: /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html (plain-zlib hybrid, 387 KB), /intel/analyses/359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c.html (AES-encrypted ftpcrack-only, 4.35 MB)
Provenance
This report draws on file.txt, pefile.txt, exiftool.json, rabin2-info.txt, strings.txt, binwalk.txt, triage.json, metadata.json, dynamic-analysis.md, yara.txt, floss.txt, capa.txt, and radare2 static analysis (entry0, main). Overlay content was recovered via custom Python zlib decompression of the post-PE overlay starting at raw offset 0x3CE00. AES key and module names were extracted from decompressed PyInstaller CFFI archive blocks. Capa signatures were unavailable due to missing capa rule installation. FLOSS failed due to incorrect command-line argument parsing.