e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612coinminer: e019096c — PyInstaller bootloader eighteenth sibling, Sep 2018 MSVC build, AES-encrypted overlay (1.18 MB)
Executive Summary
Eighteenth confirmed sibling in the September 2018 PyInstaller coinminer cluster. Shares the identical compilation timestamp (Tue Sep 4 14:43:33 2018), MSVC 14.0 linker, AES key 1qazxsw23edcvfrN, and ftpcrack build path with the encrypted-overlay subgroup (359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, f284c9aa, 6b2591e4, af7aebb9). At 1.18 MB it is the smallest AES-encrypted sibling in the cluster. Threat logic lives inside the AES-encrypted PyInstaller CFFI archive; no mining indicators are visible in the outer binary. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 1,212,268 bytes (1.18 MB) ^[exiftool.json]
- SHA-256:
e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612^[metadata.json] - Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt]
- Linker: MSVC 14.0 (Visual Studio 2015 RTM) ^[exiftool.json]
- Signed: false; checksum
0x00000000^[rabin2-info.txt] - ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[file.txt]
- Overlay: 962,924 bytes starting at raw offset
0x3CE00, zlib-compressed CFFI archive with AES-encrypted entries ^[binwalk.txt] ^[manual_analysis] - Family: coinminer (OpenCTI label) ^[triage.json]
How It Works
Standard PyInstaller single-file C bootloader. Runtime sequence is identical to the cluster documentation at pyinstaller-bootloader and coinminer:
- CRT initialisation — MSVC
entry0→main()→ PyInstaller bootstrap core ^[r2:entry0] - Archive resolution — locates CFFI archive appended past PE sections (overlay at
0x3CE00, same offset as all cluster siblings) ^[binwalk.txt] - Extraction — decompresses 8 zlib blocks and decrypts AES-encrypted entries to
%TEMP%\_MEI<XXXX>^[manual_analysis] - Python runtime bootstrap — loads Python DLL, resolves CPython API procs (
Py_Initialize,PyMarshal_ReadObjectFromString,PyEval_EvalCode, etc.) ^[strings.txt:119-212] - Script execution — unmarshals embedded code object and runs
__main__.py^[strings.txt:104-111] - Cleanup — deletes temp directory on exit unless
_MEIPASS2is set ^[strings.txt:115]
AES encryption
The first zlib chunk decompresses to a pyimod00_crypto_key module containing the hardcoded AES key: ^[manual_analysis]
`1qazxsw23edcvfrN(
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt
<module>
The key 1qazxsw23edcvfrN is a left-hand QWERTY diagonal walking pattern, identical to siblings 359fcf01, 058ab625, 983d2606, f7abdaf8, fa98331d, f284c9aa, 6b2591e4, and af7aebb9. The build path F:\files\ftp\crack\exe\build\ftpcrack\ is also identical, confirming a shared build pipeline. All remaining overlay entries (≈881 KB, 91.5% of overlay) are AES-encrypted and cannot be decompressed without the key.
Cluster delta
| Sibling | Size | Overlay | Zlib blocks | Encryption | Key visible? | Build path |
|---|---|---|---|---|---|---|
| 801fbba1 | 799 KB | ~570 KB | — | None | N/A | Not recovered |
| 39b67a79 | 4.3 MB | ~4.2 MB | — | None | N/A | Not recovered |
| 5047235c | 1.75 MB | ~1.6 MB | — | None | N/A | Not recovered |
| 640ed5b5 | 735 KB | ~555 KB | — | None | N/A | Not recovered |
| b4cc27e3 | 630 KB | ~540 KB | — | None | N/A | Not recovered |
| fbfd2d94 | 2.37 MB | ~2.2 MB | — | None | N/A | Not recovered |
| 359fcf01 | 4.35 MB | ~4.3 MB | — | AES | Yes (QWERTY) | F:\files\ftp\crack\exe\build\ftpcrack\ |
| 058ab625 | 2.76 MB | ~2.6 MB | — | AES | Yes (same QWERTY) | Same ftpcrack path |
| 983d2606 | 2.43 MB | ~2.18 MB | — | AES | Yes (same QWERTY) | Same ftpcrack path |
| f7abdaf8 | 1.96 MB | ~1.72 MB | 29 | AES | Yes (same QWERTY) | Same ftpcrack path |
| fa98331d | 4.07 MB | ~3.74 MB | — | AES | Yes (same QWERTY) | Same ftpcrack path |
| f284c9aa | 6.1 MB | ~5.84 MB | 63 | AES | Yes (same QWERTY) | Same ftpcrack path |
| 6b2591e4 | 5.34 MB | ~5.10 MB | 285 | AES | Yes (same QWERTY) | Same ftpcrack path |
| af7aebb9 | 2.25 MB | ~2.0 MB | 85 | AES | Yes (same QWERTY) | Same ftpcrack path |
| 1fed143e | 4.14 MB | — | 44 | None | N/A | Same Sep 2018 build |
| da02fd07 | 5.82 MB | — | 39 | None | N/A | Same Sep 2018 build |
| 551d2b0e | 672 KB | — | 11 | AES | Yes (same QWERTY) | Same ftpcrack path (ftpcrack payload) |
| 135b3b8d | 1.5 MB | — | 18 | None | N/A | Same ftpcrack path (ftpcrack payload) |
| e019096c | 1.18 MB | ~963 KB | 8 | AES | Yes (same QWERTY) | Same ftpcrack path |
Compilation timestamp, linker version, and bootloader strings are identical across all eighteen siblings. The only variables are payload size, the encryption toggle, and the number of zlib blocks in the overlay.
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie, callsmain(), then CRT terminators. No anti-debug or VM checks. ^[r2:entry0]main(0x00401000): Three calls — archive status resolution, UTF-8 argv conversion, then PyInstaller bootstrap core. ^[r2:main]- Imports are limited to standard Win32 +
WS2_32.dll.ntohl(pulled in by CRT, not actively used by the thin bootloader). ^[pefile.txt:249-373] .rsrcsection contains icon groups (PyInstaller default icon inheritance). ^[pefile.txt:159-492]
C2 Infrastructure
Not statically observable. Outer binary contains only generic PyInstaller error strings and MSVC CRT locale data. No hardcoded IPs, domains, pool URLs, or wallet addresses are recoverable without decrypting the overlay. Pool/C2 configuration is presumed to reside inside the AES-encrypted Python payload. ^[strings.txt]
Interesting Tidbits
floss.txtis a tool-usage error (triage script passed the sample path to--noinstead of thesamplepositional argument), yielding no decoded strings. Same failure as all prior siblings. ^[floss.txt]capa.txtfailed with missing default signature path — signatures were never installed on this station. Same failure as all prior siblings. ^[capa.txt]- Only 8 zlib blocks in the overlay, the fewest of any AES-encrypted sibling in this cluster. ^[manual_analysis]
- The
c:/PyIfragment at line 1095 ofstrings.txtconfirms the same build environment as siblings 801fbba1 and 640ed5b5. ^[strings.txt:1095] - No YARA matches beyond the generic
PE_File_Generic. ^[yara.txt] - Entropy of
.textis 6.65,.rsrcis 7.26 — neither is packed; heavy entropy lives in the encrypted overlay. ^[pefile.txt:91-172]
How To Mess With It (Homelab Replication)
Follow the recipe at pyinstaller-bootloader and python-packed-payload:
- Install Python 2.7 + PyInstaller 3.4 on a Windows research VM.
pyinstaller --onefile --windowed --key '1qazxsw23edcvfrN' your_script.py- The resulting EXE will match this cluster's MSVC 14.0 linker fingerprint,
_MEIPASSstrings, and zlib overlay structure. - Extract the payload with
pyinstxtractor.py(or manually zlib-decompress the first chunk to recover the AES key module). - Learning outcome: Recognising that
--keyencrypts the CFFI archive means simple strings/zlib extraction is insufficient; the AES key or a runtime detonation with memory dumps is required for full payload recovery.
Deployable Signatures
YARA rule
rule PyInstallerBootloader_AESCoinminer_2018_Cluster_e019096c {
meta:
description = "PyInstaller single-file bootloader with AES-encrypted coinminer payload (2018 cluster, weak QWERTY key)"
author = "Titus"
date = "2026-08-04"
sha256 = "e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612"
strings:
$pyi1 = "pyimod00_crypto_key" ascii wide
$pyi2 = "PyInstaller: FormatMessageW failed." ascii wide
$pyi3 = "_MEIPASS2" ascii wide
$pyi4 = "Failed to execute script %s" ascii wide
$pyi5 = "pyi-runtime-tmpdir" ascii wide
$pyi6 = "base_library.zip" ascii wide
$inflate = "inflate 1.2.8 Copyright 1995-2013 Mark Adler" ascii wide
$key_frag = "1qazxsw23edcvfr" ascii wide
condition:
uint16(0) == 0x5a4d and
$pyi1 and
3 of ($pyi2, $pyi3, $pyi4, $pyi5, $pyi6) and
$inflate and
$key_frag and
filesize > 1MB
}
Sigma rule
Not suitable for the outer binary — the thin PyInstaller bootloader exhibits no unique process-level behaviour beyond generic extraction. Sigma should target the child process spawned from %TEMP%\_MEI* (python.exe or a renamed miner binary) within seconds of parent launch, combined with network connections to Stratum ports (3333, 4444, 45700).
IOC list
- SHA-256:
e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612 - Temp path pattern:
%TEMP%\_MEI*\*(PyInstaller extraction directory) - AES key:
1qazxsw23edcvfrN(weak QWERTY pattern) - Build path artefact:
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt - Compilation timestamp:
Tue Sep 4 14:43:33 2018 UTC(0x5B8E9A15) - Mutex / named pipe: not observed in outer binary
- Registry: not observed in outer binary
Behavioural fingerprint
PE32 GUI executable compiled with MSVC 2015, containing a ~963 KB zlib-compressed overlay encrypted with AES-CBC via PyInstaller's --key option. At runtime it extracts the decrypted payload to a _MEI-prefixed temp directory, loads python27.dll, and executes the embedded Python bytecode. The outer binary carries no mining-specific imports or strings; all threat behaviour manifests inside the encrypted overlay and in spawned child processes.
Detection Signatures
- MITRE ATT&CK
- T1059.006 (Python) — execution via embedded Python interpreter
- T1074.001 (Data Staged: Local Data Staging) — extraction to temp directory
- T1105 (Ingress Tool Transfer) — self-contained payload delivery
- T1574.002 (DLL Side-Loading) — loading Python DLL from
_MEIpath - T1027 (Obfuscated Files or Information) — AES-encrypted overlay
- Capa: non-functional (missing signatures). No ATT&CK mapping available. ^[capa.txt]
References
- Artifact ID:
1ec59145-ee7b-4901-a297-ad1fb9948f4e^[metadata.json] - OpenCTI labels:
coinminer,exe,urlhaus^[triage.json] - Cluster sibling: /intel/analyses/801fbba19b4d4828191e87e7311480deaf81e84482dab70adf38d61afd01c1fa.html
- Cluster sibling: /intel/analyses/359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c.html
- Cluster sibling: /intel/analyses/f7abdaf88b8f90e6672e19641a40f88c91f17140c4973c8ff7dd2be52bbdde64.html
- Entity page: coinminer
- Concept page: python-packed-payload
Provenance
file.txt—filecommand (PE32 executable)strings.txt— strings (2,478 lines)pefile.txt—pefilePython module (sections, imports, resources)binwalk.txt—binwalk(zlib blocks identified)rabin2-info.txt— radare2rabin2 -I(binary metadata)exiftool.json— ExifTool PE metadatatriage.json— triage tier assignmentmetadata.json— artifact metadata from OpenCTIfloss.txt— flare-floss (tool argument error, no decoded output)capa.txt— flare-capa (signature path error, no output)- Manual overlay analysis — Python zlib decompression of first overlay chunk, PyInstaller CArchive structure inspection, AES key extraction
- R2 decompilation — radare2 via MCP (
pdgatentry0andmain)