typeanalysisfamilycoinminerconfidencemediumcreated2026-08-24updated2026-08-24compilerpemalware-familycryptominerdefense-evasionpython-pyinstallerobfuscationimpact
SHA-256: e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5

coinminer: e2b273fa — 3.35 MB AES-encrypted hybrid ftpcrack+xmrig, 176 zlib streams

Executive Summary

Twenty-eighth confirmed sibling in the September 2018 PyInstaller coinminer/ftpcrack cluster. At 3.35 MB it is the third-largest overall sibling and the largest AES-encrypted variant in the cluster, with a 92.6% overlay ratio (3.1 MB) comprising 176 zlib headers of which 34 decompress successfully. Same MSVC 14.0 build fingerprint (Sep 4 14:43:33 UTC), same weak AES key (1qazxsw23edcvfrN), same build path (F:\files\ftp\crack\exe\build\ftpcrack\). Decompressed overlay confirms a hybrid ftpcrack+xmrig payload: FTP brute-force credential dictionaries (USER_DIC, PASSWORD_DIC, RANDOM_IP_POOL) coexist with XMRig miner deployment artefacts (taskkill /F /IM xmrig.exe, config.json, link.txt, stratum pool). Static-only; CAPE skipped — no Windows guest.

What It Is

  • File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
  • Size: 3,350,119 bytes (3.35 MB) ^[triage.json] ^[exiftool.json]
  • SHA-256: e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5 ^[metadata.json]
  • Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Linker: MSVC 14.0 (Visual Studio 2015 RTM) ^[exiftool.json:18]
  • Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
  • ASLR / DEP: enabled (DllCharacteristics: 0x8140) ^[pefile.txt:74]
  • Subsystem: Windows GUI ^[file.txt]
  • Overlay: 3,100,775 bytes starting at raw offset 0x3CE00, 92.6% of file, AES-encrypted PyInstaller CFFI archive ^[binwalk.txt:11-48] ^[terminal:overlay-analysis]
  • Zlib streams: 176 zlib headers (78 01, 78 9c, 78 da) in overlay; 34 successfully decompressable ^[terminal:overlay-analysis]
  • AES key: 1qazxsw23edcvfrN (left-hand QWERTY diagonal, identical to all AES-encrypted siblings) ^[terminal:stream0-decompress]
  • Build path: F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt ^[terminal:stream0-decompress]
  • Family: coinminer (OpenCTI label) ^[triage.json]

How It Works

Standard PyInstaller single-file C bootloader flow identical to the cluster documentation at pyinstaller-bootloader and coinminer:

  1. CRT initialisation — MSVC entry0 → main() → PyInstaller bootstrap core ^[r2:entry0]
  2. Archive resolution — locates CFFI archive appended past PE sections (overlay at 0x3CE00, same offset as every cluster sibling) ^[binwalk.txt]
  3. Decryption — first zlib chunk decompresses to pyimod00_crypto_key.pyt containing the AES key 1qazxsw23edcvfrN ^[terminal:stream0-decompress]
  4. Extraction — decrypts and decompresses remaining overlay entries to %TEMP%\_MEI<XXXX> using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115]
  5. Python runtime bootstrap — loads python*.dll, resolves CPython API procs (Py_Initialize, PyMarshal_ReadObjectFromString, PyEval_EvalCode, etc.) ^[strings.txt:119-212]
  6. Script execution — unmarshals embedded ftpcrack.py code object and runs __main__.py ^[strings.txt:104-111]
  7. Cleanup — deletes temp directory on exit unless _MEIPASS2 is set ^[strings.txt:115]

Hybrid payload confirmed

Decompressed overlay stream at offset 0x3b3e within overlay (32,761 bytes) contains both:

  • FTP brute-force scanner: RANDOM_IP_POOL, USER_DIC, PASSWORD_DIC, ftplib.FTP, ICMP host-discovery (icmpPacket, icmpSocket), multi-threaded queue_task dispatch. Built-in credential templates include {user}, {user}123, admin, root, test, www-data, password, 123456, P@ssw0rd!!, 1qaz2wsx, qwerty123456. ^[terminal:stream-decompress]
  • XMRig miner deployment: taskkill /F /IM xmrig.exe, xmrig.exe staging, config.json, \link.txt, stratum, tcp://, miner, pool. ^[terminal:stream-decompress]

No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.

Cluster delta

Sibling Size Overlay Zlib blocks Encryption Hybrid? Key
801fbba1 799 KB ~570 KB — None No N/A
359fcf01 4.35 MB ~4.3 MB — AES No 1qazxsw23edcvfrN
2727eb40 387 KB 138 KB 10 None Yes N/A
c0bc0bff 2.27 MB ~2.13 MB 155 AES Yes 1qazxsw23edcvfrN
bc206453 4.7 MB ~4.68 MB 37 None Yes N/A
6c321d46 320 KB 78 KB 10 AES Yes 1qazxsw23edcvfrN
e2b273fa 3.35 MB 3.1 MB 176 AES Yes 1qazxsw23edcvfrN

This sample is unique in the cluster for being the largest AES-encrypted hybrid sibling and having the highest zlib header count (176) of any sibling observed to date. Prior AES-encrypted hybrids were smaller (c0bc0bff at 2.27 MB, 6c321d46 at 320 KB). This proves the builder pipeline can produce very large AES-encrypted hybrid payloads.

Decompiled Behaviour

  • entry0 (0x004079d3): MSVC CRT entry. Initialises security cookie and SEH, calls main(), then CRT terminators. No anti-debug or VM checks. ^[r2:entry0]
  • main (0x00401000): Three calls — archive status resolution, UTF-8 argv conversion, then PyInstaller bootstrap core (fcn.00402520). ^[r2:main]
  • PyInstaller bootstrap core: allocates ARCHIVE_STATUS, checks _MEIPASS2, opens self as archive, iterates TOC, extracts to _MEI temp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520]
  • Imports are limited to standard Win32 + WS2_32.dll.ntohl (pulled in by CRT, not actively used by the thin bootloader). ^[pefile.txt:249-373]
  • .rsrc section contains icon groups (PyInstaller default icon inheritance). ^[pefile.txt:159-534]
  • .gfids section (Guard CF IAT) present, confirming CFG-aware compilation. ^[pefile.txt:139-156]

C2 Infrastructure

Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only generic PyInstaller error strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the AES-encrypted Python payload. ^[strings.txt]

Static recovery from decompressed overlay reveals:

  • stratum, tcp://, miner, pool — confirms Stratum protocol mining ^[terminal:stream-decompress]
  • 127.0.0.1 — local interface reference for miner bind or test ^[terminal:stream-decompress]
  • link.txt — external C2/pool config file reference ^[terminal:stream-decompress]
  • No hardcoded attacker IP addresses or domains recovered from overlay.

Interesting Tidbits

  • Largest AES-encrypted hybrid in cluster: At 3.35 MB with 3.1 MB overlay (92.6%), this is the largest AES-encrypted sibling and the third-largest overall. The 176 zlib headers suggest the builder compressed each module individually before AES encryption. ^[terminal:overlay-analysis]
  • 176 zlib headers vs 34 decompressable: Only 34 of the 176 zlib headers produce valid decompressed output when fed raw bytes from the overlay. The remainder are likely AES-encrypted ciphertext blocks that happen to contain zlib-like byte sequences, or nested zlib streams inside larger AES blocks. This high header-to-success ratio is characteristic of the PyInstaller CFFI format when AES encryption is applied. ^[terminal:overlay-analysis]
  • Same QWERTY key and build path: The 1qazxsw23edcvfrN key and F:\files\ftp\crack\exe\build\ftpcrack\ path have now been observed across 15+ siblings spanning 2018–2026, confirming a long-lived, minimally maintained build pipeline. ^[terminal:stream0-decompress]
  • floss.txt is a tool-usage error (triage script passed the sample path to --no instead of the sample positional argument). ^[floss.txt]
  • capa.txt failed with missing default signature path — signatures were never installed on this station. ^[capa.txt]
  • No YARA matches beyond generic PE_File_Generic. ^[yara.txt]
  • Entropy of .text is 6.65, .rsrc is 7.26 — neither is packed; heavy entropy lives in the encrypted overlay. ^[pefile.txt:91-172]

How To Mess With It (Homelab Replication)

Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15

  1. Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
  2. Write a Python script (ftpcrack.py) that combines ftplib.FTP brute-force scanning with subprocess.Popen to deploy xmrig.exe and a config.json.
  3. Build: pyinstaller --onefile --windowed --key 1qazxsw23edcvfrN ftpcrack.py
  4. Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed AES-encrypted overlay starting at 0x3CE00 with 78 da headers.
  5. Decompress overlay with python -m zlib or binwalk -e to recover the embedded .pyc and python27.dll.

Deployable Signatures

YARA rule

rule pyinstaller_sep2018_aes_hybrid_ftpcrack_xmrig
{
    meta:
        description = "PyInstaller Sep 2018 cluster sibling with AES-encrypted hybrid ftpcrack+xmrig payload"
        author = "Demetrian Titus"
        date = "2026-08-24"
        sha256 = "e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5"
    strings:
        $pyi1 = "PyInstaller: " ascii
        $pyi2 = "_MEIPASS" ascii
        $pyi3 = "Failed to get address for Py_Initialize" ascii
        $aes_key = "1qazxsw23edcvfrN" ascii
        $build_path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii wide
        $ftpcrack = "ftpcrack.py" ascii
        $xmrig = "xmrig.exe" ascii
        $stratum = "stratum" ascii
        $taskkill = "taskkill /F /IM xmrig.exe" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 2MB and filesize < 5MB and
        2 of ($pyi*) and
        ($aes_key or $build_path) and
        ($ftpcrack or $xmrig)
}

Sigma rule

title: PyInstaller Sep 2018 Cluster Hybrid ftpcrack+xmrig Execution
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    CommandLine|contains:
      - '_MEI'
      - 'xmrig.exe'
      - 'config.json'
      - 'link.txt'
  selection2:
    CommandLine|contains:
      - 'taskkill /F /IM xmrig.exe'
      - 'ftpcrack.py'
  condition: selection or selection2
falsepositives:
  - Unknown
level: high

IOC list

Indicator Value Type
SHA-256 e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5 Hash
Build path F:\files\ftp\crack\exe\build\ftpcrack\ Build artefact
AES key 1qazxsw23edcvfrN Encryption key
Miner binary xmrig.exe Filename
Miner config config.json Filename
Pool config link.txt Filename
FTP module ftpcrack.py Filename
Temp directory %TEMP%\_MEI* Path pattern
Overlay start 0x3CE00 Raw offset

Behavioural fingerprint

This binary is a PyInstaller single-file PE32 with MSVC 14.0 CRT compiled on 4 Sep 2018 at 14:43:33 UTC. At runtime it extracts an AES-encrypted zlib-compressed Python payload to %TEMP%\_MEI<XXXX>, loads python27.dll from that directory, and executes embedded ftpcrack.py which contains both FTP brute-force credential scanning (with built-in dictionaries and random IP generation) and XMRig cryptocurrency miner deployment (via config.json/link.txt Stratum pool configuration). Post-extraction it spawns xmrig.exe from the temp directory. No anti-debug or VM detection is present.

Detection Signatures

  • PE_File_Generic YARA match (trivial, non-specific) ^[yara.txt]
  • floss.txt tool error — no decoded strings recovered ^[floss.txt]
  • capa.txt signature path missing — no capability mapping ^[capa.txt]

References

Provenance

Files consumed: file.txt, exiftool.json, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, floss.txt, capa.txt, yara.txt, triage.json, metadata.json. Tools: rabin2/radare2 (auto-analysis level 3, 930 functions), pefile, binwalk, exiftool, custom Python zlib overlay scanner. OS: pp-hermes LXC on Lab1BU (6.14.8-2-pve).