e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5coinminer: e2b273fa — 3.35 MB AES-encrypted hybrid ftpcrack+xmrig, 176 zlib streams
Executive Summary
Twenty-eighth confirmed sibling in the September 2018 PyInstaller coinminer/ftpcrack cluster. At 3.35 MB it is the third-largest overall sibling and the largest AES-encrypted variant in the cluster, with a 92.6% overlay ratio (3.1 MB) comprising 176 zlib headers of which 34 decompress successfully. Same MSVC 14.0 build fingerprint (Sep 4 14:43:33 UTC), same weak AES key (1qazxsw23edcvfrN), same build path (F:\files\ftp\crack\exe\build\ftpcrack\). Decompressed overlay confirms a hybrid ftpcrack+xmrig payload: FTP brute-force credential dictionaries (USER_DIC, PASSWORD_DIC, RANDOM_IP_POOL) coexist with XMRig miner deployment artefacts (taskkill /F /IM xmrig.exe, config.json, link.txt, stratum pool). Static-only; CAPE skipped — no Windows guest.
What It Is
- File: PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
- Size: 3,350,119 bytes (3.35 MB) ^[triage.json] ^[exiftool.json]
- SHA-256:
e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5^[metadata.json] - Compiled: Tue Sep 4 14:43:33 2018 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Linker: MSVC 14.0 (Visual Studio 2015 RTM) ^[exiftool.json:18]
- Signed: false; header checksum 0x00000000 ^[rabin2-info.txt:15]
- ASLR / DEP: enabled (
DllCharacteristics: 0x8140) ^[pefile.txt:74] - Subsystem: Windows GUI ^[file.txt]
- Overlay: 3,100,775 bytes starting at raw offset
0x3CE00, 92.6% of file, AES-encrypted PyInstaller CFFI archive ^[binwalk.txt:11-48] ^[terminal:overlay-analysis] - Zlib streams: 176 zlib headers (
78 01,78 9c,78 da) in overlay; 34 successfully decompressable ^[terminal:overlay-analysis] - AES key:
1qazxsw23edcvfrN(left-hand QWERTY diagonal, identical to all AES-encrypted siblings) ^[terminal:stream0-decompress] - Build path:
F:\files\ftp\crack\exe\build\ftpcrack\pyimod00_crypto_key.pyt^[terminal:stream0-decompress] - Family: coinminer (OpenCTI label) ^[triage.json]
How It Works
Standard PyInstaller single-file C bootloader flow identical to the cluster documentation at pyinstaller-bootloader and coinminer:
- CRT initialisation — MSVC
entry0→main()→ PyInstaller bootstrap core ^[r2:entry0] - Archive resolution — locates CFFI archive appended past PE sections (overlay at
0x3CE00, same offset as every cluster sibling) ^[binwalk.txt] - Decryption — first zlib chunk decompresses to
pyimod00_crypto_key.pytcontaining the AES key1qazxsw23edcvfrN^[terminal:stream0-decompress] - Extraction — decrypts and decompresses remaining overlay entries to
%TEMP%\_MEI<XXXX>using zlib/inflate 1.2.8 ^[strings.txt:79] ^[strings.txt:115] - Python runtime bootstrap — loads
python*.dll, resolves CPython API procs (Py_Initialize,PyMarshal_ReadObjectFromString,PyEval_EvalCode, etc.) ^[strings.txt:119-212] - Script execution — unmarshals embedded
ftpcrack.pycode object and runs__main__.py^[strings.txt:104-111] - Cleanup — deletes temp directory on exit unless
_MEIPASS2is set ^[strings.txt:115]
Hybrid payload confirmed
Decompressed overlay stream at offset 0x3b3e within overlay (32,761 bytes) contains both:
- FTP brute-force scanner:
RANDOM_IP_POOL,USER_DIC,PASSWORD_DIC,ftplib.FTP, ICMP host-discovery (icmpPacket,icmpSocket), multi-threadedqueue_taskdispatch. Built-in credential templates include{user},{user}123,admin,root,test,www-data,password,123456,P@ssw0rd!!,1qaz2wsx,qwerty123456. ^[terminal:stream-decompress] - XMRig miner deployment:
taskkill /F /IM xmrig.exe,xmrig.exestaging,config.json,\link.txt,stratum,tcp://,miner,pool. ^[terminal:stream-decompress]
No anti-debug, no VM detection, no API hashing — stock PyInstaller circa 2018.
Cluster delta
| Sibling | Size | Overlay | Zlib blocks | Encryption | Hybrid? | Key |
|---|---|---|---|---|---|---|
| 801fbba1 | 799 KB | ~570 KB | — | None | No | N/A |
| 359fcf01 | 4.35 MB | ~4.3 MB | — | AES | No | 1qazxsw23edcvfrN |
| 2727eb40 | 387 KB | 138 KB | 10 | None | Yes | N/A |
| c0bc0bff | 2.27 MB | ~2.13 MB | 155 | AES | Yes | 1qazxsw23edcvfrN |
| bc206453 | 4.7 MB | ~4.68 MB | 37 | None | Yes | N/A |
| 6c321d46 | 320 KB | 78 KB | 10 | AES | Yes | 1qazxsw23edcvfrN |
| e2b273fa | 3.35 MB | 3.1 MB | 176 | AES | Yes | 1qazxsw23edcvfrN |
This sample is unique in the cluster for being the largest AES-encrypted hybrid sibling and having the highest zlib header count (176) of any sibling observed to date. Prior AES-encrypted hybrids were smaller (c0bc0bff at 2.27 MB, 6c321d46 at 320 KB). This proves the builder pipeline can produce very large AES-encrypted hybrid payloads.
Decompiled Behaviour
entry0(0x004079d3): MSVC CRT entry. Initialises security cookie and SEH, callsmain(), then CRT terminators. No anti-debug or VM checks. ^[r2:entry0]main(0x00401000): Three calls — archive status resolution, UTF-8 argv conversion, then PyInstaller bootstrap core (fcn.00402520). ^[r2:main]- PyInstaller bootstrap core: allocates
ARCHIVE_STATUS, checks_MEIPASS2, opens self as archive, iterates TOC, extracts to_MEItemp directory, sets DLL directory, then launches Python VM. ^[r2:fcn.00402520] - Imports are limited to standard Win32 +
WS2_32.dll.ntohl(pulled in by CRT, not actively used by the thin bootloader). ^[pefile.txt:249-373] .rsrcsection contains icon groups (PyInstaller default icon inheritance). ^[pefile.txt:159-534].gfidssection (Guard CF IAT) present, confirming CFG-aware compilation. ^[pefile.txt:139-156]
C2 Infrastructure
Partially observable. Mining pool configuration is not hardcoded in the outer binary; link.txt is referenced as a runtime config file (likely fetched or bundled inside the _MEI extract). The outer binary contains only generic PyInstaller error strings and MSVC CRT locale data. Stratum/TCP pool URLs and wallet addresses live inside the AES-encrypted Python payload. ^[strings.txt]
Static recovery from decompressed overlay reveals:
stratum,tcp://,miner,pool— confirms Stratum protocol mining ^[terminal:stream-decompress]127.0.0.1— local interface reference for miner bind or test ^[terminal:stream-decompress]link.txt— external C2/pool config file reference ^[terminal:stream-decompress]- No hardcoded attacker IP addresses or domains recovered from overlay.
Interesting Tidbits
- Largest AES-encrypted hybrid in cluster: At 3.35 MB with 3.1 MB overlay (92.6%), this is the largest AES-encrypted sibling and the third-largest overall. The 176 zlib headers suggest the builder compressed each module individually before AES encryption. ^[terminal:overlay-analysis]
- 176 zlib headers vs 34 decompressable: Only 34 of the 176 zlib headers produce valid decompressed output when fed raw bytes from the overlay. The remainder are likely AES-encrypted ciphertext blocks that happen to contain zlib-like byte sequences, or nested zlib streams inside larger AES blocks. This high header-to-success ratio is characteristic of the PyInstaller CFFI format when AES encryption is applied. ^[terminal:overlay-analysis]
- Same QWERTY key and build path: The
1qazxsw23edcvfrNkey andF:\files\ftp\crack\exe\build\ftpcrack\path have now been observed across 15+ siblings spanning 2018–2026, confirming a long-lived, minimally maintained build pipeline. ^[terminal:stream0-decompress] floss.txtis a tool-usage error (triage script passed the sample path to--noinstead of thesamplepositional argument). ^[floss.txt]capa.txtfailed with missing default signature path — signatures were never installed on this station. ^[capa.txt]- No YARA matches beyond generic
PE_File_Generic. ^[yara.txt] - Entropy of
.textis 6.65,.rsrcis 7.26 — neither is packed; heavy entropy lives in the encrypted overlay. ^[pefile.txt:91-172]
How To Mess With It (Homelab Replication)
Toolchain: Visual Studio 2015 (MSVC 14.0) + PyInstaller 3.x + Python 2.7.15
- Install Python 2.7.15 and PyInstaller 3.4 on a Windows VM.
- Write a Python script (
ftpcrack.py) that combinesftplib.FTPbrute-force scanning withsubprocess.Popento deployxmrig.exeand aconfig.json. - Build:
pyinstaller --onefile --windowed --key 1qazxsw23edcvfrN ftpcrack.py - Verify: the resulting PE should show MSVC 14.0 linker, Sep 2018 timestamp (if backdated), and a zlib-compressed AES-encrypted overlay starting at 0x3CE00 with
78 daheaders. - Decompress overlay with
python -m zliborbinwalk -eto recover the embedded.pycandpython27.dll.
Deployable Signatures
YARA rule
rule pyinstaller_sep2018_aes_hybrid_ftpcrack_xmrig
{
meta:
description = "PyInstaller Sep 2018 cluster sibling with AES-encrypted hybrid ftpcrack+xmrig payload"
author = "Demetrian Titus"
date = "2026-08-24"
sha256 = "e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5"
strings:
$pyi1 = "PyInstaller: " ascii
$pyi2 = "_MEIPASS" ascii
$pyi3 = "Failed to get address for Py_Initialize" ascii
$aes_key = "1qazxsw23edcvfrN" ascii
$build_path = "F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\" ascii wide
$ftpcrack = "ftpcrack.py" ascii
$xmrig = "xmrig.exe" ascii
$stratum = "stratum" ascii
$taskkill = "taskkill /F /IM xmrig.exe" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 2MB and filesize < 5MB and
2 of ($pyi*) and
($aes_key or $build_path) and
($ftpcrack or $xmrig)
}
Sigma rule
title: PyInstaller Sep 2018 Cluster Hybrid ftpcrack+xmrig Execution
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '_MEI'
- 'xmrig.exe'
- 'config.json'
- 'link.txt'
selection2:
CommandLine|contains:
- 'taskkill /F /IM xmrig.exe'
- 'ftpcrack.py'
condition: selection or selection2
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5 |
Hash |
| Build path | F:\files\ftp\crack\exe\build\ftpcrack\ |
Build artefact |
| AES key | 1qazxsw23edcvfrN |
Encryption key |
| Miner binary | xmrig.exe |
Filename |
| Miner config | config.json |
Filename |
| Pool config | link.txt |
Filename |
| FTP module | ftpcrack.py |
Filename |
| Temp directory | %TEMP%\_MEI* |
Path pattern |
| Overlay start | 0x3CE00 |
Raw offset |
Behavioural fingerprint
This binary is a PyInstaller single-file PE32 with MSVC 14.0 CRT compiled on 4 Sep 2018 at 14:43:33 UTC. At runtime it extracts an AES-encrypted zlib-compressed Python payload to %TEMP%\_MEI<XXXX>, loads python27.dll from that directory, and executes embedded ftpcrack.py which contains both FTP brute-force credential scanning (with built-in dictionaries and random IP generation) and XMRig cryptocurrency miner deployment (via config.json/link.txt Stratum pool configuration). Post-extraction it spawns xmrig.exe from the temp directory. No anti-debug or VM detection is present.
Detection Signatures
PE_File_GenericYARA match (trivial, non-specific) ^[yara.txt]floss.txttool error — no decoded strings recovered ^[floss.txt]capa.txtsignature path missing — no capability mapping ^[capa.txt]
References
- coinminer — Cluster entity page
- ftpcrack — Shared build pipeline entity page
- pyinstaller-bootloader — Build technique concept page
- python-packed-payload — Python-in-PE concept page
- OpenCTI label:
coinminer/exe/urlhaus
Provenance
Files consumed: file.txt, exiftool.json, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, floss.txt, capa.txt, yara.txt, triage.json, metadata.json. Tools: rabin2/radare2 (auto-analysis level 3, 930 functions), pefile, binwalk, exiftool, custom Python zlib overlay scanner. OS: pp-hermes LXC on Lab1BU (6.14.8-2-pve).