typeentityconfidencemediumcreated2026-05-26updated2026-09-05malware-familycryptominerimpactdefense-evasionpe

coinminer

Overview

Broad family label applied to commodity cryptocurrency-mining malware. Encompasses stand-alone miners (XMRig, NBMiner), miner-as-a-service downloaders, and droppers that stage mining payloads via legitimate-looking installers. Typically delivered by stealers (e.g., AcrStealer) or bundled with cracked software and game cheats. First-seen in this wiki: 2026-05-26.

Build-stack typically observed

  • Miners: GCC/MinGW (CryptoNight), MSVC (XMRig MSVC builds), Go (some pool-proxy wrappers), .NET (downloader stubs)
  • Droppers: 7-Zip SFX Constructor, Inno Setup, NSIS, or custom PE droppers with embedded 7z/RAR archives
  • Obfuscation: Password-protected 7z archives (AES-256), UPX on miner binaries, string encryption in pool URLs
  • Signing: Some droppers carry valid or expired Authenticode signatures cloned from redistributables or open-source tools ^[/intel/analyses/c4ac74268abff27a68f363c4d64cdbb4f743ce5b3dcb1551bf83f4d974ec2326.html]

Deploy / TTPs typically observed

  • 7-Zip SFX silent extraction (T1059.003 / T1218.011)
  • batch script execution (T1059.003)
  • temp-directory payload staging (T1074.001)
  • job object process constraint (T1106)
  • Registry Run keys or scheduled tasks for persistence
  • Driver abuse (WinRing0x64.sys) for kernel-level hardware access on some variants
  • Exfil via mining pool Stratum/TCP on port 3333/4444/45700

Variants / aliases

  • XMRig CoinMiner (OpenCTI: de9bacb4-8101-4307-933c-cb0778b42f8c)
  • CoinMiner/Win.Agent.R631683
  • CoinMiner/Win.Zephyr.C5575600

Capabilities

  • 7z-sfx-silent-extraction
  • password-protected-archive-deployment
  • batch-script-payload-launcher
  • temp-directory-payload-staging
  • job-object-process-lifecycle
  • authenticode-signature-clone
  • self-deletion-post-extraction
  • stratum-pool-communication
  • pyinstaller-bootloader-extraction
  • python-packed-coinminer-payload
  • aes-encrypted-hybrid-ftpcrack-xmrig
  • aes-encrypted-overlay-pyinstaller-key
  • qwerty-derived-weak-key
  • ftp-brute-force-credential-cracker
  • random-ip-generation
  • multi-threaded-credential-spray
  • windows-service-masquerade
  • xmrig-miner-binary-embedded
  • hybrid-ftpcrack-xmrig-payload
  • icmp-host-discovery
  • link.txt-runtime-config

Notable analyses

  • /intel/analyses/c4ac74268abff27a68f363c4d64cdbb4f743ce5b3dcb1551bf83f4d974ec2326.html — Signed 7-Zip SFX dropper masquerading as VC++ redistributable, password-protected payload

  • /intel/analyses/801fbba19b4d4828191e87e7311480deaf81e84482dab70adf38d61afd01c1fa.html — PyInstaller single-file bootloader (MSVC 2015, Sep 2018) with embedded Python coinminer payload in zlib-compressed overlay

  • /intel/analyses/39b67a790b89fc8170703baaa98b29e1453a63416f0320bb3ae0f2936306f184.html — PyInstaller bootloader sibling, 4.3 MB with 94% zlib overlay, identical build fingerprint to 801fbba1

  • /intel/analyses/5047235c1d599c8a4e39a073c8c71e6ac6579da3f03606f51cae9b17fe971858.html — Third sibling (1.75 MB) with appended secondary PE at offset 0x173c00, 1.8 MB overlay

  • /intel/analyses/640ed5b536824541112a8b54488353d2938b4d0368a3ed14d41efff1d841c346.html — Fourth sibling (735 KB), same Sep 2018 build fingerprint

  • /intel/analyses/359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c.html — Fifth sibling (4.35 MB), AES-encrypted overlay with weak QWERTY-derived key 1qazxsw23edcvfrN, build path F:\files\ftp\crack\exe\build\ftpcrack\

  • /intel/analyses/b4cc27e365f44dd18593d7ca2b4a2d9df95268079beff47940f48cce21bfc979.html — Sixth sibling (630 KB, smallest in cluster), Python 2.7 runtime (python27.dll, libgcc_s_dw2-1.dll), same Sep 2018 build fingerprint, 60.5% zlib overlay.

  • /intel/analyses/fbfd2d94d8ee85145fc7bdc8e6c119f4c72018c06d8a9f3ebb4771a2fbd37a50.html — Seventh sibling (2.37 MB), 89% zlib overlay with 30+ compressed blocks, same Sep 2018 build fingerprint

  • /intel/analyses/058ab6252975132460f88bca500c298352643888767b81ec73afe355ec593a34.html — Eighth sibling (2.76 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical build path as 359fcf01; twin from same build pipeline

  • /intel/analyses/983d2606de9089f78df7903daf6aa53eff6d87c2216d67fb840b637d053045e1.html — Ninth sibling (2.43 MB), AES-encrypted overlay with same weak QWERTY key and identical build path as 359fcf01 and 058ab625; confirms variable payload sizes in the same build campaign

  • /intel/analyses/f7abdaf88b8f90e6672e19641a40f88c91f17140c4973c8ff7dd2be52bbdde64.html — Tenth sibling (1.96 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical ftpcrack build path; 29 zlib blocks in overlay, second-smallest AES-encrypted sibling

  • /intel/analyses/fa98331d055828f59834eda383865ba1870c0c47d9de8617c1b22862c252d582.html — Eleventh sibling (4.07 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical ftpcrack build path; 3.74 MB overlay (94% of file), largest sibling and largest AES-encrypted variant in cluster

  • /intel/analyses/f284c9aa10c186c297c5da17ee08d3b1c44be26b0623e305bb6826c9ebf9a40e.html — Twelfth sibling (6.1 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical ftpcrack build path; 5.84 MB overlay (95.9% of file), largest sibling overall and highest overlay ratio in cluster. 63 zlib blocks.

  • /intel/analyses/6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a.html — Thirteenth sibling (5.34 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical ftpcrack build path; 5.10 MB overlay (95.5% of file), second-largest AES-encrypted variant in cluster.

  • /intel/analyses/af7aebb9817900fca79fc4d193f61b7f1c7550cf4cdd8bd6beed53f0ba023043.html — Fifteenth confirmed sibling (2.25 MB), AES-encrypted overlay with 85 zlib blocks (highest block count in cluster), 2.0 MB overlay (88.9% of file). Same Sep 2018 MSVC 14.0 build fingerprint.

  • /intel/analyses/a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4.html — Divergent .NET crypter/loader sibling (7.45 MB, May 2026). ConfuserEx v1.9.0.0 obfuscated .NET Framework PE32 with RijndaelManaged+DeflateStream encrypted manifest resource (~7.29 MB). Build stack is entirely different from the PyInstaller cluster — no python27.dll, no zlib overlay, no Sep 2018 timestamp. Low-confidence coinminer attribution; may be a mislabeled crypter/loader. Static-only.

  • /intel/analyses/1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4.html — Sixteenth confirmed sibling (4.14 MB), plain-zlib overlay (no AES encryption layer, no pyimod00_crypto_key), 44 zlib blocks. Second-largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only.

  • /intel/analyses/da02fd0723caacead4f056ddcb30995785e52f60dbd5c5c00828de5b54a0aad9.html — Seventeenth confirmed sibling (5.82 MB), plain-zlib overlay (no AES), 39 zlib streams, 5.32 MB overlay (91.4% of file). Largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only.

  • /intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — Mislabelled sibling (672 KB). Same Sep 2018 MSVC 14.0 build fingerprint and ftpcrack build path as the confirmed PyInstaller cluster, but actual payload is an FTP brute-force credential cracker (ftpcrack.py), not a miner. OpenCTI coinminer label is a pipeline-level misattribution. Eleven zlib streams in overlay include pyimod00_crypto_key.pyc (weak AES key 1qazxsw23edcvfrN), three UPX-packed python27.dll dependencies, and the ftpcrack.py module with built-in user/password dictionaries and random IP generation. Static-only.

  • /intel/analyses/135b3b8d21eee1397dad0cd496e1e8f978724063ab093ee619b9bfcee87e6537.html — Plain-zlib ftpcrack sibling (1.5 MB, 18 zlib streams, no AES encryption). Same Sep 2018 MSVC 14.0 build fingerprint and ftpcrack build path as 551d2b0e, but without the weak AES key. Confirms the build pipeline produced both encrypted and unencrypted variants. Actual payload is ftpcrack.py (FTP brute-force scanner), not a miner. Static-only.

  • /intel/analyses/e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612.html — Eighteenth confirmed sibling (1.18 MB), AES-encrypted overlay with same weak QWERTY key 1qazxsw23edcvfrN and identical ftpcrack build path; 8 zlib blocks in overlay (fewest of any AES-encrypted sibling), ~963 KB overlay (79.4% of file). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only.

  • /intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html — Nineteenth confirmed PyInstaller sibling (488 KB), but actual payload is ftpcrack.py (FTP brute-force scanner), not a miner. Same Sep 2018 MSVC 14.0 build fingerprint, same weak AES key. Third confirmed ftpcrack mislabel in cluster. Static-only.

  • /intel/analyses/d90f5359a9c56265374bc44cfb1d29de2af9fa2b4f3a80e8cad7342a7dfc48d3.html — Twentieth confirmed PyInstaller sibling (984 KB, 1.0 MB), plain-zlib overlay (no AES encryption layer, no pyimod00_crypto_key). 75.3% overlay ratio (~758 KB). Same Sep 2018 MSVC 14.0 build fingerprint. No static mining indicators; payload in zlib CFFI archive. Static-only.

  • /intel/analyses/325776ec147f0e9087a068ea6aae7815c0081bb0df2cac23a80db82f1cd6ed59.html — Twenty-first confirmed PyInstaller sibling (3.61 MB), plain-zlib overlay (no AES), 47 zlib streams, 3.53 MB overlay (93.4% of file). Second-largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. No python27.dll or ftpcrack.py in overlay; payload is distinct from the ftpcrack mislabel sub-cluster. Static-only.

  • /intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html — Twenty-second confirmed PyInstaller sibling (5.98 MB), plain-zlib overlay (no AES), 47 zlib streams, 6.02 MB overlay (96.0% of file). Largest sibling in cluster. Confirms embedded xmrig.exe miner via CFFI TOC string recovery. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-09.

  • /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — Twenty-third confirmed PyInstaller sibling (387 KB, 10 zlib streams, 138 KB overlay, 35.7% ratio). First hybrid ftpcrack+xmrig payload in the cluster: decompressed overlay contains both ftpcrack.py module strings (FTP credential dictionaries, RANDOM_IP_POOL, ICMP crafting) and XMRig miner deployment artefacts (taskkill /F /IM xmrig.exe, config.json, link.txt, stratum pool config). Plain-zlib overlay (no AES). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-10.

  • /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Twenty-fourth confirmed PyInstaller sibling (2.27 MB, 155 zlib streams, 2.13 MB overlay, 89.5% ratio). Largest hybrid ftpcrack+xmrig payload in the cluster. AES-encrypted overlay with weak QWERTY-derived key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Decompressed overlay contains both ftpcrack.py FTP brute-force dictionaries and xmrig.exe miner deployment artefacts (config.json, link.txt, stratum pool config). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-10.

  • /intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Twenty-fifth confirmed PyInstaller sibling (4.7 MB, 37 zlib streams, 4.68 MB overlay, 94.9% ratio). Second-largest overall sibling in cluster. Plain-zlib overlay (no AES encryption) — pyimod00_crypto_key absent, overlay starts with zlib header 78 da. Second confirmed hybrid ftpcrack+xmrig payload after 2727eb40: decompressed overlay contains ftpcrack.py credential dictionaries (USER_DIC/PASSWORD_DIC), xmrig.exe miner artefacts (config.json, link.txt, stratum), and taskkill /F /IM xmrig.exe. Same Sep 2018 MSVC 14.0 build fingerprint. No python27.dll in strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-12.

  • /intel/analyses/6c321d46aa87d2b3d282042c886b3459b57caca76029c2d6c2f8f8e9a7e5f468.html — Twenty-sixth confirmed PyInstaller sibling (320 KB, 10 zlib streams, 78 KB overlay, 23.9% ratio). Smallest sibling ever observed in the cluster. AES-encrypted overlay with weak QWERTY-derived key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Confirmed hybrid ftpcrack+xmrig payload: overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-14.

  • /intel/analyses/0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346.html — Twenty-seventh confirmed PyInstaller sibling (2.23 MB, 139 zlib streams, 1.99 MB overlay, 88.8% ratio). Highest zlib-stream count in the cluster. AES-encrypted overlay with same weak QWERTY-derived key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-15.

  • /intel/analyses/e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5.html — Twenty-eighth confirmed PyInstaller sibling (3.35 MB, 176 zlib streams, 3.1 MB overlay, 92.6% ratio). Largest AES-encrypted hybrid ftpcrack+xmrig payload in the cluster. AES-encrypted overlay with same weak QWERTY-derived key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-24.

  • /intel/analyses/727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7.html — Twenty-ninth confirmed PyInstaller sibling (1.2 MB, 15 zlib streams, 979 KB overlay, 79.7% ratio). Lowest stream count in the AES-encrypted hybrid sub-cluster. AES-encrypted overlay with same weak QWERTY-derived key 1qazxsw23edcvfrN and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. No python27.dll in outer strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-09-05.

Related entities/concepts