coinminer
Overview
Broad family label applied to commodity cryptocurrency-mining malware. Encompasses stand-alone miners (XMRig, NBMiner), miner-as-a-service downloaders, and droppers that stage mining payloads via legitimate-looking installers. Typically delivered by stealers (e.g., AcrStealer) or bundled with cracked software and game cheats. First-seen in this wiki: 2026-05-26.
Build-stack typically observed
- Miners: GCC/MinGW (CryptoNight), MSVC (XMRig MSVC builds), Go (some pool-proxy wrappers), .NET (downloader stubs)
- Droppers: 7-Zip SFX Constructor, Inno Setup, NSIS, or custom PE droppers with embedded 7z/RAR archives
- Obfuscation: Password-protected 7z archives (AES-256), UPX on miner binaries, string encryption in pool URLs
- Signing: Some droppers carry valid or expired Authenticode signatures cloned from redistributables or open-source tools ^[/intel/analyses/c4ac74268abff27a68f363c4d64cdbb4f743ce5b3dcb1551bf83f4d974ec2326.html]
Deploy / TTPs typically observed
- 7-Zip SFX silent extraction (T1059.003 / T1218.011)
- batch script execution (T1059.003)
- temp-directory payload staging (T1074.001)
- job object process constraint (T1106)
- Registry Run keys or scheduled tasks for persistence
- Driver abuse (WinRing0x64.sys) for kernel-level hardware access on some variants
- Exfil via mining pool Stratum/TCP on port 3333/4444/45700
Variants / aliases
- XMRig CoinMiner (OpenCTI:
de9bacb4-8101-4307-933c-cb0778b42f8c) - CoinMiner/Win.Agent.R631683
- CoinMiner/Win.Zephyr.C5575600
Capabilities
- 7z-sfx-silent-extraction
- password-protected-archive-deployment
- batch-script-payload-launcher
- temp-directory-payload-staging
- job-object-process-lifecycle
- authenticode-signature-clone
- self-deletion-post-extraction
- stratum-pool-communication
- pyinstaller-bootloader-extraction
- python-packed-coinminer-payload
- aes-encrypted-hybrid-ftpcrack-xmrig
- aes-encrypted-overlay-pyinstaller-key
- qwerty-derived-weak-key
- ftp-brute-force-credential-cracker
- random-ip-generation
- multi-threaded-credential-spray
- windows-service-masquerade
- xmrig-miner-binary-embedded
- hybrid-ftpcrack-xmrig-payload
- icmp-host-discovery
- link.txt-runtime-config
Notable analyses
-
/intel/analyses/c4ac74268abff27a68f363c4d64cdbb4f743ce5b3dcb1551bf83f4d974ec2326.html — Signed 7-Zip SFX dropper masquerading as VC++ redistributable, password-protected payload
-
/intel/analyses/801fbba19b4d4828191e87e7311480deaf81e84482dab70adf38d61afd01c1fa.html — PyInstaller single-file bootloader (MSVC 2015, Sep 2018) with embedded Python coinminer payload in zlib-compressed overlay
-
/intel/analyses/39b67a790b89fc8170703baaa98b29e1453a63416f0320bb3ae0f2936306f184.html — PyInstaller bootloader sibling, 4.3 MB with 94% zlib overlay, identical build fingerprint to 801fbba1
-
/intel/analyses/5047235c1d599c8a4e39a073c8c71e6ac6579da3f03606f51cae9b17fe971858.html — Third sibling (1.75 MB) with appended secondary PE at offset 0x173c00, 1.8 MB overlay
-
/intel/analyses/640ed5b536824541112a8b54488353d2938b4d0368a3ed14d41efff1d841c346.html — Fourth sibling (735 KB), same Sep 2018 build fingerprint
-
/intel/analyses/359fcf01a54b89eabcbfcecd734e2af60b6bfa19ffd7fcdd87b1e4ed15db599c.html — Fifth sibling (4.35 MB), AES-encrypted overlay with weak QWERTY-derived key
1qazxsw23edcvfrN, build pathF:\files\ftp\crack\exe\build\ftpcrack\ -
/intel/analyses/b4cc27e365f44dd18593d7ca2b4a2d9df95268079beff47940f48cce21bfc979.html — Sixth sibling (630 KB, smallest in cluster), Python 2.7 runtime (
python27.dll,libgcc_s_dw2-1.dll), same Sep 2018 build fingerprint, 60.5% zlib overlay. -
/intel/analyses/fbfd2d94d8ee85145fc7bdc8e6c119f4c72018c06d8a9f3ebb4771a2fbd37a50.html — Seventh sibling (2.37 MB), 89% zlib overlay with 30+ compressed blocks, same Sep 2018 build fingerprint
-
/intel/analyses/058ab6252975132460f88bca500c298352643888767b81ec73afe355ec593a34.html — Eighth sibling (2.76 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identical build path as359fcf01; twin from same build pipeline -
/intel/analyses/983d2606de9089f78df7903daf6aa53eff6d87c2216d67fb840b637d053045e1.html — Ninth sibling (2.43 MB), AES-encrypted overlay with same weak QWERTY key and identical build path as
359fcf01and058ab625; confirms variable payload sizes in the same build campaign -
/intel/analyses/f7abdaf88b8f90e6672e19641a40f88c91f17140c4973c8ff7dd2be52bbdde64.html — Tenth sibling (1.96 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identicalftpcrackbuild path; 29 zlib blocks in overlay, second-smallest AES-encrypted sibling -
/intel/analyses/fa98331d055828f59834eda383865ba1870c0c47d9de8617c1b22862c252d582.html — Eleventh sibling (4.07 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identicalftpcrackbuild path; 3.74 MB overlay (94% of file), largest sibling and largest AES-encrypted variant in cluster -
/intel/analyses/f284c9aa10c186c297c5da17ee08d3b1c44be26b0623e305bb6826c9ebf9a40e.html — Twelfth sibling (6.1 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identicalftpcrackbuild path; 5.84 MB overlay (95.9% of file), largest sibling overall and highest overlay ratio in cluster. 63 zlib blocks. -
/intel/analyses/6b2591e40fbba62b96e76a515e426248ac0d9dc5d488054d143ea2e62610bc6a.html — Thirteenth sibling (5.34 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identicalftpcrackbuild path; 5.10 MB overlay (95.5% of file), second-largest AES-encrypted variant in cluster. -
/intel/analyses/af7aebb9817900fca79fc4d193f61b7f1c7550cf4cdd8bd6beed53f0ba023043.html — Fifteenth confirmed sibling (2.25 MB), AES-encrypted overlay with 85 zlib blocks (highest block count in cluster), 2.0 MB overlay (88.9% of file). Same Sep 2018 MSVC 14.0 build fingerprint.
-
/intel/analyses/a80c26e2ddd396cefdff71ba1b3fc8700e884b95b0889b229e2cc1cee96dd8e4.html — Divergent .NET crypter/loader sibling (7.45 MB, May 2026). ConfuserEx v1.9.0.0 obfuscated .NET Framework PE32 with RijndaelManaged+DeflateStream encrypted manifest resource (~7.29 MB). Build stack is entirely different from the PyInstaller cluster — no
python27.dll, no zlib overlay, no Sep 2018 timestamp. Low-confidencecoinminerattribution; may be a mislabeled crypter/loader. Static-only. -
/intel/analyses/1fed143e0f95ce0e7e6070d89745c74b6a086df0387a2e091720be20a27774b4.html — Sixteenth confirmed sibling (4.14 MB), plain-zlib overlay (no AES encryption layer, no
pyimod00_crypto_key), 44 zlib blocks. Second-largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only. -
/intel/analyses/da02fd0723caacead4f056ddcb30995785e52f60dbd5c5c00828de5b54a0aad9.html — Seventeenth confirmed sibling (5.82 MB), plain-zlib overlay (no AES), 39 zlib streams, 5.32 MB overlay (91.4% of file). Largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only.
-
/intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — Mislabelled sibling (672 KB). Same Sep 2018 MSVC 14.0 build fingerprint and
ftpcrackbuild path as the confirmed PyInstaller cluster, but actual payload is an FTP brute-force credential cracker (ftpcrack.py), not a miner. OpenCTIcoinminerlabel is a pipeline-level misattribution. Eleven zlib streams in overlay includepyimod00_crypto_key.pyc(weak AES key1qazxsw23edcvfrN), three UPX-packedpython27.dlldependencies, and theftpcrack.pymodule with built-in user/password dictionaries and random IP generation. Static-only. -
/intel/analyses/135b3b8d21eee1397dad0cd496e1e8f978724063ab093ee619b9bfcee87e6537.html — Plain-zlib ftpcrack sibling (1.5 MB, 18 zlib streams, no AES encryption). Same Sep 2018 MSVC 14.0 build fingerprint and
ftpcrackbuild path as551d2b0e, but without the weak AES key. Confirms the build pipeline produced both encrypted and unencrypted variants. Actual payload isftpcrack.py(FTP brute-force scanner), not a miner. Static-only. -
/intel/analyses/e019096c77e4954d114365a7d77ae34c828e4bf5ab30e51c4be38dbc4b066612.html — Eighteenth confirmed sibling (1.18 MB), AES-encrypted overlay with same weak QWERTY key
1qazxsw23edcvfrNand identicalftpcrackbuild path; 8 zlib blocks in overlay (fewest of any AES-encrypted sibling), ~963 KB overlay (79.4% of file). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only. -
/intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html — Nineteenth confirmed PyInstaller sibling (488 KB), but actual payload is
ftpcrack.py(FTP brute-force scanner), not a miner. Same Sep 2018 MSVC 14.0 build fingerprint, same weak AES key. Third confirmedftpcrackmislabel in cluster. Static-only. -
/intel/analyses/d90f5359a9c56265374bc44cfb1d29de2af9fa2b4f3a80e8cad7342a7dfc48d3.html — Twentieth confirmed PyInstaller sibling (984 KB, 1.0 MB), plain-zlib overlay (no AES encryption layer, no
pyimod00_crypto_key). 75.3% overlay ratio (~758 KB). Same Sep 2018 MSVC 14.0 build fingerprint. No static mining indicators; payload in zlib CFFI archive. Static-only. -
/intel/analyses/325776ec147f0e9087a068ea6aae7815c0081bb0df2cac23a80db82f1cd6ed59.html — Twenty-first confirmed PyInstaller sibling (3.61 MB), plain-zlib overlay (no AES), 47 zlib streams, 3.53 MB overlay (93.4% of file). Second-largest plain-zlib variant in cluster. Same Sep 2018 MSVC 14.0 build fingerprint. No
python27.dllorftpcrack.pyin overlay; payload is distinct from theftpcrackmislabel sub-cluster. Static-only. -
/intel/analyses/5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fca.html — Twenty-second confirmed PyInstaller sibling (5.98 MB), plain-zlib overlay (no AES), 47 zlib streams, 6.02 MB overlay (96.0% of file). Largest sibling in cluster. Confirms embedded
xmrig.exeminer via CFFI TOC string recovery. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-09. -
/intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — Twenty-third confirmed PyInstaller sibling (387 KB, 10 zlib streams, 138 KB overlay, 35.7% ratio). First hybrid ftpcrack+xmrig payload in the cluster: decompressed overlay contains both
ftpcrack.pymodule strings (FTP credential dictionaries,RANDOM_IP_POOL, ICMP crafting) and XMRig miner deployment artefacts (taskkill /F /IM xmrig.exe,config.json,link.txt,stratumpool config). Plain-zlib overlay (no AES). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-10. -
/intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Twenty-fourth confirmed PyInstaller sibling (2.27 MB, 155 zlib streams, 2.13 MB overlay, 89.5% ratio). Largest hybrid ftpcrack+xmrig payload in the cluster. AES-encrypted overlay with weak QWERTY-derived key
1qazxsw23edcvfrNand identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Decompressed overlay contains bothftpcrack.pyFTP brute-force dictionaries andxmrig.exeminer deployment artefacts (config.json,link.txt,stratumpool config). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-10. -
/intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Twenty-fifth confirmed PyInstaller sibling (4.7 MB, 37 zlib streams, 4.68 MB overlay, 94.9% ratio). Second-largest overall sibling in cluster. Plain-zlib overlay (no AES encryption) —
pyimod00_crypto_keyabsent, overlay starts with zlib header78 da. Second confirmed hybrid ftpcrack+xmrig payload after2727eb40: decompressed overlay containsftpcrack.pycredential dictionaries (USER_DIC/PASSWORD_DIC),xmrig.exeminer artefacts (config.json,link.txt,stratum), andtaskkill /F /IM xmrig.exe. Same Sep 2018 MSVC 14.0 build fingerprint. Nopython27.dllin strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-12. -
/intel/analyses/6c321d46aa87d2b3d282042c886b3459b57caca76029c2d6c2f8f8e9a7e5f468.html — Twenty-sixth confirmed PyInstaller sibling (320 KB, 10 zlib streams, 78 KB overlay, 23.9% ratio). Smallest sibling ever observed in the cluster. AES-encrypted overlay with weak QWERTY-derived key
1qazxsw23edcvfrNand identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Confirmed hybrid ftpcrack+xmrig payload: overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-14. -
/intel/analyses/0f0dbe32306f26d182bdf2a1f3ba91e0a57c15c46b5587c089dbbe645b928346.html — Twenty-seventh confirmed PyInstaller sibling (2.23 MB, 139 zlib streams, 1.99 MB overlay, 88.8% ratio). Highest zlib-stream count in the cluster. AES-encrypted overlay with same weak QWERTY-derived key
1qazxsw23edcvfrNand identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-15. -
/intel/analyses/e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5.html — Twenty-eighth confirmed PyInstaller sibling (3.35 MB, 176 zlib streams, 3.1 MB overlay, 92.6% ratio). Largest AES-encrypted hybrid ftpcrack+xmrig payload in the cluster. AES-encrypted overlay with same weak QWERTY-derived key
1qazxsw23edcvfrNand identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-24. -
/intel/analyses/727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7.html — Twenty-ninth confirmed PyInstaller sibling (1.2 MB, 15 zlib streams, 979 KB overlay, 79.7% ratio). Lowest stream count in the AES-encrypted hybrid sub-cluster. AES-encrypted overlay with same weak QWERTY-derived key
1qazxsw23edcvfrNand identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Hybrid ftpcrack+xmrig payload: decompressed streams contain both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC/RANDOM_IP) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Nopython27.dllin outer strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-09-05.
Related entities/concepts
- unclassified-dropper
- pyinstaller-bootloader
- python-packed-payload