ftpcrack
Overview
FTP brute-force credential scanner distributed as a PyInstaller single-file PE. Built from the same Sep 2018 ftpcrack build pipeline as the PyInstaller coinminer cluster (same MSVC 14.0 linker, same compilation timestamp Sep 4 14:43:33 UTC, same F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\ build path). Two confirmed siblings: 135b3b8d (1.5 MB, 18 plain-zlib streams) and 551d2b0e (672 KB, 11 AES-encrypted streams with weak key 1qazxsw23edcvfrN). The tool generates random IP addresses, scans for FTP banners, and sprays built-in credential dictionaries (USER_DIC, PASSWORD_DIC) against discovered services.
Build-stack typically observed
- Toolchain: MSVC 14.0 (Visual Studio 2015) C bootloader compiled by PyInstaller 3.x circa 2018
- Runtime: Python 2.7.15 embedded via
python27.dll - Overlay: PyInstaller CArchive with zlib-compressed Python modules (plain zlib or AES-encrypted variants)
- Obfuscation: None beyond PyInstaller default packaging; AES-encrypted siblings use weak QWERTY-derived key
1qazxsw23edcvfrN - Signing: Unsigned
- Masquerade: Windows service wrapper strings (
StateftpService) suggest background-service persistence
Deploy / TTPs typically observed
- T1059.006 (Python) — execution via embedded Python interpreter
- T1074.001 (Data Staged: Local Data Staging) — extraction to
_MEItemp directory - T1105 (Ingress Tool Transfer) — self-contained payload delivery
- T1110.001 (Brute Force: Password Guessing) — FTP credential spraying from embedded dictionaries
- T1046 (Network Service Scanning) — random IP generation and FTP banner detection
- T1574.002 (DLL Side-Loading) — loading Python DLL from
_MEIpath
Variants / aliases
- No known aliases. Not a commercial malware family; appears to be a private crimeware toolkit module.
Capabilities
- pyinstaller-bootloader-extraction
- python-packed-payload
- random-ip-generation
- ftp-banner-detection
- multi-threaded-credential-spray
- built-in-password-dictionary
- windows-service-masquerade
- plain-zlib-overlay-variant
- aes-encrypted-overlay-variant
- aes-encrypted-hybrid-ftpcrack-xmrig-variant
Notable analyses
-
/intel/analyses/135b3b8d21eee1397dad0cd496e1e8f978724063ab093ee619b9bfcee87e6537.html — Plain-zlib ftpcrack sibling (1.5 MB, 18 zlib streams, no AES)
-
/intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — AES-encrypted ftpcrack sibling (672 KB, 11 streams, weak key
1qazxsw23edcvfrN) -
/intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html — Third confirmed sibling (488 KB, 10 zlib streams, AES-encrypted, smallest in cluster). Same Sep 2018 build fingerprint. ^[/intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html]
-
/intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — Fourth confirmed sibling (387 KB, 10 zlib streams, plain-zlib, no AES). First hybrid ftpcrack+xmrig payload in the cluster: overlay contains both FTP brute-force dictionaries (
USER_DIC/PASSWORD_DIC) and XMRig miner deployment artefacts (xmrig.exe,config.json,link.txt,stratumpool config). Same Sep 2018 build fingerprint. Updated 2026-08-10. -
/intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Fifth confirmed sibling (2.27 MB, 155 zlib streams, AES-encrypted with weak QWERTY key
1qazxsw23edcvfrN). Largest hybrid ftpcrack+xmrig payload in the cluster. Same Sep 2018 build fingerprint and identicalF:\files\ftp\crack\exe\build\ftpcrack\build path. Updated 2026-08-10. -
/intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Sixth confirmed sibling (4.7 MB, 37 zlib streams, plain-zlib overlay (no AES), 94.9% overlay ratio). Second-largest overall sibling in cluster. Second confirmed hybrid ftpcrack+xmrig payload after
2727eb40: decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-12. -
/intel/analyses/6c321d46aa87d2b3d282042c886b3459b57caca76029c2d6c2f8f8e9a7e5f468.html — Seventh confirmed sibling (320 KB, 10 zlib streams, AES-encrypted overlay with weak QWERTY key
1qazxsw23edcvfrN, 23.9% overlay ratio). Smallest sibling ever observed in the cluster. Confirmed hybrid ftpcrack+xmrig payload: overlay contains both FTP brute-force dictionaries and XMRig miner artefacts. SameF:\files\ftp\crack\exe\build\ftpcrack\build path. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-14. -
/intel/analyses/e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5.html — Eighth confirmed sibling (3.35 MB, 176 zlib streams, AES-encrypted overlay with weak QWERTY key
1qazxsw23edcvfrN, 92.6% overlay ratio). Largest AES-encrypted hybrid ftpcrack+xmrig payload in the cluster. Decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). SameF:\files\ftp\crack\exe\build\ftpcrack\build path. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-24. -
/intel/analyses/727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7.html — Ninth confirmed sibling (1.2 MB, 15 zlib streams, AES-encrypted overlay with weak QWERTY key
1qazxsw23edcvfrN, 79.7% overlay ratio). Lowest stream count in the AES-encrypted hybrid sub-cluster. Decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json,link.txt,stratum,taskkill /F /IM xmrig.exe). SameF:\files\ftp\crack\exe\build\ftpcrack\build path. Same Sep 2018 MSVC 14.0 build fingerprint. Nopython27.dllin outer strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-09-05.
Related entities/concepts
- coinminer — Shared PyInstaller build pipeline; same author/toolkit
- concepts/pyinstaller-bootloader — PyInstaller single-file C bootloader
- concepts/python-packed-payload — Python logic hidden in PE overlay
- concepts/social-engineering-filename-lure — May be paired with document-themed lures