typeentityconfidencemediumcreated2026-08-03updated2026-09-05malware-familypython-pyinstallercredential-theftimpactpe

ftpcrack

Overview

FTP brute-force credential scanner distributed as a PyInstaller single-file PE. Built from the same Sep 2018 ftpcrack build pipeline as the PyInstaller coinminer cluster (same MSVC 14.0 linker, same compilation timestamp Sep 4 14:43:33 UTC, same F:\\files\\ftp\\crack\\exe\\build\\ftpcrack\\ build path). Two confirmed siblings: 135b3b8d (1.5 MB, 18 plain-zlib streams) and 551d2b0e (672 KB, 11 AES-encrypted streams with weak key 1qazxsw23edcvfrN). The tool generates random IP addresses, scans for FTP banners, and sprays built-in credential dictionaries (USER_DIC, PASSWORD_DIC) against discovered services.

Build-stack typically observed

  • Toolchain: MSVC 14.0 (Visual Studio 2015) C bootloader compiled by PyInstaller 3.x circa 2018
  • Runtime: Python 2.7.15 embedded via python27.dll
  • Overlay: PyInstaller CArchive with zlib-compressed Python modules (plain zlib or AES-encrypted variants)
  • Obfuscation: None beyond PyInstaller default packaging; AES-encrypted siblings use weak QWERTY-derived key 1qazxsw23edcvfrN
  • Signing: Unsigned
  • Masquerade: Windows service wrapper strings (StateftpService) suggest background-service persistence

Deploy / TTPs typically observed

  • T1059.006 (Python) — execution via embedded Python interpreter
  • T1074.001 (Data Staged: Local Data Staging) — extraction to _MEI temp directory
  • T1105 (Ingress Tool Transfer) — self-contained payload delivery
  • T1110.001 (Brute Force: Password Guessing) — FTP credential spraying from embedded dictionaries
  • T1046 (Network Service Scanning) — random IP generation and FTP banner detection
  • T1574.002 (DLL Side-Loading) — loading Python DLL from _MEI path

Variants / aliases

  • No known aliases. Not a commercial malware family; appears to be a private crimeware toolkit module.

Capabilities

  • pyinstaller-bootloader-extraction
  • python-packed-payload
  • random-ip-generation
  • ftp-banner-detection
  • multi-threaded-credential-spray
  • built-in-password-dictionary
  • windows-service-masquerade
  • plain-zlib-overlay-variant
  • aes-encrypted-overlay-variant
  • aes-encrypted-hybrid-ftpcrack-xmrig-variant

Notable analyses

  • /intel/analyses/135b3b8d21eee1397dad0cd496e1e8f978724063ab093ee619b9bfcee87e6537.html — Plain-zlib ftpcrack sibling (1.5 MB, 18 zlib streams, no AES)

  • /intel/analyses/551d2b0e5b243ef5abaa91e6776184ef0dc447a339609d60a3576aee31e8a822.html — AES-encrypted ftpcrack sibling (672 KB, 11 streams, weak key 1qazxsw23edcvfrN)

  • /intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html — Third confirmed sibling (488 KB, 10 zlib streams, AES-encrypted, smallest in cluster). Same Sep 2018 build fingerprint. ^[/intel/analyses/6b8812689ae1496ffc34a77c73e2569c6bd66422d1365ea41e46a7b67669b280.html]

  • /intel/analyses/2727eb40bd036c7948c38c18c22319f2842eab50deec0c365cbb8b525d8833a3.html — Fourth confirmed sibling (387 KB, 10 zlib streams, plain-zlib, no AES). First hybrid ftpcrack+xmrig payload in the cluster: overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner deployment artefacts (xmrig.exe, config.json, link.txt, stratum pool config). Same Sep 2018 build fingerprint. Updated 2026-08-10.

  • /intel/analyses/c0bc0bff17093afa87c9fd013ea1b103923179b31830a0d1566bed657b8b2853.html — Fifth confirmed sibling (2.27 MB, 155 zlib streams, AES-encrypted with weak QWERTY key 1qazxsw23edcvfrN). Largest hybrid ftpcrack+xmrig payload in the cluster. Same Sep 2018 build fingerprint and identical F:\files\ftp\crack\exe\build\ftpcrack\ build path. Updated 2026-08-10.

  • /intel/analyses/bc2064533e98deb6f98ce8807fdc0ed656e1e2bf4cdbbb832ce2433cd0885091.html — Sixth confirmed sibling (4.7 MB, 37 zlib streams, plain-zlib overlay (no AES), 94.9% overlay ratio). Second-largest overall sibling in cluster. Second confirmed hybrid ftpcrack+xmrig payload after 2727eb40: decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-12.

  • /intel/analyses/6c321d46aa87d2b3d282042c886b3459b57caca76029c2d6c2f8f8e9a7e5f468.html — Seventh confirmed sibling (320 KB, 10 zlib streams, AES-encrypted overlay with weak QWERTY key 1qazxsw23edcvfrN, 23.9% overlay ratio). Smallest sibling ever observed in the cluster. Confirmed hybrid ftpcrack+xmrig payload: overlay contains both FTP brute-force dictionaries and XMRig miner artefacts. Same F:\files\ftp\crack\exe\build\ftpcrack\ build path. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-14.

  • /intel/analyses/e2b273faecad5b46df130eef8c14d8ce3f8119361c03aaacea008cc0355a0df5.html — Eighth confirmed sibling (3.35 MB, 176 zlib streams, AES-encrypted overlay with weak QWERTY key 1qazxsw23edcvfrN, 92.6% overlay ratio). Largest AES-encrypted hybrid ftpcrack+xmrig payload in the cluster. Decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same F:\files\ftp\crack\exe\build\ftpcrack\ build path. Same Sep 2018 MSVC 14.0 build fingerprint. Static-only (CAPE skipped — no Windows guest). Updated 2026-08-24.

  • /intel/analyses/727e89ed035dbdd90191f88e8ed96e0d6dffa635084bc8a2ad790ea5615d0aa7.html — Ninth confirmed sibling (1.2 MB, 15 zlib streams, AES-encrypted overlay with weak QWERTY key 1qazxsw23edcvfrN, 79.7% overlay ratio). Lowest stream count in the AES-encrypted hybrid sub-cluster. Decompressed overlay contains both FTP brute-force dictionaries (USER_DIC/PASSWORD_DIC) and XMRig miner artefacts (config.json, link.txt, stratum, taskkill /F /IM xmrig.exe). Same F:\files\ftp\crack\exe\build\ftpcrack\ build path. Same Sep 2018 MSVC 14.0 build fingerprint. No python27.dll in outer strings.txt. Static-only (CAPE skipped — no Windows guest). Updated 2026-09-05.

Related entities/concepts

  • coinminer — Shared PyInstaller build pipeline; same author/toolkit
  • concepts/pyinstaller-bootloader — PyInstaller single-file C bootloader
  • concepts/python-packed-payload — Python logic hidden in PE overlay
  • concepts/social-engineering-filename-lure — May be paired with document-themed lures