0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398cacrstealer: 0bc8490a — Go 1.25.4 PE32+ x64, quiverquant.com cert, 66 randomized main.* functions
Executive Summary: Thirty-second confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with module path DUYgnKaDgqSNwmD, 66 randomized main.* functions (heaviest count on the quiverquant.com/WE1 cert chain), self-signed certificate CN=quiverquant.com / issuer WE1, and a five-icon .rsrc suite. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only (CAPE skipped).
What It Is
- File: PE32+ executable (GUI) x86-64, 9 sections, 8.6 MB ^[file.txt]
- Compiler: Go 1.25.4 (
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-trimpath=true) ^[strings.txt:1714] ^[strings.txt:1725] - Module:
DUYgnKaDgqSNwmD(randomized, unique per build) ^[strings.txt:1718] - PE timestamp: 0x0 (null, trimmed by Go linker) ^[pefile.txt:38]
- Entry point:
0x72640(Go runtimert0_go) ^[pefile.txt:54] - Signed: Self-signed Authenticode certificate embedded at file offset
0x839600, size0x880(2176 bytes) ^[rabin2-info.txt] ^[pefile.txt:275-277]- CN=
quiverquant.com, issuerWE1^[binwalk.txt:8623624] - Serial:
0x10f69e50b05b14f30ebf139155b65887 - Validity: 2026-05-09 21:13:51Z → 2026-08-07 22:13:46Z
- CN=
.rsrc: 5 icon entries (RT_ICON types 1–5), 16×16 through 256×256 PNG ^[binwalk.txt]- Build ID:
KmAtR0WK1PhrVkk_kUui/Vm0Xxz2pCzhMfEsDUTPB/9B_zeTWdwnOyUs4FW0v2/GWZAPfE1EtMGDiteT4RO^[strings.txt:10]
How It Works
Standard acrstealer baseline execution flow (see entity page for full family narrative). Distinctive per-sample traits:
- PRNG-seeded C2 decoding —
main.mainseedsmath/randwithtime.Now().UnixNano()at launch, then drives randomized decoder stubs. No hardcoded IP, domain, or URL in static strings. - Network surface — Statically linked
crypto/tls,net/http,http2client,http2server,tls10serverpresent in.rdata^[strings.txt:1651]. Import table is minimal Go runtime (kernel32.dllonly:VirtualAlloc,CreateThread,LoadLibraryW, etc.) ^[rabin2-info.txt]. - No custom PE parser / no multi-pass decoder — Light baseline build; does not exhibit the
orderreshop/lummastealercustom in-memory PE parser or multi-pass byte-transform decoder variants.
Decompiled Behavior
Ghidra/r2 pseudo-C of sym.main.main:
- Allocates a
math/randRNG source seeded withtime.Now().UnixNano()(the0xdd7b17f80+0x3b9aca00multiplies are Go runtime constants for nanosecond conversion). - Iterates a loop calling randomized-name decoder stubs (e.g.,
main.Fvdxrzkqrxj,main.Xjdfwjlwrpk,main.syzahfzbf,main.Oamwsrstty) that reconstruct C2 strings from PRNG-derived offsets. - No direct
net/httpcall sites visible in decompile; Go's goroutine scheduler and deferred calls obscure the actual C2 invocation from static pseudo-C.
C2 Infrastructure
No static C2 recovered. Runtime-decoded via PRNG-seeded multi-pass transform. Family-level C2 infrastructure is documented at acrstealer and prng-seeded-c2-url-decoding — historically observed: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard.digital:443.
Interesting Tidbits
- Certificate chain reuse: Sixth confirmed sample on the
quiverquant.com/WE1self-signed chain (afterf668de57,1cf857a9,725dc07c,c69b14a0,f258a5d7). Identical serial, subject, issuer, and validity window confirm the same private key is being reused across multiple builds. ^[binwalk.txt] - Heaviest function count on this chain: 66 randomized
main.*functions versus 55 inf258a5d7and 56 inf668de57. The Go compiler/linker deterministically generates this count from source shape; it is not a builder parameter. ^[strings.txt] - File size delta: 8.6 MB makes this the largest binary on the
quiverquant.comcert chain. The.rdatasection alone is ~1.35 MB (VirtualSize0x152DC8), typical for Go 1.25.4 static binaries with full HTTP/TLS runtime linkage. ^[pefile.txt] - No VS_VERSIONINFO: Absent from
.rsrc— the builder does not populate version metadata, relying instead on icon masquerade alone. ^[pefile.txt] - capa/floss failures: Both tools errored (
capamissing signatures path;flossinvalid--noargument). This is a tooling artefact, not an anti-analysis measure. ^[capa.txt] ^[floss.txt]
How To Mess With It (Homelab Replication)
Build a comparable Go binary:
go1.25.4 install golang.org/dl/go1.25.4@latest
go1.25.4 download
export GOOS=windows GOARCH=amd64 CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o repro.exe .
For the PRNG C2 decoder, replicate the pattern:
package main
import (
"math/rand"
"time"
)
func main() {
src := rand.NewSource(time.Now().UnixNano())
r := rand.New(src)
offset := r.Intn(256)
// XOR-decode embedded blob at offset
}
Verify: run strings repro.exe | grep "go1.25" and check for null PE timestamp + randomized module path.
Deployable Signatures
YARA
rule ACRStealer_Go1254_x64_Heavy {
meta:
description = "ACR Stealer Go 1.25.4 x64 heavy build (66+ randomized main.* functions)"
author = "PacketPursuit"
date = "2026-08-10"
sha256 = "0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398c"
strings:
$go_ver = "go1.25.4" ascii wide
$mod_path = "DUYgnKaDgqSNwmD" ascii
$buildmode = "-buildmode=exe" ascii
$trimpath = "-trimpath=true" ascii
$cert_cn = "quiverquant.com" ascii
$issuer = "WE1" ascii
$crypto_tls = "crypto/tls" ascii
$net_http = "net/http" ascii
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections == 9 and
$go_ver and
$mod_path and
$buildmode and
$trimpath and
$cert_cn and
$issuer and
$crypto_tls and
$net_http
}
Behavioral Fingerprint
This binary is a Go 1.25.4-compiled amd64 PE with a null PE timestamp, a self-signed certificate CN=quiverquant.com, five embedded PNG icons, and no static C2 strings. At launch it seeds math/rand with time.Now().UnixNano() and calls a sequence of randomized main.* decoder stubs before initiating TLS/HTTP C2 contact. Import table is Go-minimal (kernel32.dll only). No custom PE parser or multi-pass decoder present — this is the light baseline morph of the ACR cluster. Sixty-six randomized main.* functions make this the heaviest build observed on the quiverquant.com cert chain.
IOC List
| Indicator | Value | Source |
|---|---|---|
| SHA-256 | 0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398c |
Triage |
| ssdeep | 24576:TJqDn0Sk74bfbAKIQ95Cu+DwWJ7zShY+zIQipnKnbVb25RC1fnBele5yK2tFQg2r:TJ4n1k+cK/98uswphjzkwnU5RCOXmgDq |
ssdeep.txt |
| TLSH | FB967C4A7CE108EAD0AA633289B761817B71FC150F7263D72E50B2782FB27E85D79744 |
tlsh.txt |
| Go module | DUYgnKaDgqSNwmD |
strings.txt |
| Cert CN | quiverquant.com |
Certificate parse |
| Cert issuer | WE1 |
Certificate parse |
| Cert serial | 0x10f69e50b05b14f30ebf139155b65887 |
Certificate parse |
| Go version | go1.25.4 |
strings.txt |
| Architecture | amd64 |
pefile.txt |
| Icon count | 5 (16×16, 32×32, 64×64, 128×128, 256×256 PNG) | binwalk.txt |
| PE timestamp | 0x0 (null) |
pefile.txt |
| Randomized main.* count | 66 | strings.txt |
Detection Signatures
| capa / static observation | ATT&CK | Confidence |
|---|---|---|
| PRNG-seeded string decode | T1027.002 (Obfuscated Files or Information) | High (static) |
| TLS/HTTP C2 client | T1071.001 (Application Layer Protocol: Web Protocols) | Medium (inferred from imports/strings) |
| Browser/crypto credential theft (family pattern) | T1555 (Credentials from Password Stores) | Medium (family inference) |
| Signed PE masquerade | T1553.002 (Subvert Trust Controls: Code Signing) | High (static) |
| Icon social-engineering | T1036.005 (Masquerading: Match Legitimate Name or Location) | High (static) |
References
- Artifact ID:
9baa6b58-55ec-43f5-849c-6283c27584c1^[metadata.json] - OpenCTI labels:
acrstealer,exe,urlhaus^[triage.json] - Family entity: acrstealer
- Build pattern: golang-stealer-build-pattern
- C2 decode technique: prng-seeded-c2-url-decoding
- Sibling on same cert: /intel/analyses/f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29.html
Provenance
file.txt—file(1)outputpefile.txt— pefile Python library header dumpstrings.txt—strings -n 6outputrabin2-info.txt— radare2rabin2 -Ibinary infobinwalk.txt—binwalk -eembedded artifact scancapa.txt— Mandiant capa (error: missing signatures path)floss.txt— flare-floss (error: invalid--noargument)- Certificate extracted manually from
IMAGE_DIRECTORY_ENTRY_SECURITYat file offset0x839600
Report written: 2026-08-10. Static-only analysis — no CAPE detonation available (no Windows guest).