typeanalysisfamilyacrstealerconfidencehighcreated2026-08-10updated2026-08-10infostealergolangsigningpe
SHA-256: 0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398c

acrstealer: 0bc8490a — Go 1.25.4 PE32+ x64, quiverquant.com cert, 66 randomized main.* functions

Executive Summary: Thirty-second confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with module path DUYgnKaDgqSNwmD, 66 randomized main.* functions (heaviest count on the quiverquant.com/WE1 cert chain), self-signed certificate CN=quiverquant.com / issuer WE1, and a five-icon .rsrc suite. No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only (CAPE skipped).

What It Is

  • File: PE32+ executable (GUI) x86-64, 9 sections, 8.6 MB ^[file.txt]
  • Compiler: Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1714] ^[strings.txt:1725]
  • Module: DUYgnKaDgqSNwmD (randomized, unique per build) ^[strings.txt:1718]
  • PE timestamp: 0x0 (null, trimmed by Go linker) ^[pefile.txt:38]
  • Entry point: 0x72640 (Go runtime rt0_go) ^[pefile.txt:54]
  • Signed: Self-signed Authenticode certificate embedded at file offset 0x839600, size 0x880 (2176 bytes) ^[rabin2-info.txt] ^[pefile.txt:275-277]
    • CN=quiverquant.com, issuer WE1 ^[binwalk.txt:8623624]
    • Serial: 0x10f69e50b05b14f30ebf139155b65887
    • Validity: 2026-05-09 21:13:51Z → 2026-08-07 22:13:46Z
  • .rsrc: 5 icon entries (RT_ICON types 1–5), 16×16 through 256×256 PNG ^[binwalk.txt]
  • Build ID: KmAtR0WK1PhrVkk_kUui/Vm0Xxz2pCzhMfEsDUTPB/9B_zeTWdwnOyUs4FW0v2/GWZAPfE1EtMGDiteT4RO ^[strings.txt:10]

How It Works

Standard acrstealer baseline execution flow (see entity page for full family narrative). Distinctive per-sample traits:

  1. PRNG-seeded C2 decoding — main.main seeds math/rand with time.Now().UnixNano() at launch, then drives randomized decoder stubs. No hardcoded IP, domain, or URL in static strings.
  2. Network surface — Statically linked crypto/tls, net/http, http2client, http2server, tls10server present in .rdata ^[strings.txt:1651]. Import table is minimal Go runtime (kernel32.dll only: VirtualAlloc, CreateThread, LoadLibraryW, etc.) ^[rabin2-info.txt].
  3. No custom PE parser / no multi-pass decoder — Light baseline build; does not exhibit the orderreshop/lummastealer custom in-memory PE parser or multi-pass byte-transform decoder variants.

Decompiled Behavior

Ghidra/r2 pseudo-C of sym.main.main:

  • Allocates a math/rand RNG source seeded with time.Now().UnixNano() (the 0xdd7b17f80 + 0x3b9aca00 multiplies are Go runtime constants for nanosecond conversion).
  • Iterates a loop calling randomized-name decoder stubs (e.g., main.Fvdxrzkqrxj, main.Xjdfwjlwrpk, main.syzahfzbf, main.Oamwsrstty) that reconstruct C2 strings from PRNG-derived offsets.
  • No direct net/http call sites visible in decompile; Go's goroutine scheduler and deferred calls obscure the actual C2 invocation from static pseudo-C.

C2 Infrastructure

No static C2 recovered. Runtime-decoded via PRNG-seeded multi-pass transform. Family-level C2 infrastructure is documented at acrstealer and prng-seeded-c2-url-decoding — historically observed: 5.252.155.72, laserlogdnsop.icu, hertzfigblob.icu, blizzard.digital:443.

Interesting Tidbits

  • Certificate chain reuse: Sixth confirmed sample on the quiverquant.com/WE1 self-signed chain (after f668de57, 1cf857a9, 725dc07c, c69b14a0, f258a5d7). Identical serial, subject, issuer, and validity window confirm the same private key is being reused across multiple builds. ^[binwalk.txt]
  • Heaviest function count on this chain: 66 randomized main.* functions versus 55 in f258a5d7 and 56 in f668de57. The Go compiler/linker deterministically generates this count from source shape; it is not a builder parameter. ^[strings.txt]
  • File size delta: 8.6 MB makes this the largest binary on the quiverquant.com cert chain. The .rdata section alone is ~1.35 MB (VirtualSize 0x152DC8), typical for Go 1.25.4 static binaries with full HTTP/TLS runtime linkage. ^[pefile.txt]
  • No VS_VERSIONINFO: Absent from .rsrc — the builder does not populate version metadata, relying instead on icon masquerade alone. ^[pefile.txt]
  • capa/floss failures: Both tools errored (capa missing signatures path; floss invalid --no argument). This is a tooling artefact, not an anti-analysis measure. ^[capa.txt] ^[floss.txt]

How To Mess With It (Homelab Replication)

Build a comparable Go binary:

go1.25.4 install golang.org/dl/go1.25.4@latest
go1.25.4 download
export GOOS=windows GOARCH=amd64 CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o repro.exe .

For the PRNG C2 decoder, replicate the pattern:

package main
import (
    "math/rand"
    "time"
)
func main() {
    src := rand.NewSource(time.Now().UnixNano())
    r := rand.New(src)
    offset := r.Intn(256)
    // XOR-decode embedded blob at offset
}

Verify: run strings repro.exe | grep "go1.25" and check for null PE timestamp + randomized module path.

Deployable Signatures

YARA

rule ACRStealer_Go1254_x64_Heavy {
    meta:
        description = "ACR Stealer Go 1.25.4 x64 heavy build (66+ randomized main.* functions)"
        author = "PacketPursuit"
        date = "2026-08-10"
        sha256 = "0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398c"
    strings:
        $go_ver = "go1.25.4" ascii wide
        $mod_path = "DUYgnKaDgqSNwmD" ascii
        $buildmode = "-buildmode=exe" ascii
        $trimpath = "-trimpath=true" ascii
        $cert_cn = "quiverquant.com" ascii
        $issuer = "WE1" ascii
        $crypto_tls = "crypto/tls" ascii
        $net_http = "net/http" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections == 9 and
        $go_ver and
        $mod_path and
        $buildmode and
        $trimpath and
        $cert_cn and
        $issuer and
        $crypto_tls and
        $net_http
}

Behavioral Fingerprint

This binary is a Go 1.25.4-compiled amd64 PE with a null PE timestamp, a self-signed certificate CN=quiverquant.com, five embedded PNG icons, and no static C2 strings. At launch it seeds math/rand with time.Now().UnixNano() and calls a sequence of randomized main.* decoder stubs before initiating TLS/HTTP C2 contact. Import table is Go-minimal (kernel32.dll only). No custom PE parser or multi-pass decoder present — this is the light baseline morph of the ACR cluster. Sixty-six randomized main.* functions make this the heaviest build observed on the quiverquant.com cert chain.

IOC List

Indicator Value Source
SHA-256 0bc8490a5870f5a734aeab818fa39e919c7c221ab1071d323740871c593c398c Triage
ssdeep 24576:TJqDn0Sk74bfbAKIQ95Cu+DwWJ7zShY+zIQipnKnbVb25RC1fnBele5yK2tFQg2r:TJ4n1k+cK/98uswphjzkwnU5RCOXmgDq ssdeep.txt
TLSH FB967C4A7CE108EAD0AA633289B761817B71FC150F7263D72E50B2782FB27E85D79744 tlsh.txt
Go module DUYgnKaDgqSNwmD strings.txt
Cert CN quiverquant.com Certificate parse
Cert issuer WE1 Certificate parse
Cert serial 0x10f69e50b05b14f30ebf139155b65887 Certificate parse
Go version go1.25.4 strings.txt
Architecture amd64 pefile.txt
Icon count 5 (16×16, 32×32, 64×64, 128×128, 256×256 PNG) binwalk.txt
PE timestamp 0x0 (null) pefile.txt
Randomized main.* count 66 strings.txt

Detection Signatures

capa / static observation ATT&CK Confidence
PRNG-seeded string decode T1027.002 (Obfuscated Files or Information) High (static)
TLS/HTTP C2 client T1071.001 (Application Layer Protocol: Web Protocols) Medium (inferred from imports/strings)
Browser/crypto credential theft (family pattern) T1555 (Credentials from Password Stores) Medium (family inference)
Signed PE masquerade T1553.002 (Subvert Trust Controls: Code Signing) High (static)
Icon social-engineering T1036.005 (Masquerading: Match Legitimate Name or Location) High (static)

References

  • Artifact ID: 9baa6b58-55ec-43f5-849c-6283c27584c1 ^[metadata.json]
  • OpenCTI labels: acrstealer, exe, urlhaus ^[triage.json]
  • Family entity: acrstealer
  • Build pattern: golang-stealer-build-pattern
  • C2 decode technique: prng-seeded-c2-url-decoding
  • Sibling on same cert: /intel/analyses/f258a5d72c7058a6d4f424b2c9bf0dd96a7ab8e4548ffc9f645f2da17cf64a29.html

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • strings.txt — strings -n 6 output
  • rabin2-info.txt — radare2 rabin2 -I binary info
  • binwalk.txt — binwalk -e embedded artifact scan
  • capa.txt — Mandiant capa (error: missing signatures path)
  • floss.txt — flare-floss (error: invalid --no argument)
  • Certificate extracted manually from IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x839600

Report written: 2026-08-10. Static-only analysis — no CAPE detonation available (no Windows guest).