typeanalysisfamilyacrstealerconfidencehighcreated2026-08-02updated2026-08-02infostealermalware-familygolangsigninggo1.18.5static-only
SHA-256: 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350

acrstealer: 119b387e — Go 1.18.5 PE32, 54 randomized main.* functions, atom.hutsell.com self-signed cert

Executive Summary

Sixteenth confirmed sibling in the acrstealer Go infostealer cluster. Go 1.18.5 PE32, 7.5 MB, self-signed Authenticode CN=atom.hutsell.com / issuer WR3 (shared with six prior siblings). Builder randomized 54 main.* functions — the highest count observed in this family — while retaining the .rsrc 256×256 PNG icon for social-engineering masquerade. No static C2 strings beyond the certificate CN; network logic is runtime-decoded per family pattern. Static-only analysis (CAPE skipped — no Windows guest; floss/capa tool failures).

What It Is

  • SHA-256: 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350
  • Size: 7,526,016 bytes (7.5 MB) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386, 7 sections, stripped, null PE timestamp ^[pefile.txt:1] ^[rabin2-info.txt]
  • Compiler: Go 1.18.5 (go1.18.5 string at strings.txt:1066 and :4453; build ID R6i5Ubtr6ZSOggunTD4c/…) ^[strings.txt:8] ^[strings.txt:1066]
  • Signing: Authenticode self-signed certificate embedded at file offset 0x72CE08 (2,176 bytes). Certificate blob contains CN=atom.hutsell.com (validity window Apr 2026–Jul 2026 per sibling pattern) ^[strings.txt:7731] ^[binwalk.txt] ^[pefile.txt]
  • Module path: Not recovered in static strings; the "no module data" error string is present (typical of trimpath builds) ^[strings.txt:1030]
  • Function name randomization: 54 distinct main.* symbols, the largest set observed in this cluster ^[strings.txt]

How It Works

This sample is a cluster sibling of the documented acrstealer family. It shares the exact build pipeline documented at golang-stealer-build-pattern:

  • GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath=true
  • No external packer; .text entropy ~6.18 (normal for a static Go binary)
  • Self-signed certificate with CN borrowed from prior sibling infrastructure (atom.hutsell.com)

Per-sample deltas versus the cluster baseline:

  1. Heaviest function-name randomization to date. Prior siblings ranged from 9 (ef262340) to 22 (beff95d5) randomized main.* functions. This sample carries 54, including main.Bogtpflwpe, main.Sydvnnnfrwnrlf, main.ycvmivjwnthsktk, main.yjgxxizobladhzc, main.jloxxdfzevkbny, main.ktrybekuhzywm, and 48 others. ^[strings.txt]

  2. .rsrc icon masquerade intact. Unlike siblings 6cbac6bc and beff95d5 (builder stripped icons), this sample retains a 256×256 PNG icon in .rsrc ^[binwalk.txt:7]. The builder has an icon toggle; this sample has it enabled.

  3. No custom PE parser / multi-pass decoder. This is a light Go 1.18.5 build — it does not carry the advanced reflective-loader features observed in siblings d5655568, 7620884e, 90d54589, or fa41d6b4 (those share the orderreshop / lummastealer fork).

  4. No static C2 strings. The only domain string recovered is the certificate CN (atom.hutsell.com). No crypto/tls, net/http, or net/url Go package strings are present in the binary, suggesting the C2 URL is fully runtime-decoded (PRNG-seeded decode per family pattern documented at prng-seeded-c2-url-decoding). ^[strings.txt]

Decompiled Behavior

Ghidra / radare2 entry point (0x00457c30) presents the standard Go 1.18.5 runtime bootstrap: ^[r2:entry0]

  • MMX/CPUID feature detection (cpuid → vendor-string compare against Genu/ineI/ntel)
  • Stack canary initialization via fs:[0x14]
  • Runtime initialization chain: runtime.rt0_go → runtime.main → user main.main
  • No anti-debug or VM-detection logic in the entry stub

The user main.main is one of the 54 randomized functions. Without dynamic execution or successful Ghidra decompilation of the full 7.5 MB .text, the exact C2 decoding routine is not statically isolated, but the family pattern (time-seeded PRNG, multi-pass byte transform) is established across 15 prior siblings.

C2 Infrastructure

  • Certificate CN: atom.hutsell.com ^[strings.txt:7731]
  • Certificate issuer: WR3 (self-signed) — same certificate chain as siblings ef262340, 6cbac6bc, 44f594e2, 828405d6, 350a2b69, beff95d5
  • Static C2 URLs/IPs: None recovered
  • Protocol: Inferred TLS/HTTPS (family pattern); no crypto/tls package strings present in this specific build, but syscall.WSAStartup and WinInet/WinSock imports confirm network capability ^[strings.txt:6458]

Interesting Tidbits

  • Toolchain artefact: go1.18.5 is the oldest Go compiler in the ACR cluster. This sample confirms the builder still compiles fresh 2026 samples against the 2022 Go release. ^[strings.txt:1066]
  • Certificate validity window: The certificate string shows 260421…Z / 260720…Z — Apr 21 2026 → Jul 20 2026, matching the validity window of all atom.hutsell.com siblings. ^[strings.txt:7729–7731]
  • Fused-string API resolution: Standard Go syscall.(*LazyProc).Find and syscall.(*LazyDLL).Load strings present, meaning Windows APIs are resolved lazily at runtime rather than through a static IAT. ^[strings.txt:3878–3884]
  • Floss / capa failures: floss.txt contains only an argument-parsing error (the triage pipeline invoked it with an invalid --no flag). capa.txt reports a missing default signature path. Neither tool produced usable output for this sample. ^[floss.txt] ^[capa.txt]

How To Mess With It (Homelab Replication)

To reproduce a binary with a comparable static fingerprint:

# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.linux-amd64.tar.gz
sudo tar -C /usr/local -xzf go1.18.5.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin

# Build a minimal network-capable PE32 with trimpath and randomized module path
cat > main.go <<'EOF'
package main
import (
    "crypto/tls"
    "fmt"
    "net/http"
    "os"
    "time"
)
func main() {
    fmt.Println("hello")
    http.Get("https://example.com")
    tls.Dial("tcp", "example.com:443", nil)
    time.Sleep(1 * time.Second)
    os.Exit(0)
}
EOF

GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go

Verification: Run strings repro.exe | grep -E "^main\.|go1\.|Go build ID" — should show randomized main.* symbols and the Go build ID. The .text entropy should sit around 6.1–6.3 for a static Go binary.

Deployable Signatures

YARA rule

rule ACRStealer_Go118_AtomHutsell {
    meta:
        description = "ACR Stealer Go 1.18.5 cluster with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-02"
        sha256 = "119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $cn = "atom.hutsell.com" ascii wide
        $build_id = "Go build ID:" ascii
        $lazyproc = "syscall.(*LazyProc).Find" ascii
        $wsa = "syscall.WSAStartup" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 5MB and
        $go_ver and
        $cn and
        $build_id and
        $lazyproc and
        $wsa
}

Sigma rule (process creation — behavioral hunt)

title: ACR Stealer Go 1.18.5 AtomHutsell Cluster
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        CommandLine|contains: 
            - 'atom.hutsell.com'
    condition: selection
falsepositives:
    - None expected; the string is a self-signed certificate CN not used by legitimate software
level: high

IOC list

Type Value Notes
SHA-256 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350 Sample
ssdeep 49152:CPAEM/oShxuxPQ8vfNVljDjpWuOCYDYD1H:CPfcV3uRRnnpHAuz ^[ssdeep.txt]
TLSH T138769E81FCDB54B1EAA512320CB2A2EB2331A9090F329FC7D9547B7AAC775E10D32755 ^[tlsh.txt]
Certificate CN atom.hutsell.com Self-signed, issuer WR3
Certificate validity Apr 21 2026 – Jul 20 2026 Inferred from sibling pattern
Builder path artifact go1.18.5 Oldest Go toolchain in cluster

Behavioral fingerprint statement

This binary is a 7.5 MB PE32 GUI executable built with Go 1.18.5 (static, CGO disabled, trimpath). It carries a self-signed Authenticode certificate with CN atom.hutsell.com and issuer WR3. The .rsrc section contains a 256×256 PNG icon. The main package contains 54 randomized function names (e.g., main.Bogtpflwpe, main.ycvmivjwnthsktk). Windows APIs are resolved lazily via syscall.(*LazyProc).Find. No static C2 URLs are present; network logic is inferred to be runtime-decoded via a PRNG-seeded transform consistent with the ACR Stealer family pattern.

Detection Signatures

No capa output available (signature path missing during triage). ^[capa.txt]

Family TTPs inferred from cluster analysis (see acrstealer entity page):

  • T1071.001 — Application Layer Protocol: Web (TLS/HTTPS C2)
  • T1083 — File and Directory Discovery (browser credential store enumeration)
  • T1005 — Data from Local System (browser/crypto/FTP/SSH credential harvesting)
  • T1041 — Exfiltration Over C2 Channel (POST to decoded C2 endpoint)

References

Provenance

  • file.txt — file(1) output
  • strings.txt — strings -n 6 output (7,733 lines)
  • pefile.txt — pefile Python library dump
  • rabin2-info.txt — rabin2 -I header summary
  • binwalk.txt — binwalk embedded-artefact scan
  • exiftool.json — ExifTool metadata
  • floss.txt — Failed invocation (argument error)
  • capa.txt — Failed invocation (missing signatures)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • radare2 v5.9.4 — entry-point decompilation at 0x00457c30

Report written 2026-08-02. Static-only analysis; dynamic behavior inferred from family cluster.