119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350acrstealer: 119b387e — Go 1.18.5 PE32, 54 randomized main.* functions, atom.hutsell.com self-signed cert
Executive Summary
Sixteenth confirmed sibling in the acrstealer Go infostealer cluster. Go 1.18.5 PE32, 7.5 MB, self-signed Authenticode CN=atom.hutsell.com / issuer WR3 (shared with six prior siblings). Builder randomized 54 main.* functions — the highest count observed in this family — while retaining the .rsrc 256×256 PNG icon for social-engineering masquerade. No static C2 strings beyond the certificate CN; network logic is runtime-decoded per family pattern. Static-only analysis (CAPE skipped — no Windows guest; floss/capa tool failures).
What It Is
- SHA-256:
119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350 - Size: 7,526,016 bytes (7.5 MB) ^[file.txt]
- Format: PE32 executable (GUI) Intel 80386, 7 sections, stripped, null PE timestamp ^[pefile.txt:1] ^[rabin2-info.txt]
- Compiler: Go 1.18.5 (
go1.18.5string at strings.txt:1066 and :4453; build IDR6i5Ubtr6ZSOggunTD4c/…) ^[strings.txt:8] ^[strings.txt:1066] - Signing: Authenticode self-signed certificate embedded at file offset
0x72CE08(2,176 bytes). Certificate blob contains CN=atom.hutsell.com(validity window Apr 2026–Jul 2026 per sibling pattern) ^[strings.txt:7731] ^[binwalk.txt] ^[pefile.txt] - Module path: Not recovered in static strings; the
"no module data"error string is present (typical oftrimpathbuilds) ^[strings.txt:1030] - Function name randomization: 54 distinct
main.*symbols, the largest set observed in this cluster ^[strings.txt]
How It Works
This sample is a cluster sibling of the documented acrstealer family. It shares the exact build pipeline documented at golang-stealer-build-pattern:
GOARCH=386,GOOS=windows,CGO_ENABLED=0,-trimpath=true- No external packer;
.textentropy ~6.18 (normal for a static Go binary) - Self-signed certificate with CN borrowed from prior sibling infrastructure (
atom.hutsell.com)
Per-sample deltas versus the cluster baseline:
-
Heaviest function-name randomization to date. Prior siblings ranged from 9 (
ef262340) to 22 (beff95d5) randomizedmain.*functions. This sample carries 54, includingmain.Bogtpflwpe,main.Sydvnnnfrwnrlf,main.ycvmivjwnthsktk,main.yjgxxizobladhzc,main.jloxxdfzevkbny,main.ktrybekuhzywm, and 48 others. ^[strings.txt] -
.rsrcicon masquerade intact. Unlike siblings6cbac6bcandbeff95d5(builder stripped icons), this sample retains a 256×256 PNG icon in.rsrc^[binwalk.txt:7]. The builder has an icon toggle; this sample has it enabled. -
No custom PE parser / multi-pass decoder. This is a light Go 1.18.5 build — it does not carry the advanced reflective-loader features observed in siblings
d5655568,7620884e,90d54589, orfa41d6b4(those share the orderreshop / lummastealer fork). -
No static C2 strings. The only domain string recovered is the certificate CN (
atom.hutsell.com). Nocrypto/tls,net/http, ornet/urlGo package strings are present in the binary, suggesting the C2 URL is fully runtime-decoded (PRNG-seeded decode per family pattern documented at prng-seeded-c2-url-decoding). ^[strings.txt]
Decompiled Behavior
Ghidra / radare2 entry point (0x00457c30) presents the standard Go 1.18.5 runtime bootstrap: ^[r2:entry0]
- MMX/CPUID feature detection (
cpuid→ vendor-string compare againstGenu/ineI/ntel) - Stack canary initialization via
fs:[0x14] - Runtime initialization chain:
runtime.rt0_go→runtime.main→ usermain.main - No anti-debug or VM-detection logic in the entry stub
The user main.main is one of the 54 randomized functions. Without dynamic execution or successful Ghidra decompilation of the full 7.5 MB .text, the exact C2 decoding routine is not statically isolated, but the family pattern (time-seeded PRNG, multi-pass byte transform) is established across 15 prior siblings.
C2 Infrastructure
- Certificate CN:
atom.hutsell.com^[strings.txt:7731] - Certificate issuer:
WR3(self-signed) — same certificate chain as siblingsef262340,6cbac6bc,44f594e2,828405d6,350a2b69,beff95d5 - Static C2 URLs/IPs: None recovered
- Protocol: Inferred TLS/HTTPS (family pattern); no
crypto/tlspackage strings present in this specific build, butsyscall.WSAStartupand WinInet/WinSock imports confirm network capability ^[strings.txt:6458]
Interesting Tidbits
- Toolchain artefact:
go1.18.5is the oldest Go compiler in the ACR cluster. This sample confirms the builder still compiles fresh 2026 samples against the 2022 Go release. ^[strings.txt:1066] - Certificate validity window: The certificate string shows
260421…Z/260720…Z— Apr 21 2026 → Jul 20 2026, matching the validity window of allatom.hutsell.comsiblings. ^[strings.txt:7729–7731] - Fused-string API resolution: Standard Go
syscall.(*LazyProc).Findandsyscall.(*LazyDLL).Loadstrings present, meaning Windows APIs are resolved lazily at runtime rather than through a static IAT. ^[strings.txt:3878–3884] - Floss / capa failures:
floss.txtcontains only an argument-parsing error (the triage pipeline invoked it with an invalid--noflag).capa.txtreports a missing default signature path. Neither tool produced usable output for this sample. ^[floss.txt] ^[capa.txt]
How To Mess With It (Homelab Replication)
To reproduce a binary with a comparable static fingerprint:
# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.linux-amd64.tar.gz
sudo tar -C /usr/local -xzf go1.18.5.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
# Build a minimal network-capable PE32 with trimpath and randomized module path
cat > main.go <<'EOF'
package main
import (
"crypto/tls"
"fmt"
"net/http"
"os"
"time"
)
func main() {
fmt.Println("hello")
http.Get("https://example.com")
tls.Dial("tcp", "example.com:443", nil)
time.Sleep(1 * time.Second)
os.Exit(0)
}
EOF
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go
Verification: Run strings repro.exe | grep -E "^main\.|go1\.|Go build ID" — should show randomized main.* symbols and the Go build ID. The .text entropy should sit around 6.1–6.3 for a static Go binary.
Deployable Signatures
YARA rule
rule ACRStealer_Go118_AtomHutsell {
meta:
description = "ACR Stealer Go 1.18.5 cluster with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-02"
sha256 = "119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350"
strings:
$go_ver = "go1.18.5" ascii wide
$cn = "atom.hutsell.com" ascii wide
$build_id = "Go build ID:" ascii
$lazyproc = "syscall.(*LazyProc).Find" ascii
$wsa = "syscall.WSAStartup" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 5MB and
$go_ver and
$cn and
$build_id and
$lazyproc and
$wsa
}
Sigma rule (process creation — behavioral hunt)
title: ACR Stealer Go 1.18.5 AtomHutsell Cluster
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- 'atom.hutsell.com'
condition: selection
falsepositives:
- None expected; the string is a self-signed certificate CN not used by legitimate software
level: high
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350 |
Sample |
| ssdeep | 49152:CPAEM/oShxuxPQ8vfNVljDjpWuOCYDYD1H:CPfcV3uRRnnpHAuz |
^[ssdeep.txt] |
| TLSH | T138769E81FCDB54B1EAA512320CB2A2EB2331A9090F329FC7D9547B7AAC775E10D32755 |
^[tlsh.txt] |
| Certificate CN | atom.hutsell.com |
Self-signed, issuer WR3 |
| Certificate validity | Apr 21 2026 – Jul 20 2026 | Inferred from sibling pattern |
| Builder path artifact | go1.18.5 |
Oldest Go toolchain in cluster |
Behavioral fingerprint statement
This binary is a 7.5 MB PE32 GUI executable built with Go 1.18.5 (static, CGO disabled, trimpath). It carries a self-signed Authenticode certificate with CN atom.hutsell.com and issuer WR3. The .rsrc section contains a 256×256 PNG icon. The main package contains 54 randomized function names (e.g., main.Bogtpflwpe, main.ycvmivjwnthsktk). Windows APIs are resolved lazily via syscall.(*LazyProc).Find. No static C2 URLs are present; network logic is inferred to be runtime-decoded via a PRNG-seeded transform consistent with the ACR Stealer family pattern.
Detection Signatures
No capa output available (signature path missing during triage). ^[capa.txt]
Family TTPs inferred from cluster analysis (see acrstealer entity page):
- T1071.001 — Application Layer Protocol: Web (TLS/HTTPS C2)
- T1083 — File and Directory Discovery (browser credential store enumeration)
- T1005 — Data from Local System (browser/crypto/FTP/SSH credential harvesting)
- T1041 — Exfiltration Over C2 Channel (POST to decoded C2 endpoint)
References
- acrstealer — Entity page with full cluster analysis
- golang-stealer-build-pattern — Shared Go infostealer build artefacts
- prng-seeded-c2-url-decoding — C2 decoding technique
- Siblings sharing
atom.hutsell.com/WR3cert:ef262340,6cbac6bc,44f594e2,828405d6,350a2b69,beff95d5
Provenance
file.txt—file(1)outputstrings.txt—strings -n 6output (7,733 lines)pefile.txt—pefilePython library dumprabin2-info.txt—rabin2 -Iheader summarybinwalk.txt—binwalkembedded-artefact scanexiftool.json— ExifTool metadatafloss.txt— Failed invocation (argument error)capa.txt— Failed invocation (missing signatures)dynamic-analysis.md— CAPE skipped (no Windows guest)- radare2 v5.9.4 — entry-point decompilation at
0x00457c30
Report written 2026-08-02. Static-only analysis; dynamic behavior inferred from family cluster.