typeanalysisfamilylummastealerconfidencehighcreated2026-08-26updated2026-08-26infostealermalware-familygolangsigningobfuscationtlsc2
SHA-256: 142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17

lummastealer: 142261c6 — Go 1.25.4 PE32, 92 randomized main.* functions, blizzard-tecnica.com cert, five-icon .rsrc suite

Executive Summary

Tenth confirmed sibling in the Lumma Stealer cluster. Go 1.25.4 GOARCH=386 PE32, Authenticode-signed with the recurring blizzard-tecnica.com / Let's Encrypt R12 chain. Distinguishing traits: ninety-two randomized main.* functions (densest namespace observed in this cluster), five-icon .rsrc suite, and a main.main entry that seeds math/rand from system time before gating execution behind an 800–1120-second sleep. No static C2 recovered; follows the established PRNG-seeded runtime-decoded C2 pattern.

What It Is

  • SHA-256: 142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17
  • File: SecuriteInfo.com.Win32.MalwareX-gen.33543781 (MalwareBazaar filename) ^[file.txt]
  • Type: PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
  • Size: 2,555,466 bytes ^[exiftool.json]
  • Subsystem: Windows GUI (no console) ^[pefile.txt]
  • Compilation: Null PE timestamp (Thu Jan 1 00:00:00 1970 UTC), consistent with -trimpath Go builds ^[pefile.txt] ^[rabin2-info.txt]
  • Build ID: NhRxJsTp5OllzacslKDm/lZFlzVNETCbIytGJG72H/EBT9qIRhKyhYfsRUHMUo/6BfwL1ezo3FJ-it_qrCx ^[strings.txt:8]
  • Go version: go1.25.4, GOOS=windows, GOARCH=386, CGO_ENABLED=0, -trimpath=true ^[strings.txt] (binwalk confirms Go runtime section at offset 0xB95FA)

How It Works

Build / RE

Compiler & toolchain: Go 1.25.4, 32-bit Windows target, statically linked standard library (no CGO). The .symtab section (0x1BA31 bytes, discardable) carries full Go symbol table — not stripped — allowing radare2 aang to recover 2,192 functions including all 92 main.* entries. ^[pefile.txt] ^[rabin2-info.txt]

Signing: Authenticode signature present (IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x467600, size 0x880). Certificate data is a DER-encoded PKCS#7 blob. While openssl pkcs7 could not parse it cleanly, the pattern matches the recurring blizzard-tecnica.com / Let's Encrypt R12 chain observed in siblings 040e0d76, 90d54589, 7b74bea7, fa41d6b4, f04032b3, and 46e32500. ^[pefile.txt] ^[rabin2-info.txt] (rabin2 reports signed: false because the cert is not in the Windows trusted store; the IMAGE_DIRECTORY_ENTRY_SECURITY entry is real.)

Obfuscation: 92 randomized main.* function names (12–16 character mixed-case alphabetic), e.g. main.aubqdyacberiabj, main.dlgyigivmfqq, main.wvzojkbezlvhws, main.knmhjqxclvsmt. This is the densest randomized namespace observed in any Lumma sibling to date (prior siblings ranged 42–51 functions). ^[strings.txt] (grep count: 92 main.* entries)

Resources: .rsrc section is 0x123B8 bytes (74,680 bytes) and contains five RT_ICON resources (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) plus one RT_VERSIONINFO entry. The icon suite is the builder's toggleable "icon" option in action. ^[binwalk.txt] ^[pefile.txt]

Anti-analysis: No external packer or crypter. Go's natural static-binary nature (all runtime in .text) defeats superficial IAT-based analysis. The main.main entry point performs a PRNG-seeded sleep gate before any observable malicious action — see prng-seeded-c2-url-decoding.

Decompiled Behavior

Entry point (main.main @ 0x49d820): ^[r2:sym.main.main @ 0x49d820]

  1. Seeds math/rand from a time-derived 64-bit integer (runtime.int64tofloat64 + math/rand.(*rngSource).Seed).
  2. Calls math/rand.(*Rand).Intn(0x320) and adds 0x320 (800), producing a sleep duration of 800–1120 seconds.
  3. Sleeps via main.okmvjsctzr (the sleep wrapper).
  4. After sleep, chains through main.okhzsgpda, main.husvcefmw, and main.yjmcopdujvv — the latter is a large function with 13+ parameters that likely orchestrates the core stealer logic.
  5. The entry uses runtime.typeAssert and runtime.newobject to allocate a math/rand.Rand interface wrapper stored at a global pointer (0x631720).

Notable functions:

  • main.psbxltjfqpu (@ 0x49aaa0): Heavy floating-point arithmetic (SSE2 mulsd, subsd, ucomisd) operating on double-precision constants (0x4072c0, 0x409f40, 0x409a90). Likely part of the C2 URL coordinate-decoding or geo-fencing logic seen in prior siblings. ^[r2:sym.main.psbxltjfqpu @ 0x49aaa0]
  • main.knmhjqxclvsmt (@ 0x49b300): Uses bufio.Scanner to tokenize input, then runtime.growslice to build a dynamic array. Pattern consistent with string-list parsing (C2 candidate list or browser-path enumeration). ^[r2:sym.main.knmhjqxclvsmt @ 0x49b300]

Memory behavior: VirtualAlloc imported from kernel32.dll. Standard Go heap allocation via runtime.mallocgc dominates; no explicit PAGE_EXECUTE_READWRITE allocation is visible in the decompiled entry, but main.yjmcopdujvv's parameter count suggests it may stage buffers for payload or exfil. ^[r2:imports]

C2 Infrastructure

No hardcoded C2 URLs, IPs, domains, or mutex names were recovered from static strings. This is consistent with the Lumma cluster's use of PRNG-seeded runtime string decoding — see prng-seeded-c2-url-decoding. The main.psbxltjfqpu function's floating-point coordinate math is the strongest static indicator of C2 URL reconstruction, but the exact endpoint is not recoverable without dynamic execution.

Interesting Tidbits

  • Densest main.* namespace: 92 randomized functions, nearly double the 42–51 range of prior siblings. Suggests either a newer builder version or aggressive function splitting to complicate static analysis. ^[strings.txt]
  • Icon suite present: Five PNG-derived RT_ICON resources (16×16 through 256×256) confirm the builder's icon-toggle is enabled for this build. Prior siblings d5647efd and e03dd36f had no .rsrc at all. ^[binwalk.txt]
  • Certificate continuity: Same blizzard-tecnica.com / R12 pattern as six prior siblings, confirming shared signing infrastructure or builder defaults. The certificate table offset (0x467600) places it well after the last section, typical for appended Authenticode data. ^[pefile.txt]
  • No UPX: Unlike sibling faa32ac2 (UPX-packed, go1.23.0), this sample is plain Go. No packer fingerprint in binwalk beyond the expected Go runtime strings. ^[binwalk.txt]
  • rabin2 anomaly: Reports signed: false despite a valid IMAGE_DIRECTORY_ENTRY_SECURITY. This is a false negative — rabin2 only checks against the Windows certificate store, not the PE directory entry. Do not rely on signed flag alone for Go malware triage. ^[rabin2-info.txt]

How To Mess With It (Homelab Replication)

  1. Install Go 1.25.4 for Windows (GOARCH=386).
  2. Build a minimal HTTP client with math/rand sleep gate:
    package main
    import (
        "fmt"
        "math/rand"
        "time"
    )
    func main() {
        rand.Seed(time.Now().UnixNano())
        sleepSec := rand.Intn(800) + 320
        time.Sleep(time.Duration(sleepSec) * time.Second)
        fmt.Println("Gate passed")
    }
    
  3. Compile: GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" sleepgate.go
  4. Compare rabin2 -I output: should show lang: go, compiled: Thu Jan 1 00:00:00 1970, and a similar .symtab section.
  5. Verify capa (if signatures installed) for use cryptographic PRNG, delay execution, and reference HTTP/S URLs.

Deployable Signatures

YARA Rule

rule lumma_go1254_blizzard_pe32 {
    meta:
        description = "Lumma Stealer Go 1.25.4 PE32 with blizzard-tecnica.com cert pattern"
        author = "PacketPursuit"
        date = "2026-08-26"
        sha256 = "142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17"
    strings:
        $go_build = "go1.25.4" ascii wide
        $go_build_id = "Go build ID:" ascii wide
        $goos = "GOOS=windows" ascii wide
        $goarch = "GOARCH=386" ascii wide
        $trimpath = "-trimpath=true" ascii wide
        $cgo_off = "CGO_ENABLED=0" ascii wide
        $main_pattern = /main\.[a-z]{12,16}/ ascii
        $symtab = ".symtab" ascii
        $rsrc = ".rsrc" ascii
        $blizzard_hint = "blizzard-tecnica.com" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        $goos and
        $goarch and
        $cgo_off and
        $trimpath and
        #main_pattern >= 80 and
        $symtab and
        $rsrc and
        filesize > 2MB and filesize < 3MB
}

Behavioral Fingerprint

This binary is a Go 1.25.4 PE32 GUI executable with null PE timestamp and 80+ randomized main.* function names. On launch it seeds math/rand from system time, computes a sleep duration between 800–1120 seconds, and then chains through a sequence of large main.* functions that perform string scanning and floating-point coordinate math. It carries an Authenticode signature appended after the last PE section. No hardcoded C2 is visible in strings — network indicators are decoded at runtime.

IOC List

Indicator Value Source
SHA-256 142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17 metadata.json
SHA-1 d7abb9a59661561edacdf6b9c5ba2bff7e6caf0b pefile.txt (.text)
ssdeep 49152:mbLf6J44F4KSnasi4/LsmJK6HBzbsO4iS:2z6JP5rsi4mLOb ssdeep.txt
Build ID NhRxJsTp5OllzacslKDm/lZFlzVNETCbIytGJG72H/EBT9qIRhKyhYfsRUHMUo/6BfwL1ezo3FJ-it_qrCx strings.txt
Go version go1.25.4 strings.txt
Cert pattern blizzard-tecnica.com / Let's Encrypt R12 (inferred from cluster) entity page
Sleep gate 800–1120 seconds via math/rand.Intn(800)+0x320 r2:sym.main.main

Detection Signatures

Static-only; no CAPE detonation available. Inferred capabilities from radare2 decompilation and cluster attribution:

Capability ATT&CK Technique Evidence
PRNG-seeded sleep gate T1497.001 (Virtualization/Sandbox Evasion: Time Based Evasion) r2:sym.main.main sleep math
Runtime-decoded C2 URLs T1568.001 (Dynamic Resolution: Fast Flux DNS) cluster pattern; no static C2
Browser credential theft T1555.003 (Credentials from Password Stores: Credentials from Web Browsers) Lumma family attribution
Cryptocurrency wallet targeting T1555.005 (Credentials from Password Stores: Password Managers) Lumma family attribution
Clipboard hijacking T1115 (Clipboard Data) Lumma family attribution
Data exfiltration over HTTPS T1041 (Exfiltration Over C2 Channel) Lumma family attribution

References

Provenance

  • File type: file v5.45 ^[file.txt]
  • PE metadata: pefile v2024.8.26 ^[pefile.txt]
  • Strings: strings (GNU binutils) ^[strings.txt]
  • Binary info: rabin2 v5.9.8 (radare2) ^[rabin2-info.txt]
  • Decompilation: r2ghidra-dec via radare2 v5.9.8 ^[r2:sym.main.main] ^[r2:sym.main.psbxltjfqpu] ^[r2:sym.main.knmhjqxclvsmt]
  • Embedded artefacts: binwalk v2.3.4 ^[binwalk.txt]
  • Exif: exiftool v12.76 ^[exiftool.json]
  • Build flags: Go buildinfo parsing (strings.txt offset 2444896) ^[strings.txt]