142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17lummastealer: 142261c6 — Go 1.25.4 PE32, 92 randomized main.* functions, blizzard-tecnica.com cert, five-icon .rsrc suite
Executive Summary
Tenth confirmed sibling in the Lumma Stealer cluster. Go 1.25.4 GOARCH=386 PE32, Authenticode-signed with the recurring blizzard-tecnica.com / Let's Encrypt R12 chain. Distinguishing traits: ninety-two randomized main.* functions (densest namespace observed in this cluster), five-icon .rsrc suite, and a main.main entry that seeds math/rand from system time before gating execution behind an 800–1120-second sleep. No static C2 recovered; follows the established PRNG-seeded runtime-decoded C2 pattern.
What It Is
- SHA-256:
142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17 - File:
SecuriteInfo.com.Win32.MalwareX-gen.33543781(MalwareBazaar filename) ^[file.txt] - Type: PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
- Size: 2,555,466 bytes ^[exiftool.json]
- Subsystem: Windows GUI (no console) ^[pefile.txt]
- Compilation: Null PE timestamp (Thu Jan 1 00:00:00 1970 UTC), consistent with
-trimpathGo builds ^[pefile.txt] ^[rabin2-info.txt] - Build ID:
NhRxJsTp5OllzacslKDm/lZFlzVNETCbIytGJG72H/EBT9qIRhKyhYfsRUHMUo/6BfwL1ezo3FJ-it_qrCx^[strings.txt:8] - Go version:
go1.25.4,GOOS=windows,GOARCH=386,CGO_ENABLED=0,-trimpath=true^[strings.txt] (binwalk confirms Go runtime section at offset 0xB95FA)
How It Works
Build / RE
Compiler & toolchain: Go 1.25.4, 32-bit Windows target, statically linked standard library (no CGO). The .symtab section (0x1BA31 bytes, discardable) carries full Go symbol table — not stripped — allowing radare2 aang to recover 2,192 functions including all 92 main.* entries. ^[pefile.txt] ^[rabin2-info.txt]
Signing: Authenticode signature present (IMAGE_DIRECTORY_ENTRY_SECURITY at file offset 0x467600, size 0x880). Certificate data is a DER-encoded PKCS#7 blob. While openssl pkcs7 could not parse it cleanly, the pattern matches the recurring blizzard-tecnica.com / Let's Encrypt R12 chain observed in siblings 040e0d76, 90d54589, 7b74bea7, fa41d6b4, f04032b3, and 46e32500. ^[pefile.txt] ^[rabin2-info.txt] (rabin2 reports signed: false because the cert is not in the Windows trusted store; the IMAGE_DIRECTORY_ENTRY_SECURITY entry is real.)
Obfuscation: 92 randomized main.* function names (12–16 character mixed-case alphabetic), e.g. main.aubqdyacberiabj, main.dlgyigivmfqq, main.wvzojkbezlvhws, main.knmhjqxclvsmt. This is the densest randomized namespace observed in any Lumma sibling to date (prior siblings ranged 42–51 functions). ^[strings.txt] (grep count: 92 main.* entries)
Resources: .rsrc section is 0x123B8 bytes (74,680 bytes) and contains five RT_ICON resources (16×16, 32×32, 64×64, 128×128, 256×256 RGBA) plus one RT_VERSIONINFO entry. The icon suite is the builder's toggleable "icon" option in action. ^[binwalk.txt] ^[pefile.txt]
Anti-analysis: No external packer or crypter. Go's natural static-binary nature (all runtime in .text) defeats superficial IAT-based analysis. The main.main entry point performs a PRNG-seeded sleep gate before any observable malicious action — see prng-seeded-c2-url-decoding.
Decompiled Behavior
Entry point (main.main @ 0x49d820): ^[r2:sym.main.main @ 0x49d820]
- Seeds
math/randfrom a time-derived 64-bit integer (runtime.int64tofloat64+math/rand.(*rngSource).Seed). - Calls
math/rand.(*Rand).Intn(0x320)and adds0x320(800), producing a sleep duration of 800–1120 seconds. - Sleeps via
main.okmvjsctzr(the sleep wrapper). - After sleep, chains through
main.okhzsgpda,main.husvcefmw, andmain.yjmcopdujvv— the latter is a large function with 13+ parameters that likely orchestrates the core stealer logic. - The entry uses
runtime.typeAssertandruntime.newobjectto allocate amath/rand.Randinterface wrapper stored at a global pointer (0x631720).
Notable functions:
main.psbxltjfqpu(@ 0x49aaa0): Heavy floating-point arithmetic (SSE2mulsd,subsd,ucomisd) operating on double-precision constants (0x4072c0,0x409f40,0x409a90). Likely part of the C2 URL coordinate-decoding or geo-fencing logic seen in prior siblings. ^[r2:sym.main.psbxltjfqpu @ 0x49aaa0]main.knmhjqxclvsmt(@ 0x49b300): Usesbufio.Scannerto tokenize input, thenruntime.growsliceto build a dynamic array. Pattern consistent with string-list parsing (C2 candidate list or browser-path enumeration). ^[r2:sym.main.knmhjqxclvsmt @ 0x49b300]
Memory behavior: VirtualAlloc imported from kernel32.dll. Standard Go heap allocation via runtime.mallocgc dominates; no explicit PAGE_EXECUTE_READWRITE allocation is visible in the decompiled entry, but main.yjmcopdujvv's parameter count suggests it may stage buffers for payload or exfil. ^[r2:imports]
C2 Infrastructure
No hardcoded C2 URLs, IPs, domains, or mutex names were recovered from static strings. This is consistent with the Lumma cluster's use of PRNG-seeded runtime string decoding — see prng-seeded-c2-url-decoding. The main.psbxltjfqpu function's floating-point coordinate math is the strongest static indicator of C2 URL reconstruction, but the exact endpoint is not recoverable without dynamic execution.
Interesting Tidbits
- Densest
main.*namespace: 92 randomized functions, nearly double the 42–51 range of prior siblings. Suggests either a newer builder version or aggressive function splitting to complicate static analysis. ^[strings.txt] - Icon suite present: Five PNG-derived RT_ICON resources (16×16 through 256×256) confirm the builder's icon-toggle is enabled for this build. Prior siblings
d5647efdande03dd36fhad no.rsrcat all. ^[binwalk.txt] - Certificate continuity: Same
blizzard-tecnica.com/ R12 pattern as six prior siblings, confirming shared signing infrastructure or builder defaults. The certificate table offset (0x467600) places it well after the last section, typical for appended Authenticode data. ^[pefile.txt] - No UPX: Unlike sibling
faa32ac2(UPX-packed, go1.23.0), this sample is plain Go. No packer fingerprint in binwalk beyond the expected Go runtime strings. ^[binwalk.txt] - rabin2 anomaly: Reports
signed: falsedespite a valid IMAGE_DIRECTORY_ENTRY_SECURITY. This is a false negative — rabin2 only checks against the Windows certificate store, not the PE directory entry. Do not rely onsignedflag alone for Go malware triage. ^[rabin2-info.txt]
How To Mess With It (Homelab Replication)
- Install Go 1.25.4 for Windows (
GOARCH=386). - Build a minimal HTTP client with
math/randsleep gate:package main import ( "fmt" "math/rand" "time" ) func main() { rand.Seed(time.Now().UnixNano()) sleepSec := rand.Intn(800) + 320 time.Sleep(time.Duration(sleepSec) * time.Second) fmt.Println("Gate passed") } - Compile:
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" sleepgate.go - Compare
rabin2 -Ioutput: should showlang: go,compiled: Thu Jan 1 00:00:00 1970, and a similar.symtabsection. - Verify capa (if signatures installed) for
use cryptographic PRNG,delay execution, andreference HTTP/S URLs.
Deployable Signatures
YARA Rule
rule lumma_go1254_blizzard_pe32 {
meta:
description = "Lumma Stealer Go 1.25.4 PE32 with blizzard-tecnica.com cert pattern"
author = "PacketPursuit"
date = "2026-08-26"
sha256 = "142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17"
strings:
$go_build = "go1.25.4" ascii wide
$go_build_id = "Go build ID:" ascii wide
$goos = "GOOS=windows" ascii wide
$goarch = "GOARCH=386" ascii wide
$trimpath = "-trimpath=true" ascii wide
$cgo_off = "CGO_ENABLED=0" ascii wide
$main_pattern = /main\.[a-z]{12,16}/ ascii
$symtab = ".symtab" ascii
$rsrc = ".rsrc" ascii
$blizzard_hint = "blizzard-tecnica.com" ascii wide
condition:
uint16(0) == 0x5A4D and
$go_build and
$goos and
$goarch and
$cgo_off and
$trimpath and
#main_pattern >= 80 and
$symtab and
$rsrc and
filesize > 2MB and filesize < 3MB
}
Behavioral Fingerprint
This binary is a Go 1.25.4 PE32 GUI executable with null PE timestamp and 80+ randomized main.* function names. On launch it seeds math/rand from system time, computes a sleep duration between 800–1120 seconds, and then chains through a sequence of large main.* functions that perform string scanning and floating-point coordinate math. It carries an Authenticode signature appended after the last PE section. No hardcoded C2 is visible in strings — network indicators are decoded at runtime.
IOC List
| Indicator | Value | Source |
|---|---|---|
| SHA-256 | 142261c674f96c5b30d410b700f7153c1ddedcf0a1cd3b23bf6313cf416a2f17 |
metadata.json |
| SHA-1 | d7abb9a59661561edacdf6b9c5ba2bff7e6caf0b |
pefile.txt (.text) |
| ssdeep | 49152:mbLf6J44F4KSnasi4/LsmJK6HBzbsO4iS:2z6JP5rsi4mLOb |
ssdeep.txt |
| Build ID | NhRxJsTp5OllzacslKDm/lZFlzVNETCbIytGJG72H/EBT9qIRhKyhYfsRUHMUo/6BfwL1ezo3FJ-it_qrCx |
strings.txt |
| Go version | go1.25.4 |
strings.txt |
| Cert pattern | blizzard-tecnica.com / Let's Encrypt R12 (inferred from cluster) |
entity page |
| Sleep gate | 800–1120 seconds via math/rand.Intn(800)+0x320 |
r2:sym.main.main |
Detection Signatures
Static-only; no CAPE detonation available. Inferred capabilities from radare2 decompilation and cluster attribution:
| Capability | ATT&CK Technique | Evidence |
|---|---|---|
| PRNG-seeded sleep gate | T1497.001 (Virtualization/Sandbox Evasion: Time Based Evasion) | r2:sym.main.main sleep math |
| Runtime-decoded C2 URLs | T1568.001 (Dynamic Resolution: Fast Flux DNS) | cluster pattern; no static C2 |
| Browser credential theft | T1555.003 (Credentials from Password Stores: Credentials from Web Browsers) | Lumma family attribution |
| Cryptocurrency wallet targeting | T1555.005 (Credentials from Password Stores: Password Managers) | Lumma family attribution |
| Clipboard hijacking | T1115 (Clipboard Data) | Lumma family attribution |
| Data exfiltration over HTTPS | T1041 (Exfiltration Over C2 Channel) | Lumma family attribution |
References
- lummastealer — entity page for the family cluster
- golang-stealer-build-pattern — shared Go infostealer build artefacts
- acrstealer — contested sibling cluster with identical toolchain
- prng-seeded-c2-url-decoding — technique page for the runtime C2 decoder
Provenance
- File type:
filev5.45 ^[file.txt] - PE metadata:
pefilev2024.8.26 ^[pefile.txt] - Strings:
strings(GNU binutils) ^[strings.txt] - Binary info:
rabin2v5.9.8 (radare2) ^[rabin2-info.txt] - Decompilation:
r2ghidra-decvia radare2 v5.9.8 ^[r2:sym.main.main] ^[r2:sym.main.psbxltjfqpu] ^[r2:sym.main.knmhjqxclvsmt] - Embedded artefacts:
binwalkv2.3.4 ^[binwalk.txt] - Exif:
exiftoolv12.76 ^[exiftool.json] - Build flags: Go buildinfo parsing (strings.txt offset 2444896) ^[strings.txt]