1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832bcloud55filecc (contested → acrstealer): 1b98937b — Go 1.25.4 PE32, quiverquant.com/WE1 cert, two-icon suite
Executive Summary
PE32 executable crz.exe (7.6 MB) tagged by OpenCTI as cloud55file-cc. Static analysis shows it is the forty-second confirmed sibling in the acrstealer cluster: Go 1.25.4, self-signed Authenticode CN=quiverquant.com / issuer WE1, randomized module path jjpTdnXpemRvtWL, 11 randomized main.* functions, and no static C2. The .rsrc section carries a two-icon suite (smaller than the five-icon suite observed on earlier siblings on this cert chain). The cloud55filecc label is contested; all technical evidence resolves to ACR. ^[/intel/analyses/1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b.html]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b |
| Filename | crz.exe ^[sample 1b98937b/triage.json] |
| File type | PE32 executable (GUI) Intel 80386, 7 sections ^[sample 1b98937b/file.txt] |
| Size | 7,762,560 bytes |
| Compiler | Go 1.25.4 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath) ^[strings.txt:1661] |
| Module path | jjpTdnXpemRvtWL (devel) ^[strings.txt:1663] |
| PE timestamp | Thu Jan 1 00:00:00 1970 (stripped / builder artefact) ^[pefile.txt:38] |
| Subsystem | Windows GUI ^[exiftool.json:26] |
| ASLR / DEP | Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:78] |
Build / RE
Toolchain: Go 1.25.4 with -trimpath, producing a standard statically-linked PE32 with no external CRT. The Go build ID 6PbCxHbusTpWhTBuuBbx/Va4CCdHf8Ids7PPX1oxa/UCE05Asyf1ZaQE9csjpT/ApgT9-vSQO5e5ou8dZgW is present in .rdata ^[strings.txt:8]. No UPX or external packer — entropy in .text is 6.22, within normal Go ranges ^[pefile.txt:96].
Signing: Authenticode certificate embedded at IMAGE_DIRECTORY_ENTRY_SECURITY (RVA 0x766A00, size 0x880). Parsed via PKCS#7: CN=quiverquant.com, issuer=WE1, valid May 9 21:13:51 2026 GMT through Aug 7 22:13:46 2026 GMT. This is the seventeenth confirmed sample on the quiverquant.com/WE1 self-signed cert chain within the ACR cluster. ^[binwalk.txt:8] ^[pefile.txt:237]
Obfuscation: Standard Go anti-static measures for this cluster:
- Randomized module path (
jjpTdnXpemRvtWL) ^[strings.txt:1663] - 11 randomized
main.*function names:przwsz,Imydpet,Hmjbojily,Yvhkibobt,Aroazrgjbl,Qymccgmsvwk,Myrlhiieylox,Nplyhwszbyxm,ziialjloeoqqp,Csepdolilyflrge,qunfiulbpqmfgdx^[strings.txt:876–1354] - No custom PE parser or multi-pass byte-transform decoder (light baseline build)
Resources: .rsrc section contains 2 RT_ICON entries + 1 RT_GROUP_ICON (two-icon suite). This is a smaller set than the five-icon suite observed on siblings b3968863, 725dc07c, and 1cf857a9 on the same cert chain, suggesting a builder toggle or stripped variant. ^[rabin2-info.txt] (Python pefile confirmation: 2 icon entries in RT_ICON)
Imports: Minimal IAT — only kernel32.dll imports (standard Go runtime surface). No wininet, ws2_32, or crypt32 in the static import table; all network/crypto is resolved through Go's statically-linked runtime. ^[pefile.txt:273–327]
Anti-analysis: None observed statically. No PEB-walking, no debug checks, no VM detection strings. The null PE timestamp and randomized names are the only anti-static measures.
Deploy / ATT&CK
Execution: Inferred seed-PRNG C2 URL decoding at runtime, identical to the pattern documented for the ACR cluster (see prng-seeded-c2-url-decoding). No static C2 strings, IPs, or domains recovered. ^[sample 1b98937b/strings.txt]
Network: crypto/tls and net/http linkage confirmed via runtime strings ^[strings.txt:1585], but no specific endpoints. Family behaviour from prior siblings implies HTTPS POST exfil to runtime-decoded domains.
Collection: Inferred browser credential stores and cryptocurrency wallet targeting (family pattern). No static confirmation of wallet names or browser paths in this sample.
Persistence: None observed statically. ACR siblings have used no persistent technique (pure drop-and-run) or Task Scheduler in rare variants.
ATT&CK mapping (static inference, no dynamic execution):
- T1071.001 — Application Layer Protocol: Web (inferred from
net/http+crypto/tlsruntime linkage) - T1027 — Obfuscated Files or Information (randomized module paths and function names)
- T1620 — Reflective Code Loading (Go statically-linked binary with no disk-resident dependencies)
- T1047 — Windows Management Instrumentation (not observed in this sample; noted for cluster completeness)
- T1059.003 — Windows Command Shell (not observed in this sample)
Attribution: ACR stealer cluster. OpenCTI preliminary label cloud55file-cc is contested; same label also appears on sibling b3968863 which was resolved to ACR on 2026-08-16. No independent technical fingerprint separates cloud55filecc from the ACR cluster.
C2 Infrastructure
None recovered statically. The binary contains no hardcoded URLs, IPs, domains, or mutex names. C2 is fully runtime-decoded via the family's PRNG-seeded string-decoding routine. This is consistent with the "no static C2" pattern observed on seventeen prior siblings on the quiverquant.com/WE1 cert chain.
Interesting Tidbits
- Two-icon suite variant: First observed sibling on the
quiverquant.com/WE1chain with only 2 icons in.rsrcinstead of 5. Suggests a builder "icon count" toggle or a stripped-down distribution package. ^[rabin2-info.txt] - Smallest function-name count on this chain: 11 randomized
main.*functions ties the smallest count observed on this cert chain (siblings94cf86f6and43998b11dalso have 11). The cluster ranges from 11 to 92. ^[strings.txt:876] - Standard baseline build: No custom PE parser, no multi-pass decoder, no
.rsrcstripping — a light, mid-config build from what appears to be a builder kit with multiple toggles. - Certificate validity window: May 9 → Aug 7 2026 is the same 90-day window as the rest of the
quiverquant.com/WE1chain, consistent with automated cert generation in the builder.
How To Mess With It (Homelab Replication)
Build a comparable Go binary with randomized names:
package main
import (
"fmt"
"math/rand"
"time"
)
func przwsz() { fmt.Println("entry") }
func Imydpet() {}
func Hmjbojily() {}
func Yvhkibobt() {}
func Aroazrgjbl() {}
func Qymccgmsvwk() {}
func Myrlhiieylox() {}
func Nplyhwszbyxm() {}
func ziialjloeoqqp() {}
func Csepdolilyflrge() {}
func qunfiulbpqmfgdx() {}
func main() {
rand.Seed(time.Now().Unix())
przwsz()
}
Compile: GOOS=windows GOARCH=386 go build -trimpath -ldflags="-s -w" -o repro.exe
Verification: rabin2 -I repro.exe should show lang: go, signed: false, stripped: false, and strings should contain the randomized main.* names.
Deployable Signatures
YARA Rule
rule ACR_Stealer_Go1254_quiverquant_WE1 {
meta:
description = "ACR stealer cluster — Go 1.25.4 PE32 with self-signed quiverquant.com/WE1 cert"
author = "PacketPursuit"
family = "acrstealer"
hash = "1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b"
strings:
$go_ver = "go1.25.4" ascii wide
$mod_path = /path [a-zA-Z]{10,20}/ ascii
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$main_rand = /\*main\.[a-z]{5,15}/ ascii
condition:
uint16(0) == 0x5A4D and
filesize > 5MB and
$go_ver and
($cert_cn or $cert_issuer) and
#main_rand >= 8
}
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b |
Hash |
| Filename | crz.exe |
Filename |
| Certificate CN | quiverquant.com |
Signing cert |
| Certificate Issuer | WE1 |
Signing cert |
| Go module | jjpTdnXpemRvtWL |
Build artefact |
| Build toolchain | Go 1.25.4 | Toolchain |
Behavioral Fingerprint
This binary is a Go 1.25.4 PE32 executable with a self-signed Authenticode certificate CN quiverquant.com / issuer WE1. It contains 11 randomized main.* function names and a two-icon .rsrc suite. No static C2 strings are present; network communication is inferred to use HTTPS with runtime-decoded endpoints via a PRNG-seeded string decoder. The PE timestamp is null (1970-01-01). All imports are satisfied by kernel32.dll through the Go runtime; no wininet, ws2_32, or crypt32 static imports.
Detection Signatures
| ATT&CK Technique | Static Evidence | Confidence |
|---|---|---|
| T1071.001 | net/http + crypto/tls in Go runtime strings |
Medium (inferred) |
| T1027 | Randomized module path and 11 main.* function names |
High |
| T1620 | Go statically-linked binary with no disk-resident dependencies | High |
References
- Artifact ID:
f443627c-c877-4157-a6d7-1efa8fb22332^[sample 1b98937b/triage.json] - OpenCTI labels:
cloud55file-cc,flur-constzoo-surf,exe,malware-bazaar,signed^[sample 1b98937b/triage.json] - ACR stealer cluster entity: acrstealer
- Contested label entity: cloud55filecc
- Build pattern: golang-stealer-build-pattern
- C2 decode technique: prng-seeded-c2-url-decoding
Provenance
file.txt,exiftool.json,pefile.txt,strings.txt,rabin2-info.txt,binwalk.txt,yara.txt,triage.json,metadata.json— standard triage pipeline- Certificate extracted manually via
dd+openssl pkcs7fromIMAGE_DIRECTORY_ENTRY_SECURITY capa.txt— capa signatures missing (default path not installed on triage host)floss.txt— floss invocation failed (argument parsing error)dynamic-analysis.md— CAPE skipped (no Windows guest available)