typeanalysisfamilyacrstealerconfidencehighcreated2026-08-16updated2026-08-16infostealermalware-familygolangsigningevasionc2
SHA-256: 1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b

cloud55filecc (contested → acrstealer): 1b98937b — Go 1.25.4 PE32, quiverquant.com/WE1 cert, two-icon suite

Executive Summary

PE32 executable crz.exe (7.6 MB) tagged by OpenCTI as cloud55file-cc. Static analysis shows it is the forty-second confirmed sibling in the acrstealer cluster: Go 1.25.4, self-signed Authenticode CN=quiverquant.com / issuer WE1, randomized module path jjpTdnXpemRvtWL, 11 randomized main.* functions, and no static C2. The .rsrc section carries a two-icon suite (smaller than the five-icon suite observed on earlier siblings on this cert chain). The cloud55filecc label is contested; all technical evidence resolves to ACR. ^[/intel/analyses/1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b.html]

What It Is

Field Value
SHA-256 1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b
Filename crz.exe ^[sample 1b98937b/triage.json]
File type PE32 executable (GUI) Intel 80386, 7 sections ^[sample 1b98937b/file.txt]
Size 7,762,560 bytes
Compiler Go 1.25.4 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath) ^[strings.txt:1661]
Module path jjpTdnXpemRvtWL (devel) ^[strings.txt:1663]
PE timestamp Thu Jan 1 00:00:00 1970 (stripped / builder artefact) ^[pefile.txt:38]
Subsystem Windows GUI ^[exiftool.json:26]
ASLR / DEP Enabled (DYNAMIC_BASE, NX_COMPAT) ^[pefile.txt:78]

Build / RE

Toolchain: Go 1.25.4 with -trimpath, producing a standard statically-linked PE32 with no external CRT. The Go build ID 6PbCxHbusTpWhTBuuBbx/Va4CCdHf8Ids7PPX1oxa/UCE05Asyf1ZaQE9csjpT/ApgT9-vSQO5e5ou8dZgW is present in .rdata ^[strings.txt:8]. No UPX or external packer — entropy in .text is 6.22, within normal Go ranges ^[pefile.txt:96].

Signing: Authenticode certificate embedded at IMAGE_DIRECTORY_ENTRY_SECURITY (RVA 0x766A00, size 0x880). Parsed via PKCS#7: CN=quiverquant.com, issuer=WE1, valid May 9 21:13:51 2026 GMT through Aug 7 22:13:46 2026 GMT. This is the seventeenth confirmed sample on the quiverquant.com/WE1 self-signed cert chain within the ACR cluster. ^[binwalk.txt:8] ^[pefile.txt:237]

Obfuscation: Standard Go anti-static measures for this cluster:

  • Randomized module path (jjpTdnXpemRvtWL) ^[strings.txt:1663]
  • 11 randomized main.* function names: przwsz, Imydpet, Hmjbojily, Yvhkibobt, Aroazrgjbl, Qymccgmsvwk, Myrlhiieylox, Nplyhwszbyxm, ziialjloeoqqp, Csepdolilyflrge, qunfiulbpqmfgdx ^[strings.txt:876–1354]
  • No custom PE parser or multi-pass byte-transform decoder (light baseline build)

Resources: .rsrc section contains 2 RT_ICON entries + 1 RT_GROUP_ICON (two-icon suite). This is a smaller set than the five-icon suite observed on siblings b3968863, 725dc07c, and 1cf857a9 on the same cert chain, suggesting a builder toggle or stripped variant. ^[rabin2-info.txt] (Python pefile confirmation: 2 icon entries in RT_ICON)

Imports: Minimal IAT — only kernel32.dll imports (standard Go runtime surface). No wininet, ws2_32, or crypt32 in the static import table; all network/crypto is resolved through Go's statically-linked runtime. ^[pefile.txt:273–327]

Anti-analysis: None observed statically. No PEB-walking, no debug checks, no VM detection strings. The null PE timestamp and randomized names are the only anti-static measures.

Deploy / ATT&CK

Execution: Inferred seed-PRNG C2 URL decoding at runtime, identical to the pattern documented for the ACR cluster (see prng-seeded-c2-url-decoding). No static C2 strings, IPs, or domains recovered. ^[sample 1b98937b/strings.txt]

Network: crypto/tls and net/http linkage confirmed via runtime strings ^[strings.txt:1585], but no specific endpoints. Family behaviour from prior siblings implies HTTPS POST exfil to runtime-decoded domains.

Collection: Inferred browser credential stores and cryptocurrency wallet targeting (family pattern). No static confirmation of wallet names or browser paths in this sample.

Persistence: None observed statically. ACR siblings have used no persistent technique (pure drop-and-run) or Task Scheduler in rare variants.

ATT&CK mapping (static inference, no dynamic execution):

  • T1071.001 — Application Layer Protocol: Web (inferred from net/http + crypto/tls runtime linkage)
  • T1027 — Obfuscated Files or Information (randomized module paths and function names)
  • T1620 — Reflective Code Loading (Go statically-linked binary with no disk-resident dependencies)
  • T1047 — Windows Management Instrumentation (not observed in this sample; noted for cluster completeness)
  • T1059.003 — Windows Command Shell (not observed in this sample)

Attribution: ACR stealer cluster. OpenCTI preliminary label cloud55file-cc is contested; same label also appears on sibling b3968863 which was resolved to ACR on 2026-08-16. No independent technical fingerprint separates cloud55filecc from the ACR cluster.

C2 Infrastructure

None recovered statically. The binary contains no hardcoded URLs, IPs, domains, or mutex names. C2 is fully runtime-decoded via the family's PRNG-seeded string-decoding routine. This is consistent with the "no static C2" pattern observed on seventeen prior siblings on the quiverquant.com/WE1 cert chain.

Interesting Tidbits

  • Two-icon suite variant: First observed sibling on the quiverquant.com/WE1 chain with only 2 icons in .rsrc instead of 5. Suggests a builder "icon count" toggle or a stripped-down distribution package. ^[rabin2-info.txt]
  • Smallest function-name count on this chain: 11 randomized main.* functions ties the smallest count observed on this cert chain (siblings 94cf86f6 and 43998b11d also have 11). The cluster ranges from 11 to 92. ^[strings.txt:876]
  • Standard baseline build: No custom PE parser, no multi-pass decoder, no .rsrc stripping — a light, mid-config build from what appears to be a builder kit with multiple toggles.
  • Certificate validity window: May 9 → Aug 7 2026 is the same 90-day window as the rest of the quiverquant.com/WE1 chain, consistent with automated cert generation in the builder.

How To Mess With It (Homelab Replication)

Build a comparable Go binary with randomized names:

package main

import (
    "fmt"
    "math/rand"
    "time"
)

func przwsz() { fmt.Println("entry") }
func Imydpet() {}
func Hmjbojily() {}
func Yvhkibobt() {}
func Aroazrgjbl() {}
func Qymccgmsvwk() {}
func Myrlhiieylox() {}
func Nplyhwszbyxm() {}
func ziialjloeoqqp() {}
func Csepdolilyflrge() {}
func qunfiulbpqmfgdx() {}

func main() {
    rand.Seed(time.Now().Unix())
    przwsz()
}

Compile: GOOS=windows GOARCH=386 go build -trimpath -ldflags="-s -w" -o repro.exe

Verification: rabin2 -I repro.exe should show lang: go, signed: false, stripped: false, and strings should contain the randomized main.* names.

Deployable Signatures

YARA Rule

rule ACR_Stealer_Go1254_quiverquant_WE1 {
    meta:
        description = "ACR stealer cluster — Go 1.25.4 PE32 with self-signed quiverquant.com/WE1 cert"
        author = "PacketPursuit"
        family = "acrstealer"
        hash = "1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b"
    strings:
        $go_ver = "go1.25.4" ascii wide
        $mod_path = /path	[a-zA-Z]{10,20}/ ascii
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $main_rand = /\*main\.[a-z]{5,15}/ ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 5MB and
        $go_ver and
        ($cert_cn or $cert_issuer) and
        #main_rand >= 8
}

IOC List

Indicator Value Type
SHA-256 1b98937b0559f1b27de90a7d5e767c3b11464d2b40db87608bf788f619b9832b Hash
Filename crz.exe Filename
Certificate CN quiverquant.com Signing cert
Certificate Issuer WE1 Signing cert
Go module jjpTdnXpemRvtWL Build artefact
Build toolchain Go 1.25.4 Toolchain

Behavioral Fingerprint

This binary is a Go 1.25.4 PE32 executable with a self-signed Authenticode certificate CN quiverquant.com / issuer WE1. It contains 11 randomized main.* function names and a two-icon .rsrc suite. No static C2 strings are present; network communication is inferred to use HTTPS with runtime-decoded endpoints via a PRNG-seeded string decoder. The PE timestamp is null (1970-01-01). All imports are satisfied by kernel32.dll through the Go runtime; no wininet, ws2_32, or crypt32 static imports.

Detection Signatures

ATT&CK Technique Static Evidence Confidence
T1071.001 net/http + crypto/tls in Go runtime strings Medium (inferred)
T1027 Randomized module path and 11 main.* function names High
T1620 Go statically-linked binary with no disk-resident dependencies High

References

Provenance

  • file.txt, exiftool.json, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, yara.txt, triage.json, metadata.json — standard triage pipeline
  • Certificate extracted manually via dd + openssl pkcs7 from IMAGE_DIRECTORY_ENTRY_SECURITY
  • capa.txt — capa signatures missing (default path not installed on triage host)
  • floss.txt — floss invocation failed (argument parsing error)
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)