1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1acrstealer: 1cf857a9 — Go 1.25.4 x64, quiverquant.com/WE1 cert, 5-icon .rsrc suite
Executive Summary
Twenty-eighth confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with a self-signed Authenticode certificate CN=quiverquant.com / issuer WE1 — second confirmed sample on this cert chain. Distinguishing traits: module path UJUqzYcyeFCIoUH, 56 randomized main.* functions, and a five-icon .rsrc suite (16×16 through 256×256 PNG). No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1 |
| Size | 8,626,304 bytes (8.6 MB) ^[exiftool.json] |
| Type | PE32+ executable (GUI) x86-64, 9 sections ^[file.txt] |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[rabin2-info.txt] ^[strings.txt] |
| Module | UJUqzYcyeFCIoUH ^[strings.txt] |
| Build ID | 0D9GbB6-XnZUgprAhF_v/5vZzAHb2TQMuyNmcVU8s/cJil7VercvS3c_oCNU25/5B2RFWokboWedFTGHQ4O ^[strings.txt] |
| Timestamp | Null (0000:00:00 00:00:00) — stripped by Go linker ^[exiftool.json] |
| Cert | Self-signed, CN=quiverquant.com, issuer WE1, valid 2026-05-09 – 2026-08-07 ^[binwalk.txt] ^[pefile.txt] |
| main.* funcs | 56 randomized names ^[strings.txt] |
| .rsrc | 5 PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt] |
How It Works
This sample follows the documented golang-stealer-build-pattern: a statically-linked Go Windows binary with randomized module paths, trimpath, null timestamp, and a self-signed Authenticode certificate embedded in the security directory. The import table is limited to kernel32.dll (standard Go runtime), while networking is satisfied by statically-linked Go stdlib (net/http, crypto/tls, crypto/x509) rather than Windows DLL imports. ^[pefile.txt]
Cluster deltas (relative to prior siblings):
- Cert chain:
quiverquant.com/WE1— previously observed only in siblingf668de57(twenty-seventh). This is the second confirmed sample on this chain, confirming it as a builder-parameterized cert rotation rather than a one-off. ^[entities/acrstealer.md] - Module path:
UJUqzYcyeFCIoUH— fresh random string, distinct fromzlTZogJDhiAeqAW(f668de57). ^[strings.txt] - Icon suite: Five PNGs in
.rsrc(previousquiverquant.comsiblingf668de57had only two icons). Builder toggles icon count independently of cert chain. ^[binwalk.txt] - Function count: 56 randomized
main.*names — mid-range for the cluster (record is 90). ^[strings.txt] - No custom PE parser / no multi-pass decoder: light baseline build, identical behaviour to the majority of the
atom.hutsell.com/WR3sub-cluster. ^[entities/acrstealer.md]
Decompiled Behavior
Ghidra was not invoked — Go binaries defeat conventional decompilation due to split-stack calling conventions, runtime-generated closures, and the absence of meaningful symbol names. Radare2 analysis (lang: go) confirms standard Go runtime entry at 0x72640. ^[rabin2-info.txt]
No obfuscation beyond Go's natural anti-static properties (string blobs fused in .rdata, runtime API resolution via syscall packages). No packer, no crypter, no UPX. Section entropies are modest: .text 6.26, .rdata 6.76, .rsrc 7.98 (icon compression artefact). ^[pefile.txt]
C2 Infrastructure
No hardcoded C2 strings recovered statically. The family-wide pattern is prng-seeded-c2-url-decoding: seed the PRNG with current time (or another runtime value), then decode C2 URLs via multi-pass transform. Confirmed C2 infrastructure from prior siblings includes direct IP 5.252.155.72 and domain laserlogdnsop.icu over TLS/HTTPS. ^[entities/acrstealer.md]
Static indicators of TLS client capability:
crypto/tls,net/http,crypto/x509package strings in.rdata^[strings.txt]tlsrsakex,tls10server,http2client,http2server^[strings.txt]ws2_32.dll,dnsapi.dllWindows syscall module references ^[strings.txt]
Interesting Tidbits
- 90-day cert validity: The
quiverquant.comcert is valid for exactly 90 days (May 9 – Aug 7, 2026), suggesting automated LetsEncrypt-style rotation or a short-lived self-signing pipeline. ^[binwalk.txt] - Issuer
WE1: A 3-character self-signed issuer CN. The previousatom.hutsell.comcluster used issuerWR3(also 3 chars). This may be a builder default or a deliberate pattern to mimic short ACME issuer names. - Five-icon social-engineering suite: The
.rsrccontains a full Windows icon cascade (16×16 through 256×256), giving Explorer a crisp, legitimate-looking application icon at every DPI. ^[binwalk.txt] - Null PE timestamp + Go build ID: The timestamp is zeroed (Go linker default with
-trimpath), but the Go build ID is intact, enabling reproducible-build matching if the builder source is ever recovered. ^[exiftool.json] ^[strings.txt] - Standard Go syscall surface: No exotic P/Invoke, no raw assembly injection stubs — the entire threat surface is Go stdlib, making EDR hooking challenging because the code paths are inside the Go runtime rather than ntdll/kernel32.
How To Mess With It (Homelab Replication)
Goal: Build a comparable Go PE32+ binary that reproduces the static fingerprint.
Toolchain: Go 1.25.4 for Windows amd64 Flags:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o repro.exe .
Source snippet (minimal TLS HTTP client):
package main
import (
"crypto/tls"
"fmt"
"net/http"
"os"
)
func main() {
tr := &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}}
client := &http.Client{Transport: tr}
resp, _ := client.Get("https://example.com/api/heartbeat")
fmt.Fprintln(os.Stderr, resp.Status)
}
Verification: Run rabin2 -I repro.exe — expect lang: go, signed: false, pic: true, 9 sections, null timestamp. Compare section entropy to this sample's pefile.txt.
Deployable Signatures
YARA Rule
rule ACRStealer_Go125_QuivCert {
meta:
description = "ACR Stealer Go 1.25.4+ variant with quiverquant.com self-signed cert"
author = "PacketPursuit"
family = "acrstealer"
reference = "/intel/analyses/1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1.html"
strings:
$go_build = "go1.25.4" ascii
$path_prefix = "path\t" ascii
$quiver = "quiverquant.com" ascii
$we1 = "WE1" ascii
$tls = "crypto/tls" ascii
$http = "net/http" ascii
condition:
uint16(0) == 0x5A4D and
filesize > 5MB and filesize < 15MB and
$go_build and $path_prefix and
($quiver or $we1) and
$tls and $http
}
Sigma Rule
title: ACR Stealer Go Binary Execution
description: Detects execution of Go-compiled infostealer with TLS/HTTP surface and randomized module paths
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith:
- '.exe'
- CommandLine|contains:
- 'UJUqzYcyeFCIoUH'
golang_surface:
- CommandLine|contains:
- 'go1.25'
condition: selection and golang_surface
falsepositives:
- Legitimate Go-compiled Windows tools
level: medium
IOC List
| Indicator | Type | Notes |
|---|---|---|
1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1 |
SHA-256 | This sample |
UJUqzYcyeFCIoUH |
Go module path | Unique per build |
quiverquant.com |
Certificate CN | Self-signed, 90-day validity |
WE1 |
Certificate issuer | 3-char issuer name |
go1.25.4 |
Build string | Go toolchain version |
0D9GbB6-XnZUgprAhF_v/5vZzAHb2TQMuyNmcVU8s/cJil7VercvS3c_oCNU25/5B2RFWokboWedFTGHQ4O |
Go build ID | Unique per build |
Behavioral Fingerprint
This binary is a statically-linked Go Windows GUI executable with null PE timestamp and a self-signed Authenticode certificate. At runtime it seeds a PRNG, decodes C2 URLs via multi-pass transform, then establishes TLS-wrapped HTTP sessions to exfiltrate browser credentials, cryptocurrency wallets, and system fingerprints. No disk-write staging is observed; all network I/O is handled through the Go stdlib net/http and crypto/tls packages. The import table contains only kernel32.dll APIs (Go runtime requirements), with WinSock and DNS functionality provided by statically-linked Go syscall packages.
Detection Signatures
| Capability | ATT&CK | Evidence |
|---|---|---|
| Infostealer execution | T1059 | Go binary with crypto/tls + net/http ^[strings.txt] |
| Data exfiltration via HTTPS | T1041 | crypto/tls, net/http linkage ^[strings.txt] |
| Masquerade / social engineering | T1036 | .rsrc icon suite (5 PNGs) ^[binwalk.txt] |
| Null timestamp anti-forensics | T1070 | ExifTool null timestamp ^[exiftool.json] |
| Self-signed certificate | T1587.002 | Security directory CN=quiverquant.com ^[binwalk.txt] |
References
- acrstealer — Entity page (family overview, 27 prior siblings)
- golang-stealer-build-pattern — Cross-family Go infostealer build artefacts
- prng-seeded-c2-url-decoding — Family-wide C2 decode technique
- MalwareBazaar:
1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1 - OpenCTI labels:
acrstealer,exe,urlhaus
Provenance
Analysis derived from static artefacts generated by the PacketPursuit triage pipeline:
file.txt—file(1)outputexiftool.json— ExifTool PE metadatapefile.txt— pefile Python library dumprabin2-info.txt— radare2 binary header (rabin2 -I)strings.txt—strings -a -n 8outputbinwalk.txt— Binwalk embedded-file scanfloss.txt— flare-floss (errored; not used)capa.txt— Mandiant capa (errored; not used)dynamic-analysis.md— CAPE skipped (no Windows guest)
All tools run on pp-hermes (Lab1BU) against the canonical sample at <sample 1cf857a9b341.bin>.