typeanalysisfamilyacrstealerconfidencehighcreated2026-08-10updated2026-08-10infostealermalware-familygolangsigning
SHA-256: 1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1

acrstealer: 1cf857a9 — Go 1.25.4 x64, quiverquant.com/WE1 cert, 5-icon .rsrc suite

Executive Summary

Twenty-eighth confirmed sibling in the acrstealer Go infostealer cluster. Go 1.25.4 PE32+ x64 build with a self-signed Authenticode certificate CN=quiverquant.com / issuer WE1 — second confirmed sample on this cert chain. Distinguishing traits: module path UJUqzYcyeFCIoUH, 56 randomized main.* functions, and a five-icon .rsrc suite (16×16 through 256×256 PNG). No static C2, no custom PE parser, no multi-pass decoder — a light baseline build. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1
Size 8,626,304 bytes (8.6 MB) ^[exiftool.json]
Type PE32+ executable (GUI) x86-64, 9 sections ^[file.txt]
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[rabin2-info.txt] ^[strings.txt]
Module UJUqzYcyeFCIoUH ^[strings.txt]
Build ID 0D9GbB6-XnZUgprAhF_v/5vZzAHb2TQMuyNmcVU8s/cJil7VercvS3c_oCNU25/5B2RFWokboWedFTGHQ4O ^[strings.txt]
Timestamp Null (0000:00:00 00:00:00) — stripped by Go linker ^[exiftool.json]
Cert Self-signed, CN=quiverquant.com, issuer WE1, valid 2026-05-09 – 2026-08-07 ^[binwalk.txt] ^[pefile.txt]
main.* funcs 56 randomized names ^[strings.txt]
.rsrc 5 PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt]

How It Works

This sample follows the documented golang-stealer-build-pattern: a statically-linked Go Windows binary with randomized module paths, trimpath, null timestamp, and a self-signed Authenticode certificate embedded in the security directory. The import table is limited to kernel32.dll (standard Go runtime), while networking is satisfied by statically-linked Go stdlib (net/http, crypto/tls, crypto/x509) rather than Windows DLL imports. ^[pefile.txt]

Cluster deltas (relative to prior siblings):

  • Cert chain: quiverquant.com/WE1 — previously observed only in sibling f668de57 (twenty-seventh). This is the second confirmed sample on this chain, confirming it as a builder-parameterized cert rotation rather than a one-off. ^[entities/acrstealer.md]
  • Module path: UJUqzYcyeFCIoUH — fresh random string, distinct from zlTZogJDhiAeqAW (f668de57). ^[strings.txt]
  • Icon suite: Five PNGs in .rsrc (previous quiverquant.com sibling f668de57 had only two icons). Builder toggles icon count independently of cert chain. ^[binwalk.txt]
  • Function count: 56 randomized main.* names — mid-range for the cluster (record is 90). ^[strings.txt]
  • No custom PE parser / no multi-pass decoder: light baseline build, identical behaviour to the majority of the atom.hutsell.com/WR3 sub-cluster. ^[entities/acrstealer.md]

Decompiled Behavior

Ghidra was not invoked — Go binaries defeat conventional decompilation due to split-stack calling conventions, runtime-generated closures, and the absence of meaningful symbol names. Radare2 analysis (lang: go) confirms standard Go runtime entry at 0x72640. ^[rabin2-info.txt]

No obfuscation beyond Go's natural anti-static properties (string blobs fused in .rdata, runtime API resolution via syscall packages). No packer, no crypter, no UPX. Section entropies are modest: .text 6.26, .rdata 6.76, .rsrc 7.98 (icon compression artefact). ^[pefile.txt]

C2 Infrastructure

No hardcoded C2 strings recovered statically. The family-wide pattern is prng-seeded-c2-url-decoding: seed the PRNG with current time (or another runtime value), then decode C2 URLs via multi-pass transform. Confirmed C2 infrastructure from prior siblings includes direct IP 5.252.155.72 and domain laserlogdnsop.icu over TLS/HTTPS. ^[entities/acrstealer.md]

Static indicators of TLS client capability:

  • crypto/tls, net/http, crypto/x509 package strings in .rdata ^[strings.txt]
  • tlsrsakex, tls10server, http2client, http2server ^[strings.txt]
  • ws2_32.dll, dnsapi.dll Windows syscall module references ^[strings.txt]

Interesting Tidbits

  • 90-day cert validity: The quiverquant.com cert is valid for exactly 90 days (May 9 – Aug 7, 2026), suggesting automated LetsEncrypt-style rotation or a short-lived self-signing pipeline. ^[binwalk.txt]
  • Issuer WE1: A 3-character self-signed issuer CN. The previous atom.hutsell.com cluster used issuer WR3 (also 3 chars). This may be a builder default or a deliberate pattern to mimic short ACME issuer names.
  • Five-icon social-engineering suite: The .rsrc contains a full Windows icon cascade (16×16 through 256×256), giving Explorer a crisp, legitimate-looking application icon at every DPI. ^[binwalk.txt]
  • Null PE timestamp + Go build ID: The timestamp is zeroed (Go linker default with -trimpath), but the Go build ID is intact, enabling reproducible-build matching if the builder source is ever recovered. ^[exiftool.json] ^[strings.txt]
  • Standard Go syscall surface: No exotic P/Invoke, no raw assembly injection stubs — the entire threat surface is Go stdlib, making EDR hooking challenging because the code paths are inside the Go runtime rather than ntdll/kernel32.

How To Mess With It (Homelab Replication)

Goal: Build a comparable Go PE32+ binary that reproduces the static fingerprint.

Toolchain: Go 1.25.4 for Windows amd64 Flags:

GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o repro.exe .

Source snippet (minimal TLS HTTP client):

package main
import (
    "crypto/tls"
    "fmt"
    "net/http"
    "os"
)
func main() {
    tr := &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}}
    client := &http.Client{Transport: tr}
    resp, _ := client.Get("https://example.com/api/heartbeat")
    fmt.Fprintln(os.Stderr, resp.Status)
}

Verification: Run rabin2 -I repro.exe — expect lang: go, signed: false, pic: true, 9 sections, null timestamp. Compare section entropy to this sample's pefile.txt.

Deployable Signatures

YARA Rule

rule ACRStealer_Go125_QuivCert {
    meta:
        description = "ACR Stealer Go 1.25.4+ variant with quiverquant.com self-signed cert"
        author = "PacketPursuit"
        family = "acrstealer"
        reference = "/intel/analyses/1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1.html"
    strings:
        $go_build = "go1.25.4" ascii
        $path_prefix = "path\t" ascii
        $quiver = "quiverquant.com" ascii
        $we1 = "WE1" ascii
        $tls = "crypto/tls" ascii
        $http = "net/http" ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize > 5MB and filesize < 15MB and
        $go_build and $path_prefix and
        ($quiver or $we1) and
        $tls and $http
}

Sigma Rule

title: ACR Stealer Go Binary Execution
description: Detects execution of Go-compiled infostealer with TLS/HTTP surface and randomized module paths
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith:
            - '.exe'
        - CommandLine|contains:
            - 'UJUqzYcyeFCIoUH'
    golang_surface:
        - CommandLine|contains:
            - 'go1.25'
    condition: selection and golang_surface
falsepositives:
    - Legitimate Go-compiled Windows tools
level: medium

IOC List

Indicator Type Notes
1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1 SHA-256 This sample
UJUqzYcyeFCIoUH Go module path Unique per build
quiverquant.com Certificate CN Self-signed, 90-day validity
WE1 Certificate issuer 3-char issuer name
go1.25.4 Build string Go toolchain version
0D9GbB6-XnZUgprAhF_v/5vZzAHb2TQMuyNmcVU8s/cJil7VercvS3c_oCNU25/5B2RFWokboWedFTGHQ4O Go build ID Unique per build

Behavioral Fingerprint

This binary is a statically-linked Go Windows GUI executable with null PE timestamp and a self-signed Authenticode certificate. At runtime it seeds a PRNG, decodes C2 URLs via multi-pass transform, then establishes TLS-wrapped HTTP sessions to exfiltrate browser credentials, cryptocurrency wallets, and system fingerprints. No disk-write staging is observed; all network I/O is handled through the Go stdlib net/http and crypto/tls packages. The import table contains only kernel32.dll APIs (Go runtime requirements), with WinSock and DNS functionality provided by statically-linked Go syscall packages.

Detection Signatures

Capability ATT&CK Evidence
Infostealer execution T1059 Go binary with crypto/tls + net/http ^[strings.txt]
Data exfiltration via HTTPS T1041 crypto/tls, net/http linkage ^[strings.txt]
Masquerade / social engineering T1036 .rsrc icon suite (5 PNGs) ^[binwalk.txt]
Null timestamp anti-forensics T1070 ExifTool null timestamp ^[exiftool.json]
Self-signed certificate T1587.002 Security directory CN=quiverquant.com ^[binwalk.txt]

References

  • acrstealer — Entity page (family overview, 27 prior siblings)
  • golang-stealer-build-pattern — Cross-family Go infostealer build artefacts
  • prng-seeded-c2-url-decoding — Family-wide C2 decode technique
  • MalwareBazaar: 1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1
  • OpenCTI labels: acrstealer, exe, urlhaus

Provenance

Analysis derived from static artefacts generated by the PacketPursuit triage pipeline:

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile Python library dump
  • rabin2-info.txt — radare2 binary header (rabin2 -I)
  • strings.txt — strings -a -n 8 output
  • binwalk.txt — Binwalk embedded-file scan
  • floss.txt — flare-floss (errored; not used)
  • capa.txt — Mandiant capa (errored; not used)
  • dynamic-analysis.md — CAPE skipped (no Windows guest)

All tools run on pp-hermes (Lab1BU) against the canonical sample at <sample 1cf857a9b341.bin>.