typeanalysisfamilylummastealerconfidencehighgolanginfostealersigned-pe-masqueradeobfuscationc2tls-httpsregistryprocess-injectiongoroutine-concurrencyprng-decoded-c2lummastealer
SHA-256: 2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d

lummastealer: 2f04e1e4 — 17th confirmed sibling, Go 1.25.4 x64, identical .text template to eaa52e19, placeholder cert + five-icon .rsrc + 726 KB null overlay + 2 goroutine closures

Executive Summary

PE32+ x86-64 Go binary compiled with Go 1.25.4. This is the 17th confirmed Lumma-native sibling in the cluster, sharing the identical .text section SHA-256 hash with eaa52e19 (16th sibling) and 9ca2ebb8 (also 16th), confirming use of the same x64 compiler template / build cache. Distinctive features: five-icon .rsrc suite (16×16 through 256×256 RGBA), placeholder self-signed certificate (CN=xxx.com, issuer E7), 726 KB null-padded overlay (100% zeros, entropy 0.0), 30 randomized main.* functions, and 2 goroutine .func1 closures (pyocwfeeou.func1 and jtpisrathivs.func1). Static-only analysis; CAPE skipped due to no Windows guest.

What It Is

Field Value Source
SHA-256 2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d metadata.json
File name SecuriteInfo.com.Win64.MalwareX-gen.82596579 metadata.json
Size 3,361,408 bytes (3.2 MB) exiftool.json
Type PE32+ executable (GUI) x86-64, 9 sections file.txt
Go version 1.25.4 strings.txt:1736
Build ID hyPfkpGedK99uJ_fBZi8/EwgSdwFrIa6kLSAwExPx/gGqyEXHxVvL4xtlpCa8b/nEZuxCYpRJk5_S0c9naC strings.txt:10
Subsystem Windows GUI exiftool.json
PE timestamp 1970-01-01 00:00:00 (null) pefile.txt
.text hash 13e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cb computed
Overlay 726 KB, 100% null bytes, entropy 0.0 computed

Family ascription: High-confidence lummastealer sibling. Decisive evidence:

  1. Placeholder certificate chain — CN=xxx.com, issuer E7, 3-month validity, self-signed sha256WithRSA — matches the xxx.com/E7 chain observed on siblings eaa52e19, c25d9423, ae3ee04f, and 9ca2ebb8. ^[pefile.txt] ^[binwalk.txt:16-18]
  2. Identical .text section hash — SHA-256 13e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cb matches eaa52e19 and 9ca2ebb8, confirming the same x64 compiler template / build cache. ^[computed]
  3. Five-icon .rsrc suite — 16×16, 32×32, 64×64, 128×128, and 256×256 RGBA PNG icons, matching the .rsrc pattern on eaa52e19, c25d9423, ae3ee04f, and 9ca2ebb8. ^[pefile.txt:365-485] ^[binwalk.txt:6-15]
  4. Go 1.25.4 + randomized main.* function names — 30 randomized main.* functions, consistent with the Lumma-native x64 cluster pattern. ^[r2: list_functions]
  5. Goroutine .func1 closures — main.pyocwfeeou.func1 and main.jtpisrathivs.func1, confirming goroutine-based concurrency primitives first observed in c25d9423. ^[r2: list_functions]

How It Works

Entry Point and Initialization

main.main at 0x14009afa0 initializes math_rand and runtime.newobject before dispatching to the primary payload functions. ^[r2:sym.main.main @ 0x14009afa0] The binary uses standard Go runtime.main entry with Windows GUI subsystem; no console window is allocated. ^[strings.txt:1736] ^[exiftool.json]

C2 URL Resolution

No hardcoded C2 URL is present in strings. C2 endpoints are resolved at runtime using a PRNG-seeded transform — a cluster-wide pattern observed in e03dd36f, 040e0d76, and all subsequent siblings. The decompiled main.kghpjqunuhqoph at 0x140098cc0 seeds math_rand with time.Now().UnixNano(), then calls math_rand._Rand_.Float64() and math_rand._Rand_.Intn() in a loop to build what appears to be a randomized C2 URL string. ^[r2:sym.main.kghpjqunuhqoph @ 0x140098cc0] This matches the prng-seeded-c2-url-decoding technique documented in the Lumma cluster. ^[lummastealer]

API Loading and String Decoding

main.tmxulsechnosyax at 0x140096e80 calls syscall.LoadLibrary with fused DLL+API strings, consistent with the fused-string-api-decoding technique. ^[r2:sym.main.tmxulsechnosyax @ 0x140096e80] The main.klzqxryn helper at 0x140096c40 appears to slice fused strings at runtime to reconstruct API names, defeating naive string extraction. ^[r2:sym.main.klzqxryn @ 0x140096c40]

Memory Staging

main.hbeauy at 0x140097ae0 and main.ongoeekepf at 0x140097b40 both call main.sjakmasksdmnea (at 0x1400979a0) with parameters 0x3000 (MEM_COMMIT | MEM_RESERVE) and 0x40 (PAGE_EXECUTE_READWRITE), allocating RWX memory for reflective payload staging. ^[r2:sym.main.hbeauy @ 0x140097ae0] ^[r2:sym.main.ongoeekepf @ 0x140097b40] This is the standard Lumma reflective-loader pattern.

Registry Manipulation

Registry strings RegSetValueExW and RegCloseKey are present in the fused string blobs, indicating the binary writes to the registry — likely for persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run or similar. ^[strings.txt:1671] ^[strings.txt:1680]

Process Manipulation

CreateProcessW, ExitProcess, OpenProcess, and DuplicateHandle are all present in the fused string API surface. ^[strings.txt:1686] ^[strings.txt:1671] The presence of OpenProcess + DuplicateHandle + VirtualAlloc + RWX suggests process injection or hollowed-process creation, though the exact target process is not recoverable statically.

Goroutine Concurrency

Two main.*.func1 closures are present: main.pyocwfeeou.func1 at 0x1400980a0 and main.jtpisrathivs.func1 at 0x140098c60. These are Go compiler-generated anonymous closures for goroutine or callback dispatch. This is the second Lumma sibling with multiple goroutine closures, building on the c25d9423 discovery. ^[r2: list_functions]

Decompiled Behavior

Notable Functions

Function Address Role
main.main 0x14009afa0 Entry point; initializes rand, dispatches payload. ^[r2:sym.main.main]
main.kghpjqunuhqoph 0x140098cc0 PRNG C2 URL builder (Float64/Intn loop, time.Now seed). ^[r2:sym.main.kghpjqunuhqoph]
main.klzqxryn 0x140096c40 Fused-string API slicer / decoder. ^[r2:sym.main.klzqxryn]
main.tmxulsechnosyax 0x140096e80 syscall.LoadLibrary wrapper; loads decoded DLL strings. ^[r2:sym.main.tmxulsechnosyax]
main.hbeauy 0x140097ae0 RWX VirtualAlloc caller (0x3000, 0x40). ^[r2:sym.main.hbeauy]
main.ongoeekepf 0x140097b40 Second RWX VirtualAlloc caller. ^[r2:sym.main.ongoeekepf]
main.sjakmasksdmnea 0x1400979a0 VirtualAlloc helper with RWX parameters. ^[r2:sym.main.sjakmasksdmnea]
main.jtpisrathivs 0x140098b80 Calls main.jtpisrathivs.func1 (goroutine closure). ^[r2:sym.main.jtpisrathivs]
main.pyocwfeeou 0x140097ec0 Calls main.pyocwfeeou.func1 (goroutine closure). ^[r2:sym.main.pyocwfeeou]
main.jtpisrathivs.func1 0x140098c60 Goroutine closure (anonymous func1). ^[r2:sym.main.jtpisrathivs.func1]
main.pyocwfeeou.func1 0x1400980a0 Goroutine closure (anonymous func1). ^[r2:sym.main.pyocwfeeou.func1]

Control Flow Patterns

  • Standard Go runtime prologue (runtime.morestack_noctxt.abi0) before each function body. ^[r2:sym.main.kghpjqunuhqoph]
  • Heavy use of math_rand._Rand_.Float64() + addsd / mulsd floating-point operations for C2 URL randomization. ^[r2:sym.main.kghpjqunuhqoph]
  • runtime.growslice calls indicating dynamic string/slice building during C2 resolution. ^[r2:sym.main.kghpjqunuhqoph]
  • No observed control-flow flattening or junk code — the obfuscation is purely in the randomized function names and the fused-string API decoder.

C2 Infrastructure

No static C2 URL recovered. The PRNG C2 decoder uses time.Now().UnixNano() as the seed, making C2 URLs deterministic only for a given launch time. The builder likely computes the C2 URL on the server side using the same seed. No IP addresses, domains, or hardcoded ports are present in the binary strings.

Interesting Tidbits

  • Identical .text template: The .text section hash matches eaa52e19 and 9ca2ebb8 exactly, suggesting the builder reuses a cached compiled object file or a pre-built template for the x64 architecture. The 17th and 16th siblings share the same compiled code, differing only in the randomized function names, module path, and data sections. ^[computed]
  • Placeholder certificate: The self-signed cert with CN=xxx.com and issuer E7 has null PE timestamps (1970-01-01) and a 3-month validity window. It is not a trusted CA certificate and serves only as a signing masquerade. ^[binwalk.txt:16-18] ^[pefile.txt]
  • 726 KB null overlay: The overlay after the security directory is 726,504 bytes of 100% null bytes (entropy 0.0). This is a builder padding artifact — the exact size varies per sibling (1.05 MB on eaa52e19, 726 KB here), but the 100% null composition is consistent. ^[computed]
  • Five-icon .rsrc suite: The resource section contains 5 PNG icons at standard Windows resolutions (16×16, 32×32, 64×64, 128×128, 256×256), all 8-bit RGBA. Total .rsrc size: ~84 KB. This is a cluster-wide builder option. ^[pefile.txt:365-485] ^[binwalk.txt:6-15]
  • No github.com paths: Unlike typical Go malware that imports github.com packages for browser credential theft, this binary has no github.com strings — it may use a custom / vendored infostealer library embedded in the randomized module path. ^[strings.txt search]
  • Module path not recovered: The Go build path is garbled/embedded in the .rdata string blob and not easily extractable; standard go version -m output is not present because -trimpath=true was used. ^[golang-stealer-build-pattern]

How To Mess With It (Homelab Replication)

Build a comparable Go binary

# Go 1.25.4 (matching observed version)
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o repro.exe .

Verification step

Run capa repro.exe (if signatures installed) and compare to the cluster's expected capability hits:

  • contain obfuscated stack strings (fused-string API decoder)
  • link function at runtime on Windows (LoadLibrary via syscall)
  • allocate or change RWX memory (VirtualAlloc 0x3000, 0x40)

What you'll learn

The Go compiler with -trimpath and -ldflags="-s -w" strips all source paths and debug info, producing a binary that looks like a Lumma sibling in terms of section layout and entropy. Adding randomized function names and a PRNG C2 decoder would require a small Go source transform.

Deployable Signatures

YARA Rule

rule LummaStealer_Go1254_x64_PlaceholderCert {
    meta:
        description = "Lumma Stealer Go 1.25.4 x64 with placeholder self-signed cert and five-icon .rsrc"
        author = "PacketPursuit"
        reference = "/intel/analyses/2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d.html"
        date = "2026-09-01"
        sha256 = "2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d"
    strings:
        $go1254 = "go1.25.4" ascii wide
        $cert_cn = "xxx.com" ascii wide
        $issuer_e7 = "E7" ascii wide
        $rwx1 = { 00 30 00 00 00 40 00 00 }  // VirtualAlloc params: 0x3000, 0x40
        $rwx2 = { B8 0D 00 00 00 40 00 00 }  // alt param encoding
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + 0x18) == 0x20B and  // PE32+
        $go1254 and
        $cert_cn and
        $issuer_e7 and
        any of ($rwx*) and
        filesize > 3MB
}

Behavioral Hunt Query (Splunk/EQL style)

(process_name="*.exe" AND go_version="1.25.4" AND 
 (mem_alloc_type="MEM_COMMIT|MEM_RESERVE" AND protection="PAGE_EXECUTE_READWRITE") AND
 (registry_write="HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" OR 
  network_https_connection))

IOC List

Indicator Type Value Confidence
SHA-256 hash 2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d high
File name filename SecuriteInfo.com.Win64.MalwareX-gen.82596579 high
Certificate CN cert xxx.com high (placeholder)
Certificate issuer cert E7 high (placeholder)
.text hash hash 13e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cb high (template match)
Overlay pattern pattern 726 KB null-padded overlay (100% zeros) medium
Go build build GOOS=windows, GOARCH=amd64, CGO_ENABLED=0, -trimpath=true high
RWX alloc behavior VirtualAlloc with 0x3000 + 0x40 high

Behavioral Fingerprint Statement

This binary is a PE32+ x86-64 Go 1.25.4 executable with a Windows GUI subsystem. On launch, it initializes the Go runtime and math_rand, seeds the PRNG with the current Unix timestamp, and enters a loop of Float64/Intn calls to decode a runtime C2 URL. It loads Windows APIs via syscall.LoadLibrary using fused DLL+API strings that are sliced at runtime. It allocates RWX memory with VirtualAlloc (MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE) and writes to the registry for persistence. No hardcoded C2 URL is present in the binary; the C2 is fully runtime-derived. Two goroutine closures (func1) are emitted by the compiler for concurrent payload operations. The binary is Authenticode-signed with a placeholder self-signed certificate (CN=xxx.com, issuer E7, 3-month validity) that has null PE timestamps. The .text section hash matches the known Lumma x64 template (13e54677...).

Detection Signatures

MITRE ATT&CK Mapping

Technique ID Evidence Source
Obfuscated Files or Information T1027.002 Randomized main.* function names; fused-string API decoder ^[r2: list_functions] ^[strings.txt:1671]
Application Layer Protocol T1071.001 net/http + crypto/tls for HTTPS C2 ^[strings.txt:1671]
Data from Local System T1005 Inferred browser/crypto credential collection (family pattern) ^[lummastealer]
Credentials from Web Browsers T1555.003 Inferred from family label and shared build pattern ^[lummastealer]
Process Injection T1055 VirtualAlloc RWX + OpenProcess + DuplicateHandle ^[r2:sym.main.hbeauy] ^[strings.txt:1686]
Registry Run Keys / Startup Folder T1547.001 RegSetValueExW present in fused strings ^[strings.txt:1680]
Code Signing T1553.002 Self-signed placeholder Authenticode certificate (CN=xxx.com) ^[pefile.txt] ^[binwalk.txt:16-18]
Masquerading T1036.001 Windows GUI subsystem, legitimate-looking icon suite ^[exiftool.json] ^[binwalk.txt:6-15]
System Information Discovery T1082 Inferred systeminfo collection (family pattern) ^[lummastealer]

References

Provenance

This report was generated from static analysis of the binary at <sample 2f04e1e48d9d.bin> using:

  • radare2 (analysis level 3, 2,124 functions identified, 30 main.* functions recovered)
  • pefile (PE header parsing, section enumeration, resource directory extraction)
  • binwalk (embedded PNG icons and PKCS7 certificate detection)
  • strings (8,323 strings recovered, Go version and runtime API strings)
  • exiftool (PE metadata extraction)
  • Python cryptography library (PKCS7 certificate parsing: CN=xxx.com, issuer E7, serial 0x058A17A1BA839735A8B356D22913964CBBDC, notBefore 2026-05-22, notAfter 2026-08-20)
  • CAPE sandbox: skipped (no Windows guest available)