2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784dlummastealer: 2f04e1e4 — 17th confirmed sibling, Go 1.25.4 x64, identical .text template to eaa52e19, placeholder cert + five-icon .rsrc + 726 KB null overlay + 2 goroutine closures
Executive Summary
PE32+ x86-64 Go binary compiled with Go 1.25.4. This is the 17th confirmed Lumma-native sibling in the cluster, sharing the identical .text section SHA-256 hash with eaa52e19 (16th sibling) and 9ca2ebb8 (also 16th), confirming use of the same x64 compiler template / build cache. Distinctive features: five-icon .rsrc suite (16×16 through 256×256 RGBA), placeholder self-signed certificate (CN=xxx.com, issuer E7), 726 KB null-padded overlay (100% zeros, entropy 0.0), 30 randomized main.* functions, and 2 goroutine .func1 closures (pyocwfeeou.func1 and jtpisrathivs.func1). Static-only analysis; CAPE skipped due to no Windows guest.
What It Is
| Field | Value | Source |
|---|---|---|
| SHA-256 | 2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d |
metadata.json |
| File name | SecuriteInfo.com.Win64.MalwareX-gen.82596579 |
metadata.json |
| Size | 3,361,408 bytes (3.2 MB) | exiftool.json |
| Type | PE32+ executable (GUI) x86-64, 9 sections | file.txt |
| Go version | 1.25.4 | strings.txt:1736 |
| Build ID | hyPfkpGedK99uJ_fBZi8/EwgSdwFrIa6kLSAwExPx/gGqyEXHxVvL4xtlpCa8b/nEZuxCYpRJk5_S0c9naC |
strings.txt:10 |
| Subsystem | Windows GUI | exiftool.json |
| PE timestamp | 1970-01-01 00:00:00 (null) | pefile.txt |
.text hash |
13e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cb |
computed |
| Overlay | 726 KB, 100% null bytes, entropy 0.0 | computed |
Family ascription: High-confidence lummastealer sibling. Decisive evidence:
- Placeholder certificate chain — CN=
xxx.com, issuerE7, 3-month validity, self-signed sha256WithRSA — matches thexxx.com/E7chain observed on siblingseaa52e19,c25d9423,ae3ee04f, and9ca2ebb8. ^[pefile.txt] ^[binwalk.txt:16-18] - Identical
.textsection hash — SHA-25613e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cbmatcheseaa52e19and9ca2ebb8, confirming the same x64 compiler template / build cache. ^[computed] - Five-icon
.rsrcsuite — 16×16, 32×32, 64×64, 128×128, and 256×256 RGBA PNG icons, matching the.rsrcpattern oneaa52e19,c25d9423,ae3ee04f, and9ca2ebb8. ^[pefile.txt:365-485] ^[binwalk.txt:6-15] - Go 1.25.4 + randomized
main.*function names — 30 randomizedmain.*functions, consistent with the Lumma-native x64 cluster pattern. ^[r2: list_functions] - Goroutine
.func1closures —main.pyocwfeeou.func1andmain.jtpisrathivs.func1, confirming goroutine-based concurrency primitives first observed inc25d9423. ^[r2: list_functions]
How It Works
Entry Point and Initialization
main.main at 0x14009afa0 initializes math_rand and runtime.newobject before dispatching to the primary payload functions. ^[r2:sym.main.main @ 0x14009afa0] The binary uses standard Go runtime.main entry with Windows GUI subsystem; no console window is allocated. ^[strings.txt:1736] ^[exiftool.json]
C2 URL Resolution
No hardcoded C2 URL is present in strings. C2 endpoints are resolved at runtime using a PRNG-seeded transform — a cluster-wide pattern observed in e03dd36f, 040e0d76, and all subsequent siblings. The decompiled main.kghpjqunuhqoph at 0x140098cc0 seeds math_rand with time.Now().UnixNano(), then calls math_rand._Rand_.Float64() and math_rand._Rand_.Intn() in a loop to build what appears to be a randomized C2 URL string. ^[r2:sym.main.kghpjqunuhqoph @ 0x140098cc0] This matches the prng-seeded-c2-url-decoding technique documented in the Lumma cluster. ^[lummastealer]
API Loading and String Decoding
main.tmxulsechnosyax at 0x140096e80 calls syscall.LoadLibrary with fused DLL+API strings, consistent with the fused-string-api-decoding technique. ^[r2:sym.main.tmxulsechnosyax @ 0x140096e80] The main.klzqxryn helper at 0x140096c40 appears to slice fused strings at runtime to reconstruct API names, defeating naive string extraction. ^[r2:sym.main.klzqxryn @ 0x140096c40]
Memory Staging
main.hbeauy at 0x140097ae0 and main.ongoeekepf at 0x140097b40 both call main.sjakmasksdmnea (at 0x1400979a0) with parameters 0x3000 (MEM_COMMIT | MEM_RESERVE) and 0x40 (PAGE_EXECUTE_READWRITE), allocating RWX memory for reflective payload staging. ^[r2:sym.main.hbeauy @ 0x140097ae0] ^[r2:sym.main.ongoeekepf @ 0x140097b40] This is the standard Lumma reflective-loader pattern.
Registry Manipulation
Registry strings RegSetValueExW and RegCloseKey are present in the fused string blobs, indicating the binary writes to the registry — likely for persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run or similar. ^[strings.txt:1671] ^[strings.txt:1680]
Process Manipulation
CreateProcessW, ExitProcess, OpenProcess, and DuplicateHandle are all present in the fused string API surface. ^[strings.txt:1686] ^[strings.txt:1671] The presence of OpenProcess + DuplicateHandle + VirtualAlloc + RWX suggests process injection or hollowed-process creation, though the exact target process is not recoverable statically.
Goroutine Concurrency
Two main.*.func1 closures are present: main.pyocwfeeou.func1 at 0x1400980a0 and main.jtpisrathivs.func1 at 0x140098c60. These are Go compiler-generated anonymous closures for goroutine or callback dispatch. This is the second Lumma sibling with multiple goroutine closures, building on the c25d9423 discovery. ^[r2: list_functions]
Decompiled Behavior
Notable Functions
| Function | Address | Role |
|---|---|---|
main.main |
0x14009afa0 |
Entry point; initializes rand, dispatches payload. ^[r2:sym.main.main] |
main.kghpjqunuhqoph |
0x140098cc0 |
PRNG C2 URL builder (Float64/Intn loop, time.Now seed). ^[r2:sym.main.kghpjqunuhqoph] |
main.klzqxryn |
0x140096c40 |
Fused-string API slicer / decoder. ^[r2:sym.main.klzqxryn] |
main.tmxulsechnosyax |
0x140096e80 |
syscall.LoadLibrary wrapper; loads decoded DLL strings. ^[r2:sym.main.tmxulsechnosyax] |
main.hbeauy |
0x140097ae0 |
RWX VirtualAlloc caller (0x3000, 0x40). ^[r2:sym.main.hbeauy] |
main.ongoeekepf |
0x140097b40 |
Second RWX VirtualAlloc caller. ^[r2:sym.main.ongoeekepf] |
main.sjakmasksdmnea |
0x1400979a0 |
VirtualAlloc helper with RWX parameters. ^[r2:sym.main.sjakmasksdmnea] |
main.jtpisrathivs |
0x140098b80 |
Calls main.jtpisrathivs.func1 (goroutine closure). ^[r2:sym.main.jtpisrathivs] |
main.pyocwfeeou |
0x140097ec0 |
Calls main.pyocwfeeou.func1 (goroutine closure). ^[r2:sym.main.pyocwfeeou] |
main.jtpisrathivs.func1 |
0x140098c60 |
Goroutine closure (anonymous func1). ^[r2:sym.main.jtpisrathivs.func1] |
main.pyocwfeeou.func1 |
0x1400980a0 |
Goroutine closure (anonymous func1). ^[r2:sym.main.pyocwfeeou.func1] |
Control Flow Patterns
- Standard Go runtime prologue (
runtime.morestack_noctxt.abi0) before each function body. ^[r2:sym.main.kghpjqunuhqoph] - Heavy use of
math_rand._Rand_.Float64()+addsd/mulsdfloating-point operations for C2 URL randomization. ^[r2:sym.main.kghpjqunuhqoph] runtime.growslicecalls indicating dynamic string/slice building during C2 resolution. ^[r2:sym.main.kghpjqunuhqoph]- No observed control-flow flattening or junk code — the obfuscation is purely in the randomized function names and the fused-string API decoder.
C2 Infrastructure
No static C2 URL recovered. The PRNG C2 decoder uses time.Now().UnixNano() as the seed, making C2 URLs deterministic only for a given launch time. The builder likely computes the C2 URL on the server side using the same seed. No IP addresses, domains, or hardcoded ports are present in the binary strings.
Interesting Tidbits
- Identical .text template: The
.textsection hash matcheseaa52e19and9ca2ebb8exactly, suggesting the builder reuses a cached compiled object file or a pre-built template for the x64 architecture. The 17th and 16th siblings share the same compiled code, differing only in the randomized function names, module path, and data sections. ^[computed] - Placeholder certificate: The self-signed cert with CN=
xxx.comand issuerE7has null PE timestamps (1970-01-01) and a 3-month validity window. It is not a trusted CA certificate and serves only as a signing masquerade. ^[binwalk.txt:16-18] ^[pefile.txt] - 726 KB null overlay: The overlay after the security directory is 726,504 bytes of 100% null bytes (entropy 0.0). This is a builder padding artifact — the exact size varies per sibling (1.05 MB on
eaa52e19, 726 KB here), but the 100% null composition is consistent. ^[computed] - Five-icon
.rsrcsuite: The resource section contains 5 PNG icons at standard Windows resolutions (16×16, 32×32, 64×64, 128×128, 256×256), all 8-bit RGBA. Total.rsrcsize: ~84 KB. This is a cluster-wide builder option. ^[pefile.txt:365-485] ^[binwalk.txt:6-15] - No
github.compaths: Unlike typical Go malware that importsgithub.compackages for browser credential theft, this binary has nogithub.comstrings — it may use a custom / vendored infostealer library embedded in the randomized module path. ^[strings.txt search] - Module path not recovered: The Go build path is garbled/embedded in the
.rdatastring blob and not easily extractable; standardgo version -moutput is not present because-trimpath=truewas used. ^[golang-stealer-build-pattern]
How To Mess With It (Homelab Replication)
Build a comparable Go binary
# Go 1.25.4 (matching observed version)
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o repro.exe .
Verification step
Run capa repro.exe (if signatures installed) and compare to the cluster's expected capability hits:
contain obfuscated stack strings(fused-string API decoder)link function at runtime on Windows(LoadLibrary via syscall)allocate or change RWX memory(VirtualAlloc 0x3000, 0x40)
What you'll learn
The Go compiler with -trimpath and -ldflags="-s -w" strips all source paths and debug info, producing a binary that looks like a Lumma sibling in terms of section layout and entropy. Adding randomized function names and a PRNG C2 decoder would require a small Go source transform.
Deployable Signatures
YARA Rule
rule LummaStealer_Go1254_x64_PlaceholderCert {
meta:
description = "Lumma Stealer Go 1.25.4 x64 with placeholder self-signed cert and five-icon .rsrc"
author = "PacketPursuit"
reference = "/intel/analyses/2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d.html"
date = "2026-09-01"
sha256 = "2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d"
strings:
$go1254 = "go1.25.4" ascii wide
$cert_cn = "xxx.com" ascii wide
$issuer_e7 = "E7" ascii wide
$rwx1 = { 00 30 00 00 00 40 00 00 } // VirtualAlloc params: 0x3000, 0x40
$rwx2 = { B8 0D 00 00 00 40 00 00 } // alt param encoding
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + 0x18) == 0x20B and // PE32+
$go1254 and
$cert_cn and
$issuer_e7 and
any of ($rwx*) and
filesize > 3MB
}
Behavioral Hunt Query (Splunk/EQL style)
(process_name="*.exe" AND go_version="1.25.4" AND
(mem_alloc_type="MEM_COMMIT|MEM_RESERVE" AND protection="PAGE_EXECUTE_READWRITE") AND
(registry_write="HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" OR
network_https_connection))
IOC List
| Indicator | Type | Value | Confidence |
|---|---|---|---|
| SHA-256 | hash | 2f04e1e48d9db645118b69c7d55dfe2b3a21a12f7ecd70bcb26840b73557784d |
high |
| File name | filename | SecuriteInfo.com.Win64.MalwareX-gen.82596579 |
high |
| Certificate CN | cert | xxx.com |
high (placeholder) |
| Certificate issuer | cert | E7 |
high (placeholder) |
| .text hash | hash | 13e5467745d583a2c842b7fceb25a3a4db03bdb10107df6c1d795a828eb7e1cb |
high (template match) |
| Overlay pattern | pattern | 726 KB null-padded overlay (100% zeros) | medium |
| Go build | build | GOOS=windows, GOARCH=amd64, CGO_ENABLED=0, -trimpath=true |
high |
| RWX alloc | behavior | VirtualAlloc with 0x3000 + 0x40 |
high |
Behavioral Fingerprint Statement
This binary is a PE32+ x86-64 Go 1.25.4 executable with a Windows GUI subsystem. On launch, it initializes the Go runtime and math_rand, seeds the PRNG with the current Unix timestamp, and enters a loop of Float64/Intn calls to decode a runtime C2 URL. It loads Windows APIs via syscall.LoadLibrary using fused DLL+API strings that are sliced at runtime. It allocates RWX memory with VirtualAlloc (MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE) and writes to the registry for persistence. No hardcoded C2 URL is present in the binary; the C2 is fully runtime-derived. Two goroutine closures (func1) are emitted by the compiler for concurrent payload operations. The binary is Authenticode-signed with a placeholder self-signed certificate (CN=xxx.com, issuer E7, 3-month validity) that has null PE timestamps. The .text section hash matches the known Lumma x64 template (13e54677...).
Detection Signatures
MITRE ATT&CK Mapping
| Technique | ID | Evidence | Source |
|---|---|---|---|
| Obfuscated Files or Information | T1027.002 | Randomized main.* function names; fused-string API decoder |
^[r2: list_functions] ^[strings.txt:1671] |
| Application Layer Protocol | T1071.001 | net/http + crypto/tls for HTTPS C2 |
^[strings.txt:1671] |
| Data from Local System | T1005 | Inferred browser/crypto credential collection (family pattern) | ^[lummastealer] |
| Credentials from Web Browsers | T1555.003 | Inferred from family label and shared build pattern | ^[lummastealer] |
| Process Injection | T1055 | VirtualAlloc RWX + OpenProcess + DuplicateHandle |
^[r2:sym.main.hbeauy] ^[strings.txt:1686] |
| Registry Run Keys / Startup Folder | T1547.001 | RegSetValueExW present in fused strings |
^[strings.txt:1680] |
| Code Signing | T1553.002 | Self-signed placeholder Authenticode certificate (CN=xxx.com) |
^[pefile.txt] ^[binwalk.txt:16-18] |
| Masquerading | T1036.001 | Windows GUI subsystem, legitimate-looking icon suite | ^[exiftool.json] ^[binwalk.txt:6-15] |
| System Information Discovery | T1082 | Inferred systeminfo collection (family pattern) | ^[lummastealer] |
References
- Artifact ID:
c6d607f2-11b3-4833-8c9b-cbc15dbcad35(OpenCTI / MalwareBazaar) - OpenCTI labels:
exe,malware-bazaar - Related wiki pages: lummastealer, golang-stealer-build-pattern, fused-string-api-decoding, prng-seeded-c2-url-decoding, go-goroutine-concurrency-in-main
Provenance
This report was generated from static analysis of the binary at <sample 2f04e1e48d9d.bin> using:
radare2(analysis level 3, 2,124 functions identified, 30main.*functions recovered)pefile(PE header parsing, section enumeration, resource directory extraction)binwalk(embedded PNG icons and PKCS7 certificate detection)strings(8,323 strings recovered, Go version and runtime API strings)exiftool(PE metadata extraction)- Python
cryptographylibrary (PKCS7 certificate parsing: CN=xxx.com, issuerE7, serial0x058A17A1BA839735A8B356D22913964CBBDC, notBefore2026-05-22, notAfter2026-08-20) - CAPE sandbox: skipped (no Windows guest available)