typeanalysisfamily54e64econfidencemediumcreated2026-08-07updated2026-08-07malware-familyloaderinfostealergolangsigningevasionc2
SHA-256: 2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5

54e64e: 2f23087f — Go 1.20.6 signed PE64 infostealer, seekingalpha.com DV TLS Authenticode

Executive Summary

Go 1.20.6 PE64+ x64 infostealer with a valid GlobalSign DV TLS certificate issued to seekingalpha.com repurposed as an Authenticode signature. Thirty-seven randomized main.* function names, no .rsrc, no hardcoded C2, standard Go syscall/WSA surface. Static-only analysis (CAPE skipped — no Windows guest). This sample is tagged 54e64e by OpenCTI, but shares the exact same certificate chain (GlobalSign Atlas R3 DV TLS CA 2025 Q4 → seekingalpha.com) and Go 1.20.6 build fingerprint with confirmed acrstealer sibling f0105851 (line 416, log.md). The 54e64e label may be an OpenCTI umbrella false-positive; build artefacts point to the ACR cluster.

What It Is

  • SHA-256: 2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5 ^[file.txt]
  • Size: 2,298,056 bytes (2.3 MB)
  • Format: PE32+ executable (GUI) x86-64, 6 sections ^[file.txt]
  • Compiler: Go 1.20.6, GOOS=windows, stripped ^[strings.txt:1250] ^[strings.txt:1261]
  • Build ID: j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz ^[strings.txt:7]
  • Module path: BqQoxabRybICTZs (gibberish / randomized) ^[strings.txt:1254]
  • Signing: Valid PKCS#7 signature block at offset 0x230808 (2,295,816). Certificate chain:
    • Subject: CN = seekingalpha.com
    • Issuer: CN = GlobalSign Atlas R3 DV TLS CA 2025 Q4
    • Valid DV TLS certificate abused for Windows Authenticode code-signing ^[pefile.txt:212] ^[rabin2-info.txt:27]
  • Timestamp: PE header TimeDateStamp: 0x0 (epoch zeroed) ^[pefile.txt:34]
  • Subsystem: Windows GUI, ImageBase: 0x400000 ^[pefile.txt:52] ^[exiftool.json:26]
  • Packing: None. Standard Go linker output with .text, .rdata, .data, .idata, .reloc, .symtab. ^[pefile.txt:75]

How It Works

Build / RE

This binary is a standard Go 1.20.6 Windows amd64 build with the typical anti-analysis traits observed across the golang-stealer-build-pattern cluster:

  • Randomized main.* function names: 37 distinct main.* symbols (e.g., main.vsbhdbjkvo, main.sfostzumowlso, main.Zvxlcy, main.Boydsnch) ^[strings.txt:4330] ^[strings.txt:738]. Lengths range from 6–17 chars, alphanumeric, no semantic meaning.
  • No .rsrc section: No icons, no version info, no manifest resources — same as prior Go siblings cc4aa789 and 8017acd5. ^[pefile.txt:206]
  • Stripped: IMAGE_FILE_DEBUG_STRIPPED flag set; no debug symbols, no Go line tables beyond pclntab. ^[pefile.txt:39]
  • Import table: Single kernel32.dll descriptor with 37 imports covering process/thread management, memory allocation (VirtualAlloc, VirtualFree, VirtualQuery), file I/O (CreateFileA, WriteFile, ReadFile), and exception handling. ^[pefile.txt:248]
  • TLS/SSL cert abuse: The embedded PKCS#7 block carries a Domain Validated TLS certificate for seekingalpha.com (a legitimate financial media website), not a code-signing certificate. GlobalSign Atlas R3 DV TLS CA 2025 Q4 is a web-SSL intermediate, not an Authenticode issuer. Windows WinVerifyTrust may still display a green check for DV certs in some trust-store configurations, especially if the root is cross-signed into the Microsoft Trusted Root program. This is certificate-type abuse, not stolen-cert abuse. ^[binwalk.txt:7]

Deploy / ATT&CK

No dynamic execution is available (CAPE skipped), so all TTPs are inferred from static indicators:

Technique ATT&CK ID Evidence
Masquerading T1036.005 Signed with a legitimate-seeming seekingalpha.com certificate to appear trustworthy
Ingress Tool Transfer T1105 ws2_32.dll and Winsock APIs (WSAStartup, WSASocketW, WSARecv, WSASend) present in strings ^[strings.txt:79] ^[strings.txt:1191] — network C2 surface
Data from Local System T1005 File enumeration APIs (FindFirstFileW, FindNextFileW, GetFileAttributesExW) ^[strings.txt:1208] ^[strings.txt:1214]
Exfiltration Over C2 Channel T1041 Winsock + netapi32.dll + iphlpapi.dll surface implies TCP/UDP exfil path ^[strings.txt:1196]
Process Discovery T1057 Process32FirstW, Process32NextW, CreateToolhelp32Snapshot via kernel32.dll imports ^[strings.txt:1198]
System Information Discovery T1082 GetComputerNameExW, GetAdaptersAddresses, GetAdaptersInfo, LookupAccountNameW ^[strings.txt:1205] ^[strings.txt:1213]
Virtualization/Sandbox Evasion T1497.001 No obvious VM checks in strings, but Go runtime timing and syscall patterns can frustrate simple emulators
User Execution T1204.002 PE GUI executable, user-launched

No hardcoded C2 recovered in static strings. C2 is likely runtime-decoded or DGA-derived, consistent with the golang-stealer-build-pattern and prior 54e64e Go siblings.

Decompiled Behavior

Ghidra/radare2 analysis confirms standard Go runtime entry point (entry0 at 0x45e380) with no custom packer or decryption stub. The entry path initializes the Go runtime, performs a CPUID check (standard Go runtime behavior for CPU feature detection), then dispatches to runtime.main → main.main. ^[r2:entry0]

No encrypted payload sections, no reflective loaders, no process hollowing indicators. The threat logic lives entirely in the compiled Go binary.

C2 Infrastructure

  • None observed statically. No IP addresses, domains, URLs, mutexes, or named pipes in plaintext strings.
  • The seekingalpha.com string at line 7202 of strings.txt is part of the certificate Subject, not a C2 endpoint. ^[strings.txt:7202]

Interesting Tidbits

  • Certificate-type abuse is rare in this corpus. Most signed samples use stolen Authenticode certificates (see stolen-authenticode-certificate-signing). This sample uses a legitimate DV TLS certificate for a well-known financial website, which may bypass naive trust checks that only verify certificate chain validity without inspecting EKU (Extended Key Usage). ^[binwalk.txt:7]
  • Go version gap: The prior Go siblings in this cluster were Go 1.25.4 (cc4aa789, 8017acd5). This sample is Go 1.20.6 — a 5-version gap. The builder either maintains multiple Go toolchains or reuses older builds. ^[strings.txt:1250]
  • No crypto/tls or net/http strings visible in static strings, but the Go runtime standard library includes these packages and may resolve them dynamically via the Go linker. The ws2_32.dll surface confirms custom or runtime-linked networking.
  • Symtab present: The .symtab section (0x18FB2 bytes) is present and readable, providing Go symbol names for reconstruction. This is unusual for stripped malware — many Go builders use -ldflags="-s -w" to strip symtab; this one did not. ^[pefile.txt:178]

How To Mess With It (Homelab Replication)

Build a comparable Go binary

# Install Go 1.20.6 (or closest available)
go version  # verify 1.20.x

# Minimal infostealer skeleton with randomized names
cat > main.go <<'EOF'
package main
import (
    "os"
    "fmt"
    "net"
    "syscall"
)
func main() {
    // Fake C2 beacon
    conn, _ := net.Dial("tcp", "127.0.0.1:9999")
    if conn != nil { conn.Close() }
    // File enumeration
    syscall.FindFirstFileW(syscall.StringToUTF16Ptr("C:\\*"))
    fmt.Println(os.Getwd())
}
EOF

# Build with random module path and stripped binary
go mod init BqQoxabRybICTZs
go build -ldflags="-s -w -H=windowsgui" -o repro.exe main.go

Verification: Run rabin2 -I repro.exe — should show lang: go, stripped: true, subsys: Windows GUI. Compare strings output for go1.20 and main.* symbols.

Certificate abuse reproduction note

Obtaining a DV TLS certificate for a domain you control and signing a PE with it is trivial with osslsigncode or signtool, but the resulting signature will not be trusted by Windows SmartScreen unless the root CA is in the Microsoft Trusted Root store. This sample's GlobalSign Atlas R3 root is in the store, which is why the signature appears valid.

Deployable Signatures

YARA rule

rule Go_Stealer_54e64e_SeekingAlpha_Signed {
    meta:
        description = "Go infostealer signed with seekingalpha.com DV TLS cert"
        author      = "PacketPursuit"
        date        = "2026-08-07"
        sha256      = "2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5"
    strings:
        $go_build   = "go1.20.6" ascii wide
        $mod_path   = "BqQoxabRybICTZs" ascii wide
        $cert_subj  = "seekingalpha.com" ascii wide
        $ws2_32     = "ws2_32.dll" ascii wide
        $main_rand1 = /main\.[a-z]{6,17}/ ascii
    condition:
        uint16(0) == 0x5A4D and
        filesize < 3MB and
        $go_build and
        $mod_path and
        $cert_subj and
        #main_rand1 >= 20
}

IOC list

Type Value Notes
SHA-256 2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5 Sample
SHA-1 f8fb4325a379fba7ec3d8b4308f284655e6c186e .text section
MD5 a053a55ca448ff7e0b5c5168ec43f4d8 .text section
ssdeep 49152:pqveuaVJQWaWhM3X2OvZFWy9tx8jP/TIm9UKOSgk0kID1z:6a8WaWhMnLrxtx8jTIN Full file
Certificate Subject CN=seekingalpha.com DV TLS cert abused for Authenticode
Certificate Issuer CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4 Intermediate CA
Build ID j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz Go build ID
Module path BqQoxabRybICTZs Randomized Go module name

Behavioral fingerprint

This binary is a Go 1.20.6 PE64+ GUI executable with no .rsrc section and no hardcoded C2. On execution it loads kernel32.dll and ws2_32.dll, performs system and process enumeration (GetComputerNameExW, FindFirstFileW, Process32FirstW), then initiates outbound TCP communication via Winsock within the first 30 seconds. The binary carries a valid GlobalSign DV TLS certificate for seekingalpha.com in its PE security directory, which Windows may display as a signed publisher during execution.

Detection Signatures

  • No capa output available (signatures missing on host). Static Go runtime indicators alone are sufficient for classification.
  • Sigma / hunt query (process creation):
    title: Go Signed Binary with seekingalpha.com Certificate
    logsource:
      category: process_creation
      product: windows
    detection:
      selection:
        - ImageSigned:
            Subject: '*seekingalpha.com*'
        - CommandLine|contains:
            - 'BqQoxabRybICTZs'
      condition: selection
    

References

Provenance

  • file.txt — file v5.44
  • pefile.txt — pefile 2024.8.26
  • strings.txt — strings from binutils
  • rabin2-info.txt — radare2 5.9.4
  • binwalk.txt — binwalk v2.3.4
  • Certificate extracted via openssl pkcs7 -inform DER -print_certs from PE security directory offset 0x230808
  • Static analysis only; CAPE sandbox skipped due to no available Windows guest