2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b554e64e: 2f23087f — Go 1.20.6 signed PE64 infostealer, seekingalpha.com DV TLS Authenticode
Executive Summary
Go 1.20.6 PE64+ x64 infostealer with a valid GlobalSign DV TLS certificate issued to seekingalpha.com repurposed as an Authenticode signature. Thirty-seven randomized main.* function names, no .rsrc, no hardcoded C2, standard Go syscall/WSA surface. Static-only analysis (CAPE skipped — no Windows guest). This sample is tagged 54e64e by OpenCTI, but shares the exact same certificate chain (GlobalSign Atlas R3 DV TLS CA 2025 Q4 → seekingalpha.com) and Go 1.20.6 build fingerprint with confirmed acrstealer sibling f0105851 (line 416, log.md). The 54e64e label may be an OpenCTI umbrella false-positive; build artefacts point to the ACR cluster.
What It Is
- SHA-256:
2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5^[file.txt] - Size: 2,298,056 bytes (2.3 MB)
- Format: PE32+ executable (GUI) x86-64, 6 sections ^[file.txt]
- Compiler: Go 1.20.6,
GOOS=windows, stripped ^[strings.txt:1250] ^[strings.txt:1261] - Build ID:
j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz^[strings.txt:7] - Module path:
BqQoxabRybICTZs(gibberish / randomized) ^[strings.txt:1254] - Signing: Valid PKCS#7 signature block at offset
0x230808(2,295,816). Certificate chain:- Subject:
CN = seekingalpha.com - Issuer:
CN = GlobalSign Atlas R3 DV TLS CA 2025 Q4 - Valid DV TLS certificate abused for Windows Authenticode code-signing ^[pefile.txt:212] ^[rabin2-info.txt:27]
- Subject:
- Timestamp: PE header
TimeDateStamp: 0x0(epoch zeroed) ^[pefile.txt:34] - Subsystem: Windows GUI,
ImageBase: 0x400000^[pefile.txt:52] ^[exiftool.json:26] - Packing: None. Standard Go linker output with
.text,.rdata,.data,.idata,.reloc,.symtab. ^[pefile.txt:75]
How It Works
Build / RE
This binary is a standard Go 1.20.6 Windows amd64 build with the typical anti-analysis traits observed across the golang-stealer-build-pattern cluster:
- Randomized
main.*function names: 37 distinctmain.*symbols (e.g.,main.vsbhdbjkvo,main.sfostzumowlso,main.Zvxlcy,main.Boydsnch) ^[strings.txt:4330] ^[strings.txt:738]. Lengths range from 6–17 chars, alphanumeric, no semantic meaning. - No
.rsrcsection: No icons, no version info, no manifest resources — same as prior Go siblingscc4aa789and8017acd5. ^[pefile.txt:206] - Stripped:
IMAGE_FILE_DEBUG_STRIPPEDflag set; no debug symbols, no Go line tables beyond pclntab. ^[pefile.txt:39] - Import table: Single
kernel32.dlldescriptor with 37 imports covering process/thread management, memory allocation (VirtualAlloc,VirtualFree,VirtualQuery), file I/O (CreateFileA,WriteFile,ReadFile), and exception handling. ^[pefile.txt:248] - TLS/SSL cert abuse: The embedded PKCS#7 block carries a Domain Validated TLS certificate for
seekingalpha.com(a legitimate financial media website), not a code-signing certificate. GlobalSign Atlas R3 DV TLS CA 2025 Q4 is a web-SSL intermediate, not an Authenticode issuer. WindowsWinVerifyTrustmay still display a green check for DV certs in some trust-store configurations, especially if the root is cross-signed into the Microsoft Trusted Root program. This is certificate-type abuse, not stolen-cert abuse. ^[binwalk.txt:7]
Deploy / ATT&CK
No dynamic execution is available (CAPE skipped), so all TTPs are inferred from static indicators:
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Masquerading | T1036.005 | Signed with a legitimate-seeming seekingalpha.com certificate to appear trustworthy |
| Ingress Tool Transfer | T1105 | ws2_32.dll and Winsock APIs (WSAStartup, WSASocketW, WSARecv, WSASend) present in strings ^[strings.txt:79] ^[strings.txt:1191] — network C2 surface |
| Data from Local System | T1005 | File enumeration APIs (FindFirstFileW, FindNextFileW, GetFileAttributesExW) ^[strings.txt:1208] ^[strings.txt:1214] |
| Exfiltration Over C2 Channel | T1041 | Winsock + netapi32.dll + iphlpapi.dll surface implies TCP/UDP exfil path ^[strings.txt:1196] |
| Process Discovery | T1057 | Process32FirstW, Process32NextW, CreateToolhelp32Snapshot via kernel32.dll imports ^[strings.txt:1198] |
| System Information Discovery | T1082 | GetComputerNameExW, GetAdaptersAddresses, GetAdaptersInfo, LookupAccountNameW ^[strings.txt:1205] ^[strings.txt:1213] |
| Virtualization/Sandbox Evasion | T1497.001 | No obvious VM checks in strings, but Go runtime timing and syscall patterns can frustrate simple emulators |
| User Execution | T1204.002 | PE GUI executable, user-launched |
No hardcoded C2 recovered in static strings. C2 is likely runtime-decoded or DGA-derived, consistent with the golang-stealer-build-pattern and prior 54e64e Go siblings.
Decompiled Behavior
Ghidra/radare2 analysis confirms standard Go runtime entry point (entry0 at 0x45e380) with no custom packer or decryption stub. The entry path initializes the Go runtime, performs a CPUID check (standard Go runtime behavior for CPU feature detection), then dispatches to runtime.main → main.main. ^[r2:entry0]
No encrypted payload sections, no reflective loaders, no process hollowing indicators. The threat logic lives entirely in the compiled Go binary.
C2 Infrastructure
- None observed statically. No IP addresses, domains, URLs, mutexes, or named pipes in plaintext strings.
- The
seekingalpha.comstring at line 7202 of strings.txt is part of the certificate Subject, not a C2 endpoint. ^[strings.txt:7202]
Interesting Tidbits
- Certificate-type abuse is rare in this corpus. Most signed samples use stolen Authenticode certificates (see stolen-authenticode-certificate-signing). This sample uses a legitimate DV TLS certificate for a well-known financial website, which may bypass naive trust checks that only verify certificate chain validity without inspecting EKU (Extended Key Usage). ^[binwalk.txt:7]
- Go version gap: The prior Go siblings in this cluster were Go 1.25.4 (
cc4aa789,8017acd5). This sample is Go 1.20.6 — a 5-version gap. The builder either maintains multiple Go toolchains or reuses older builds. ^[strings.txt:1250] - No
crypto/tlsornet/httpstrings visible in static strings, but the Go runtime standard library includes these packages and may resolve them dynamically via the Go linker. Thews2_32.dllsurface confirms custom or runtime-linked networking. - Symtab present: The
.symtabsection (0x18FB2 bytes) is present and readable, providing Go symbol names for reconstruction. This is unusual for stripped malware — many Go builders use-ldflags="-s -w"to strip symtab; this one did not. ^[pefile.txt:178]
How To Mess With It (Homelab Replication)
Build a comparable Go binary
# Install Go 1.20.6 (or closest available)
go version # verify 1.20.x
# Minimal infostealer skeleton with randomized names
cat > main.go <<'EOF'
package main
import (
"os"
"fmt"
"net"
"syscall"
)
func main() {
// Fake C2 beacon
conn, _ := net.Dial("tcp", "127.0.0.1:9999")
if conn != nil { conn.Close() }
// File enumeration
syscall.FindFirstFileW(syscall.StringToUTF16Ptr("C:\\*"))
fmt.Println(os.Getwd())
}
EOF
# Build with random module path and stripped binary
go mod init BqQoxabRybICTZs
go build -ldflags="-s -w -H=windowsgui" -o repro.exe main.go
Verification: Run rabin2 -I repro.exe — should show lang: go, stripped: true, subsys: Windows GUI. Compare strings output for go1.20 and main.* symbols.
Certificate abuse reproduction note
Obtaining a DV TLS certificate for a domain you control and signing a PE with it is trivial with osslsigncode or signtool, but the resulting signature will not be trusted by Windows SmartScreen unless the root CA is in the Microsoft Trusted Root store. This sample's GlobalSign Atlas R3 root is in the store, which is why the signature appears valid.
Deployable Signatures
YARA rule
rule Go_Stealer_54e64e_SeekingAlpha_Signed {
meta:
description = "Go infostealer signed with seekingalpha.com DV TLS cert"
author = "PacketPursuit"
date = "2026-08-07"
sha256 = "2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5"
strings:
$go_build = "go1.20.6" ascii wide
$mod_path = "BqQoxabRybICTZs" ascii wide
$cert_subj = "seekingalpha.com" ascii wide
$ws2_32 = "ws2_32.dll" ascii wide
$main_rand1 = /main\.[a-z]{6,17}/ ascii
condition:
uint16(0) == 0x5A4D and
filesize < 3MB and
$go_build and
$mod_path and
$cert_subj and
#main_rand1 >= 20
}
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 2f23087fd9b9804115c782d2d0f88046d370162b5b982299ae0a518ade9664b5 |
Sample |
| SHA-1 | f8fb4325a379fba7ec3d8b4308f284655e6c186e |
.text section |
| MD5 | a053a55ca448ff7e0b5c5168ec43f4d8 |
.text section |
| ssdeep | 49152:pqveuaVJQWaWhM3X2OvZFWy9tx8jP/TIm9UKOSgk0kID1z:6a8WaWhMnLrxtx8jTIN |
Full file |
| Certificate Subject | CN=seekingalpha.com |
DV TLS cert abused for Authenticode |
| Certificate Issuer | CN=GlobalSign Atlas R3 DV TLS CA 2025 Q4 |
Intermediate CA |
| Build ID | j4TU-TUCinBSRq731KfD/46rs2fE3K03_WH702efI/rExPYpfWfYGdZACfJ5CC/iGgE5wPJV-mL0oAGkjmz |
Go build ID |
| Module path | BqQoxabRybICTZs |
Randomized Go module name |
Behavioral fingerprint
This binary is a Go 1.20.6 PE64+ GUI executable with no .rsrc section and no hardcoded C2. On execution it loads kernel32.dll and ws2_32.dll, performs system and process enumeration (GetComputerNameExW, FindFirstFileW, Process32FirstW), then initiates outbound TCP communication via Winsock within the first 30 seconds. The binary carries a valid GlobalSign DV TLS certificate for seekingalpha.com in its PE security directory, which Windows may display as a signed publisher during execution.
Detection Signatures
- No capa output available (signatures missing on host). Static Go runtime indicators alone are sufficient for classification.
- Sigma / hunt query (process creation):
title: Go Signed Binary with seekingalpha.com Certificate logsource: category: process_creation product: windows detection: selection: - ImageSigned: Subject: '*seekingalpha.com*' - CommandLine|contains: - 'BqQoxabRybICTZs' condition: selection
References
- 54e64e — Family entity page (OpenCTI opaque label)
- golang-stealer-build-pattern — Shared build artefacts across Go infostealer families
- stolen-authenticode-certificate-signing — Related technique (stolen certs vs. TLS cert abuse)
- OpenCTI artifact:
5e8260b2-888c-403a-9730-e7e4ca76d207
Provenance
file.txt—filev5.44pefile.txt—pefile2024.8.26strings.txt—stringsfrom binutilsrabin2-info.txt— radare2 5.9.4binwalk.txt— binwalk v2.3.4- Certificate extracted via
openssl pkcs7 -inform DER -print_certsfrom PE security directory offset0x230808 - Static analysis only; CAPE sandbox skipped due to no available Windows guest