typedeep-analysisfamilyunclassified-go-pe64confidencelowcreated2026-08-19
SHA-256: 31f5df22bbc18d0068ae3ca520e06a7826695718f5a3796dd1df450dfdf5f2e2

31f5df22 — Go PE64+ loader with OT-software filename masquerade

1. Build / RE

Toolchain: Go 1.25.4 (gc), CGO_ENABLED=0, GOARCH=amd64, GOOS=windows ^[strings.txt:1714]. Null PE timestamp (TimeDateStamp: 0x0) ^[pefile.txt:34]. Subsystem WINDOWS_GUI (0x2) ^[pefile.txt:65].

Obfuscation / anti-analysis:

  • 92 randomized main.* function names (e.g. main.hvkxnhsya, main.rnsmxgsxwdq, main.tdazpkajyhdph, main.xkxhgzjkneub) ^[strings.txt]. This matches the go-function-name-randomization technique observed across the unclassified-go-pe64 cluster.
  • No external module paths in strings; only standard-library Go paths (net/http, crypto/tls, crypto/rsa, html/template) appear inside runtime panic/format strings ^[strings.txt:1644-1645]. Suggests -trimpath or minimal module naming.
  • IAT restricted to kernel32.dll (43 imports) ^[pefile.txt:308-363] — networking and cryptography resolved at runtime via statically-linked Go stdlib, a hallmark of the golang-stealer-build-pattern.

PE structure:

  • Nine sections: .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab, .rsrc ^[pefile.txt:75-255].
  • .rsrc contains a six-icon PNG suite (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt:6-17]. Typical Explorer social-engineering adornment.
  • Authenticode security directory entry present (VirtualAddress: 0x44B600, Size: 0x880) ^[pefile.txt:271-274], but the address lies past EOF (file size 0x24B800). No embedded certificate exists; entry is either a linker artifact or stripped post-build.

Code quality / notable functions:

  • main.tdazpkajyhdph (0x140097720) implements a PE parser: checks MZ (0x5A4D) and PE\0\0 (0x4550) signatures, reads e_lfanew, parses IMAGE_FILE_HEADER fields (Machine, NumberOfSections, SizeOfOptionalHeader, Characteristics), and copies section table entries into a Go slice ^[r2:sym.main.tdazpkajyhdph].
  • main.nyhfxyrvf (0x1400988A0) wraps bufio.Scanner.Scan, suggesting line- or token-oriented parsing of an embedded config or second-stage payload ^[r2:sym.main.nyhfxyrvf].
  • main.main (0x14009AD60) seeds math/rand with hardcoded constants (0xdd7b17f80, 0xa1b203eb3d1a0000), performs float-scaling operations, then dispatches to obfuscated subroutines ^[r2:sym.main.main]. The RNG scaffolding is consistent with runtime decision-making or key generation seen in sibling samples.

2. Deploy / ATT&CK

Static-only inference — CAPE skipped due to no Windows guest ^[dynamic-analysis.md].

Initial Access / Execution:

  • T1204.002 — Malicious Link: filename cx-programmer 9.1 free download full.exe masquerades as OMRON CX-Programmer, a widely used PLC engineering suite. This is an OT-software lure distinct from the usual business-document filenames ^[triage.json].
  • T1036.005 — Masquerading: the icon suite and filename together impersonate legitimate industrial software.

Defense Evasion:

  • T1027.002 — Obfuscated Files or Information: randomized main.* function names and null PE timestamp strip developer identity and hinder static clustering.
  • T1027.009 — Embedded Payloads: the PE parser (main.tdazpkajyhdph) and scanner (main.nyhfxyrvf) suggest an embedded resource or appended payload is parsed at runtime. No cleartext payload marker found in strings.

Command and Control (inferred):

  • T1071.001 — Application Layer Protocol: Web — standard-library net/http present ^[strings.txt:1644].
  • T1573.002 — Encrypted Channel: crypto/tls and crypto/rsa present in stdlib strings ^[strings.txt:1644]. No pinned certificate or C2 URL recovered statically; C2 likely runtime-resolved or decoded via the RNG-seeded routine.

Persistence / Impact:

  • No static evidence of registry persistence, scheduled tasks, or service installation. The binary may be a single-stage dropper that unpacks and executes a second payload in memory.

3. Attribution / Family Linkage

  • OpenCTI label de-pumped / depumped is an umbrella tag with no independent technical fingerprint ^[entities/depumped.md]. The actual technical family is unclassified-go-pe64 Cluster A (randomized-function-name builds).
  • Build artefacts match the golang-stealer-build-pattern: Go 1.25.4, CGO disabled, randomized main.* names, kernel32-only IAT, .rsrc icon suite, null timestamp.
  • The OT-software lure (cx-programmer) is a new targeting vector not observed in prior siblings, which used generic business-document or software-installer filenames.

Capabilities Summary

  • go-pe-parser-runtime
  • math-rand-seeded-runtime-decision
  • bufio-scanner-config-parse
  • ot-software-filename-masquerade
  • icon-suite-social-engineering
  • kernel32-only-iat
  • golang-stdlib-networking-tls
  • null-pe-timestamp