350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802acrstealer: 350a2b69 — Go 1.18.5 PE32 sibling, self-signed atom.hutsell.com/WR3 cert, .rsrc icon masquerade, no static C2
Executive Summary
Fourteenth confirmed sibling in the acrstealer Go infostealer cluster. PE32 compiled with Go 1.18.5 (GOARCH=386, CGO_ENABLED=0), randomized module path YUJFqOiYcDAmDOn, self-signed Authenticode certificate CN=atom.hutsell.com / issuer WR3 (shared with four prior siblings), .rsrc section containing four PNG icons for social-engineering masquerade. No hardcoded C2 strings recovered statically — relies on PRNG-seeded runtime decoding per established family pattern. Static-only analysis (CAPE skipped — no Windows guest). This sample restores the .rsrc icon suite that sibling 6cbac6bc stripped, confirming the builder supports an icon-toggle configuration.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802 |
| Size | 7.43 MB (7,430,272 bytes) ^[file.txt] |
| File type | PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt] |
| Compiler | Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, GO386=sse2) ^[strings.txt:1067] ^[strings.txt:1072] |
| Module path | YUJFqOiYcDAmDOn ^[strings.txt:1069] |
| PE timestamp | 0x0 (null / stripped) ^[pefile.txt:38] |
| Entropy | .text 6.19, .rdata 7.28, .rsrc 5.14 ^[pefile.txt:96] ^[pefile.txt:116] ^[pefile.txt:216] |
| Signing | Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, validity 2026-04-21 → 2026-07-20 ^[pefile.txt:237] ^[strings.txt:7734] |
| .rsrc | 4 icons: 16×16, 32×32, 48×48, 256×256 PNG ^[binwalk.txt:7] ^[pefile.txt:203] |
| capa | Failed (missing signatures) ^[capa.txt] |
| Dynamic | CAPE skipped — no Windows guest available ^[dynamic-analysis.md:1] |
Family attribution is high confidence: matches the golang-stealer-build-pattern (Go 1.18.5, randomized module path, randomized main.* function names, self-signed cert, null PE timestamp, .rsrc icon suite) and shares the atom.hutsell.com / WR3 certificate chain with four confirmed siblings: ef262340, 44f594e2, 6cbac6bc, and 828405d6.
How It Works
This is a light Go 1.18.5 variant — it does not exhibit the custom in-memory PE parser or multi-pass byte-transform decoder observed in siblings d5655568, 7620884e, and d353d849. Instead, it follows the simpler template of ef262340 and 44f594e2: standard Go static binary with runtime-randomized C2 decoding.
Build pipeline observations:
trimpath=true(no absolute source paths in pclntab) ^[strings.txt:1069]- Randomized
mainpackage function names (main.rwwmlminnoxqyxx,main.rzhcmqvp,main.lnrpmbak,main.zeignmwuwz,main.tblhsvlsfzcnpfg,main.zmsbkokvlr,main.Hqhicbqf,main.Raokbytrao,main.yizhfmfesbpyi,main.wdmbvkdqtjthc,main.mdnaml,main.wlwaxkgkuuhvddy,main.wkikuckduvtmo,main.rosvcnbk,main.muzdmrbsm) ^[strings.txt:4177] ^[strings.txt:4191] — 15+ randomized names, hindering symbol-based clustering. - No
crypto/tlsorcrypto/x509package strings visible in static extraction, but the family pattern implies TLS-wrapped HTTP C2 (see sibling6871848bwhich contacts5.252.155.72andlaserlogdnsop.icu).
C2 decoding: No static C2 strings. The math/rand package is linked ^[strings.txt:379], consistent with the family-wide PRNG-seeded runtime C2 decoding documented at prng-seeded-c2-url-decoding.
Resource masquerade: The .rsrc section contains a 256×256 PNG icon (likely a fake application icon) alongside standard 16×16, 32×32, and 48×48 variants ^[binwalk.txt:7]. This is identical in structure to siblings ef262340, 44f594e2, and 828405d6, and contrasts with 6cbac6bc which stripped .rsrc entirely. Builder supports icon toggle.
Decompiled Behavior
No Ghidra decompilation was attempted — the binary is a Go 1.18.5 static PE with ~534 KB .text and ~1.3 MB .rdata (high entropy 7.28), making automated decompilation of the randomized main functions low-yield without dynamic tracing. Radare2 analysis confirms:
- Entry point at
0x00457c30^[rabin2-info.txt:11] ^[r2:entry0] - Import table limited to
kernel32.dll(standard Go runtime imports: VirtualAlloc, CreateFile, LoadLibrary, GetProcAddress, etc.) ^[pefile.txt:275] - No COM descriptor (not .NET) ^[pefile.txt:267]
- No TLS callbacks ^[pefile.txt:252]
- No delay imports ^[pefile.txt:264]
- Overlay present (Authenticode certificate at file offset
0x715800) ^[rabin2-info.txt:23] ^[pefile.txt:237]
The main.wijtudpep function (line 4217 in strings.txt) appears to be the entry-point goroutine dispatch wrapper, but without dynamic execution its callees cannot be resolved statically.
C2 Infrastructure
Static C2: None recovered. The certificate CN atom.hutsell.com is the self-signer domain, not a C2 endpoint.
Inferred C2: Based on sibling analyses and family TTPs:
- Direct IP and domain over TLS/HTTP (implied by
crypto/tlslinkage in other siblings) - PRNG-seeded runtime decoding of C2 strings at launch ^[prng-seeded-c2-url-decoding]
- No hardcoded ports, mutex names, or named pipes observed statically
Interesting Tidbits
- Certificate recycling: The
atom.hutsell.com/WR3self-signed certificate is reused across at least five siblings spanning PE32 and PE32+ (x64) builds (ef262340,44f594e2,6cbac6bc,828405d6, and this sample). Validity window 2026-04-21 → 2026-07-20. This is a builder-level artefact, not per-sample generation. ^[strings.txt:7732] ^[strings.txt:7734] - Builder icon toggle: Sibling
6cbac6bc(eleventh) stripped.rsrc; this sample (fourteenth) and828405d6(thirteenth) restore it. The builder clearly supports both modes. - Null PE timestamp: Like all siblings, the PE
TimeDateStampis0x0— a Go linker default when-trimpathis used, not anti-forensics. ^[pefile.txt:38] - Floss failure: The flare-floss run failed with an argument-parsing error ^[floss.txt:6], likely due to CLI invocation issues in the triage pipeline. This is a pipeline artefact, not a binary property.
- Capa failure: Mandiant capa aborted due to missing signatures directory ^[capa.txt:1]. Also a pipeline issue.
- Large
.rdata: At 1.3 MB with entropy 7.28,.rdatais larger than typical Go 1.18.5 binaries. This may contain encrypted string tables or embedded payload data, but no readable headers were recovered.
How To Mess With It (Homelab Replication)
To reproduce a comparable Go static binary fingerprint:
Toolchain:
- Go 1.18.5 for Windows/386
CGO_ENABLED=0 GOOS=windows GOARCH=386 go build -trimpath -ldflags="-s -w"
Compiler/linker flags:
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o sample.exe
Verification step:
Run rabin2 -I sample.exe and confirm:
lang: cstripped: truesigned: false(unless you add a self-signed cert)subsys: Windows GUIcompiled: Thu Jan 1 00:00:00 1970
Compare .rdata entropy to this sample (~7.28). Populate .rdata with high-entropy dummy data (e.g., encrypted strings, random padding) to match.
What you'll learn: How Go static binaries appear in PE analysis tools and why randomized module paths defeat naive string-clustering.
Deployable Signatures
YARA rule
rule ACRStealer_Go1185_AtomHutsell : infostealer
{
meta:
description = "ACR Stealer Go 1.18.5 PE32 variant with self-signed atom.hutsell.com certificate"
author = "PacketPursuit"
date = "2026-08-01"
sha256 = "350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802"
family = "acrstealer"
strings:
$go_build = "go1.18.5" ascii wide
$go_buildinf = "Go buildinf:" ascii wide
$go_cgo = "CGO_ENABLED=0" ascii wide
$go_arch = "GOARCH=386" ascii wide
$go_os = "GOOS=windows" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$mod_path = "path\t" ascii wide
$mod_devel = "(devel)" ascii wide
$main_rand = /main\.[a-z]{10,20}/ ascii wide
condition:
uint16(0) == 0x5A4D and
($go_build and $go_buildinf) and
($go_cgo and $go_arch and $go_os) and
($cert_cn and $cert_issuer) and
($mod_path or $mod_devel) and
#main_rand >= 5
}
Behavioral hunt query (KQL / Microsoft Sentinel)
let acrstealer_certs = dynamic(["atom.hutsell.com"]);
DeviceFileCertificateInfo
| where Signer in (acrstealer_certs) or Issuer in (acrstealer_certs)
| where FileName endswith ".exe"
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Count=count() by DeviceName, FileName, SHA256, Signer, Issuer
IOC list
| Type | Value | Note |
|---|---|---|
| SHA-256 | 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802 |
This sample |
| SHA-256 | ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 |
Tenth sibling (same cert) |
| SHA-256 | 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd |
Twelfth sibling (same cert) |
| SHA-256 | 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e |
Eleventh sibling (same cert, stripped .rsrc) |
| SHA-256 | 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a |
Thirteenth sibling (same cert, PE32+ x64) |
| Certificate CN | atom.hutsell.com |
Self-signer across 5+ siblings |
| Certificate Issuer | WR3 |
Self-signed issuer |
| Go module path | YUJFqOiYcDAmDOn |
This sample only |
| File size | ~7.4 MB | Consistent with Go 1.18.5 static + icons |
Behavioral fingerprint statement
This binary is a Go 1.18.5-compiled PE32 GUI executable with a null PE timestamp, stripped symbol table, and self-signed Authenticode certificate (CN atom.hutsell.com, issuer WR3). It imports only kernel32.dll APIs via the standard Go runtime IAT and contains a .rsrc section with four PNG icons (16×16 through 256×256). No hardcoded C2 strings are present; C2 infrastructure is decoded at runtime using a PRNG-seeded transform. The main package contains 15+ randomized alphanumeric function names (e.g., main.rwwmlminnoxqyxx, main.zeignmwuwz) that defeat static clustering. On execution, it is expected to contact an attacker-controlled HTTPS endpoint via crypto/tls and exfiltrate browser credentials, cryptocurrency wallet data, and system fingerprints per the ACR Stealer family TTPs.
Detection Signatures
No capa output available (signatures directory missing during triage). Based on static indicators, the following ATT&CK techniques are mappable:
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Infostealer family targeting local credential stores |
| Input Capture: Clipboard Data | T1115 | Family TTP (crypto clipper component in siblings) |
| Credentials from Password Stores | T1555 | Browser credential theft (family TTP) |
| Exfiltration Over C2 Channel | T1041 | TLS/HTTPS C2 (family TTP) |
| Obfuscated Files or Information | T1027 | Randomized module paths and function names ^[strings.txt:1069] ^[strings.txt:4177] |
| Application Layer Protocol: Web Protocols | T1071.001 | HTTPS C2 (family TTP) |
| Dynamic Resolution | T1568 | PRNG-seeded runtime C2 decoding ^[prng-seeded-c2-url-decoding] |
| Masquerading | T1036 | .rsrc PNG icon suite for social engineering ^[binwalk.txt:7] |
| Signed Binary Proxy Execution | T1218 | Self-signed cert to appear legitimate ^[pefile.txt:237] |
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Shared Go infostealer build artefacts
- prng-seeded-c2-url-decoding — Family C2 decoding technique
- Sibling:
ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7^[/intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html] - Sibling:
44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd^[/intel/analyses/44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd.html] - Sibling:
828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a^[/intel/analyses/828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a.html] - Sibling:
6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e^[/intel/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e.html] - OpenCTI artifact:
1eb1b174-82da-4be6-804f-f6f77f36cfce^[metadata.json:2]
Provenance
Analysis derived from:
filev5.44 — file type identification ^[file.txt]pefile(Python) — PE header and section analysis ^[pefile.txt]strings(GNU binutils) — ASCII/Unicode string extraction ^[strings.txt]radare2v5.9.8 — binary info, entry point, imports ^[rabin2-info.txt] ^[r2:entry0]binwalkv2.3.4 — embedded artefact detection ^[binwalk.txt]exiftoolv12.76 — metadata extraction ^[exiftool.json]openssl— PKCS#7 certificate parsing fromIMAGE_DIRECTORY_ENTRY_SECURITYoverlayssdeepandtlsh— fuzzy hashing ^[ssdeep.txt] ^[tlsh.txt]- YARA (generic
PE_File_Genericmatch only) ^[yara.txt]
All tools run on pp-hermes (Lab1BU, <lan>) against the sample at <sample 350a2b69e5de.bin>.