typeanalysisfamilyacrstealerconfidencehighcreated2026-08-01updated2026-08-01infostealermalware-familygolangsigningpec2exfiltration
SHA-256: 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802

acrstealer: 350a2b69 — Go 1.18.5 PE32 sibling, self-signed atom.hutsell.com/WR3 cert, .rsrc icon masquerade, no static C2

Executive Summary

Fourteenth confirmed sibling in the acrstealer Go infostealer cluster. PE32 compiled with Go 1.18.5 (GOARCH=386, CGO_ENABLED=0), randomized module path YUJFqOiYcDAmDOn, self-signed Authenticode certificate CN=atom.hutsell.com / issuer WR3 (shared with four prior siblings), .rsrc section containing four PNG icons for social-engineering masquerade. No hardcoded C2 strings recovered statically — relies on PRNG-seeded runtime decoding per established family pattern. Static-only analysis (CAPE skipped — no Windows guest). This sample restores the .rsrc icon suite that sibling 6cbac6bc stripped, confirming the builder supports an icon-toggle configuration.

What It Is

Field Value
SHA-256 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802
Size 7.43 MB (7,430,272 bytes) ^[file.txt]
File type PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
Compiler Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, GO386=sse2) ^[strings.txt:1067] ^[strings.txt:1072]
Module path YUJFqOiYcDAmDOn ^[strings.txt:1069]
PE timestamp 0x0 (null / stripped) ^[pefile.txt:38]
Entropy .text 6.19, .rdata 7.28, .rsrc 5.14 ^[pefile.txt:96] ^[pefile.txt:116] ^[pefile.txt:216]
Signing Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, validity 2026-04-21 → 2026-07-20 ^[pefile.txt:237] ^[strings.txt:7734]
.rsrc 4 icons: 16×16, 32×32, 48×48, 256×256 PNG ^[binwalk.txt:7] ^[pefile.txt:203]
capa Failed (missing signatures) ^[capa.txt]
Dynamic CAPE skipped — no Windows guest available ^[dynamic-analysis.md:1]

Family attribution is high confidence: matches the golang-stealer-build-pattern (Go 1.18.5, randomized module path, randomized main.* function names, self-signed cert, null PE timestamp, .rsrc icon suite) and shares the atom.hutsell.com / WR3 certificate chain with four confirmed siblings: ef262340, 44f594e2, 6cbac6bc, and 828405d6.

How It Works

This is a light Go 1.18.5 variant — it does not exhibit the custom in-memory PE parser or multi-pass byte-transform decoder observed in siblings d5655568, 7620884e, and d353d849. Instead, it follows the simpler template of ef262340 and 44f594e2: standard Go static binary with runtime-randomized C2 decoding.

Build pipeline observations:

  • trimpath=true (no absolute source paths in pclntab) ^[strings.txt:1069]
  • Randomized main package function names (main.rwwmlminnoxqyxx, main.rzhcmqvp, main.lnrpmbak, main.zeignmwuwz, main.tblhsvlsfzcnpfg, main.zmsbkokvlr, main.Hqhicbqf, main.Raokbytrao, main.yizhfmfesbpyi, main.wdmbvkdqtjthc, main.mdnaml, main.wlwaxkgkuuhvddy, main.wkikuckduvtmo, main.rosvcnbk, main.muzdmrbsm) ^[strings.txt:4177] ^[strings.txt:4191] — 15+ randomized names, hindering symbol-based clustering.
  • No crypto/tls or crypto/x509 package strings visible in static extraction, but the family pattern implies TLS-wrapped HTTP C2 (see sibling 6871848b which contacts 5.252.155.72 and laserlogdnsop.icu).

C2 decoding: No static C2 strings. The math/rand package is linked ^[strings.txt:379], consistent with the family-wide PRNG-seeded runtime C2 decoding documented at prng-seeded-c2-url-decoding.

Resource masquerade: The .rsrc section contains a 256×256 PNG icon (likely a fake application icon) alongside standard 16×16, 32×32, and 48×48 variants ^[binwalk.txt:7]. This is identical in structure to siblings ef262340, 44f594e2, and 828405d6, and contrasts with 6cbac6bc which stripped .rsrc entirely. Builder supports icon toggle.

Decompiled Behavior

No Ghidra decompilation was attempted — the binary is a Go 1.18.5 static PE with ~534 KB .text and ~1.3 MB .rdata (high entropy 7.28), making automated decompilation of the randomized main functions low-yield without dynamic tracing. Radare2 analysis confirms:

  • Entry point at 0x00457c30 ^[rabin2-info.txt:11] ^[r2:entry0]
  • Import table limited to kernel32.dll (standard Go runtime imports: VirtualAlloc, CreateFile, LoadLibrary, GetProcAddress, etc.) ^[pefile.txt:275]
  • No COM descriptor (not .NET) ^[pefile.txt:267]
  • No TLS callbacks ^[pefile.txt:252]
  • No delay imports ^[pefile.txt:264]
  • Overlay present (Authenticode certificate at file offset 0x715800) ^[rabin2-info.txt:23] ^[pefile.txt:237]

The main.wijtudpep function (line 4217 in strings.txt) appears to be the entry-point goroutine dispatch wrapper, but without dynamic execution its callees cannot be resolved statically.

C2 Infrastructure

Static C2: None recovered. The certificate CN atom.hutsell.com is the self-signer domain, not a C2 endpoint.

Inferred C2: Based on sibling analyses and family TTPs:

  • Direct IP and domain over TLS/HTTP (implied by crypto/tls linkage in other siblings)
  • PRNG-seeded runtime decoding of C2 strings at launch ^[prng-seeded-c2-url-decoding]
  • No hardcoded ports, mutex names, or named pipes observed statically

Interesting Tidbits

  • Certificate recycling: The atom.hutsell.com / WR3 self-signed certificate is reused across at least five siblings spanning PE32 and PE32+ (x64) builds (ef262340, 44f594e2, 6cbac6bc, 828405d6, and this sample). Validity window 2026-04-21 → 2026-07-20. This is a builder-level artefact, not per-sample generation. ^[strings.txt:7732] ^[strings.txt:7734]
  • Builder icon toggle: Sibling 6cbac6bc (eleventh) stripped .rsrc; this sample (fourteenth) and 828405d6 (thirteenth) restore it. The builder clearly supports both modes.
  • Null PE timestamp: Like all siblings, the PE TimeDateStamp is 0x0 — a Go linker default when -trimpath is used, not anti-forensics. ^[pefile.txt:38]
  • Floss failure: The flare-floss run failed with an argument-parsing error ^[floss.txt:6], likely due to CLI invocation issues in the triage pipeline. This is a pipeline artefact, not a binary property.
  • Capa failure: Mandiant capa aborted due to missing signatures directory ^[capa.txt:1]. Also a pipeline issue.
  • Large .rdata: At 1.3 MB with entropy 7.28, .rdata is larger than typical Go 1.18.5 binaries. This may contain encrypted string tables or embedded payload data, but no readable headers were recovered.

How To Mess With It (Homelab Replication)

To reproduce a comparable Go static binary fingerprint:

Toolchain:

  • Go 1.18.5 for Windows/386
  • CGO_ENABLED=0 GOOS=windows GOARCH=386 go build -trimpath -ldflags="-s -w"

Compiler/linker flags:

GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o sample.exe

Verification step: Run rabin2 -I sample.exe and confirm:

  • lang: c
  • stripped: true
  • signed: false (unless you add a self-signed cert)
  • subsys: Windows GUI
  • compiled: Thu Jan 1 00:00:00 1970

Compare .rdata entropy to this sample (~7.28). Populate .rdata with high-entropy dummy data (e.g., encrypted strings, random padding) to match.

What you'll learn: How Go static binaries appear in PE analysis tools and why randomized module paths defeat naive string-clustering.

Deployable Signatures

YARA rule

rule ACRStealer_Go1185_AtomHutsell : infostealer
{
    meta:
        description = "ACR Stealer Go 1.18.5 PE32 variant with self-signed atom.hutsell.com certificate"
        author = "PacketPursuit"
        date = "2026-08-01"
        sha256 = "350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802"
        family = "acrstealer"
    strings:
        $go_build = "go1.18.5" ascii wide
        $go_buildinf = "Go buildinf:" ascii wide
        $go_cgo = "CGO_ENABLED=0" ascii wide
        $go_arch = "GOARCH=386" ascii wide
        $go_os = "GOOS=windows" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $mod_path = "path\t" ascii wide
        $mod_devel = "(devel)" ascii wide
        $main_rand = /main\.[a-z]{10,20}/ ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ($go_build and $go_buildinf) and
        ($go_cgo and $go_arch and $go_os) and
        ($cert_cn and $cert_issuer) and
        ($mod_path or $mod_devel) and
        #main_rand >= 5
}

Behavioral hunt query (KQL / Microsoft Sentinel)

let acrstealer_certs = dynamic(["atom.hutsell.com"]);
DeviceFileCertificateInfo
| where Signer in (acrstealer_certs) or Issuer in (acrstealer_certs)
| where FileName endswith ".exe"
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Count=count() by DeviceName, FileName, SHA256, Signer, Issuer

IOC list

Type Value Note
SHA-256 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802 This sample
SHA-256 ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 Tenth sibling (same cert)
SHA-256 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd Twelfth sibling (same cert)
SHA-256 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e Eleventh sibling (same cert, stripped .rsrc)
SHA-256 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a Thirteenth sibling (same cert, PE32+ x64)
Certificate CN atom.hutsell.com Self-signer across 5+ siblings
Certificate Issuer WR3 Self-signed issuer
Go module path YUJFqOiYcDAmDOn This sample only
File size ~7.4 MB Consistent with Go 1.18.5 static + icons

Behavioral fingerprint statement

This binary is a Go 1.18.5-compiled PE32 GUI executable with a null PE timestamp, stripped symbol table, and self-signed Authenticode certificate (CN atom.hutsell.com, issuer WR3). It imports only kernel32.dll APIs via the standard Go runtime IAT and contains a .rsrc section with four PNG icons (16×16 through 256×256). No hardcoded C2 strings are present; C2 infrastructure is decoded at runtime using a PRNG-seeded transform. The main package contains 15+ randomized alphanumeric function names (e.g., main.rwwmlminnoxqyxx, main.zeignmwuwz) that defeat static clustering. On execution, it is expected to contact an attacker-controlled HTTPS endpoint via crypto/tls and exfiltrate browser credentials, cryptocurrency wallet data, and system fingerprints per the ACR Stealer family TTPs.

Detection Signatures

No capa output available (signatures directory missing during triage). Based on static indicators, the following ATT&CK techniques are mappable:

Technique ID Evidence
Data from Local System T1005 Infostealer family targeting local credential stores
Input Capture: Clipboard Data T1115 Family TTP (crypto clipper component in siblings)
Credentials from Password Stores T1555 Browser credential theft (family TTP)
Exfiltration Over C2 Channel T1041 TLS/HTTPS C2 (family TTP)
Obfuscated Files or Information T1027 Randomized module paths and function names ^[strings.txt:1069] ^[strings.txt:4177]
Application Layer Protocol: Web Protocols T1071.001 HTTPS C2 (family TTP)
Dynamic Resolution T1568 PRNG-seeded runtime C2 decoding ^[prng-seeded-c2-url-decoding]
Masquerading T1036 .rsrc PNG icon suite for social engineering ^[binwalk.txt:7]
Signed Binary Proxy Execution T1218 Self-signed cert to appear legitimate ^[pefile.txt:237]

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Shared Go infostealer build artefacts
  • prng-seeded-c2-url-decoding — Family C2 decoding technique
  • Sibling: ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7 ^[/intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html]
  • Sibling: 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd ^[/intel/analyses/44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd.html]
  • Sibling: 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a ^[/intel/analyses/828405d66881b770753d58349534c978672cda97591e8eb393beca734896539a.html]
  • Sibling: 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e ^[/intel/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e.html]
  • OpenCTI artifact: 1eb1b174-82da-4be6-804f-f6f77f36cfce ^[metadata.json:2]

Provenance

Analysis derived from:

  • file v5.44 — file type identification ^[file.txt]
  • pefile (Python) — PE header and section analysis ^[pefile.txt]
  • strings (GNU binutils) — ASCII/Unicode string extraction ^[strings.txt]
  • radare2 v5.9.8 — binary info, entry point, imports ^[rabin2-info.txt] ^[r2:entry0]
  • binwalk v2.3.4 — embedded artefact detection ^[binwalk.txt]
  • exiftool v12.76 — metadata extraction ^[exiftool.json]
  • openssl — PKCS#7 certificate parsing from IMAGE_DIRECTORY_ENTRY_SECURITY overlay
  • ssdeep and tlsh — fuzzy hashing ^[ssdeep.txt] ^[tlsh.txt]
  • YARA (generic PE_File_Generic match only) ^[yara.txt]

All tools run on pp-hermes (Lab1BU, <lan>) against the sample at <sample 350a2b69e5de.bin>.