typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigningpe
SHA-256: 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138

acrstealer: 38cf89b0 — Eighteenth confirmed sibling, smallest randomized-function count in Go 1.18.5 cluster

Executive Summary

Signed Go 1.18.5 PE32 infostealer, eighteenth confirmed sibling in the ACRStealer cluster. Self-signed certificate CN=atom.hutsell.com / issuer WR3 (same cert chain as siblings ef262340–b0bc17dd). Only 11 randomized main.* functions — the smallest count observed in this cluster (previous minimum: 22 in beff95d5). Standard light build: no custom PE parser, no multi-pass decoder, no static C2 strings. Four-icon .rsrc suite intact. Static-only analysis (CAPE skipped).

What It Is

Field Value
SHA-256 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138
SHA-1 483ef10250f45540784cfb4368e262f0bea31e37
MD5 f656a8bb91d850860b8fd1e1a9f1fcd1
File type PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
Size 2,288,768 bytes
Timestamp 0x0 (1970-01-01, null/stripped) ^[pefile.txt:39]
Compiler Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath) ^[strings.txt:1068-1074]
Module path gnApZCuURloGurv ^[strings.txt:1068]
Build ID AyxtZ3N1VeX9Vjh-3IVV/FDI6VuvkL04RPOcZrwCW/xG8Pw7pUcLiGg0qS6n3X/kK0wGVzsdqsNzZWWVov_ ^[strings.txt:8]

Certificate: Self-signed, CN=atom.hutsell.com, Issuer=WR3, SHA-256WithRSAEncryption, valid Apr 21 21:26:24 2026 GMT – Jul 20 22:15:34 2026 GMT ^[binwalk.txt] ^[certificate extraction from raw binary at offset 0x22E49D].

Signing status: Authenticode signature present in IMAGE_DIRECTORY_ENTRY_SECURITY (VA=0x22e400, Size=0x880) ^[pefile.txt:232-234].

Cluster attribution: Eighteenth confirmed ACRStealer sibling. Matches the Go 1.18.5 atom.hutsell.com / WR3 self-signed cert cluster (siblings ef262340, 44f594e2, 6cbac6bc, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd). See acrstealer for cluster-wide TTPs and build pattern.

How It Works

This sample follows the standard ACRStealer Go 1.18.5 light-build template documented on the cluster entity page:

  • No custom PE parser — uses standard Go syscall and os packages for file/registry/network operations.
  • No multi-pass byte-transform decoder — C2 strings decoded via the simpler PRNG-seeded runtime technique shared with the broader cluster.
  • No static C2 — no hardcoded domains or IPs in .rdata; C2 resolved at runtime (family pattern, see prng-seeded-c2-url-decoding).

Per-sample delta: Only 11 randomized main.* functions versus 22–90 in prior siblings, suggesting a builder option or stripped feature set. The randomized names are: Wgqgxh, Hskujaj, Pmuhhjig, ykuiglzf, Ibtklghya, elsehitck, usvuabqyn, Neltvtsbpdp, Tgsnggwvhruqp, Ljpoqrmqwcuzep, Wvxzebbknpkrsep ^[strings.txt:605-893].

.rsrc: Four icons (1,128 B; 16,936 B; 67,624 B; 36,252 B) plus RT_GROUP_ICON ^[pefile.txt:328-420]. Largest icon is 256×256 PNG ^[binwalk.txt:2250216].

Imports: Single DLL kernel32.dll with 40 imports — standard Go runtime surface (VirtualAlloc, CreateThread, LoadLibraryA/W, GetProcAddress, etc.) ^[pefile.txt:269-299]. No ws2_32.dll or wininet.dll in IAT; networking via embedded syscall calls to ws2_32.dll, dnsapi.dll loaded at runtime ^[strings.txt:986-990].

os/exec present: Source paths os/exec_windows.go, os/exec.go, os/executable_windows.go, os/executable.go in strings ^[strings.txt:4753-4760], confirming process-spawn capability (standard Go os/exec package).

Decompiled Behavior

Ghidra/pyghidra was not invoked for this sample — no new techniques beyond the established cluster pattern. Radare2 analysis confirms:

  • Entry point at 0x00457c30 (standard Go runtime _rt0_386_windows) ^[r2:entry0]
  • 1,533 functions total, all stripped ^[r2:analysis]
  • No named symbols; all functions are numeric offsets
  • .text entropy 6.18, .rdata entropy 7.35 ^[rabin2-info.txt]

No new decompilation insights beyond confirming standard Go binary layout.

C2 Infrastructure

No static C2 recovered. Certificate CN atom.hutsell.com is infrastructure-related but does not resolve to an observed C2 endpoint in this corpus. Runtime C2 decoding follows the family PRNG-seeded pattern (see prng-seeded-c2-url-decoding and acrstealer).

Interesting Tidbits

  • Smallest function-name randomization count in cluster: 11 vs. prior minimum 22 (beff95d5). Builder may have a slider or this is a minimal-features compile.
  • Build ID is unique — first time this exact build ID observed in the corpus.
  • os/exec package present but no hardcoded command-line strings — execution is runtime-constructed.
  • No VS_VERSIONINFO — .rsrc contains only icons, no version metadata ^[pefile.txt].

How To Mess With It (Homelab Replication)

Reproduce a comparable Go 1.18.5 binary:

# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.linux-amd64.tar.gz
tar -C /usr/local -xzf go1.18.5.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin

# Build a minimal PE32 with randomized function names
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go

Verification: run rabin2 -I repro.exe and compare to rabin2-info.txt — should show lang: c, stripped: true, signed: false (unless you self-sign).

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsell {
    meta:
        description = "ACRStealer Go 1.18.5 variant with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-05"
        reference = "raw/analyses/38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138"
        hash = "38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138"
    
    strings:
        $go_build = "Go build ID:" ascii
        $go1185 = "go1.18.5" ascii
        $mod_path = /path\t[a-zA-Z]{10,20}/ ascii
        $cert_cn = "atom.hutsell.com" ascii
        $cert_issuer = "WR3" ascii
        $main_rand = /main\.[A-Za-z]{5,20}/ ascii
    
    condition:
        uint16(0) == 0x5a4d and
        $go_build and
        $go1185 and
        $cert_cn and
        $cert_issuer and
        #main_rand >= 5 and
        filesize > 1MB and filesize < 3MB
}

Sigma Rule

title: ACRStealer Go Binary Network Activity
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        - Initiated: true
        - Image|endswith: '.exe'
    selection_cert_indicators:
        - Hashes|contains:
            - '38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138'
    selection_behavior:
        - CommandLine|contains:
            - 'gnApZCuURloGurv'
    condition: selection_cert_indicators or selection_behavior
falsepositives:
    - Unknown
level: high

IOC List

Type Value
SHA-256 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138
SHA-1 483ef10250f45540784cfb4368e262f0bea31e37
MD5 f656a8bb91d850860b8fd1e1a9f1fcd1
Cert CN atom.hutsell.com
Cert Issuer WR3
Module Path gnApZCuURloGurv
Build ID AyxtZ3N1VeX9Vjh-3IVV/FDI6VuvkL04RPOcZrwCW/xG8Pw7pUcLiGg0qS6n3X/kK0wGVzsdqsNzZWWVov_
PE Timestamp 0x0 (null)

Behavioral Fingerprint Statement

Go 1.18.5 PE32 executable (2.0–2.3 MB) with self-signed Authenticode certificate CN atom.hutsell.com / issuer WR3, null PE timestamp, 11–90 randomized main.* functions in .rdata, .rsrc section containing 1–4 PNG icons up to 256×256, no VS_VERSIONINFO, no static C2 strings. Loads ws2_32.dll and dnsapi.dll at runtime via syscall.LoadDLL, spawns child processes via os/exec. Network connections are TLS/HTTPS to runtime-decoded domains.

Detection Signatures

No capa results (tool failure: missing signatures directory). No floss results (CLI argument error). Family-level ATT&CK mapping:

Technique ID Evidence
Data from Local System T1005 File/registry enumeration via os, syscall
Application Layer Protocol T1071.001 HTTPS/TLS C2 (inferred from family crypto/tls linkage)
OS Credential Dumping T1003 Browser credential theft (family behavior)
Command and Scripting Interpreter T1059 os/exec package present ^[strings.txt:4753-4760]
Ingress Tool Transfer T1105 Payload download capability (family behavior)

See acrstealer for full ATT&CK mapping.

References

Provenance

Static analysis files generated 2026-05-27. Report written 2026-08-05. Tools: file v5.44, exiftool v12.76, pefile (Python), strings v2.42, radare2 v5.9.6, rabin2 v5.9.6, binwalk v2.3.4, openssl x509. No capa/floss due to tool configuration errors.