38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138acrstealer: 38cf89b0 — Eighteenth confirmed sibling, smallest randomized-function count in Go 1.18.5 cluster
Executive Summary
Signed Go 1.18.5 PE32 infostealer, eighteenth confirmed sibling in the ACRStealer cluster. Self-signed certificate CN=atom.hutsell.com / issuer WR3 (same cert chain as siblings ef262340–b0bc17dd). Only 11 randomized main.* functions — the smallest count observed in this cluster (previous minimum: 22 in beff95d5). Standard light build: no custom PE parser, no multi-pass decoder, no static C2 strings. Four-icon .rsrc suite intact. Static-only analysis (CAPE skipped).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138 |
| SHA-1 | 483ef10250f45540784cfb4368e262f0bea31e37 |
| MD5 | f656a8bb91d850860b8fd1e1a9f1fcd1 |
| File type | PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt] |
| Size | 2,288,768 bytes |
| Timestamp | 0x0 (1970-01-01, null/stripped) ^[pefile.txt:39] |
| Compiler | Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath) ^[strings.txt:1068-1074] |
| Module path | gnApZCuURloGurv ^[strings.txt:1068] |
| Build ID | AyxtZ3N1VeX9Vjh-3IVV/FDI6VuvkL04RPOcZrwCW/xG8Pw7pUcLiGg0qS6n3X/kK0wGVzsdqsNzZWWVov_ ^[strings.txt:8] |
Certificate: Self-signed, CN=atom.hutsell.com, Issuer=WR3, SHA-256WithRSAEncryption, valid Apr 21 21:26:24 2026 GMT – Jul 20 22:15:34 2026 GMT ^[binwalk.txt] ^[certificate extraction from raw binary at offset 0x22E49D].
Signing status: Authenticode signature present in IMAGE_DIRECTORY_ENTRY_SECURITY (VA=0x22e400, Size=0x880) ^[pefile.txt:232-234].
Cluster attribution: Eighteenth confirmed ACRStealer sibling. Matches the Go 1.18.5 atom.hutsell.com / WR3 self-signed cert cluster (siblings ef262340, 44f594e2, 6cbac6bc, 828405d6, 350a2b69, beff95d5, 119b387e, b0bc17dd). See acrstealer for cluster-wide TTPs and build pattern.
How It Works
This sample follows the standard ACRStealer Go 1.18.5 light-build template documented on the cluster entity page:
- No custom PE parser — uses standard Go
syscallandospackages for file/registry/network operations. - No multi-pass byte-transform decoder — C2 strings decoded via the simpler PRNG-seeded runtime technique shared with the broader cluster.
- No static C2 — no hardcoded domains or IPs in
.rdata; C2 resolved at runtime (family pattern, see prng-seeded-c2-url-decoding).
Per-sample delta: Only 11 randomized main.* functions versus 22–90 in prior siblings, suggesting a builder option or stripped feature set. The randomized names are: Wgqgxh, Hskujaj, Pmuhhjig, ykuiglzf, Ibtklghya, elsehitck, usvuabqyn, Neltvtsbpdp, Tgsnggwvhruqp, Ljpoqrmqwcuzep, Wvxzebbknpkrsep ^[strings.txt:605-893].
.rsrc: Four icons (1,128 B; 16,936 B; 67,624 B; 36,252 B) plus RT_GROUP_ICON ^[pefile.txt:328-420]. Largest icon is 256×256 PNG ^[binwalk.txt:2250216].
Imports: Single DLL kernel32.dll with 40 imports — standard Go runtime surface (VirtualAlloc, CreateThread, LoadLibraryA/W, GetProcAddress, etc.) ^[pefile.txt:269-299]. No ws2_32.dll or wininet.dll in IAT; networking via embedded syscall calls to ws2_32.dll, dnsapi.dll loaded at runtime ^[strings.txt:986-990].
os/exec present: Source paths os/exec_windows.go, os/exec.go, os/executable_windows.go, os/executable.go in strings ^[strings.txt:4753-4760], confirming process-spawn capability (standard Go os/exec package).
Decompiled Behavior
Ghidra/pyghidra was not invoked for this sample — no new techniques beyond the established cluster pattern. Radare2 analysis confirms:
- Entry point at
0x00457c30(standard Go runtime_rt0_386_windows) ^[r2:entry0] - 1,533 functions total, all stripped ^[r2:analysis]
- No named symbols; all functions are numeric offsets
.textentropy 6.18,.rdataentropy 7.35 ^[rabin2-info.txt]
No new decompilation insights beyond confirming standard Go binary layout.
C2 Infrastructure
No static C2 recovered. Certificate CN atom.hutsell.com is infrastructure-related but does not resolve to an observed C2 endpoint in this corpus. Runtime C2 decoding follows the family PRNG-seeded pattern (see prng-seeded-c2-url-decoding and acrstealer).
Interesting Tidbits
- Smallest function-name randomization count in cluster: 11 vs. prior minimum 22 (
beff95d5). Builder may have a slider or this is a minimal-features compile. - Build ID is unique — first time this exact build ID observed in the corpus.
os/execpackage present but no hardcoded command-line strings — execution is runtime-constructed.- No VS_VERSIONINFO —
.rsrccontains only icons, no version metadata ^[pefile.txt].
How To Mess With It (Homelab Replication)
Reproduce a comparable Go 1.18.5 binary:
# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.linux-amd64.tar.gz
tar -C /usr/local -xzf go1.18.5.linux-amd64.tar.gz
export PATH=$PATH:/usr/local/go/bin
# Build a minimal PE32 with randomized function names
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go
Verification: run rabin2 -I repro.exe and compare to rabin2-info.txt — should show lang: c, stripped: true, signed: false (unless you self-sign).
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsell {
meta:
description = "ACRStealer Go 1.18.5 variant with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-05"
reference = "raw/analyses/38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138"
hash = "38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138"
strings:
$go_build = "Go build ID:" ascii
$go1185 = "go1.18.5" ascii
$mod_path = /path\t[a-zA-Z]{10,20}/ ascii
$cert_cn = "atom.hutsell.com" ascii
$cert_issuer = "WR3" ascii
$main_rand = /main\.[A-Za-z]{5,20}/ ascii
condition:
uint16(0) == 0x5a4d and
$go_build and
$go1185 and
$cert_cn and
$cert_issuer and
#main_rand >= 5 and
filesize > 1MB and filesize < 3MB
}
Sigma Rule
title: ACRStealer Go Binary Network Activity
logsource:
category: network_connection
product: windows
detection:
selection:
- Initiated: true
- Image|endswith: '.exe'
selection_cert_indicators:
- Hashes|contains:
- '38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138'
selection_behavior:
- CommandLine|contains:
- 'gnApZCuURloGurv'
condition: selection_cert_indicators or selection_behavior
falsepositives:
- Unknown
level: high
IOC List
| Type | Value |
|---|---|
| SHA-256 | 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138 |
| SHA-1 | 483ef10250f45540784cfb4368e262f0bea31e37 |
| MD5 | f656a8bb91d850860b8fd1e1a9f1fcd1 |
| Cert CN | atom.hutsell.com |
| Cert Issuer | WR3 |
| Module Path | gnApZCuURloGurv |
| Build ID | AyxtZ3N1VeX9Vjh-3IVV/FDI6VuvkL04RPOcZrwCW/xG8Pw7pUcLiGg0qS6n3X/kK0wGVzsdqsNzZWWVov_ |
| PE Timestamp | 0x0 (null) |
Behavioral Fingerprint Statement
Go 1.18.5 PE32 executable (2.0–2.3 MB) with self-signed Authenticode certificate CN atom.hutsell.com / issuer WR3, null PE timestamp, 11–90 randomized main.* functions in .rdata, .rsrc section containing 1–4 PNG icons up to 256×256, no VS_VERSIONINFO, no static C2 strings. Loads ws2_32.dll and dnsapi.dll at runtime via syscall.LoadDLL, spawns child processes via os/exec. Network connections are TLS/HTTPS to runtime-decoded domains.
Detection Signatures
No capa results (tool failure: missing signatures directory). No floss results (CLI argument error). Family-level ATT&CK mapping:
| Technique | ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | File/registry enumeration via os, syscall |
| Application Layer Protocol | T1071.001 | HTTPS/TLS C2 (inferred from family crypto/tls linkage) |
| OS Credential Dumping | T1003 | Browser credential theft (family behavior) |
| Command and Scripting Interpreter | T1059 | os/exec package present ^[strings.txt:4753-4760] |
| Ingress Tool Transfer | T1105 | Payload download capability (family behavior) |
See acrstealer for full ATT&CK mapping.
References
- acrstealer — Cluster entity page
- golang-stealer-build-pattern — Build pattern concept
- prng-seeded-c2-url-decoding — C2 decoding technique
- MalwareBazaar / OpenCTI artifact:
38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138(labelacrstealer)
Provenance
Static analysis files generated 2026-05-27. Report written 2026-08-05. Tools: file v5.44, exiftool v12.76, pefile (Python), strings v2.42, radare2 v5.9.6, rabin2 v5.9.6, binwalk v2.3.4, openssl x509. No capa/floss due to tool configuration errors.