3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206cacrstealer: 3f7d51dd — Go 1.25.4 PE32, quiverquant.com cert, 42 randomized functions, icon-toggle off
Executive Summary
Go 1.25.4 infostealer statically linked with no CGO, carrying the quiverquant.com/WE1 self-signed certificate chain previously observed across the ACR Stealer cluster. OpenCTI labels this sample lummastealer; the certificate chain resolves it to ACR. No .rsrc section (builder icon-toggle disabled). PRNG-seeded sleep gate and runtime C2 decoding. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c - File: PE32 executable (GUI) Intel 80386, 6 sections, 1,926,272 bytes ^[file.txt]
- Compiler: Go 1.25.4 (
GOARCH=386,GOOS=windows,CGO_ENABLED=0,-trimpath=true) ^[strings.txt:1660] - Module path:
rPNTPRIvOgSxctC^[strings.txt:1662] - Build ID:
L1OpqSTG5x5xOqtHDiVk/3UMRTw440FRfnk5jYSbo/G5hZlLfdOr5WtsZ0FqNl/pmhcwd-4LBjfee-_Jn_C^[strings.txt:7] - PE timestamp: null (0x0) ^[pefile.txt:34]
- Authenticode: self-signed CN=
quiverquant.com, issuerWE1^[binwalk.txt:9] ^[strings.txt:8970] .rsrc: absent (icon-toggle off) ^[pefile.txt:207]main.*functions: 42 randomized names ^[strings.txt:5035-5079]
How It Works
Entry via standard Go runtime.main → main.main. The main.main function:
- Seeds
math/randwithtime.Now().UnixNano()^[r2:sym.main.main @ 0x49d820] - Spins a PRNG-based sleep gate:
rand.Intn(800) + 0x320(800–1120 seconds, ~13–18 min) ^[r2:sym.main.main @ 0x49d820] - Calls
main.iobmrgfn(system fingerprint / info collection, inferred) - Calls
main.ilnmwdnnl(likely C2 connect) - Calls
main.zfwndzopbxkdg(likely exfil) - Finally calls
main.ccnncnnmbnfv(main payload orchestrator)
main.newtiyolmkq formats system information using strconv.Itoa, strconv.FormatFloat, and bytes.Buffer.WriteString — building a victim fingerprint string for exfil. ^[r2:sym.main.newtiyolmkq @ 0x49b030]
Decompiled Behavior
main.main decompilation reveals PRNG seeding with UnixNano, a double-precision sleep calculation, and sequential invocation of randomized main.* functions. No hardcoded C2 URLs are present in .text or .rdata; C2 is runtime-decoded (consistent with prng-seeded-c2-url-decoding). The import table is minimal (kernel32.dll only); all networking is statically-linked Go net/http + crypto/tls.
C2 Infrastructure
No static C2 recovered. Runtime-decoded via PRNG (family pattern). No hardcoded domains, IPs, or URLs in strings.
Interesting Tidbits
- Contested attribution: OpenCTI tag is
lummastealer, but thequiverquant.com/WE1certificate chain is exclusive to the ACR Stealer cluster. See lummastealer for the contested-samples note. - 42
main.*functions — mid-range count for this cluster (range observed: 11–92) - No
.rsrc— builder stripped icons, a toggle observed across both ACR and Lumma clusters - Go buildinf preserved despite
-trimpath=true; module path and build ID remain recoverable
How To Mess With It (Homelab Replication)
Build a comparable Go binary:
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go
Use math/rand.Seed(time.Now().UnixNano()) and a sleep gate pattern. Sign with a self-signed cert via osslsigncode. Verify: strings repro.exe | grep -E 'go1\.|CGO_ENABLED|GOARCH' should match this sample's fingerprint.
Deployable Signatures
YARA
rule acrstealer_go1254_quiverquant {
meta:
description = "ACR Stealer / contested Lumma — Go 1.25.4 PE32 with quiverquant.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-15"
hash = "3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c"
strings:
$go_build = "go1.25.4" ascii
$mod_path = /path\tr[A-Za-z0-9]{15,20}/ ascii
$cert_cn = "quiverquant.com" ascii
$cert_issuer = "WE1" ascii
$build_cgo = "CGO_ENABLED=0" ascii
$build_arch = "GOARCH=386" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
$cert_cn and
$cert_issuer and
$build_cgo and
$build_arch and
filesize < 3MB
}
IOCs
| Indicator | Value | Note |
|---|---|---|
| SHA-256 | 3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c |
Sample |
| Cert CN | quiverquant.com |
Self-signed |
| Cert Issuer | WE1 |
Self-signed |
| Module path | rPNTPRIvOgSxctC |
Randomized per build |
| Build ID | L1OpqSTG5x5xOqtHDiVk/3UMRTw440FRfnk5jYSbo/G5hZlLfdOr5WtsZ0FqNl/pmhcwd-4LBjfee-_Jn_C |
Unique per build |
| PE Timestamp | 0x0 (null) |
Go trimpath artefact |
Behavioral Fingerprint
Go 1.25.4 PE32 with null PE timestamp, minimal kernel32.dll IAT, no .rsrc section, 40+ randomized main.* functions, PRNG-seeded sleep of 800–1120 seconds after launch, then HTTPS C2 beacon. Authenticode self-signed with rotating CN values.
Detection Signatures
- No capa output (signature path error during triage)
- No floss output (flag error during triage)
- Static imports: kernel32.dll only (VirtualAlloc, LoadLibraryW, GetProcAddress, SuspendThread, ResumeThread, SetThreadContext, GetThreadContext) ^[pefile.txt:259-303]
References
- acrstealer — cluster entity page
- lummastealer — contested attribution note
- golang-stealer-build-pattern — shared build pattern
- prng-seeded-c2-url-decoding — runtime C2 decode technique
Provenance
- file.txt:
filev5.44 - pefile.txt:
pefilePython library - strings.txt:
stringsGNU binutils - r2 decompilation: radare2 v5.9.9
- cert extraction:
openssl x509viaddoffset 0x1D5C08