typeanalysisfamilyacrstealerconfidencehighcreated2026-08-15updated2026-08-15infostealergolangsigningobfuscationcompilerevasion
SHA-256: 3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c

acrstealer: 3f7d51dd — Go 1.25.4 PE32, quiverquant.com cert, 42 randomized functions, icon-toggle off

Executive Summary

Go 1.25.4 infostealer statically linked with no CGO, carrying the quiverquant.com/WE1 self-signed certificate chain previously observed across the ACR Stealer cluster. OpenCTI labels this sample lummastealer; the certificate chain resolves it to ACR. No .rsrc section (builder icon-toggle disabled). PRNG-seeded sleep gate and runtime C2 decoding. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c
  • File: PE32 executable (GUI) Intel 80386, 6 sections, 1,926,272 bytes ^[file.txt]
  • Compiler: Go 1.25.4 (GOARCH=386, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1660]
  • Module path: rPNTPRIvOgSxctC ^[strings.txt:1662]
  • Build ID: L1OpqSTG5x5xOqtHDiVk/3UMRTw440FRfnk5jYSbo/G5hZlLfdOr5WtsZ0FqNl/pmhcwd-4LBjfee-_Jn_C ^[strings.txt:7]
  • PE timestamp: null (0x0) ^[pefile.txt:34]
  • Authenticode: self-signed CN=quiverquant.com, issuer WE1 ^[binwalk.txt:9] ^[strings.txt:8970]
  • .rsrc: absent (icon-toggle off) ^[pefile.txt:207]
  • main.* functions: 42 randomized names ^[strings.txt:5035-5079]

How It Works

Entry via standard Go runtime.main → main.main. The main.main function:

  1. Seeds math/rand with time.Now().UnixNano() ^[r2:sym.main.main @ 0x49d820]
  2. Spins a PRNG-based sleep gate: rand.Intn(800) + 0x320 (800–1120 seconds, ~13–18 min) ^[r2:sym.main.main @ 0x49d820]
  3. Calls main.iobmrgfn (system fingerprint / info collection, inferred)
  4. Calls main.ilnmwdnnl (likely C2 connect)
  5. Calls main.zfwndzopbxkdg (likely exfil)
  6. Finally calls main.ccnncnnmbnfv (main payload orchestrator)

main.newtiyolmkq formats system information using strconv.Itoa, strconv.FormatFloat, and bytes.Buffer.WriteString — building a victim fingerprint string for exfil. ^[r2:sym.main.newtiyolmkq @ 0x49b030]

Decompiled Behavior

main.main decompilation reveals PRNG seeding with UnixNano, a double-precision sleep calculation, and sequential invocation of randomized main.* functions. No hardcoded C2 URLs are present in .text or .rdata; C2 is runtime-decoded (consistent with prng-seeded-c2-url-decoding). The import table is minimal (kernel32.dll only); all networking is statically-linked Go net/http + crypto/tls.

C2 Infrastructure

No static C2 recovered. Runtime-decoded via PRNG (family pattern). No hardcoded domains, IPs, or URLs in strings.

Interesting Tidbits

  • Contested attribution: OpenCTI tag is lummastealer, but the quiverquant.com/WE1 certificate chain is exclusive to the ACR Stealer cluster. See lummastealer for the contested-samples note.
  • 42 main.* functions — mid-range count for this cluster (range observed: 11–92)
  • No .rsrc — builder stripped icons, a toggle observed across both ACR and Lumma clusters
  • Go buildinf preserved despite -trimpath=true; module path and build ID remain recoverable

How To Mess With It (Homelab Replication)

Build a comparable Go binary:

GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o repro.exe main.go

Use math/rand.Seed(time.Now().UnixNano()) and a sleep gate pattern. Sign with a self-signed cert via osslsigncode. Verify: strings repro.exe | grep -E 'go1\.|CGO_ENABLED|GOARCH' should match this sample's fingerprint.

Deployable Signatures

YARA

rule acrstealer_go1254_quiverquant {
    meta:
        description = "ACR Stealer / contested Lumma — Go 1.25.4 PE32 with quiverquant.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-15"
        hash = "3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c"
    strings:
        $go_build = "go1.25.4" ascii
        $mod_path = /path\tr[A-Za-z0-9]{15,20}/ ascii
        $cert_cn = "quiverquant.com" ascii
        $cert_issuer = "WE1" ascii
        $build_cgo = "CGO_ENABLED=0" ascii
        $build_arch = "GOARCH=386" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        $cert_cn and
        $cert_issuer and
        $build_cgo and
        $build_arch and
        filesize < 3MB
}

IOCs

Indicator Value Note
SHA-256 3f7d51dd1fd7024371b155765420f2220d247a49fdc593b2eae02bc96b2a206c Sample
Cert CN quiverquant.com Self-signed
Cert Issuer WE1 Self-signed
Module path rPNTPRIvOgSxctC Randomized per build
Build ID L1OpqSTG5x5xOqtHDiVk/3UMRTw440FRfnk5jYSbo/G5hZlLfdOr5WtsZ0FqNl/pmhcwd-4LBjfee-_Jn_C Unique per build
PE Timestamp 0x0 (null) Go trimpath artefact

Behavioral Fingerprint

Go 1.25.4 PE32 with null PE timestamp, minimal kernel32.dll IAT, no .rsrc section, 40+ randomized main.* functions, PRNG-seeded sleep of 800–1120 seconds after launch, then HTTPS C2 beacon. Authenticode self-signed with rotating CN values.

Detection Signatures

  • No capa output (signature path error during triage)
  • No floss output (flag error during triage)
  • Static imports: kernel32.dll only (VirtualAlloc, LoadLibraryW, GetProcAddress, SuspendThread, ResumeThread, SetThreadContext, GetThreadContext) ^[pefile.txt:259-303]

References

Provenance

  • file.txt: file v5.44
  • pefile.txt: pefile Python library
  • strings.txt: strings GNU binutils
  • r2 decompilation: radare2 v5.9.9
  • cert extraction: openssl x509 via dd offset 0x1D5C08