typeanalysisfamilyacrstealerconfidencehighcreated2026-08-14updated2026-08-14infostealergolangsigningcompilerc2exfiltration
SHA-256: 43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002

stealc: 43998b11d473 — contested OpenCTI label; Go PE64+ infostealer with quiverquant.com Authenticode

Executive Summary

OpenCTI tagged this sample stealc and vidar, but static analysis reveals a Go-compiled PE64+ infostealer that shares every build fingerprint with the acrstealer cluster: the quiverquant.com/WE1 self-signed Authenticode chain, randomized main.* function names, absent .rsrc section, and Go runtime syscall modules for ADVAPI32, CRYPT32, SHELL32, WS2_32, and NTDDL. No Stealc-specific strings (ssstealer, keyboard.txt, SQLite, MSVC RTTI) are present. This is an ACR stealer sibling mislabelled by upstream telemetry. Static-only; CAPE skipped (no Windows guest).

What It Is

Field Value
SHA-256 43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002
File name Setup.exe
File type PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
Size 2 558 592 bytes ^[metadata.json]
Compiler Go (rabin2-info lang: go) ^[rabin2-info.txt]
Build ID 7_tz-i36QEjsdducXfBp/uuiYeAXztcZbXuVgGQ76/l0tJh0JepwHKP4EKH5JP/bEaRFPbIsSYY0GChaRgE ^[strings.txt:9]
Linker Go internal linker (MajorLinkerVersion 3.0) ^[pefile.txt]
Base address 0x140000000 ^[pefile.txt]
Signing Self-signed Authenticode CN=quiverquant.com, issuer=WE1 ^[binwalk.txt]
Sections .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab — no .rsrc ^[pefile.txt]
Imports kernel32.dll only (Go runtime resolves the rest at load time via syscall.LazyDLL) ^[pefile.txt]

Build / RE

Toolchain

  • Go compiler, CGO-disabled (internal/syscall/windows modules dominate the string table). ^[strings.txt]
  • No go.mod path visible; -trimpath was likely used. The randomized main.* symbols (main.Iwqvqjh, main.Zwmtinke, main.Ydjyxjzqx, main.Fpwtmqlpgrflom, main.Htvsewazzpeazyk, main.Rmgtfxvmqqmawaf, main.Ayqgkkhzzo, main.rbyigyjpwtzl, main.ibesfcochvgie, main.hssehuow, main.Ypxucxssb) match the golang-stealer-build-pattern observed across the ACR/Lumma/OrderRe cluster. ^[strings.txt:1000–1414]
  • Standard Go runtime section layout with .symtab present (not stripped).

Packing / Obfuscation

  • None. No UPX, Themida, or custom packer. Go runtime strings are unobfuscated. ^[strings.txt]
  • No embedded payload resource or encrypted overlay. The full 2.5 MB is compiled Go code plus the security directory.

Anti-analysis

  • Minimal static anti-analysis. No VM-detection strings, no debug checks in the visible string set. Go binaries typically rely on runtime environment checks rather than compile-time anti-debug.
  • The quiverquant.com certificate is a self-signed fabrication — it will fail Windows Authenticode validation but may pass superficial triage. ^[binwalk.txt]

Code quality

  • 11 randomized main.* functions (relatively small compared to the 64+ seen in some ACR siblings), suggesting a lighter build or older builder template. ^[strings.txt:1000–1414]
  • Full exception-handling metadata in .pdata and .xdata — standard Go Windows ABI.

Deploy / ATT&CK (static inference only)

No dynamic execution was possible (CAPE skipped — no Windows guest). The following is inferred from imports and strings.

Technique Evidence Confidence
T1082 System Information Discovery GetComputerNameExW, GetAdaptersInfo, GetAdaptersAddresses, GetProcessMemoryInfo, RtlGetVersion in Go runtime syscall strings ^[strings.txt:1648–1671] high
T1012 Query Registry RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegCreateKeyExW, RegDeleteValueW, RegEnumValueW in internal/syscall/windows/registry strings ^[strings.txt:5615,6105,8597–8599] high
T1071.001 Application Layer Protocol: Web crypto/tls, x509, net/http (implied by Go runtime), WSAStartup, WSASocketW, WSARecv, WSASend, dnsapi.dll, ws2_32.dll ^[strings.txt:1648–1650] medium
T1041 Exfiltration Over C2 HTTPS client implied by TLS + socket surface; no hardcoded C2 URL recovered statically low
T1555 Credentials from Password Stores Standard ACR stealer capability (see acrstealer), but no browser-specific strings recovered statically — likely runtime-decoded medium
T1649 Steal Crypto Wallet Same as above; ACR cluster fingerprint includes wallet/seed regex harvesting medium

C2 Infrastructure

  • No static C2 strings recovered. The ACR cluster typically uses PRNG-seeded C2 URL decoding at runtime (see prng-seeded-c2-url-decoding); static string extraction yields nothing.

Decompiled Behavior

Ghidra was not invoked for this sample because the Go runtime produces tens of thousands of small functions and the decompiler output is dominated by runtime internals. Radare2 confirms the entry point at 0x140072640 (Go runtime.main → main.main chain). The 11 main.* functions are the only non-runtime logic; their names are randomized and their bodies are not trivially decompilable without extensive Go plugin setup.

The control flow is standard for a Go Windows executable:

  1. runtime.rt0_go sets up TLS and g0 stack.
  2. runtime.main initializes packages and spawns goroutines.
  3. main.main (one of the 11 randomized functions) executes the stealer payload.
  4. Network and registry operations use Go's internal/syscall/windows wrappers, which call syscall.SyscallN through kernel32.dll!GetProcAddress resolution. ^[strings.txt:5084–5094]

Interesting Tidbits

  • The quiverquant.com/WE1 certificate chain is a high-confidence ACR cluster fingerprint. It has now been observed on at least eight samples in this corpus (see acrstealer). Any future PE carrying this chain should be treated as ACR-family until proven otherwise.
  • OpenCTI co-labelled this sample vidar as well. The existing vidar.md page already documents a contested sample (94cf86f6) that carries the exact same quiverquant.com/WE1 chain and resolves to ACR. This strengthens the conclusion that both stealc and vidar labels are false positives for the ACR builder pipeline.
  • The .symtab section is unusually large (0x1B15B bytes), indicating an unstripped build. This is atypical for malware but common in Go binaries where the linker strips less aggressively than MSVC.
  • No .rsrc section means no icon group, no version info masquerade, and no manifest resource — a clean, minimal Go build.

How To Mess With It (Homelab Replication)

  1. Toolchain: Go 1.25.x for Windows amd64, CGO_ENABLED=0.
  2. Build flags: go build -trimpath -ldflags "-s -w" to produce a minimal PE.
  3. Sign it: Generate a self-signed cert with openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=quiverquant.com", then sign with osslsigncode or a Go signing tool.
  4. Randomize: Use a simple script to rename main.* functions via go:linkname or build a custom obfuscator that rewrites Go symbol table entries post-build.
  5. Add capability: Import crypto/tls, net/http, golang.org/x/sys/windows/registry to replicate the network + registry surface observed here.
  6. Verification: Run rabin2 -I — confirm lang: go, signed: true, and no .rsrc section.

Deployable Signatures

YARA rule

rule ACR_Stealer_Quiverquant_Cert
{
    meta:
        description = "ACR stealer family — Go PE64+ signed with self-signed quiverquant.com/WE1 cert"
        author = "PacketPursuit"
        date = "2026-08-14"
        hash = "43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002"
    strings:
        $go_build = "Go build ID:" ascii
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $mod_advapi = "syscall.modadvapi32" ascii
        $mod_crypt = "syscall.modcrypt32" ascii
        $mod_ws2 = "syscall.modws2_32" ascii
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)+4) == 0x00004550 and // PE signature
        $go_build and
        any of ($cert_cn, $cert_issuer) and
        2 of ($mod_advapi, $mod_crypt, $mod_ws2)
}

Behavioral fingerprint

This binary is a Go-compiled Windows PE64+ executable with no .rsrc section, signed with a self-self Authenticode certificate whose subject CN is quiverquant.com and issuer is WE1. It loads kernel32.dll for syscall trampoline resolution, then uses Go's internal/syscall/windows packages to access the registry (ADVAPI32), crypto (CRYPT32), and network (WS2_32, DNSAPI) subsystems. No hardcoded C2 strings are present in the PE; network targets are likely decoded at runtime via a PRNG-seeded transform consistent with the ACR/Lumma cluster pattern.

IOC list

Type Value Notes
SHA-256 43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002
File name Setup.exe Social-engineering masquerade
Certificate CN quiverquant.com Self-signed, ACR cluster fingerprint
Certificate issuer WE1
Section anomaly No .rsrc Common in ACR Go builds

Detection Signatures

Capability ATT&CK Evidence
System info discovery T1082 GetComputerNameExW, GetAdaptersInfo, RtlGetVersion strings ^[strings.txt:1648–1671]
Registry query T1012 RegOpenKeyExW, RegQueryValueExW strings ^[strings.txt:5615,6105]
HTTPS C2 T1071.001 crypto/tls, x509, WSAStartup, WSASocketW strings ^[strings.txt:1648–1650]
Credential theft T1555 ACR cluster capability; no static browser strings recovered
Crypto-wallet theft T1649 ACR cluster capability; inferred from family pattern

References

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • rabin2-info.txt — radare2 rabin2 -I output
  • strings.txt — strings extraction via GNU strings
  • binwalk.txt — binwalk embedded-artefact scan (PKCS certificate at 0x270208)
  • exiftool.json — ExifTool PE metadata
  • metadata.json / triage.json — OpenCTI connector metadata
  • capa.txt: capa signatures unavailable (missing signature database)
  • floss.txt: floss failed (argument-parsing error in triage pipeline)
  • dynamic-analysis.md: CAPE skipped (no Windows guest)