43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002stealc: 43998b11d473 — contested OpenCTI label; Go PE64+ infostealer with quiverquant.com Authenticode
Executive Summary
OpenCTI tagged this sample stealc and vidar, but static analysis reveals a Go-compiled PE64+ infostealer that shares every build fingerprint with the acrstealer cluster: the quiverquant.com/WE1 self-signed Authenticode chain, randomized main.* function names, absent .rsrc section, and Go runtime syscall modules for ADVAPI32, CRYPT32, SHELL32, WS2_32, and NTDDL. No Stealc-specific strings (ssstealer, keyboard.txt, SQLite, MSVC RTTI) are present. This is an ACR stealer sibling mislabelled by upstream telemetry. Static-only; CAPE skipped (no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002 |
| File name | Setup.exe |
| File type | PE32+ executable (GUI) x86-64, 8 sections ^[file.txt] |
| Size | 2 558 592 bytes ^[metadata.json] |
| Compiler | Go (rabin2-info lang: go) ^[rabin2-info.txt] |
| Build ID | 7_tz-i36QEjsdducXfBp/uuiYeAXztcZbXuVgGQ76/l0tJh0JepwHKP4EKH5JP/bEaRFPbIsSYY0GChaRgE ^[strings.txt:9] |
| Linker | Go internal linker (MajorLinkerVersion 3.0) ^[pefile.txt] |
| Base address | 0x140000000 ^[pefile.txt] |
| Signing | Self-signed Authenticode CN=quiverquant.com, issuer=WE1 ^[binwalk.txt] |
| Sections | .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab — no .rsrc ^[pefile.txt] |
| Imports | kernel32.dll only (Go runtime resolves the rest at load time via syscall.LazyDLL) ^[pefile.txt] |
Build / RE
Toolchain
- Go compiler, CGO-disabled (
internal/syscall/windowsmodules dominate the string table). ^[strings.txt] - No
go.modpath visible;-trimpathwas likely used. The randomizedmain.*symbols (main.Iwqvqjh,main.Zwmtinke,main.Ydjyxjzqx,main.Fpwtmqlpgrflom,main.Htvsewazzpeazyk,main.Rmgtfxvmqqmawaf,main.Ayqgkkhzzo,main.rbyigyjpwtzl,main.ibesfcochvgie,main.hssehuow,main.Ypxucxssb) match the golang-stealer-build-pattern observed across the ACR/Lumma/OrderRe cluster. ^[strings.txt:1000–1414] - Standard Go runtime section layout with
.symtabpresent (not stripped).
Packing / Obfuscation
- None. No UPX, Themida, or custom packer. Go runtime strings are unobfuscated. ^[strings.txt]
- No embedded payload resource or encrypted overlay. The full 2.5 MB is compiled Go code plus the security directory.
Anti-analysis
- Minimal static anti-analysis. No VM-detection strings, no debug checks in the visible string set. Go binaries typically rely on runtime environment checks rather than compile-time anti-debug.
- The
quiverquant.comcertificate is a self-signed fabrication — it will fail Windows Authenticode validation but may pass superficial triage. ^[binwalk.txt]
Code quality
- 11 randomized
main.*functions (relatively small compared to the 64+ seen in some ACR siblings), suggesting a lighter build or older builder template. ^[strings.txt:1000–1414] - Full exception-handling metadata in
.pdataand.xdata— standard Go Windows ABI.
Deploy / ATT&CK (static inference only)
No dynamic execution was possible (CAPE skipped — no Windows guest). The following is inferred from imports and strings.
| Technique | Evidence | Confidence |
|---|---|---|
| T1082 System Information Discovery | GetComputerNameExW, GetAdaptersInfo, GetAdaptersAddresses, GetProcessMemoryInfo, RtlGetVersion in Go runtime syscall strings ^[strings.txt:1648–1671] |
high |
| T1012 Query Registry | RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegCreateKeyExW, RegDeleteValueW, RegEnumValueW in internal/syscall/windows/registry strings ^[strings.txt:5615,6105,8597–8599] |
high |
| T1071.001 Application Layer Protocol: Web | crypto/tls, x509, net/http (implied by Go runtime), WSAStartup, WSASocketW, WSARecv, WSASend, dnsapi.dll, ws2_32.dll ^[strings.txt:1648–1650] |
medium |
| T1041 Exfiltration Over C2 | HTTPS client implied by TLS + socket surface; no hardcoded C2 URL recovered statically | low |
| T1555 Credentials from Password Stores | Standard ACR stealer capability (see acrstealer), but no browser-specific strings recovered statically — likely runtime-decoded | medium |
| T1649 Steal Crypto Wallet | Same as above; ACR cluster fingerprint includes wallet/seed regex harvesting | medium |
C2 Infrastructure
- No static C2 strings recovered. The ACR cluster typically uses PRNG-seeded C2 URL decoding at runtime (see prng-seeded-c2-url-decoding); static string extraction yields nothing.
Decompiled Behavior
Ghidra was not invoked for this sample because the Go runtime produces tens of thousands of small functions and the decompiler output is dominated by runtime internals. Radare2 confirms the entry point at 0x140072640 (Go runtime.main → main.main chain). The 11 main.* functions are the only non-runtime logic; their names are randomized and their bodies are not trivially decompilable without extensive Go plugin setup.
The control flow is standard for a Go Windows executable:
runtime.rt0_gosets up TLS and g0 stack.runtime.maininitializes packages and spawns goroutines.main.main(one of the 11 randomized functions) executes the stealer payload.- Network and registry operations use Go's
internal/syscall/windowswrappers, which callsyscall.SyscallNthroughkernel32.dll!GetProcAddressresolution. ^[strings.txt:5084–5094]
Interesting Tidbits
- The
quiverquant.com/WE1certificate chain is a high-confidence ACR cluster fingerprint. It has now been observed on at least eight samples in this corpus (see acrstealer). Any future PE carrying this chain should be treated as ACR-family until proven otherwise. - OpenCTI co-labelled this sample
vidaras well. The existingvidar.mdpage already documents a contested sample (94cf86f6) that carries the exact samequiverquant.com/WE1chain and resolves to ACR. This strengthens the conclusion that bothstealcandvidarlabels are false positives for the ACR builder pipeline. - The
.symtabsection is unusually large (0x1B15B bytes), indicating an unstripped build. This is atypical for malware but common in Go binaries where the linker strips less aggressively than MSVC. - No
.rsrcsection means no icon group, no version info masquerade, and no manifest resource — a clean, minimal Go build.
How To Mess With It (Homelab Replication)
- Toolchain: Go 1.25.x for Windows amd64,
CGO_ENABLED=0. - Build flags:
go build -trimpath -ldflags "-s -w"to produce a minimal PE. - Sign it: Generate a self-signed cert with
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=quiverquant.com", then sign withosslsigncodeor a Go signing tool. - Randomize: Use a simple script to rename
main.*functions viago:linknameor build a custom obfuscator that rewrites Go symbol table entries post-build. - Add capability: Import
crypto/tls,net/http,golang.org/x/sys/windows/registryto replicate the network + registry surface observed here. - Verification: Run
rabin2 -I— confirmlang: go,signed: true, and no.rsrcsection.
Deployable Signatures
YARA rule
rule ACR_Stealer_Quiverquant_Cert
{
meta:
description = "ACR stealer family — Go PE64+ signed with self-signed quiverquant.com/WE1 cert"
author = "PacketPursuit"
date = "2026-08-14"
hash = "43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002"
strings:
$go_build = "Go build ID:" ascii
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$mod_advapi = "syscall.modadvapi32" ascii
$mod_crypt = "syscall.modcrypt32" ascii
$mod_ws2 = "syscall.modws2_32" ascii
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)+4) == 0x00004550 and // PE signature
$go_build and
any of ($cert_cn, $cert_issuer) and
2 of ($mod_advapi, $mod_crypt, $mod_ws2)
}
Behavioral fingerprint
This binary is a Go-compiled Windows PE64+ executable with no .rsrc section, signed with a self-self Authenticode certificate whose subject CN is quiverquant.com and issuer is WE1. It loads kernel32.dll for syscall trampoline resolution, then uses Go's internal/syscall/windows packages to access the registry (ADVAPI32), crypto (CRYPT32), and network (WS2_32, DNSAPI) subsystems. No hardcoded C2 strings are present in the PE; network targets are likely decoded at runtime via a PRNG-seeded transform consistent with the ACR/Lumma cluster pattern.
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 43998b11d473dd4ddc92545ef21b5bde25d99ca31b7c6346f89ced93d9574002 |
|
| File name | Setup.exe |
Social-engineering masquerade |
| Certificate CN | quiverquant.com |
Self-signed, ACR cluster fingerprint |
| Certificate issuer | WE1 |
|
| Section anomaly | No .rsrc |
Common in ACR Go builds |
Detection Signatures
| Capability | ATT&CK | Evidence |
|---|---|---|
| System info discovery | T1082 | GetComputerNameExW, GetAdaptersInfo, RtlGetVersion strings ^[strings.txt:1648–1671] |
| Registry query | T1012 | RegOpenKeyExW, RegQueryValueExW strings ^[strings.txt:5615,6105] |
| HTTPS C2 | T1071.001 | crypto/tls, x509, WSAStartup, WSASocketW strings ^[strings.txt:1648–1650] |
| Credential theft | T1555 | ACR cluster capability; no static browser strings recovered |
| Crypto-wallet theft | T1649 | ACR cluster capability; inferred from family pattern |
References
- Artifact ID:
02655efe-b92e-44ae-9112-caadd77cf8d4 - Source: OpenCTI (MalwareBazaar connector), labels
stealc,vidar,go,signed - Related wiki pages: acrstealer, vidar, stealc, golang-stealer-build-pattern, prng-seeded-c2-url-decoding
Provenance
file.txt— file(1) outputpefile.txt— pefile Python library header dumprabin2-info.txt— radare2rabin2 -Ioutputstrings.txt— strings extraction via GNU stringsbinwalk.txt— binwalk embedded-artefact scan (PKCS certificate at 0x270208)exiftool.json— ExifTool PE metadatametadata.json/triage.json— OpenCTI connector metadata- capa.txt: capa signatures unavailable (missing signature database)
- floss.txt: floss failed (argument-parsing error in triage pipeline)
- dynamic-analysis.md: CAPE skipped (no Windows guest)