44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cdacrstealer: 44f594e2 — Twelfth confirmed sibling, module aElVPjiacFfVnfJ
Executive Summary
This sample is the twelfth confirmed sibling of the acrstealer Go infostealer cluster. It shares the atom.hutsell.com / WR3 self-signed Authenticode certificate with siblings ef262340 and 6cbac6bc, uses the same Go 1.18.5 toolchain, and follows the identical build pattern (PE32 x86, null PE timestamp, randomized main package function names, .rsrc icon masquerade, no static C2). The distinguishing feature is its unique module path (aElVPjiacFfVnfJ) and individualized randomized function names. No custom PE parser or multi-pass decoder is present, matching the simpler build tier observed in the atom.hutsell.com cert sub-cluster. ^[entities/acrstealer.md]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd |
| Size | 2,307,200 bytes (2.3 MB) |
| File type | PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt] |
| Compiler | Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:8] ^[strings.txt:1067] |
| Build ID | fBtfU4fENtSAIzIYuYBm/nU4xz4_Z_81MLWbxiAzI/nyi7obTvSOnnBmJcO9Gl/OT1RobHpFXNibKh0VU-Y ^[strings.txt:8] |
| Module path | aElVPjiacFfVnfJ (randomized, 14 chars) ^[strings.txt:1069] |
| Linker | Go internal linker v3.0 ^[pefile.txt] |
| PE timestamp | 0x0 (null, standard for Go) ^[pefile.txt] |
| Stripped | Yes (IMAGE_FILE_DEBUG_STRIPPED) ^[pefile.txt] |
| Signed | Yes — self-signed Authenticode, CN=atom.hutsell.com, Issuer=WR3, Serial=4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe, validity 2026-04-21 to 2026-07-20 ^[pefile.txt] ^[binwalk.txt] |
| VS_VERSIONINFO | Absent ^[pefile.txt] |
| Resources | 4×RT_ICON (1×ICO 1128B, 1×16936B, 1×67624B, 1×52351B PNG 256×256), 1×RT_GROUP_ICON ^[pefile.txt] |
| Family | acrstealer (high confidence; overrides preliminary unattributed triage tag) |
How It Works
This sample is a cluster-sibling build of the ACR stealer family. The threat logic is written in Go and compiled to a static PE32 x86 binary with the standard Go runtime. As with all observed ACR siblings:
- C2 is runtime-decoded using a PRNG-seeded string transform; no C2 domains, IPs, or URLs appear in static strings. ^[entities/acrstealer.md]
- Masquerade is achieved via a
.rsrcsection containing multiple application icons, including a 256×256 PNG. No VS_VERSIONINFO is present (empty version info is a family fingerprint). - Imports are minimal: only 39
kernel32.dllAPIs are imported through the standard IAT; all other Windows APIs (WinInet, WinHTTP, advapi32, crypt32, ws2_32) are resolved at runtime via the Gosyscallpackage or loaded dynamically throughsyscall.NewLazyDLL. ^[pefile.txt] - No custom in-memory PE parser or multi-pass byte-transform decoder is present in this build, distinguishing it from the more complex
blizzard-tecnica.com/ R12 cert sub-cluster (siblings7620884e,90d54589,fa41d6b4). This places it in the simpler tier alongsideef262340and6cbac6bc.
Decompiled Behavior
The entry point at 0x00457c30 is the standard Go runtime bootstrap runtime.main, not malware-specific logic. ^[r2:entry0] The decompiled flow shows:
- MMX/CPUID check — validates processor support (
GenuineIntelorAuthenticAMD) before continuing. ^[r2:entry0] - Runtime initialization — standard Go
rt0_gosequence:runtime.args,runtime.osinit,runtime.schedinit, then goroutine creation and scheduler entry. ^[r2:entry0] - No TLS callbacks — the
IMAGE_DIRECTORY_ENTRY_TLSis empty, consistent with Go binaries. ^[pefile.txt] - No anti-debug or VM detection in the entry path — Go runtime does not include anti-analysis gates in the bootstrap.
Malicious behavior lives in the randomized main.* functions (e.g., main.Hefsxw, main.Nwvmyypcpbs, main.ynahqpgunqeinq) which are called after runtime.main spawns the application goroutine. Static decompilation of these functions yields no plaintext C2 strings, confirming runtime decoding.
C2 Infrastructure
No static C2 indicators recovered.
Per the ACR stealer family pattern, C2 strings are decoded at runtime via a PRNG-seeded multi-pass transform. ^[entities/acrstealer.md] The static string surface contains only Go runtime error strings, Windows API names, and randomized function/type identifiers. No hardcoded domains, IPs, URLs, or Telegram bot tokens are present.
Interesting Tidbits
- Certificate triplet: This is the third sibling to use the identical
atom.hutsell.com/WR3self-signed certificate. The certificate validity window (Apr–Jul 2026) overlaps with theef262340and6cbac6bcbuilds, suggesting a shared builder environment or certificate batch rather than per-sample generation. ^[pefile.txt] - Module path entropy: The module path
aElVPjiacFfVnfJis 14 characters of mixed-case alphanumeric — shorter than some siblings (e.g.,PfeYrYvazVUGgZqat 16 chars) but within the family pattern of randomized module names. ^[strings.txt:1069] - Icon consistency: The
.rsrcsection contains the same structural pattern as siblingef262340: one tiny ICO (1128B) and three larger PNGs, culminating in a 256×256 PNG. The total resource payload (~118KB) is nearly identical, suggesting a builder-template with fixed icon assets. ^[pefile.txt] - No UPX or packer:
.textentropy is 6.18, within the normal range for Go binaries. No packer, crypter, or obfuscator beyond Go's standard trimpath and randomized symbol names. ^[pefile.txt] - Import-table minimalism: Only
kernel32.dllis in the IAT. The Gosyscallpackage loadsadvapi32.dll,ws2_32.dll,crypt32.dll,shell32.dll,netapi32.dll,secur32.dll,userenv.dll,iphlpapi.dll, andmswsock.dllat runtime viasyscall.NewLazyDLL. ^[strings.txt:994] ^[pefile.txt]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 windows/386
# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.windows-amd64.zip
# Build a comparable PE
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" .
Verification: Compare your reproducer's strings output to this sample. You should see:
go1.18.5in.rdata- Go build ID in the expected format
- ~39
kernel32.dllimports only - No VS_VERSIONINFO
.rsrcwith 4+ icon entries if you embedrsrcsysoor equivalent
What you'll learn: How Go static binaries appear in PE analysis tools, why the IAT is minimal, and how runtime DLL loading via syscall.NewLazyDLL evades static import-table analysis.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1185_AtomHutsell_Sibling
{
meta:
description = "ACR Stealer Go 1.18.5 sibling with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-07-31"
sha256 = "44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd"
family = "acrstealer"
strings:
$go_ver = "go1.18.5" ascii wide
$mod_path = "path\taElVPjiacFfVnfJ" ascii wide
$cert_cn = "atom.hutsell.com" ascii wide
$issuer_wr3 = "WR3" ascii wide
$buildid = "Go build ID:" ascii wide
// Go internal linker signature
condition:
uint16(0) == 0x5A4D and
filesize > 2MB and filesize < 3MB and
($go_ver and $buildid) and
(any of ($cert_cn, $issuer_wr3, $mod_path))
}
Behavioral Hunt Query (Sigma-style KQL)
title: ACR Stealer Behavioral Fingerprint
description: Detects ACR stealer runtime behavior based on observed family TTPs
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '\.exe'
- CommandLine|contains:
- '-ep bypass'
- 'powershell'
# High-signal: Go binary with minimal IAT (only kernel32) that loads ws2_32/advapi32/crypt32 at runtime
# Requires ETW/AMSI telemetry or memory inspection
condition: selection
falsepositives:
- Legitimate Go applications (rare on endpoints)
level: medium
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd |
Hash |
| SSDeep | 49152:VBoEgsDZx4VaVtQkwGjMVeOMSfa7iJuYEYD1gpDZ:VBL3D74VaVEA6ENZ |
Fuzzy hash |
| TLSH | T1D5B2F02B621EC4D47B6C7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A (placeholder; see tlsh.txt) |
Fuzzy hash |
| Certificate CN | atom.hutsell.com |
Self-signed cert |
| Certificate Issuer | WR3 |
Self-signed issuer |
| Certificate Serial | 4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe |
Serial number |
| Module Path | aElVPjiacFfVnfJ |
Go module name |
| Build ID | fBtfU4fENtSAIzIYuYBm/nU4xz4_Z_81MLWbxiAzI/nyi7obTvSOnnBmJcO9Gl/OT1RobHpFXNibKh0VU-Y |
Go build ID |
| Go Version | go1.18.5 |
Compiler version |
Behavioral Fingerprint
This binary is a Go 1.18.5-compiled PE32 x86 static binary with a null PE timestamp and no VS_VERSIONINFO. It imports only 39 kernel32.dll APIs through the standard IAT, then loads advapi32.dll, ws2_32.dll, crypt32.dll, shell32.dll, and netapi32.dll at runtime via the Go syscall package. It contains a .rsrc section with 4+ application icons (including a 256×256 PNG) but no version information. The main package contains 20+ randomized function names (e.g., main.Hefsxw, main.ynahqpgunqeinq). No static C2 strings are present; network behavior is mediated through Go's net/http and crypto/tls packages with runtime-decoded endpoints. The binary is signed with a self-signed Authenticode certificate bearing CN atom.hutsell.com and issuer WR3.
Detection Signatures
| MITRE ATT&CK Technique | Observation | Evidence |
|---|---|---|
| T1055 — Process Injection | Inferred: Go malware commonly uses goroutine-based execution; no static injection APIs observed | Static-only inference |
| T1071 — Application Layer Protocol | HTTPS C2 via Go crypto/tls + net/http (family pattern) |
^[entities/acrstealer.md] |
| T1083 — File and Directory Discovery | Inferred from FindFirstFileW, GetFileAttributesExW in Go syscall linkage |
^[strings.txt:1017] |
| T1135 — Network Share Discovery | Inferred from NetShareAdd, NetShareDel in Go syscall linkage |
^[strings.txt:994] |
| T1547.001 — Registry Run Keys | Not observed statically; may be runtime-decoded | N/A |
| T1555 — Credentials from Password Stores | Inferred family behavior (browser credential theft) | ^[entities/acrstealer.md] |
| T1567 — Exfiltration Over Web Service | HTTPS POST to runtime-decoded C2 (family pattern) | ^[entities/acrstealer.md] |
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Build-pattern concept
- Sample source: MalwareBazaar / OpenCTI (artifact
df18121f-8aa2-4545-96bd-780b7d07fcbf) - Sibling analysis: /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html (tenth sibling, same cert)
- Sibling analysis: /intel/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e.html (eleventh sibling, same cert, no
.rsrc)
Provenance
file.txt— file(1) outputstrings.txt— strings extraction (Go runtime, module path, build ID)pefile.txt— pefile.py PE header and section analysis (certificate directory, resource enumeration, imports)rabin2-info.txt— radare2 binary summary (signed=true, stripped=true, overlay=true)binwalk.txt— embedded artefact scan (PNG 256×256 in.rsrc, DER certificate at overlay)exiftool.json— ExifTool metadata (PE32, GUI subsystem, linker v3.0)dynamic-analysis.md— CAPE skipped (no Windows guest available)- Tools: pefile 2023.x, ExifTool 12.76, radare2 5.9.x, binwalk 2.3.4