typeanalysisfamilyacrstealerconfidencehighcreated2026-07-31updated2026-07-31infostealermalware-familygolangsigning
SHA-256: 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd

acrstealer: 44f594e2 — Twelfth confirmed sibling, module aElVPjiacFfVnfJ

Executive Summary

This sample is the twelfth confirmed sibling of the acrstealer Go infostealer cluster. It shares the atom.hutsell.com / WR3 self-signed Authenticode certificate with siblings ef262340 and 6cbac6bc, uses the same Go 1.18.5 toolchain, and follows the identical build pattern (PE32 x86, null PE timestamp, randomized main package function names, .rsrc icon masquerade, no static C2). The distinguishing feature is its unique module path (aElVPjiacFfVnfJ) and individualized randomized function names. No custom PE parser or multi-pass decoder is present, matching the simpler build tier observed in the atom.hutsell.com cert sub-cluster. ^[entities/acrstealer.md]

What It Is

Field Value
SHA-256 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd
Size 2,307,200 bytes (2.3 MB)
File type PE32 executable (GUI) Intel 80386, 7 sections ^[file.txt]
Compiler Go 1.18.5 (GOARCH=386, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:8] ^[strings.txt:1067]
Build ID fBtfU4fENtSAIzIYuYBm/nU4xz4_Z_81MLWbxiAzI/nyi7obTvSOnnBmJcO9Gl/OT1RobHpFXNibKh0VU-Y ^[strings.txt:8]
Module path aElVPjiacFfVnfJ (randomized, 14 chars) ^[strings.txt:1069]
Linker Go internal linker v3.0 ^[pefile.txt]
PE timestamp 0x0 (null, standard for Go) ^[pefile.txt]
Stripped Yes (IMAGE_FILE_DEBUG_STRIPPED) ^[pefile.txt]
Signed Yes — self-signed Authenticode, CN=atom.hutsell.com, Issuer=WR3, Serial=4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe, validity 2026-04-21 to 2026-07-20 ^[pefile.txt] ^[binwalk.txt]
VS_VERSIONINFO Absent ^[pefile.txt]
Resources 4×RT_ICON (1×ICO 1128B, 1×16936B, 1×67624B, 1×52351B PNG 256×256), 1×RT_GROUP_ICON ^[pefile.txt]
Family acrstealer (high confidence; overrides preliminary unattributed triage tag)

How It Works

This sample is a cluster-sibling build of the ACR stealer family. The threat logic is written in Go and compiled to a static PE32 x86 binary with the standard Go runtime. As with all observed ACR siblings:

  • C2 is runtime-decoded using a PRNG-seeded string transform; no C2 domains, IPs, or URLs appear in static strings. ^[entities/acrstealer.md]
  • Masquerade is achieved via a .rsrc section containing multiple application icons, including a 256×256 PNG. No VS_VERSIONINFO is present (empty version info is a family fingerprint).
  • Imports are minimal: only 39 kernel32.dll APIs are imported through the standard IAT; all other Windows APIs (WinInet, WinHTTP, advapi32, crypt32, ws2_32) are resolved at runtime via the Go syscall package or loaded dynamically through syscall.NewLazyDLL. ^[pefile.txt]
  • No custom in-memory PE parser or multi-pass byte-transform decoder is present in this build, distinguishing it from the more complex blizzard-tecnica.com / R12 cert sub-cluster (siblings 7620884e, 90d54589, fa41d6b4). This places it in the simpler tier alongside ef262340 and 6cbac6bc.

Decompiled Behavior

The entry point at 0x00457c30 is the standard Go runtime bootstrap runtime.main, not malware-specific logic. ^[r2:entry0] The decompiled flow shows:

  1. MMX/CPUID check — validates processor support (GenuineIntel or AuthenticAMD) before continuing. ^[r2:entry0]
  2. Runtime initialization — standard Go rt0_go sequence: runtime.args, runtime.osinit, runtime.schedinit, then goroutine creation and scheduler entry. ^[r2:entry0]
  3. No TLS callbacks — the IMAGE_DIRECTORY_ENTRY_TLS is empty, consistent with Go binaries. ^[pefile.txt]
  4. No anti-debug or VM detection in the entry path — Go runtime does not include anti-analysis gates in the bootstrap.

Malicious behavior lives in the randomized main.* functions (e.g., main.Hefsxw, main.Nwvmyypcpbs, main.ynahqpgunqeinq) which are called after runtime.main spawns the application goroutine. Static decompilation of these functions yields no plaintext C2 strings, confirming runtime decoding.

C2 Infrastructure

No static C2 indicators recovered.

Per the ACR stealer family pattern, C2 strings are decoded at runtime via a PRNG-seeded multi-pass transform. ^[entities/acrstealer.md] The static string surface contains only Go runtime error strings, Windows API names, and randomized function/type identifiers. No hardcoded domains, IPs, URLs, or Telegram bot tokens are present.

Interesting Tidbits

  • Certificate triplet: This is the third sibling to use the identical atom.hutsell.com / WR3 self-signed certificate. The certificate validity window (Apr–Jul 2026) overlaps with the ef262340 and 6cbac6bc builds, suggesting a shared builder environment or certificate batch rather than per-sample generation. ^[pefile.txt]
  • Module path entropy: The module path aElVPjiacFfVnfJ is 14 characters of mixed-case alphanumeric — shorter than some siblings (e.g., PfeYrYvazVUGgZq at 16 chars) but within the family pattern of randomized module names. ^[strings.txt:1069]
  • Icon consistency: The .rsrc section contains the same structural pattern as sibling ef262340: one tiny ICO (1128B) and three larger PNGs, culminating in a 256×256 PNG. The total resource payload (~118KB) is nearly identical, suggesting a builder-template with fixed icon assets. ^[pefile.txt]
  • No UPX or packer: .text entropy is 6.18, within the normal range for Go binaries. No packer, crypter, or obfuscator beyond Go's standard trimpath and randomized symbol names. ^[pefile.txt]
  • Import-table minimalism: Only kernel32.dll is in the IAT. The Go syscall package loads advapi32.dll, ws2_32.dll, crypt32.dll, shell32.dll, netapi32.dll, secur32.dll, userenv.dll, iphlpapi.dll, and mswsock.dll at runtime via syscall.NewLazyDLL. ^[strings.txt:994] ^[pefile.txt]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 windows/386

# Install Go 1.18.5
wget https://go.dev/dl/go1.18.5.windows-amd64.zip
# Build a comparable PE
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" .

Verification: Compare your reproducer's strings output to this sample. You should see:

  • go1.18.5 in .rdata
  • Go build ID in the expected format
  • ~39 kernel32.dll imports only
  • No VS_VERSIONINFO
  • .rsrc with 4+ icon entries if you embed rsrcsyso or equivalent

What you'll learn: How Go static binaries appear in PE analysis tools, why the IAT is minimal, and how runtime DLL loading via syscall.NewLazyDLL evades static import-table analysis.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1185_AtomHutsell_Sibling
{
    meta:
        description = "ACR Stealer Go 1.18.5 sibling with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-07-31"
        sha256 = "44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd"
        family = "acrstealer"
    strings:
        $go_ver = "go1.18.5" ascii wide
        $mod_path = "path\taElVPjiacFfVnfJ" ascii wide
        $cert_cn = "atom.hutsell.com" ascii wide
        $issuer_wr3 = "WR3" ascii wide
        $buildid = "Go build ID:" ascii wide
        // Go internal linker signature
    condition:
        uint16(0) == 0x5A4D and
        filesize > 2MB and filesize < 3MB and
        ($go_ver and $buildid) and
        (any of ($cert_cn, $issuer_wr3, $mod_path))
}

Behavioral Hunt Query (Sigma-style KQL)

title: ACR Stealer Behavioral Fingerprint
description: Detects ACR stealer runtime behavior based on observed family TTPs
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: '\.exe'
    - CommandLine|contains: 
      - '-ep bypass'
      - 'powershell'
  # High-signal: Go binary with minimal IAT (only kernel32) that loads ws2_32/advapi32/crypt32 at runtime
  # Requires ETW/AMSI telemetry or memory inspection
  condition: selection
falsepositives:
  - Legitimate Go applications (rare on endpoints)
level: medium

IOC List

Indicator Value Type
SHA-256 44f594e2a9168c6de0d3f74e0d493920fac5210a49ebc73b6bd292eede9e81cd Hash
SSDeep 49152:VBoEgsDZx4VaVtQkwGjMVeOMSfa7iJuYEYD1gpDZ:VBL3D74VaVEA6ENZ Fuzzy hash
TLSH T1D5B2F02B621EC4D47B6C7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A6D4B7A (placeholder; see tlsh.txt) Fuzzy hash
Certificate CN atom.hutsell.com Self-signed cert
Certificate Issuer WR3 Self-signed issuer
Certificate Serial 4c:3a:4a:81:98:f1:cb:ef:10:10:f5:fb:31:57:d6:fe Serial number
Module Path aElVPjiacFfVnfJ Go module name
Build ID fBtfU4fENtSAIzIYuYBm/nU4xz4_Z_81MLWbxiAzI/nyi7obTvSOnnBmJcO9Gl/OT1RobHpFXNibKh0VU-Y Go build ID
Go Version go1.18.5 Compiler version

Behavioral Fingerprint

This binary is a Go 1.18.5-compiled PE32 x86 static binary with a null PE timestamp and no VS_VERSIONINFO. It imports only 39 kernel32.dll APIs through the standard IAT, then loads advapi32.dll, ws2_32.dll, crypt32.dll, shell32.dll, and netapi32.dll at runtime via the Go syscall package. It contains a .rsrc section with 4+ application icons (including a 256×256 PNG) but no version information. The main package contains 20+ randomized function names (e.g., main.Hefsxw, main.ynahqpgunqeinq). No static C2 strings are present; network behavior is mediated through Go's net/http and crypto/tls packages with runtime-decoded endpoints. The binary is signed with a self-signed Authenticode certificate bearing CN atom.hutsell.com and issuer WR3.

Detection Signatures

MITRE ATT&CK Technique Observation Evidence
T1055 — Process Injection Inferred: Go malware commonly uses goroutine-based execution; no static injection APIs observed Static-only inference
T1071 — Application Layer Protocol HTTPS C2 via Go crypto/tls + net/http (family pattern) ^[entities/acrstealer.md]
T1083 — File and Directory Discovery Inferred from FindFirstFileW, GetFileAttributesExW in Go syscall linkage ^[strings.txt:1017]
T1135 — Network Share Discovery Inferred from NetShareAdd, NetShareDel in Go syscall linkage ^[strings.txt:994]
T1547.001 — Registry Run Keys Not observed statically; may be runtime-decoded N/A
T1555 — Credentials from Password Stores Inferred family behavior (browser credential theft) ^[entities/acrstealer.md]
T1567 — Exfiltration Over Web Service HTTPS POST to runtime-decoded C2 (family pattern) ^[entities/acrstealer.md]

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Build-pattern concept
  • Sample source: MalwareBazaar / OpenCTI (artifact df18121f-8aa2-4545-96bd-780b7d07fcbf)
  • Sibling analysis: /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html (tenth sibling, same cert)
  • Sibling analysis: /intel/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e.html (eleventh sibling, same cert, no .rsrc)

Provenance

  • file.txt — file(1) output
  • strings.txt — strings extraction (Go runtime, module path, build ID)
  • pefile.txt — pefile.py PE header and section analysis (certificate directory, resource enumeration, imports)
  • rabin2-info.txt — radare2 binary summary (signed=true, stripped=true, overlay=true)
  • binwalk.txt — embedded artefact scan (PNG 256×256 in .rsrc, DER certificate at overlay)
  • exiftool.json — ExifTool metadata (PE32, GUI subsystem, linker v3.0)
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)
  • Tools: pefile 2023.x, ExifTool 12.76, radare2 5.9.x, binwalk 2.3.4