typeanalysisfamilylummastealerconfidencehighcreated2026-08-15updated2026-08-15infostealergolangsigningobfuscationc2defense-evasion
SHA-256: 46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c

lummastealer: 46e32500 — Go 1.25.4 PE32, blizzard-tecnica.com R12-signed, standard PRNG C2 decoder variant

Executive Summary

Ninth confirmed Lumma-native sibling. Go 1.25.4 PE32 GUI static binary, Authenticode-signed with a Let's Encrypt R12 certificate for blizzard-tecnica.com. No .rsrc section. Fifty-one randomized main.* function names. Standard PRNG sleep gate (800–1120 s) and runtime-decoded C2 URL. RWX memory staging for reflective payload execution. Filename ws-Setup-Complete.exe is a social-engineering masquerade. No dynamic execution available.

What It Is

  • SHA-256: 46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c
  • Filename: ws-Setup-Complete.exe
  • Type: PE32 executable (GUI) Intel 80386, 6 sections, 1.78 MB ^[file.txt]
  • Compiler: Go 1.25.4 (go1.25.4 in strings, Go build ID present) ^[strings.txt:1615] ^[strings.txt:7]
  • Signing: Authenticode valid, CN=blizzard-tecnica.com, issuer=R12 (Let's Encrypt), validity 2026-04-27 to 2026-07-26 ^[binwalk.txt:8-9] ^[openssl extraction from IMAGE_DIRECTORY_ENTRY_SECURITY]
  • Resources: No .rsrc section ^[pefile.txt section list]
  • Symbols: 51 randomized main.* functions (e.g., main.gvccyoryltpma, main.cnqixlpw, main.bohzbto) ^[r2:sym.main.* list]

This sample belongs to the Lumma-native cert chain (blizzard-tecnica.com/R12), not the contested ACR quiverquant.com/WE1 chain. It is a sibling of 040e0d76, 90d54589, 7b74bea7, fa41d6b4, and f04032b3.

How It Works

Entry point is standard Go runtime.main → main.main. main.main seeds math/rand with a time-derived value and calls math/rand.Intn(0x320) and math/rand.Intn(0x1868f), producing a sleep gate of roughly 800–1120 seconds before the payload activates. ^[r2:sym.main.main @ 0x48cfa0]

After the gate, main.main calls main.bohzbto, which:

  1. Copies a ~47 KB embedded blob from .rdata to a freshly allocated RWX region (VirtualAlloc with PAGE_EXECUTE_READWRITE, 0x3000|0x40). ^[r2:sym.main.bohzbto @ 0x48afe0]
  2. Calls main.gvccyoryltpma and main.cnqixlpw — likely a decryption or deobfuscation routine followed by reflective execution.
  3. Uses math/rand.Float64 and time.Now/time.Time.UnixNano heavily, consistent with the PRNG-based C2 URL decoding observed across this cluster.

No hardcoded C2 URL is present in strings; the C2 endpoint is resolved at runtime via the PRNG transform. This is the standard PRNG C2 decoder variant (not the custom in-memory PE parser + multi-pass decoder seen in siblings 90d54589 and fa41d6b4).

Decompiled Behavior

sym.main.main (0x48cfa0): seeds RNG, computes two Intn bounds, then calls sym.main.pzkyifx (floating-point math helper, likely PRNG state transformation) and sym.main.bohzbto. ^[r2:sym.main.main]

sym.main.bohzbto (0x48afe0): large function (~3400 bytes of decompiled pseudocode). Key behaviours:

  • rep movsd copies 0xB940 bytes from .rdata (0x4cc83c) to stack, then to RWX heap. ^[r2:sym.main.bohzbto:0x48b001]
  • Calls sym.main.aulmlzfo (wrapper around VirtualAlloc with 0x3000, 0x40). ^[r2:sym.main.bohzbto:0x48b0b4]
  • Calls sym.main.gvccyoryltpma and sym.main.cnqixlpw on the copied buffer. ^[r2:sym.main.bohzbto:0x48b2ed]
  • Uses time.Now, math_rand.NewSource, math_rand._Rand_.Float64, and math_rand._Rand_.Intn repeatedly — the PRNG C2 decoding loop. ^[r2:sym.main.bohzbto:0x48b3b3]

sym.main.pzkyifx (0x48a870): small floating-point routine using math.Sin, mulsd, divsd, and addsd on constant pools — part of the PRNG transform or time-based C2 decoder. ^[r2:sym.main.pzkyifx]

C2 Infrastructure

No static C2 URL recovered. The family uses PRNG-seeded C2 URL decoding at runtime. Historical Lumma-native siblings with the same cert chain have not yielded plaintext C2 strings either. C2 transport is inferred to be HTTPS via Go net/http + crypto/tls (present in the statically linked runtime). ^[strings.txt:1542]

Interesting Tidbits

  • Filename masquerade: ws-Setup-Complete.exe mimics a software-setup completion wrapper. No VS_VERSIONINFO resource to complete the illusion (no .rsrc section).
  • Certificate opsec: 90-day Let's Encrypt R12 cert, auto-renewable, low friction. The same CN has been reused across at least five prior siblings.
  • Standard variant: This build lacks the custom in-memory PE parser and multi-pass byte-transform decoder seen in 90d54589 and fa41d6b4. It is a lighter build, closer to 7b74bea7 and f04032b3.
  • No dynamic detonation: CAPE skipped because no Windows guest is available. All TTPs are statically inferred.

Deployable Signatures

YARA

rule lummastealer_go1254_blizzard_tecnica {
    meta:
        description = "Lumma native Go 1.25.4 infostealer with blizzard-tecnica.com R12 cert chain"
        author = "PacketPursuit"
        date = "2026-08-15"
        sha256 = "46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c"
    strings:
        $go_build = "Go build ID:"
        $go_ver = "go1.25.4"
        $cert_cn = "blizzard-tecnica.com"
        $math_rand = "math/rand"
        $crypto_tls = "crypto/tls"
        $main_pattern = /main\.[a-zA-Z]{10,20}/
    condition:
        uint16(0) == 0x5a4d and
        filesize < 3MB and
        $go_build and $go_ver and
        $cert_cn and
        $math_rand and $crypto_tls and
        #main_pattern > 40
}

IOC List

Indicator Value Notes
SHA-256 46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c
SHA-1 1e3b731abe468e86f61736362e69c9f621199fbf .text section hash
Filename ws-Setup-Complete.exe Social-engineering masquerade
Certificate CN blizzard-tecnica.com Let's Encrypt R12
Cert validity 2026-04-27 – 2026-07-26 90-day window
Sleep gate ~800–1120 s PRNG Intn(0x320) + Intn(0x1868f)

Behavioral Fingerprint

A Go 1.25.4 PE32 GUI executable with no .rsrc section, 40+ randomized main.* symbols, and an Authenticode signature from a Let's Encrypt R12 cert with CN containing blizzard-tecnica.com. On launch it seeds math/rand from system time, sleeps 13–19 minutes, allocates RWX memory via VirtualAlloc, copies an embedded blob from .rdata, and invokes a chain of randomized main.* functions that perform floating-point math (math.Sin, mulsd, divsd) and time.Now/UnixNano calls before initiating HTTPS outbound communication.

Detection Signatures

  • MITRE ATT&CK: T1204.002 (User Execution: Malicious File), T1055 (Process Injection — inferred from RWX alloc + indirect execution), T1027.002 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion: Time-Based Evasion), T1071.001 (Application Layer Protocol: Web Protocols — inferred HTTPS), T1555 (Credentials from Password Stores — inferred from family behavior).

References

Provenance

  • Static analysis: file, exiftool, pefile, strings, rabin2, radare2 (analysis level 2, 2039 functions recovered), binwalk
  • Certificate extraction: Python pefile + OpenSSL pkcs7/x509
  • Report generated 2026-08-15 by Demetrian Titus (Hermes agent, pp-hermes)
  • Dynamic analysis skipped: no CAPE Windows guest available ^[dynamic-analysis.md]