46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8clummastealer: 46e32500 — Go 1.25.4 PE32, blizzard-tecnica.com R12-signed, standard PRNG C2 decoder variant
Executive Summary
Ninth confirmed Lumma-native sibling. Go 1.25.4 PE32 GUI static binary, Authenticode-signed with a Let's Encrypt R12 certificate for blizzard-tecnica.com. No .rsrc section. Fifty-one randomized main.* function names. Standard PRNG sleep gate (800–1120 s) and runtime-decoded C2 URL. RWX memory staging for reflective payload execution. Filename ws-Setup-Complete.exe is a social-engineering masquerade. No dynamic execution available.
What It Is
- SHA-256:
46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c - Filename:
ws-Setup-Complete.exe - Type: PE32 executable (GUI) Intel 80386, 6 sections, 1.78 MB ^[file.txt]
- Compiler: Go 1.25.4 (
go1.25.4in strings, Go build ID present) ^[strings.txt:1615] ^[strings.txt:7] - Signing: Authenticode valid, CN=
blizzard-tecnica.com, issuer=R12(Let's Encrypt), validity 2026-04-27 to 2026-07-26 ^[binwalk.txt:8-9] ^[openssl extraction from IMAGE_DIRECTORY_ENTRY_SECURITY] - Resources: No
.rsrcsection ^[pefile.txt section list] - Symbols: 51 randomized
main.*functions (e.g.,main.gvccyoryltpma,main.cnqixlpw,main.bohzbto) ^[r2:sym.main.* list]
This sample belongs to the Lumma-native cert chain (blizzard-tecnica.com/R12), not the contested ACR quiverquant.com/WE1 chain. It is a sibling of 040e0d76, 90d54589, 7b74bea7, fa41d6b4, and f04032b3.
How It Works
Entry point is standard Go runtime.main → main.main. main.main seeds math/rand with a time-derived value and calls math/rand.Intn(0x320) and math/rand.Intn(0x1868f), producing a sleep gate of roughly 800–1120 seconds before the payload activates. ^[r2:sym.main.main @ 0x48cfa0]
After the gate, main.main calls main.bohzbto, which:
- Copies a ~47 KB embedded blob from
.rdatato a freshly allocated RWX region (VirtualAllocwithPAGE_EXECUTE_READWRITE,0x3000|0x40). ^[r2:sym.main.bohzbto @ 0x48afe0] - Calls
main.gvccyoryltpmaandmain.cnqixlpw— likely a decryption or deobfuscation routine followed by reflective execution. - Uses
math/rand.Float64andtime.Now/time.Time.UnixNanoheavily, consistent with the PRNG-based C2 URL decoding observed across this cluster.
No hardcoded C2 URL is present in strings; the C2 endpoint is resolved at runtime via the PRNG transform. This is the standard PRNG C2 decoder variant (not the custom in-memory PE parser + multi-pass decoder seen in siblings 90d54589 and fa41d6b4).
Decompiled Behavior
sym.main.main (0x48cfa0): seeds RNG, computes two Intn bounds, then calls sym.main.pzkyifx (floating-point math helper, likely PRNG state transformation) and sym.main.bohzbto. ^[r2:sym.main.main]
sym.main.bohzbto (0x48afe0): large function (~3400 bytes of decompiled pseudocode). Key behaviours:
rep movsdcopies 0xB940 bytes from.rdata(0x4cc83c) to stack, then to RWX heap. ^[r2:sym.main.bohzbto:0x48b001]- Calls
sym.main.aulmlzfo(wrapper aroundVirtualAllocwith0x3000, 0x40). ^[r2:sym.main.bohzbto:0x48b0b4] - Calls
sym.main.gvccyoryltpmaandsym.main.cnqixlpwon the copied buffer. ^[r2:sym.main.bohzbto:0x48b2ed] - Uses
time.Now,math_rand.NewSource,math_rand._Rand_.Float64, andmath_rand._Rand_.Intnrepeatedly — the PRNG C2 decoding loop. ^[r2:sym.main.bohzbto:0x48b3b3]
sym.main.pzkyifx (0x48a870): small floating-point routine using math.Sin, mulsd, divsd, and addsd on constant pools — part of the PRNG transform or time-based C2 decoder. ^[r2:sym.main.pzkyifx]
C2 Infrastructure
No static C2 URL recovered. The family uses PRNG-seeded C2 URL decoding at runtime. Historical Lumma-native siblings with the same cert chain have not yielded plaintext C2 strings either. C2 transport is inferred to be HTTPS via Go net/http + crypto/tls (present in the statically linked runtime). ^[strings.txt:1542]
Interesting Tidbits
- Filename masquerade:
ws-Setup-Complete.exemimics a software-setup completion wrapper. No VS_VERSIONINFO resource to complete the illusion (no.rsrcsection). - Certificate opsec: 90-day Let's Encrypt R12 cert, auto-renewable, low friction. The same CN has been reused across at least five prior siblings.
- Standard variant: This build lacks the custom in-memory PE parser and multi-pass byte-transform decoder seen in
90d54589andfa41d6b4. It is a lighter build, closer to7b74bea7andf04032b3. - No dynamic detonation: CAPE skipped because no Windows guest is available. All TTPs are statically inferred.
Deployable Signatures
YARA
rule lummastealer_go1254_blizzard_tecnica {
meta:
description = "Lumma native Go 1.25.4 infostealer with blizzard-tecnica.com R12 cert chain"
author = "PacketPursuit"
date = "2026-08-15"
sha256 = "46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c"
strings:
$go_build = "Go build ID:"
$go_ver = "go1.25.4"
$cert_cn = "blizzard-tecnica.com"
$math_rand = "math/rand"
$crypto_tls = "crypto/tls"
$main_pattern = /main\.[a-zA-Z]{10,20}/
condition:
uint16(0) == 0x5a4d and
filesize < 3MB and
$go_build and $go_ver and
$cert_cn and
$math_rand and $crypto_tls and
#main_pattern > 40
}
IOC List
| Indicator | Value | Notes |
|---|---|---|
| SHA-256 | 46e32500cd24395dd140293758e72fe8671217f5f5b0307858fc118a125aab8c |
|
| SHA-1 | 1e3b731abe468e86f61736362e69c9f621199fbf |
.text section hash |
| Filename | ws-Setup-Complete.exe |
Social-engineering masquerade |
| Certificate CN | blizzard-tecnica.com |
Let's Encrypt R12 |
| Cert validity | 2026-04-27 – 2026-07-26 | 90-day window |
| Sleep gate | ~800–1120 s | PRNG Intn(0x320) + Intn(0x1868f) |
Behavioral Fingerprint
A Go 1.25.4 PE32 GUI executable with no .rsrc section, 40+ randomized main.* symbols, and an Authenticode signature from a Let's Encrypt R12 cert with CN containing blizzard-tecnica.com. On launch it seeds math/rand from system time, sleeps 13–19 minutes, allocates RWX memory via VirtualAlloc, copies an embedded blob from .rdata, and invokes a chain of randomized main.* functions that perform floating-point math (math.Sin, mulsd, divsd) and time.Now/UnixNano calls before initiating HTTPS outbound communication.
Detection Signatures
- MITRE ATT&CK: T1204.002 (User Execution: Malicious File), T1055 (Process Injection — inferred from RWX alloc + indirect execution), T1027.002 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion: Time-Based Evasion), T1071.001 (Application Layer Protocol: Web Protocols — inferred HTTPS), T1555 (Credentials from Password Stores — inferred from family behavior).
References
- lummastealer — cluster entity page
- acrstealer — sibling cluster (contested attribution)
- golang-stealer-build-pattern — shared Go infostealer build artefacts
- fused-string-api-decoding — runtime API resolution technique observed in siblings
Provenance
- Static analysis:
file,exiftool,pefile,strings,rabin2, radare2 (analysis level 2, 2039 functions recovered),binwalk - Certificate extraction: Python
pefile+ OpenSSLpkcs7/x509 - Report generated 2026-08-15 by Demetrian Titus (Hermes agent, pp-hermes)
- Dynamic analysis skipped: no CAPE Windows guest available ^[dynamic-analysis.md]