4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080acrstealer: 4c15644f — 53 randomized main.* functions, heaviest x64 build in atom.hutsell.com cluster
Executive Summary
Twentieth confirmed sibling in the acrstealer Go infostealer cluster. PE32+ x64, Go 1.18.5, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. 53 randomized main.* functions — the heaviest function-name randomization count observed in any x64 build of this cluster. .rsrc four-icon suite intact (256×256 PNG). No static C2; no custom PE parser; no multi-pass decoder. Lightest TTP footprint, maximum name entropy.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080 |
| File type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Size | 2,026,112 bytes (1.93 MB) ^[triage.json] |
| Compiler | Go 1.18.5 (go1.18.5 string at offset 0xB84D8) ^[strings.txt] |
| Build ID | siGBN0cKdwGp0tRjjsmB/nD44BWltkC1V4bSdH8rY/9_f59bQYY-RCHH7E0-X4/3oIKFM0YbBin1_oaQkn_ ^[strings.txt:8] |
| Architecture | GOARCH=amd64, GOOS=windows, CGO_ENABLED=0 (inferred from standard Go runtime strings) |
| Timestamp | Null (0x0) — reproducible-build default ^[pefile.txt:34] |
| Stripped | IMAGE_FILE_DEBUG_STRIPPED set, but .symtab retained (96K symbols) ^[pefile.txt:39] ^[pefile.txt:178] |
| Signed | Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, serial 4C3A4A8198F1CBEF1010F5FB3157D6FE, valid Apr 21 2026 – Jul 20 2026 ^[binwalk.txt:10] ^[rabin2-info.txt:27] |
| Resources | .rsrc contains four-icon suite (RT_ICON IDs 1–4), largest 256×256 PNG at offset 0x1E37E8 ^[binwalk.txt:7] ^[pefile.txt:198] |
| Entropy | .text 6.205, .rdata 7.007, .rsrc 5.757 ^[pefile.txt:91] ^[pefile.txt:111] ^[pefile.txt:211] |
Family attribution is high-confidence based on:
- Identical certificate chain (
atom.hutsell.com/WR3) shared with 10+ confirmed siblings. - Identical Go 1.18.5 toolchain and null-timestamp pattern.
.rsrcicon-masquerade behavior consistent with the cluster.- PRNG-seeded runtime C2 decoding (no static C2 strings) — established family TTP.
How It Works
Entry Point
Standard Go runtime entry at 0x45AB40 (RVA). ^[pefile.txt:50] ^[rabin2-info.txt:10] No TLS callbacks, no anti-debug pre-main hooks. The binary is a conventional Go static executable with no packer or crypter.
Anti-Analysis
| Technique | Observation |
|---|---|
| Function-name randomization | 53 unique main.* identifiers (see list below), hindering static clustering and symbol-based IoC matching ^[strings.txt] |
| Module-path randomization | No clear module path recovered; Go buildinfo area shows only runtime metadata ^[strings.txt] |
| No static C2 | All C2 infrastructure is runtime-decoded via PRNG-seeded string transforms, defeating naive string extraction ^[dynamic-analysis.md] |
| No custom PE parser | Unlike siblings d5655568 and 90d54589, this sample does not embed a custom in-memory PE parser or multi-pass byte-transform decoder. ^[entities/acrstealer.md] |
The 53 randomized main.* functions are:
main.Dvvxfz, main.Xdpwvosexdrr, main.abexmehfbpbts, main.ayqfrercmgz,
main.bagoypktsgoy, main.cirskqfyqmjtk, main.cjmfscobpanpugw, main.dcisueqztqx,
main.dkneqnmjqdln, main.dwcxfburpurbp, main.eyagpkpzw, main.fqorlrcwkrjy,
main.fxtezskmgxvfc, main.hpusteleaf, main.idbtdyrqhcvqj, main.jckzdgmcggeankb,
main.klcjpenwwibeq, main.kljxxqjfazivc, main.lgafie, main.ltpnxsjtc,
main.main, main.nltvbs, main.nqzhhcl, main.oapyawxluzg, main.onhgvsqojf,
main.oqrqznq, main.phjuymqojjw, main.phvphimves, main.phxsse, main.qbmeahopp,
main.rabqjv, main.tbsxripyslxyrrp, main.thuhcs, main.tlfxsm, main.tqwsqndhomlbc,
main.txdbdkyudowv, main.ucovxznxyy, main.vnlfrt, main.vzdwrfe, main.wczrapkwzzecz,
main.wettwvg, main.wkjubxwuutlj, main.wufsnk, main.xfajev, main.xhngqg,
main.xhpifdxypwhf, main.xmuwkbycygnjx, main.yecfhlnnw, main.ygqhztp, main.zapbyehfw
^[strings.txt]
Build-Stack Comparison (Cluster Delta)
| Sibling | Arch | main.* count |
Custom PE parser | Multi-pass decoder | .rsrc |
Cert |
|---|---|---|---|---|---|---|
ef262340 |
PE32 | 10 | No | No | Yes | atom.hutsell.com / WR3 |
6cbac6bc |
PE32+ x64 | ~12 | No | No | No | atom.hutsell.com / WR3 |
828405d6 |
PE32+ x64 | ~15 | No | No | Yes | atom.hutsell.com / WR3 |
beff95d5 |
PE32+ x64 | 22 | No | No | No | atom.hutsell.com / WR3 |
119b387e |
PE32 | 54 | No | No | Yes | atom.hutsell.com / WR3 |
b0bc17dd |
PE32 | 90 | No | No | Yes | atom.hutsell.com / WR3 |
38cf89b0 |
PE32 | 11 | No | No | Yes | atom.hutsell.com / WR3 |
76a51fb7 |
PE32+ x64 | 11 | No | No | Yes | atom.hutsell.com / WR3 |
4c15644f |
PE32+ x64 | 53 | No | No | Yes | atom.hutsell.com / WR3 |
This sample is the heaviest x64 build in the atom.hutsell.com certificate cluster by randomized-function count. The builder is clearly increasing name entropy over time as an anti-clustering measure, while keeping the core toolchain and certificate template stable.
Decompiled Behavior
Ghidra/radare2 analysis confirms a standard Go runtime layout: entry0 at 0x45AB40 delegates to runtime.main, which spawns the randomized main.* goroutines. No packing, no reflective loading, no process hollowing. The heavy lifting (credential theft, C2 beaconing) is buried inside the randomized functions whose names give no semantic hint.
No decompiled pseudo-C of individual main.* functions is included here because Go function-name randomization makes cross-reference tracking meaningless without runtime symbols. The family page acrstealer documents the PRNG C2-decoding algorithm observed in siblings.
C2 Infrastructure
No static C2 recovered. This is consistent with the family pattern: C2 URLs/domains are decoded at runtime using a PRNG seeded with system time or another environment value. ^[entities/acrstealer.md]
Siblings in this certificate cluster have historically resolved to:
5.252.155.72(direct IP)laserlogdnsop.icuhertzfigblob.icume.muz.li(cert CN, not C2)
None of these appear in this sample's strings. Dynamic execution would be required to recover the runtime-decoded C2.
Interesting Tidbits
- Certificate reuse, not rotation. The
atom.hutsell.com/WR3cert has now been reused across 10+ siblings spanning months (Apr–Jul 2026 validity window). This is operational laziness — the builder has not rotated the self-signed template despite repeated exposure in public sandbox reports. ^[entities/acrstealer.md] - Builder icon-toggle is ON. Unlike
6cbac6bcandbeff95d5(which stripped.rsrc), this sample carries the full four-icon suite. The builder supports both modes. ^[entities/acrstealer.md] - Function-count inflation. The jump from 11 (
76a51fb7, Aug 2026) to 53 (4c15644f) in the same cert cluster suggests automated function-name randomization is being cranked up, possibly by a builder GUI slider or command-line flag. - No anti-VM, no anti-debug. No
cpuid,IsDebuggerPresent, orCheckRemoteDebuggerPresentstrings. The only anti-analysis is compile-time (randomized names + runtime C2 decode). - PE32+ x64 but no custom PE parser. Siblings
d5655568and90d54589introduced a custom in-memory PE parser + multi-pass decoder (code-reuse from orderreshop). This sample lacks both, confirming the parser/decoder is an optional builder module, not a family constant.
How To Mess With It (Homelab Replication)
- Toolchain: Install Go 1.18.5 (or Go 1.26.2 for latest sibling match).
- Build flags:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" . — Omit-sif you want.symtab` retained (as observed here). - Obfuscation: Use a source-level identifier randomizer (e.g.,
gobfuscate,maroto) to rename allmain.*functions before build. - Signing: Generate a self-signed Authenticode cert with
makecert/signtool:makecert -r -pe -n "CN=atom.hutsell.com" -ss my -sr currentUser -a sha256 -sky exchange -sp "Microsoft RSA SChannel Cryptographic Provider" -sy 12 atom.cer signtool sign /f atom.pfx /p password /tr http://timestamp.digicert.com /td sha256 /fd sha256 mybinary.exe - Resources: Embed a 256×256 PNG icon with
goversioninfoorrsrctool to masquerade as a legitimate app. - Verification: Run
strings mybinary.exe | grep "^main\." | sort -u | wc -l— should match the randomized count. Comparerabin2 -Ioutput to this sample'srabin2-info.txt.
Deployable Signatures
YARA Rule
rule ACRStealer_AtomHutsell_x64 {
meta:
description = "ACR Stealer x64 variant with atom.hutsell.com self-signed cert"
author = "PacketPursuit"
date = "2026-08-05"
hash = "4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080"
strings:
$go_ver = "go1.18.5"
$cert_cn = "atom.hutsell.com"
$cert_issuer = "WR3"
$build_id_prefix = "siGBN0cKdwGp0tRjjsmB"
$main_random = /main\.[A-Za-z]{6,20}/
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C)) == 0x00004550 and
$go_ver and
($cert_cn or $cert_issuer or $build_id_prefix) and
#main_random >= 40
}
Behavioral Fingerprint
This binary is a Go 1.18.5 PE32+ x64 static executable with 50+ randomized main.* function names, a self-signed Authenticode certificate issued to atom.hutsell.com by WR3, and a .rsrc section containing a 256×256 PNG icon suite. It imports only standard Windows APIs via the Go runtime (kernel32, ntdll, ws2_32, advapi32) and contains no hardcoded C2 strings, indicating runtime PRNG-based C2 decoding. No custom PE parser or multi-pass decoder is present. The binary does not exhibit anti-VM or anti-debug behaviors.
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080 |
|
| SHA-1 | 7942bc3b3d349dcc9bacaf8c449eb11f059154a7 |
.text section |
| SSDeep | 24576:ly44R3aAvdvGfZ6D/nLijd/k75rEKLWmI7iaLjQ6OgLP88WJlLd2sPD1bKiH:lyr3HvEUDP+jIt4mIKgLPcPD1zH |
|
| TLSH | T18F42E12AB6A8027C2D267F358B470B058FED7707D87B4E3A7C823E42B85B54E3E6D95 |
|
| Cert CN | atom.hutsell.com |
Self-signed |
| Cert Issuer | WR3 |
|
| Cert Serial | 4C3A4A8198F1CBEF1010F5FB3157D6FE |
|
| Cert Validity | Apr 21 2026 – Jul 20 2026 | |
| Build ID | siGBN0cKdwGp0tRjjsmB/nD44BWltkC1V4bSdH8rY/9_f59bQYY-RCHH7E0-X4/3oIKFM0YbBin1_oaQkn_ |
|
| Icon hash (256×256 PNG) | 80ca67c7c259a86bcb2b399767b7935dd8155b55533cd03580760954d3fe34a9 |
.rsrc section |
Detection Signatures
No capa.txt or floss.txt available for this sample (capa signature path missing, floss argument error). ^[capa.txt] ^[floss.txt]
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Cross-family build-pattern concept
- /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html — Tenth sibling (oldest Go 1.18.5, same cert)
- /intel/analyses/beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54.html — Fifteenth sibling (x64, no
.rsrc) - /intel/analyses/119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350.html — Sixteenth sibling (PE32, 54 functions)
- /intel/analyses/76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6.html — Nineteenth sibling (x64, 11 functions)
Provenance
file.txt—filev5.45pefile.txt—pefilev2023.2.7rabin2-info.txt—radare2v5.9.9strings.txt—stringsv2.40binwalk.txt—binwalkv2.3.4exiftool.json—exiftoolv12.76- Certificate extracted manually via
dd+openssl x509fromIMAGE_DIRECTORY_ENTRY_SECURITYat offset0x1EE208 dynamic-analysis.md— CAPE skipped (no Windows guest available)