typeanalysisfamilyacrstealerconfidencehighinfostealergolangsigningpec2obfuscation
SHA-256: 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080

acrstealer: 4c15644f — 53 randomized main.* functions, heaviest x64 build in atom.hutsell.com cluster

Executive Summary

Twentieth confirmed sibling in the acrstealer Go infostealer cluster. PE32+ x64, Go 1.18.5, self-signed Authenticode CN=atom.hutsell.com / issuer WR3. 53 randomized main.* functions — the heaviest function-name randomization count observed in any x64 build of this cluster. .rsrc four-icon suite intact (256×256 PNG). No static C2; no custom PE parser; no multi-pass decoder. Lightest TTP footprint, maximum name entropy.

What It Is

Field Value
SHA-256 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080
File type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Size 2,026,112 bytes (1.93 MB) ^[triage.json]
Compiler Go 1.18.5 (go1.18.5 string at offset 0xB84D8) ^[strings.txt]
Build ID siGBN0cKdwGp0tRjjsmB/nD44BWltkC1V4bSdH8rY/9_f59bQYY-RCHH7E0-X4/3oIKFM0YbBin1_oaQkn_ ^[strings.txt:8]
Architecture GOARCH=amd64, GOOS=windows, CGO_ENABLED=0 (inferred from standard Go runtime strings)
Timestamp Null (0x0) — reproducible-build default ^[pefile.txt:34]
Stripped IMAGE_FILE_DEBUG_STRIPPED set, but .symtab retained (96K symbols) ^[pefile.txt:39] ^[pefile.txt:178]
Signed Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3, serial 4C3A4A8198F1CBEF1010F5FB3157D6FE, valid Apr 21 2026 – Jul 20 2026 ^[binwalk.txt:10] ^[rabin2-info.txt:27]
Resources .rsrc contains four-icon suite (RT_ICON IDs 1–4), largest 256×256 PNG at offset 0x1E37E8 ^[binwalk.txt:7] ^[pefile.txt:198]
Entropy .text 6.205, .rdata 7.007, .rsrc 5.757 ^[pefile.txt:91] ^[pefile.txt:111] ^[pefile.txt:211]

Family attribution is high-confidence based on:

  • Identical certificate chain (atom.hutsell.com / WR3) shared with 10+ confirmed siblings.
  • Identical Go 1.18.5 toolchain and null-timestamp pattern.
  • .rsrc icon-masquerade behavior consistent with the cluster.
  • PRNG-seeded runtime C2 decoding (no static C2 strings) — established family TTP.

How It Works

Entry Point

Standard Go runtime entry at 0x45AB40 (RVA). ^[pefile.txt:50] ^[rabin2-info.txt:10] No TLS callbacks, no anti-debug pre-main hooks. The binary is a conventional Go static executable with no packer or crypter.

Anti-Analysis

Technique Observation
Function-name randomization 53 unique main.* identifiers (see list below), hindering static clustering and symbol-based IoC matching ^[strings.txt]
Module-path randomization No clear module path recovered; Go buildinfo area shows only runtime metadata ^[strings.txt]
No static C2 All C2 infrastructure is runtime-decoded via PRNG-seeded string transforms, defeating naive string extraction ^[dynamic-analysis.md]
No custom PE parser Unlike siblings d5655568 and 90d54589, this sample does not embed a custom in-memory PE parser or multi-pass byte-transform decoder. ^[entities/acrstealer.md]

The 53 randomized main.* functions are:

main.Dvvxfz, main.Xdpwvosexdrr, main.abexmehfbpbts, main.ayqfrercmgz,
main.bagoypktsgoy, main.cirskqfyqmjtk, main.cjmfscobpanpugw, main.dcisueqztqx,
main.dkneqnmjqdln, main.dwcxfburpurbp, main.eyagpkpzw, main.fqorlrcwkrjy,
main.fxtezskmgxvfc, main.hpusteleaf, main.idbtdyrqhcvqj, main.jckzdgmcggeankb,
main.klcjpenwwibeq, main.kljxxqjfazivc, main.lgafie, main.ltpnxsjtc,
main.main, main.nltvbs, main.nqzhhcl, main.oapyawxluzg, main.onhgvsqojf,
main.oqrqznq, main.phjuymqojjw, main.phvphimves, main.phxsse, main.qbmeahopp,
main.rabqjv, main.tbsxripyslxyrrp, main.thuhcs, main.tlfxsm, main.tqwsqndhomlbc,
main.txdbdkyudowv, main.ucovxznxyy, main.vnlfrt, main.vzdwrfe, main.wczrapkwzzecz,
main.wettwvg, main.wkjubxwuutlj, main.wufsnk, main.xfajev, main.xhngqg,
main.xhpifdxypwhf, main.xmuwkbycygnjx, main.yecfhlnnw, main.ygqhztp, main.zapbyehfw

^[strings.txt]

Build-Stack Comparison (Cluster Delta)

Sibling Arch main.* count Custom PE parser Multi-pass decoder .rsrc Cert
ef262340 PE32 10 No No Yes atom.hutsell.com / WR3
6cbac6bc PE32+ x64 ~12 No No No atom.hutsell.com / WR3
828405d6 PE32+ x64 ~15 No No Yes atom.hutsell.com / WR3
beff95d5 PE32+ x64 22 No No No atom.hutsell.com / WR3
119b387e PE32 54 No No Yes atom.hutsell.com / WR3
b0bc17dd PE32 90 No No Yes atom.hutsell.com / WR3
38cf89b0 PE32 11 No No Yes atom.hutsell.com / WR3
76a51fb7 PE32+ x64 11 No No Yes atom.hutsell.com / WR3
4c15644f PE32+ x64 53 No No Yes atom.hutsell.com / WR3

This sample is the heaviest x64 build in the atom.hutsell.com certificate cluster by randomized-function count. The builder is clearly increasing name entropy over time as an anti-clustering measure, while keeping the core toolchain and certificate template stable.

Decompiled Behavior

Ghidra/radare2 analysis confirms a standard Go runtime layout: entry0 at 0x45AB40 delegates to runtime.main, which spawns the randomized main.* goroutines. No packing, no reflective loading, no process hollowing. The heavy lifting (credential theft, C2 beaconing) is buried inside the randomized functions whose names give no semantic hint.

No decompiled pseudo-C of individual main.* functions is included here because Go function-name randomization makes cross-reference tracking meaningless without runtime symbols. The family page acrstealer documents the PRNG C2-decoding algorithm observed in siblings.

C2 Infrastructure

No static C2 recovered. This is consistent with the family pattern: C2 URLs/domains are decoded at runtime using a PRNG seeded with system time or another environment value. ^[entities/acrstealer.md]

Siblings in this certificate cluster have historically resolved to:

  • 5.252.155.72 (direct IP)
  • laserlogdnsop.icu
  • hertzfigblob.icu
  • me.muz.li (cert CN, not C2)

None of these appear in this sample's strings. Dynamic execution would be required to recover the runtime-decoded C2.

Interesting Tidbits

  • Certificate reuse, not rotation. The atom.hutsell.com / WR3 cert has now been reused across 10+ siblings spanning months (Apr–Jul 2026 validity window). This is operational laziness — the builder has not rotated the self-signed template despite repeated exposure in public sandbox reports. ^[entities/acrstealer.md]
  • Builder icon-toggle is ON. Unlike 6cbac6bc and beff95d5 (which stripped .rsrc), this sample carries the full four-icon suite. The builder supports both modes. ^[entities/acrstealer.md]
  • Function-count inflation. The jump from 11 (76a51fb7, Aug 2026) to 53 (4c15644f) in the same cert cluster suggests automated function-name randomization is being cranked up, possibly by a builder GUI slider or command-line flag.
  • No anti-VM, no anti-debug. No cpuid, IsDebuggerPresent, or CheckRemoteDebuggerPresent strings. The only anti-analysis is compile-time (randomized names + runtime C2 decode).
  • PE32+ x64 but no custom PE parser. Siblings d5655568 and 90d54589 introduced a custom in-memory PE parser + multi-pass decoder (code-reuse from orderreshop). This sample lacks both, confirming the parser/decoder is an optional builder module, not a family constant.

How To Mess With It (Homelab Replication)

  1. Toolchain: Install Go 1.18.5 (or Go 1.26.2 for latest sibling match).
  2. Build flags: GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" . — Omit -sif you want.symtab` retained (as observed here).
  3. Obfuscation: Use a source-level identifier randomizer (e.g., gobfuscate, maroto) to rename all main.* functions before build.
  4. Signing: Generate a self-signed Authenticode cert with makecert / signtool:
    makecert -r -pe -n "CN=atom.hutsell.com" -ss my -sr currentUser -a sha256 -sky exchange -sp "Microsoft RSA SChannel Cryptographic Provider" -sy 12 atom.cer
    signtool sign /f atom.pfx /p password /tr http://timestamp.digicert.com /td sha256 /fd sha256 mybinary.exe
    
  5. Resources: Embed a 256×256 PNG icon with goversioninfo or rsrc tool to masquerade as a legitimate app.
  6. Verification: Run strings mybinary.exe | grep "^main\." | sort -u | wc -l — should match the randomized count. Compare rabin2 -I output to this sample's rabin2-info.txt.

Deployable Signatures

YARA Rule

rule ACRStealer_AtomHutsell_x64 {
    meta:
        description = "ACR Stealer x64 variant with atom.hutsell.com self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-05"
        hash = "4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080"
    strings:
        $go_ver = "go1.18.5"
        $cert_cn = "atom.hutsell.com"
        $cert_issuer = "WR3"
        $build_id_prefix = "siGBN0cKdwGp0tRjjsmB"
        $main_random = /main\.[A-Za-z]{6,20}/
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        $go_ver and
        ($cert_cn or $cert_issuer or $build_id_prefix) and
        #main_random >= 40
}

Behavioral Fingerprint

This binary is a Go 1.18.5 PE32+ x64 static executable with 50+ randomized main.* function names, a self-signed Authenticode certificate issued to atom.hutsell.com by WR3, and a .rsrc section containing a 256×256 PNG icon suite. It imports only standard Windows APIs via the Go runtime (kernel32, ntdll, ws2_32, advapi32) and contains no hardcoded C2 strings, indicating runtime PRNG-based C2 decoding. No custom PE parser or multi-pass decoder is present. The binary does not exhibit anti-VM or anti-debug behaviors.

IOC List

Type Value Notes
SHA-256 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080
SHA-1 7942bc3b3d349dcc9bacaf8c449eb11f059154a7 .text section
SSDeep 24576:ly44R3aAvdvGfZ6D/nLijd/k75rEKLWmI7iaLjQ6OgLP88WJlLd2sPD1bKiH:lyr3HvEUDP+jIt4mIKgLPcPD1zH
TLSH T18F42E12AB6A8027C2D267F358B470B058FED7707D87B4E3A7C823E42B85B54E3E6D95
Cert CN atom.hutsell.com Self-signed
Cert Issuer WR3
Cert Serial 4C3A4A8198F1CBEF1010F5FB3157D6FE
Cert Validity Apr 21 2026 – Jul 20 2026
Build ID siGBN0cKdwGp0tRjjsmB/nD44BWltkC1V4bSdH8rY/9_f59bQYY-RCHH7E0-X4/3oIKFM0YbBin1_oaQkn_
Icon hash (256×256 PNG) 80ca67c7c259a86bcb2b399767b7935dd8155b55533cd03580760954d3fe34a9 .rsrc section

Detection Signatures

No capa.txt or floss.txt available for this sample (capa signature path missing, floss argument error). ^[capa.txt] ^[floss.txt]

References

  • acrstealer — Family entity page
  • golang-stealer-build-pattern — Cross-family build-pattern concept
  • /intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html — Tenth sibling (oldest Go 1.18.5, same cert)
  • /intel/analyses/beff95d5326762401e1ea804d3c75f8cc71533f152a5711361476ce466b39b54.html — Fifteenth sibling (x64, no .rsrc)
  • /intel/analyses/119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350.html — Sixteenth sibling (PE32, 54 functions)
  • /intel/analyses/76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6.html — Nineteenth sibling (x64, 11 functions)

Provenance

  • file.txt — file v5.45
  • pefile.txt — pefile v2023.2.7
  • rabin2-info.txt — radare2 v5.9.9
  • strings.txt — strings v2.40
  • binwalk.txt — binwalk v2.3.4
  • exiftool.json — exiftool v12.76
  • Certificate extracted manually via dd + openssl x509 from IMAGE_DIRECTORY_ENTRY_SECURITY at offset 0x1EE208
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)