typeanalysisfamilyacrstealerconfidencehighcreated2026-08-17updated2026-08-17infostealergolangsigningpemalware-familycontested
SHA-256: 58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04

acrstealer: 58eda486 — 90 randomized main.* functions, GlobalSign-seekingalpha.com chain (3rd sample)

Executive Summary

Go 1.20.6 PE32+ x64 infostealer, forty-fourth confirmed sibling in the ACR cluster. Ties the cluster record with 90 randomized main.* functions. Signed with a commercially-trusted GlobalSign Atlas R3 DV TLS certificate for seekingalpha.com (third confirmed sample on this chain). Preliminary OpenCTI labels cloud55file-cc and neuralpulsecore5-sbs contested; resolves to ACR by certificate chain and Go build fingerprint. Static-only (CAPE skipped).

What It Is

Field Value
SHA-256 58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04
Filename JKHKJ7.exe ^[metadata.json]
Size 2,087,112 bytes (2.0 MB) ^[metadata.json]
Type PE32+ executable (GUI) x86-64, 7 sections ^[file.txt]
Compiler Go 1.20.6 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1252-1258]
Entry point 0x45e380 (standard Go runtime._rt0_amd64_windows) ^[pefile.txt:50]
Timestamp 0x0 (null, stripped) ^[pefile.txt:34]
Certificate GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com, serial 01FD9F5B7B690B97FFB8332C60FE090F ^[rabin2-info.txt:27]
Resources .rsrc contains 4 RT_ICON entries (1 RT_GROUP_ICON) ^[pefile.txt:217-450]
Build ID lbdBnnyBahB8NB14vyKX/SfPqRAAFe2DICx9s4L-B/I29dyJ_gSnleVnfGA_2i/GI9T5NiJhyV_MslTqwpB ^[strings.txt:8]
Overlay None (2,048 bytes: WIN_CERTIFICATE header + PKCS#7) ^[binwalk.txt:9-10]
Entropy .text 6.22, .rdata 6.96, .data 4.85 ^[pefile.txt:91,111,131]

How It Works

This sample is a cluster sibling of acrstealer. For shared family behavior see the ACR entity page. This report covers per-sample deltas.

Build deltas

  • Go 1.20.6 — intermediate toolchain between the legacy Go 1.18.5 sub-cluster (ef262340 through f251271a) and the newer Go 1.25.4 sub-cluster (f668de57 onwards). First observed Go 1.20.6 sibling was f0105851 (26th); this is the second Go 1.20.6 sibling, sharing the same GlobalSign certificate chain. ^[strings.txt:1252-1258]
  • 90 randomized main.* functions — ties the cluster record held by b0bc17dd, f251271a, and 8f454dc1. The randomized names are 6–17 characters, consonant-heavy, no vowel clusters (e.g. lugltquyoqkaen, hekspdcwuydem, Srucrpfaphsudpr). ^[strings.txt:4226-4268]
  • Four-icon .rsrc suite — 1 group icon + 4 size variants. The builder's icon-toggle is ON for this sample. ^[pefile.txt:319-450]
  • No static C2 — no hardcoded URLs, IPs, or domains in strings. C2 is runtime-decoded via PRNG-seeded string decoding per family pattern. ^[strings.txt:1-7148]
  • No custom PE parser / no multi-pass decoder — light build matching the baseline ACR template, not the heavier orderreshop/lummastealer divergent builds. ^[strings.txt]

Certificate chain

Third confirmed sample on the GlobalSign Atlas R3 DV TLS → seekingalpha.com chain, after f0105851 (26th sibling, Go 1.20.6 PE32, 90 functions) and a02296ce (43rd sibling, Go 1.20.6 PE32, 34 functions). All three share identical issuer and CA lineage. ^[rabin2-info.txt:27]

Decompiled Behavior

Entrypoint at 0x45e380 is standard Go runtime initialisation: CPUID vendor check (GenuineIntel), runtime.main setup via fcn.0045f3e0, goroutine scheduler init, then dispatch to main.main (main.main symbol at string offset ~4267). ^[r2:entry0]

No non-standard entry behaviour. The 90 main.* functions resolve to benign-looking Go symbols with randomized names; their control flow is standard Go static-binary dispatch with no observed obfuscation beyond name randomisation.

C2 Infrastructure

No static C2 recovered. Per family pattern, C2 URLs are decoded at runtime via a PRNG-seeded multi-pass transform. See prng-seeded-c2-url-decoding for the technique. The binary links net/http and crypto/tls statically. ^[strings.txt:500-600]

Interesting Tidbits

  • Filename entropy: JKHKJ7.exe — 7-character random uppercase filename, no social-engineering masquerade. Unlike siblings with .pdf.exe double-extensions or purchase-order lures, this uses a bare random name. Possible builder "no masquerade" mode or test build. ^[metadata.json]
  • Record-tying function count: 90 main.* functions equals the highest count observed in the entire ACR corpus. The builder appears to allow configurable function-name generation density. ^[strings.txt:4226-4268]
  • Intermediate toolchain: Go 1.20.6 sits between the large Go 1.18.5 sub-cluster (22 samples) and the Go 1.25.4 sub-cluster (18+ samples). This cert chain (seekingalpha.com) is only observed on Go 1.20.6 builds so far. ^[strings.txt:1252-1258]
  • GlobalSign commercial trust: Unlike the majority of ACR siblings using self-signed quiverquant.com/WE1 or atom.hutsell.com/WR3 certs, this chain uses a real DV TLS certificate issued by GlobalSign. The cert is TLS (not code-signing) but Windows treats it as Authenticode during superficial triage, reducing alert friction. ^[rabin2-info.txt:27]

How To Mess With It (Homelab Replication)

This binary is a standard Go static build with randomized identifiers. To reproduce the capa fingerprint (if capa were working):

  • Toolchain: Go 1.20.6, Windows amd64 target
  • Flags: GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w"
  • Obfuscation: Use a Go source transformer (e.g. garble with -literals -seed=<random>) to randomize package and function names in the main package
  • Signing: Obtain any DV TLS certificate and sign with signtool.exe /a (or self-sign with a fabricated CN)
  • Verification: Run capa and strings; expect high-entropy main.* symbols, Go runtime strings, and no static C2 URLs

Deployable Signatures

YARA rule

rule acrstealer_golang_seekingalpha_chain
{
    meta:
        description = "ACR stealer cluster — Go static binary with GlobalSign seekingalpha.com cert chain"
        author = "PacketPursuit"
        date = "2026-08-17"
        sha256 = "58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04"
        family = "acrstealer"
    strings:
        $go1 = "go1.20.6" ascii
        $go2 = "go1.25.4" ascii
        $go3 = "go1.18.5" ascii
        $go4 = "go1.26.2" ascii
        $build = "build\t-trimpath=true" ascii
        $cgo = "build\tCGO_ENABLED=0" ascii
        $seekingalpha = "seekingalpha.com" ascii
        $quiverquant = "quiverquant.com" ascii
        $atom = "atom.hutsell.com" ascii
        $blizzard = "blizzard-tecnica.com" ascii
        $sedo = "sedo.com" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.number_of_sections >= 6 and
        1 of ($go*) and
        $build and
        $cgo and
        1 of ($seekingalpha, $quiverquant, $atom, $blizzard, $sedo) and
        pe.signatures[0].issuer contains "GlobalSign" or
        pe.signatures[0].issuer contains "WE1" or
        pe.signatures[0].issuer contains "WR3" or
        pe.signatures[0].issuer contains "R12" or
        pe.signatures[0].issuer contains "Sectigo"
}

Sigma rule

title: ACR Stealer Go Static Binary Execution
description: Detects execution of Go static binaries matching the ACR stealer build pattern with randomized main.* functions and known certificate chains.
status: experimental
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        - ImageLoaded|endswith:
            - '\\JKHKJ7.exe'
        - CommandLine|contains:
            - 'JKHKJ7.exe'
    golang_indicators:
        - ImageLoaded|contains:
            - 'Go build ID:'
    cert_chains:
        - Hashes|contains:
            - 'seekingalpha.com'
            - 'quiverquant.com'
            - 'atom.hutsell.com'
            - 'blizzard-tecnica.com'
            - 'sedo.com'
    condition: selection and golang_indicators and cert_chains
falsepositives:
    - None expected for this specific filename; adjust for generic Go binaries.
level: high

IOC list

Type Value Note
SHA-256 58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04 This sample
SHA-256 f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a 26th sibling, same cert chain
SHA-256 a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992 43rd sibling, same cert chain
Cert CN seekingalpha.com GlobalSign Atlas R3 DV TLS CA 2025 Q4
Cert serial 01FD9F5B7B690B97FFB8332C60FE090F This sample
Filename JKHKJ7.exe Bare random name
Build ID lbdBnnyBahB8NB14vyKX/SfPqRAAFe2DICx9s4L-B/I29dyJ_gSnleVnfGA_2i/GI9T5NiJhyV_MslTqwpB Unique per build
Go version go1.20.6 Intermediate toolchain

Behavioral fingerprint

This binary is a Go 1.20.6 static PE32+ x64 with null timestamp, 90 randomized main.* function names (6–17 chars, consonant-heavy), four embedded icons in .rsrc, and a GlobalSign DV TLS Authenticode signature for seekingalpha.com. It links net/http and crypto/tls but contains no static C2 strings. Execution follows standard Go runtime initialisation (CPUID check → scheduler init → main.main). No observed anti-debug, VM checks, or process injection in static analysis. The heavy randomized symbol count (90) is a cluster fingerprint.

Detection Signatures

Technique ATT&CK ID Evidence
Data from Local System T1005 Inferred from infostealer family behaviour
Exfiltration Over C2 Channel T1041 net/http + crypto/tls linkage, runtime C2 decode
Obfuscated Files or Information T1027 90 randomized main.* function names
Masquerading T1036.005 DV TLS certificate for seekingalpha.com
Application Layer Protocol: Web Protocols T1071.001 net/http static linkage
Ingress Tool Transfer T1105 Inferred from downloader/stager behaviour

References

Provenance

Static analysis performed 2026-08-17 on pp-hermes. Files consumed: file.txt, pefile.txt, strings.txt, rabin2-info.txt, exiftool.json, metadata.json, binwalk.txt, triage.json. Dynamic analysis skipped: CAPE has no Windows guest available. Capa and floss failed at triage time (capa signature path missing; floss argument parsing error). Certificate extracted via pefile + OpenSSL PKCS#7 parse. Go version from .rdata string search. Icon count via pefile resource enumeration. Radare2 v5.x used for entrypoint decompilation (level-2 analysis, 1627 functions recovered).