58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04acrstealer: 58eda486 — 90 randomized main.* functions, GlobalSign-seekingalpha.com chain (3rd sample)
Executive Summary
Go 1.20.6 PE32+ x64 infostealer, forty-fourth confirmed sibling in the ACR cluster. Ties the cluster record with 90 randomized main.* functions. Signed with a commercially-trusted GlobalSign Atlas R3 DV TLS certificate for seekingalpha.com (third confirmed sample on this chain). Preliminary OpenCTI labels cloud55file-cc and neuralpulsecore5-sbs contested; resolves to ACR by certificate chain and Go build fingerprint. Static-only (CAPE skipped).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04 |
| Filename | JKHKJ7.exe ^[metadata.json] |
| Size | 2,087,112 bytes (2.0 MB) ^[metadata.json] |
| Type | PE32+ executable (GUI) x86-64, 7 sections ^[file.txt] |
| Compiler | Go 1.20.6 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1252-1258] |
| Entry point | 0x45e380 (standard Go runtime._rt0_amd64_windows) ^[pefile.txt:50] |
| Timestamp | 0x0 (null, stripped) ^[pefile.txt:34] |
| Certificate | GlobalSign Atlas R3 DV TLS CA 2025 Q4 → CN=seekingalpha.com, serial 01FD9F5B7B690B97FFB8332C60FE090F ^[rabin2-info.txt:27] |
| Resources | .rsrc contains 4 RT_ICON entries (1 RT_GROUP_ICON) ^[pefile.txt:217-450] |
| Build ID | lbdBnnyBahB8NB14vyKX/SfPqRAAFe2DICx9s4L-B/I29dyJ_gSnleVnfGA_2i/GI9T5NiJhyV_MslTqwpB ^[strings.txt:8] |
| Overlay | None (2,048 bytes: WIN_CERTIFICATE header + PKCS#7) ^[binwalk.txt:9-10] |
| Entropy | .text 6.22, .rdata 6.96, .data 4.85 ^[pefile.txt:91,111,131] |
How It Works
This sample is a cluster sibling of acrstealer. For shared family behavior see the ACR entity page. This report covers per-sample deltas.
Build deltas
- Go 1.20.6 — intermediate toolchain between the legacy Go 1.18.5 sub-cluster (
ef262340throughf251271a) and the newer Go 1.25.4 sub-cluster (f668de57onwards). First observed Go 1.20.6 sibling wasf0105851(26th); this is the second Go 1.20.6 sibling, sharing the same GlobalSign certificate chain. ^[strings.txt:1252-1258] - 90 randomized
main.*functions — ties the cluster record held byb0bc17dd,f251271a, and8f454dc1. The randomized names are 6–17 characters, consonant-heavy, no vowel clusters (e.g.lugltquyoqkaen,hekspdcwuydem,Srucrpfaphsudpr). ^[strings.txt:4226-4268] - Four-icon
.rsrcsuite — 1 group icon + 4 size variants. The builder's icon-toggle is ON for this sample. ^[pefile.txt:319-450] - No static C2 — no hardcoded URLs, IPs, or domains in strings. C2 is runtime-decoded via PRNG-seeded string decoding per family pattern. ^[strings.txt:1-7148]
- No custom PE parser / no multi-pass decoder — light build matching the baseline ACR template, not the heavier
orderreshop/lummastealerdivergent builds. ^[strings.txt]
Certificate chain
Third confirmed sample on the GlobalSign Atlas R3 DV TLS → seekingalpha.com chain, after f0105851 (26th sibling, Go 1.20.6 PE32, 90 functions) and a02296ce (43rd sibling, Go 1.20.6 PE32, 34 functions). All three share identical issuer and CA lineage. ^[rabin2-info.txt:27]
Decompiled Behavior
Entrypoint at 0x45e380 is standard Go runtime initialisation: CPUID vendor check (GenuineIntel), runtime.main setup via fcn.0045f3e0, goroutine scheduler init, then dispatch to main.main (main.main symbol at string offset ~4267). ^[r2:entry0]
No non-standard entry behaviour. The 90 main.* functions resolve to benign-looking Go symbols with randomized names; their control flow is standard Go static-binary dispatch with no observed obfuscation beyond name randomisation.
C2 Infrastructure
No static C2 recovered. Per family pattern, C2 URLs are decoded at runtime via a PRNG-seeded multi-pass transform. See prng-seeded-c2-url-decoding for the technique. The binary links net/http and crypto/tls statically. ^[strings.txt:500-600]
Interesting Tidbits
- Filename entropy:
JKHKJ7.exe— 7-character random uppercase filename, no social-engineering masquerade. Unlike siblings with.pdf.exedouble-extensions or purchase-order lures, this uses a bare random name. Possible builder "no masquerade" mode or test build. ^[metadata.json] - Record-tying function count: 90
main.*functions equals the highest count observed in the entire ACR corpus. The builder appears to allow configurable function-name generation density. ^[strings.txt:4226-4268] - Intermediate toolchain: Go 1.20.6 sits between the large Go 1.18.5 sub-cluster (22 samples) and the Go 1.25.4 sub-cluster (18+ samples). This cert chain (
seekingalpha.com) is only observed on Go 1.20.6 builds so far. ^[strings.txt:1252-1258] - GlobalSign commercial trust: Unlike the majority of ACR siblings using self-signed
quiverquant.com/WE1oratom.hutsell.com/WR3certs, this chain uses a real DV TLS certificate issued by GlobalSign. The cert is TLS (not code-signing) but Windows treats it as Authenticode during superficial triage, reducing alert friction. ^[rabin2-info.txt:27]
How To Mess With It (Homelab Replication)
This binary is a standard Go static build with randomized identifiers. To reproduce the capa fingerprint (if capa were working):
- Toolchain: Go 1.20.6, Windows amd64 target
- Flags:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" - Obfuscation: Use a Go source transformer (e.g.
garblewith-literals -seed=<random>) to randomize package and function names in themainpackage - Signing: Obtain any DV TLS certificate and sign with
signtool.exe /a(or self-sign with a fabricated CN) - Verification: Run
capaandstrings; expect high-entropymain.*symbols, Go runtime strings, and no static C2 URLs
Deployable Signatures
YARA rule
rule acrstealer_golang_seekingalpha_chain
{
meta:
description = "ACR stealer cluster — Go static binary with GlobalSign seekingalpha.com cert chain"
author = "PacketPursuit"
date = "2026-08-17"
sha256 = "58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04"
family = "acrstealer"
strings:
$go1 = "go1.20.6" ascii
$go2 = "go1.25.4" ascii
$go3 = "go1.18.5" ascii
$go4 = "go1.26.2" ascii
$build = "build\t-trimpath=true" ascii
$cgo = "build\tCGO_ENABLED=0" ascii
$seekingalpha = "seekingalpha.com" ascii
$quiverquant = "quiverquant.com" ascii
$atom = "atom.hutsell.com" ascii
$blizzard = "blizzard-tecnica.com" ascii
$sedo = "sedo.com" ascii
condition:
uint16(0) == 0x5A4D and
pe.number_of_sections >= 6 and
1 of ($go*) and
$build and
$cgo and
1 of ($seekingalpha, $quiverquant, $atom, $blizzard, $sedo) and
pe.signatures[0].issuer contains "GlobalSign" or
pe.signatures[0].issuer contains "WE1" or
pe.signatures[0].issuer contains "WR3" or
pe.signatures[0].issuer contains "R12" or
pe.signatures[0].issuer contains "Sectigo"
}
Sigma rule
title: ACR Stealer Go Static Binary Execution
description: Detects execution of Go static binaries matching the ACR stealer build pattern with randomized main.* functions and known certificate chains.
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection:
- ImageLoaded|endswith:
- '\\JKHKJ7.exe'
- CommandLine|contains:
- 'JKHKJ7.exe'
golang_indicators:
- ImageLoaded|contains:
- 'Go build ID:'
cert_chains:
- Hashes|contains:
- 'seekingalpha.com'
- 'quiverquant.com'
- 'atom.hutsell.com'
- 'blizzard-tecnica.com'
- 'sedo.com'
condition: selection and golang_indicators and cert_chains
falsepositives:
- None expected for this specific filename; adjust for generic Go binaries.
level: high
IOC list
| Type | Value | Note |
|---|---|---|
| SHA-256 | 58eda486d34d649502ff6f451760ef1fb340c15ed808c226e9831e785d39dc04 |
This sample |
| SHA-256 | f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68a |
26th sibling, same cert chain |
| SHA-256 | a02296ceeb8f1419fe18a4376ce3b563e5de0fe8d85e7bf1b8461784d3c17992 |
43rd sibling, same cert chain |
| Cert CN | seekingalpha.com |
GlobalSign Atlas R3 DV TLS CA 2025 Q4 |
| Cert serial | 01FD9F5B7B690B97FFB8332C60FE090F |
This sample |
| Filename | JKHKJ7.exe |
Bare random name |
| Build ID | lbdBnnyBahB8NB14vyKX/SfPqRAAFe2DICx9s4L-B/I29dyJ_gSnleVnfGA_2i/GI9T5NiJhyV_MslTqwpB |
Unique per build |
| Go version | go1.20.6 |
Intermediate toolchain |
Behavioral fingerprint
This binary is a Go 1.20.6 static PE32+ x64 with null timestamp, 90 randomized main.* function names (6–17 chars, consonant-heavy), four embedded icons in .rsrc, and a GlobalSign DV TLS Authenticode signature for seekingalpha.com. It links net/http and crypto/tls but contains no static C2 strings. Execution follows standard Go runtime initialisation (CPUID check → scheduler init → main.main). No observed anti-debug, VM checks, or process injection in static analysis. The heavy randomized symbol count (90) is a cluster fingerprint.
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Data from Local System | T1005 | Inferred from infostealer family behaviour |
| Exfiltration Over C2 Channel | T1041 | net/http + crypto/tls linkage, runtime C2 decode |
| Obfuscated Files or Information | T1027 | 90 randomized main.* function names |
| Masquerading | T1036.005 | DV TLS certificate for seekingalpha.com |
| Application Layer Protocol: Web Protocols | T1071.001 | net/http static linkage |
| Ingress Tool Transfer | T1105 | Inferred from downloader/stager behaviour |
References
- acrstealer — Resolved family entity
- cloud55filecc — Contested OpenCTI label stub
- neuralpulsecore5sbs — Contested OpenCTI label stub
- golang-stealer-build-pattern — Shared build artefacts
- prng-seeded-c2-url-decoding — C2 decode technique
- OpenCTI artifact:
67fb5254-7c71-474f-9870-e6604707935e^[metadata.json]
Provenance
Static analysis performed 2026-08-17 on pp-hermes. Files consumed: file.txt, pefile.txt, strings.txt, rabin2-info.txt, exiftool.json, metadata.json, binwalk.txt, triage.json. Dynamic analysis skipped: CAPE has no Windows guest available. Capa and floss failed at triage time (capa signature path missing; floss argument parsing error). Certificate extracted via pefile + OpenSSL PKCS#7 parse. Go version from .rdata string search. Icon count via pefile resource enumeration. Radare2 v5.x used for entrypoint decompilation (level-2 analysis, 1627 functions recovered).