5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917acrstealer: 5ef623d6 — Go 1.25.4 x64, module SSvPYYKzNMNpCZi, 42 randomized main.* functions, no .rsrc
Executive Summary. Forty-eighth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64, self-signed Authenticode CN=quiverquant.com / issuer WE1, randomized module path SSvPYYKzNMNpCZi, 42 randomized main.* function names, no .rsrc section (builder stripped icons). No static C2 strings; family-pattern PRNG-seeded runtime decode expected. Static-only — CAPE skipped (no Windows guest).
1. Build / RE
Toolchain. Go 1.25.4, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1734]. Build ID hD1zzQOJ2WlOx-mut9lg/mt8pNQiLMG1IRYZeJvUZ/SBU6JQHmkX8Ih1zXdNiq/hADkXIhjoANT8atxShpA ^[strings.txt:9].
Language runtime. Standard Go runtime with full garbage-collector, goroutine scheduler, and runtime panic strings intact ^[strings.txt:1-8594]. No external packer — .text entropy 6.25, .rdata 7.03 ^[pefile.txt:91,111]. No UPX, Themida, or custom section encryption.
Obfuscation. Randomized module path SSvPYYKzNMNpCZi ^[strings.txt:1736]; 42 randomized main.* function names (e.g., main.eikxtfwwlw, main.vfghcfjmoxdm, main.ozbmdstqcolw) ^[strings.txt:grep]. No other static obfuscation — Go symbol table and pclntab are intact (radare2 recovered 2119 functions).
Anti-analysis. No explicit debugger/VM checks observed statically. Null PE timestamp (Thu Jan 1 00:00:00 1970) ^[pefile.txt:34]. No .rsrc section ^[pefile.txt:sections]; icon masquerade stripped, leaving a bare binary.
Signing. Authenticode-signed PE. Certificate extracted from raw offset 0x248E08 (binwalk-identified PKCS header): self-signed X.509 CN=quiverquant.com, issuer WE1, validity 2026-05-09 → 2026-08-07 ^[binwalk.txt:6] ^[cert-info.txt]. Same cert chain as 18 prior ACR siblings. Security directory RVA 0x248E00, size 0x880 ^[pefile.txt:252-253].
Notable functions. main.main at 0x140071e40 is the standard Go runtime.main entry; no direct C2 or credential APIs in static imports. Import table limited to kernel32.dll base APIs (VirtualAlloc, CreateThread, LoadLibraryW, etc.) ^[pefile.txt:288-343]. Family behavior is runtime-resolved via Go standard libraries.
2. Deploy / ATT&CK
Execution. Standard Go binary execution; no persistence mechanisms observed statically. Family pattern suggests a PRNG-seeded sleep gate (800–1120 s range) before C2 contact ^[acrstealer.md], though this sample shows no hardcoded sleep values.
Network / C2. No static C2 strings recovered. Family behaviour: seed PRNG with current time to decode runtime C2 URLs ^[techniques/prng-seeded-c2-url-decoding.md]. Standard Go crypto/tls, net/http, and crypto/x509 packages present ^[strings.txt], implying TLS-wrapped HTTPS C2.
Collection. Inferred from family: browser credential stores, cryptocurrency wallets, FTP/SSH credentials. Not statically confirmable in this sample.
Exfiltration. HTTPS POST to runtime-decoded C2 endpoint (inferred from family pattern).
Attribution. High-confidence ACR Stealer cluster by: (1) self-signed quiverquant.com/WE1 cert chain, (2) Go 1.25.4 amd64 build fingerprint, (3) randomized module path + main.* function names, (4) dropped-by-gcleaner OpenCTI label ^[triage.json]. OpenCTI did not assign cloud55filecc to this sample.
MITRE ATT&CK mapping.
- T1071.001 — Application Layer Protocol: Web Protocols (TLS/HTTPS C2, inferred)
- T1059.003 — Windows Command Shell (not observed statically; family uses Go stdlib only)
- T1083 — File and Directory Discovery (browser/wallet targeting, inferred)
- T1005 — Data from Local System (credential harvesting, inferred)
- T1041 — Exfiltration Over C2 Channel (HTTPS POST, inferred)
C2 Infrastructure
Runtime-decoded. No static domains, IPs, or URLs recovered. Family C2 rotation is time-seeded PRNG; expect domain/ IP changes per campaign.
Interesting Tidbits
- Builder stripped the
.rsrcicon suite (present on mostquiverquant.com/WE1siblings). This reduces social-engineering masquerade but also shrinks file size and removes a high-signal clustering artefact. ^[pefile.txt:sections] - 42 randomized
main.*functions places this sample in the mid-range of the cluster (smallest: 11, largest: 92). ^[strings.txt:grep] - No
crypto/aesorcrypto/cipherstrings observed, suggesting the inner payload uses Go'scrypto/tlsrather than a custom cryptor. ^[strings.txt]
Deployable Signatures
YARA rule
rule acrstealer_quiverquant_we1 {
meta:
description = "ACR Stealer Go infostealer — quiverquant.com / WE1 cert chain"
author = "PacketPursuit"
date = "2026-08-18"
sha256 = "5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917"
strings:
$go_build = "go1.25.4" ascii
$cert_cn = "quiverquant.com" ascii
$cert_issuer = "WE1" ascii
$mod_path = /[A-Za-z0-9]{14,18}\/main\.go/
$build_cgo = "build\tCGO_ENABLED=0" ascii
$build_win = "build\tGOOS=windows" ascii
$build_amd = "build\tGOARCH=amd64" ascii
condition:
uint16(0) == 0x5A4D and
$go_build and
($cert_cn or $cert_issuer) and
$mod_path and
all of ($build_*)
}
IOC list
- SHA-256:
5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917 - SHA-1:
a050e53db43fe800b9149c8f78a12d57b4577b60(.textsection) - Certificate CN:
quiverquant.com - Certificate issuer:
WE1 - Validity: 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC
- Build module path:
SSvPYYKzNMNpCZi - Go build ID:
hD1zzQOJ2WlOx-mut9lg/mt8pNQiLMG1IRYZeJvUZ/SBU6JQHmkX8Ih1zXdNiq/hADkXIhjoANT8atxShpA
Behavioral fingerprint. Go 1.25.4 static binary (amd64) with randomized main.* function names, self-signed Authenticode certificate CN=quiverquant.com / issuer WE1, no .rsrc section, null PE timestamp, and no hardcoded network indicators. Launches a single goroutine that sleeps before contacting a runtime-decoded HTTPS C2 endpoint over TLS 1.3.
References
- acrstealer — Cluster entity page (47 prior siblings)
- golang-stealer-build-pattern — Shared Go infostealer build artefacts
- techniques/prng-seeded-c2-url-decoding — Family C2 decode technique
Provenance
Analysis derived from static artefacts in raw/analyses/5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917/: file.txt, strings.txt, pefile.txt, triage.json, rabin2-info.txt, binwalk.txt, cert-info.txt (custom extraction). Dynamic analysis skipped — CAPE has no Windows guest. No capa.txt or floss.txt due to tool misconfiguration.