typeanalysisfamilyacrstealerconfidencehighcreated2026-08-18updated2026-08-18infostealermalware-familygolangsigninganti-vmc2
SHA-256: 5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917

acrstealer: 5ef623d6 — Go 1.25.4 x64, module SSvPYYKzNMNpCZi, 42 randomized main.* functions, no .rsrc

Executive Summary. Forty-eighth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64, self-signed Authenticode CN=quiverquant.com / issuer WE1, randomized module path SSvPYYKzNMNpCZi, 42 randomized main.* function names, no .rsrc section (builder stripped icons). No static C2 strings; family-pattern PRNG-seeded runtime decode expected. Static-only — CAPE skipped (no Windows guest).

1. Build / RE

Toolchain. Go 1.25.4, GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1734]. Build ID hD1zzQOJ2WlOx-mut9lg/mt8pNQiLMG1IRYZeJvUZ/SBU6JQHmkX8Ih1zXdNiq/hADkXIhjoANT8atxShpA ^[strings.txt:9].

Language runtime. Standard Go runtime with full garbage-collector, goroutine scheduler, and runtime panic strings intact ^[strings.txt:1-8594]. No external packer — .text entropy 6.25, .rdata 7.03 ^[pefile.txt:91,111]. No UPX, Themida, or custom section encryption.

Obfuscation. Randomized module path SSvPYYKzNMNpCZi ^[strings.txt:1736]; 42 randomized main.* function names (e.g., main.eikxtfwwlw, main.vfghcfjmoxdm, main.ozbmdstqcolw) ^[strings.txt:grep]. No other static obfuscation — Go symbol table and pclntab are intact (radare2 recovered 2119 functions).

Anti-analysis. No explicit debugger/VM checks observed statically. Null PE timestamp (Thu Jan 1 00:00:00 1970) ^[pefile.txt:34]. No .rsrc section ^[pefile.txt:sections]; icon masquerade stripped, leaving a bare binary.

Signing. Authenticode-signed PE. Certificate extracted from raw offset 0x248E08 (binwalk-identified PKCS header): self-signed X.509 CN=quiverquant.com, issuer WE1, validity 2026-05-09 → 2026-08-07 ^[binwalk.txt:6] ^[cert-info.txt]. Same cert chain as 18 prior ACR siblings. Security directory RVA 0x248E00, size 0x880 ^[pefile.txt:252-253].

Notable functions. main.main at 0x140071e40 is the standard Go runtime.main entry; no direct C2 or credential APIs in static imports. Import table limited to kernel32.dll base APIs (VirtualAlloc, CreateThread, LoadLibraryW, etc.) ^[pefile.txt:288-343]. Family behavior is runtime-resolved via Go standard libraries.

2. Deploy / ATT&CK

Execution. Standard Go binary execution; no persistence mechanisms observed statically. Family pattern suggests a PRNG-seeded sleep gate (800–1120 s range) before C2 contact ^[acrstealer.md], though this sample shows no hardcoded sleep values.

Network / C2. No static C2 strings recovered. Family behaviour: seed PRNG with current time to decode runtime C2 URLs ^[techniques/prng-seeded-c2-url-decoding.md]. Standard Go crypto/tls, net/http, and crypto/x509 packages present ^[strings.txt], implying TLS-wrapped HTTPS C2.

Collection. Inferred from family: browser credential stores, cryptocurrency wallets, FTP/SSH credentials. Not statically confirmable in this sample.

Exfiltration. HTTPS POST to runtime-decoded C2 endpoint (inferred from family pattern).

Attribution. High-confidence ACR Stealer cluster by: (1) self-signed quiverquant.com/WE1 cert chain, (2) Go 1.25.4 amd64 build fingerprint, (3) randomized module path + main.* function names, (4) dropped-by-gcleaner OpenCTI label ^[triage.json]. OpenCTI did not assign cloud55filecc to this sample.

MITRE ATT&CK mapping.

  • T1071.001 — Application Layer Protocol: Web Protocols (TLS/HTTPS C2, inferred)
  • T1059.003 — Windows Command Shell (not observed statically; family uses Go stdlib only)
  • T1083 — File and Directory Discovery (browser/wallet targeting, inferred)
  • T1005 — Data from Local System (credential harvesting, inferred)
  • T1041 — Exfiltration Over C2 Channel (HTTPS POST, inferred)

C2 Infrastructure

Runtime-decoded. No static domains, IPs, or URLs recovered. Family C2 rotation is time-seeded PRNG; expect domain/ IP changes per campaign.

Interesting Tidbits

  • Builder stripped the .rsrc icon suite (present on most quiverquant.com/WE1 siblings). This reduces social-engineering masquerade but also shrinks file size and removes a high-signal clustering artefact. ^[pefile.txt:sections]
  • 42 randomized main.* functions places this sample in the mid-range of the cluster (smallest: 11, largest: 92). ^[strings.txt:grep]
  • No crypto/aes or crypto/cipher strings observed, suggesting the inner payload uses Go's crypto/tls rather than a custom cryptor. ^[strings.txt]

Deployable Signatures

YARA rule

rule acrstealer_quiverquant_we1 {
    meta:
        description = "ACR Stealer Go infostealer — quiverquant.com / WE1 cert chain"
        author = "PacketPursuit"
        date = "2026-08-18"
        sha256 = "5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917"
    strings:
        $go_build = "go1.25.4" ascii
        $cert_cn = "quiverquant.com" ascii
        $cert_issuer = "WE1" ascii
        $mod_path = /[A-Za-z0-9]{14,18}\/main\.go/
        $build_cgo = "build\tCGO_ENABLED=0" ascii
        $build_win = "build\tGOOS=windows" ascii
        $build_amd = "build\tGOARCH=amd64" ascii
    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        ($cert_cn or $cert_issuer) and
        $mod_path and
        all of ($build_*)
}

IOC list

  • SHA-256: 5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917
  • SHA-1: a050e53db43fe800b9149c8f78a12d57b4577b60 (.text section)
  • Certificate CN: quiverquant.com
  • Certificate issuer: WE1
  • Validity: 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC
  • Build module path: SSvPYYKzNMNpCZi
  • Go build ID: hD1zzQOJ2WlOx-mut9lg/mt8pNQiLMG1IRYZeJvUZ/SBU6JQHmkX8Ih1zXdNiq/hADkXIhjoANT8atxShpA

Behavioral fingerprint. Go 1.25.4 static binary (amd64) with randomized main.* function names, self-signed Authenticode certificate CN=quiverquant.com / issuer WE1, no .rsrc section, null PE timestamp, and no hardcoded network indicators. Launches a single goroutine that sleeps before contacting a runtime-decoded HTTPS C2 endpoint over TLS 1.3.

References

  • acrstealer — Cluster entity page (47 prior siblings)
  • golang-stealer-build-pattern — Shared Go infostealer build artefacts
  • techniques/prng-seeded-c2-url-decoding — Family C2 decode technique

Provenance

Analysis derived from static artefacts in raw/analyses/5ef623d696ac40bb710cd841fb558136c8325401b08cc680f8cb56fc16bc9917/: file.txt, strings.txt, pefile.txt, triage.json, rabin2-info.txt, binwalk.txt, cert-info.txt (custom extraction). Dynamic analysis skipped — CAPE has no Windows guest. No capa.txt or floss.txt due to tool misconfiguration.