typeanalysisfamilyacrstealerconfidencehighcreated2026-08-15updated2026-08-15infostealermalware-familygolangsigningobfuscation
SHA-256: 6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c

acrstealer: 6baf80c1 — Go 1.25.4 x64, forty-first confirmed sibling, quiverquant.com/WE1 cert chain

Executive Summary

Fortieth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64, self-signed Authenticode with CN=quiverquant.com / issuer WE1 (fifteenth confirmed sample on this cert chain), randomized module path edmjkExqBBpnduw, 49 randomized main.* functions (mid-range count), no .rsrc section (icon-toggle off), no custom PE parser, no multi-pass decoder. PRNG-seeded C2 decoding confirmed in main.main decompilation. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c
File type PE32+ executable (GUI) x86-64, 8 sections ^[file.txt]
Size 2,556,032 bytes (2.44 MB)
Compiler Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1715] ^[strings.txt:6413]
Module path edmjkExqBBpnduw (randomized) ^[buildinfo extraction]
Build timestamp Null (Thu Jan 1 00:00:00 1970 UTC) ^[pefile.txt:34]
Certificate Self-signed, CN=quiverquant.com, issuer CN=WE1, 4096-bit RSA, validity 2026-05-09 → 2026-08-07 ^[certificate DER parsing]
.rsrc Absent (no icon masquerade) ^[pefile section list]
OpenCTI labels c, dropped-by-gcleaner, exe, malware-bazaar, mix4.file, signed ^[triage.json]

How It Works

This sample is a cluster sibling of acrstealer — see the entity page for shared TTPs. Per-sample deltas follow.

Build Deltas

  • Toolchain: Go 1.25.4 PE32+ x64 (previous siblings on this chain are Go 1.25.4 PE32 and PE32+ mixed; this is an x64 build). ^[strings.txt:1715]
  • Module path: edmjkExqBBpnduw — 15-character randomized lowercase+uppercase alphanumeric string, consistent with the cluster's -trimpath randomized module path obfuscation. ^[buildinfo extraction]
  • Randomized function count: 49 main.* functions (47 all-lowercase + 2 CamelCase: main.Oywijxhpspk, main.Vrrajrtqvfxmxix). This is mid-range for the cluster (range: 11–92). ^[strings.txt function enumeration]
  • Custom type count: 8 type:.eq.main.* symbols (Gyfyknixvxgjd, Huhiwvsv, Lzhtjnrw, Qhvrsberllbct, Rgmtwtoy, Sxebodyia, Sxzvxhjcmqvez, Tdofqlgtwytcovk). Mixed-case type naming is consistent across the quiverquant.com/WE1 chain. ^[strings.txt:6147–6154]
  • No .rsrc: Builder icon-toggle is off. The eight PE sections are .text, .rdata, .data, .pdata, .xdata, .idata, .reloc, .symtab. ^[pefile.txt section headers]
  • No VS_VERSIONINFO: No version-resource masquerade. ^[pefile.txt version info absence]
  • No external Go modules: Standard library only (crypto/tls, crypto/x509, net/http, os/exec, math/rand, time, syscall, etc.). No github.com/ or golang.org/x/ imports recovered. ^[strings.txt import analysis]

Decompiled Behavior

Entry via main.main (radare2 @ 0x14009ad60) performs the following before any external I/O:

  1. Computes a 64-bit seed value from a chain of arithmetic operations on constants (0xdd7b17f80, 0x3b9aca00, 0xa1b203eb3d1a0000) combined with a masked random component. ^[r2:sym.main.main @ 0x14009ad60]
  2. Allocates a runtime object and calls math_rand._rngSource_.Seed() with the computed seed. ^[r2:sym.main.main @ 0x14009ad95]
  3. Iterates a lookup table (base 0x1400ac240, 16-byte stride) performing runtime.typeAssert on each entry, filtering by a type-comparison check. ^[r2:sym.main.main @ 0x14009adea]
  4. Exits to further main-package functions (main.pypurxl, main.dxfehvtd, etc.) without any static C2 string materialization in the decompiled trace.

This is the standard ACR-cluster PRNG-seeded C2 decode pattern observed in siblings d353d849, 725dc07c, etc. — no static C2, no custom PE parser, no multi-pass decoder.

Static Import Surface (Windows APIs)

Standard Go syscall package bindings to:

  • kernel32.dll: VirtualAlloc, VirtualFree, VirtualQuery, LoadLibraryW, GetProcAddress, CreateThread, WaitForSingleObject, CloseHandle, ExitProcess, WriteFile, ReadFile, CreateFileW, DeleteFileW, SetFileTime, GetStdHandle, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetConsoleMode, WriteConsoleW, ReadConsoleW, TlsAlloc, SwitchToThread, SuspendThread, ResumeThread, SetWaitableTimer, SetEvent, DuplicateHandle, AddVectoredExceptionHandler, AddVectoredContinueHandler, RtlVirtualUnwind, RtlLookupFunctionEntry, GetThreadContext, SetThreadContext, PostQueuedCompletionStatus, GetQueuedCompletionStatusEx, CreateIoCompletionPort, CreateEventA, CreateWaitableTimerExW, WerSetFlags, WerGetFlags ^[r2 import listing]
  • ws2_32.dll: WSAStartup, WSARecv, WSASend, WSAEnumProtocolsW, closesocket, setsockopt, getpeername, getsockname ^[strings.txt]
  • dnsapi.dll: DnsQuery_W, DnsNameCompare_W, DnsRecordListFree ^[strings.txt]
  • crypt32.dll: CertOpenStore, CertCloseStore, CertEnumCertificatesInStore, CertGetCertificateChain, CertVerifyCertificateChainPolicy, CertCreateCertificateContext, CertAddCertificateContextToStore, CertFreeCertificateContext, CertFreeCertificateChain, CryptGenRandom ^[strings.txt]
  • secur32.dll, mswsock.dll, shell32.dll, userenv.dll, netapi32.dll, iphlpapi.dll, advapi32.dll ^[strings.txt]

C2 Infrastructure

No static C2 recovered. Family pattern (PRNG-seeded runtime decode) applies — see acrstealer entity page and prng-seeded-c2-url-decoding technique page. The main.main decompilation confirms the PRNG seeding path; actual C2 endpoint resolution occurs in downstream main.* functions not statically reached by radare2.

Interesting Tidbits

  • Fifteenth confirmed sample on the quiverquant.com/WE1 cert chain, and the first x64 build on this chain (all prior 14 siblings are PE32 or mixed-arch; f668de57, 1cf857a9, 725dc07c, c69b14a0, f258a5d7, 55c7b564, bd783215, 94cf86f6, c64eb93f, 43998b11d, c5b8d1b8, 3f7d51dd, plus the contested ACR/Lumma bridge 7620884e on blizzard-tecnica.com).
  • Two CamelCase main.* functions (main.Oywijxhpspk, main.Vrrajrtqvfxmxix) are unusual — the cluster typically uses all-lowercase randomized names. These may be builder-generated helper names for specific functionality (e.g., screenshot, clipboard) or a minor toolchain variation.
  • .symtab section present: 111 KB symbol table with full Go runtime debugging info, indicating a non-stripped build. This is common in Go malware (stripping is optional and rarely used by these operators).
  • Certificate serial: 10:f6:9e:50:b0:5b:14:f3:0e:bf:13:91:55:b6:58:87 — unique per-sample, not reused across the chain.
  • Section entropy: .rdata at 7.095 is high but normal for Go binaries (packed string tables, error messages, type descriptors). .text at 6.256 is moderate — no packing, just Go's standard instruction encoding. ^[pefile.txt entropy values]

How To Mess With It (Homelab Replication)

To produce a binary with a comparable capa/capa-like fingerprint:

  1. Install Go 1.25.4 on Windows or cross-compile from Linux.
  2. Build a minimal Windows GUI stub that imports crypto/tls, net/http, os/exec, syscall, and math/rand.
  3. Set GOARCH=amd64 GOOS=windows CGO_ENABLED=0 and -trimpath=true.
  4. Randomize the module path by placing source in a directory with a nonsense name (e.g., ~/go/src/edmjkExqBBpnduw/main.go).
  5. Compile: go build -ldflags "-H=windowsgui" -o stub.exe.
  6. Sign with a self-signed certificate: openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 90 -subj "/CN=quiverquant.com" then osslsigncode sign -certs cert.pem -key key.pem -in stub.exe -out signed.exe.
  7. Verify: strings signed.exe | grep "Go build ID" should show a build ID; rabin2 -I signed.exe should show lang: go, signed: true.

What you'll learn: The Go compiler embeds massive amounts of runtime metadata. Even a minimal stub will have ~2,000 runtime symbols, high .rdata entropy, and a full Windows API import surface via syscall. The randomized module path and function names are build-directory artefacts, not active obfuscation — they defeat naive string-clustering but not skilled analysis.

Deployable Signatures

YARA Rule

rule ACRStealer_Go1254_x64_Quiverquant_WE1
{
    meta:
        description = "ACR Stealer cluster sibling - Go 1.25.4 x64, quiverquant.com/WE1 self-signed cert"
        author = "PacketPursuit"
        date = "2026-08-15"
        hash = "6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c"
        family = "acrstealer"
        confidence = "high"

    strings:
        $go_ver = "go1.25.4" ascii wide
        $cert_cn = "quiverquant.com" ascii wide
        $cert_issuer = "WE1" ascii wide
        $buildinfo = "go:buildinfo" ascii wide
        $go_buildid = /Go build ID: "[a-zA-Z0-9_\/+-]+"/ ascii wide
        $mod_path = "edmjkExqBBpnduw" ascii wide

        // Standard Go runtime strings expected in any Go 1.25+ binary
        $go_rt1 = "runtime.newobject" ascii wide
        $go_rt2 = "runtime.main" ascii wide
        $go_rt3 = "math/rand" ascii wide

    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C) + uint32(0x28)) == 0x00086664 and  // AMD64
        $go_ver and
        $cert_cn and
        $cert_issuer and
        $buildinfo and
        all of ($go_rt*) and
        filesize > 2MB and filesize < 3MB
}

Behavioral Hunt Query (Sigma-like)

title: ACR Stealer Go 1.25.4 x64 Execution
description: Detects execution of Go 1.25.4 x64 infostealer with PRNG-seeded C2 and no .rsrc
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - ImageLoaded|contains:
        - 'kernel32.dll'
        - 'ws2_32.dll'
        - 'crypt32.dll'
        - 'dnsapi.dll'
    - CommandLine|contains:
        - 'go1.25.4'  # unlikely in cmdline, but fallback
  golang_heap:
    - Hashes|contains: 'sha256=6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c'
  condition: selection and golang_heap
falsepositives:
  - Legitimate Go 1.25.4 binaries signed by quiverquant.com (none known)
level: high

Note: The above Sigma is illustrative — the true hunt value is in certificate-chain clustering and the Go build-ID entropy. A better operational hunt:

// KQL (Microsoft Sentinel / Defender for Endpoint)
DeviceFileEvents
| where SHA256 == "6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c"
    or (FolderPath endswith ".exe"
        and FileSize between (2500000 .. 2600000)
        and (FileName matches regex "^[a-zA-Z]{10,20}\.exe$" or true))
| join kind=inner (
    DeviceNetworkEvents
    | where RemoteUrl contains "quiverquant.com"
      or RemoteIP in ("5.252.155.72", "laserlogdnsop.icu")
) on DeviceId, Timestamp

IOC List

Indicator Value Type
SHA-256 6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c Hash
MD5 2c29929e39ad7550ec5157d6e2334e21 Hash (.text section)
Certificate CN quiverquant.com Cert Subject
Certificate Issuer CN=WE1 Cert Issuer
Certificate Serial 10:f6:9e:50:b0:5b:14:f3:0e:bf:13:91:55:b6:58:87 Cert Serial
Validity 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC Cert Window
Go Build ID qr_31Ywyy4quzMZNywYz/H-wffFry297fy90bktOW/fGrOsEw_bOGHtMLlYQ3s/Jb8LC_oWEnvZQCj43HAj Build Fingerprint
Module Path edmjkExqBBpnduw Go Module
File Size 2,556,032 bytes Size
Entropy (.text) 6.2557 Section Metric
Entropy (.rdata) 7.0955 Section Metric

Behavioral Fingerprint

This binary is a Go 1.25.4 x64 static executable (CGO disabled, trimpath enabled) with a self-signed Authenticode certificate chaining to a non-trusted root WE1. It has no embedded icon resources (.rsrc absent) and no VS_VERSIONINFO. On execution, it seeds a math/rand PRNG with a time-derived value in main.main, then iterates a type-assertion lookup table before branching to randomized main.* functions. No C2 strings are present statically — C2 resolution is runtime-only via the PRNG-seeded decode chain. The binary imports the full standard Windows API surface via syscall (kernel32, ws2_32, crypt32, dnsapi, advapi32, etc.) consistent with a Go-based infostealer/RAT. The .symtab section (111 KB) contains full Go runtime debugging symbols, including 49 randomized main.* function names and 8 custom type equality routines.

Detection Signatures

Technique ATT&CK ID Evidence
Command Obfuscation T1027.002 Randomized Go module path and function names ^[strings.txt]
Data from Local System T1005 Inferred from infostealer family behaviour
Exfiltration Over C2 Channel T1041 Inferred from net/http + crypto/tls linkage and family pattern
Input Capture T1056 Inferred from family behaviour (clipboard, keylogging)
Screen Capture T1113 Inferred from family behaviour
Credentials from Password Stores T1555 Inferred from family behaviour (browser credential theft)
Application Layer Protocol: Web Protocols T1071.001 Inferred from net/http + crypto/tls

References

Provenance

  • file.txt — file(1) output (file type identification)
  • pefile.txt — pefile Python library PE header dump (sections, timestamps, entropy)
  • strings.txt — strings -a -n 6 output (9,073 lines) — primary source for Go build artefacts, function names, type names, Windows API references
  • rabin2-info.txt — radare2 rabin2 -I summary (Go language detection, signed status, overlay)
  • exiftool.json — ExifTool PE metadata (linker version, subsystem, entry point)
  • binwalk.txt — binwalk surface scan (certificate detection at offset 0x26F808)
  • metadata.json — OpenCTI label provenance (dropped-by-gcleaner, mix4.file, signed)
  • triage.json — Pipeline tier assignment (deep, no family attribution)
  • radare2 analysis (aaa level 3) — 2,134 functions recovered, main.main decompiled at 0x14009ad60
  • Certificate DER parsing via openssl pkcs7 -inform DER -noout -print_certs -text
  • Go buildinfo extraction via direct binary offset inspection (offset 0x23ce02 for Go buildinf, 0xe4610 for go1.25.4)
  • capa.txt — capa signatures not installed (OSError); no capability data available
  • floss.txt — flare-floss invocation error (invalid --no argument); no decoded strings available
  • dynamic-analysis.md — CAPE skipped (no Windows guest available)