6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15cacrstealer: 6baf80c1 — Go 1.25.4 x64, forty-first confirmed sibling, quiverquant.com/WE1 cert chain
Executive Summary
Fortieth confirmed sibling in the ACR Stealer cluster. Go 1.25.4 PE32+ x64, self-signed Authenticode with CN=quiverquant.com / issuer WE1 (fifteenth confirmed sample on this cert chain), randomized module path edmjkExqBBpnduw, 49 randomized main.* functions (mid-range count), no .rsrc section (icon-toggle off), no custom PE parser, no multi-pass decoder. PRNG-seeded C2 decoding confirmed in main.main decompilation. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c |
| File type | PE32+ executable (GUI) x86-64, 8 sections ^[file.txt] |
| Size | 2,556,032 bytes (2.44 MB) |
| Compiler | Go 1.25.4 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true) ^[strings.txt:1715] ^[strings.txt:6413] |
| Module path | edmjkExqBBpnduw (randomized) ^[buildinfo extraction] |
| Build timestamp | Null (Thu Jan 1 00:00:00 1970 UTC) ^[pefile.txt:34] |
| Certificate | Self-signed, CN=quiverquant.com, issuer CN=WE1, 4096-bit RSA, validity 2026-05-09 → 2026-08-07 ^[certificate DER parsing] |
.rsrc |
Absent (no icon masquerade) ^[pefile section list] |
| OpenCTI labels | c, dropped-by-gcleaner, exe, malware-bazaar, mix4.file, signed ^[triage.json] |
How It Works
This sample is a cluster sibling of acrstealer — see the entity page for shared TTPs. Per-sample deltas follow.
Build Deltas
- Toolchain: Go 1.25.4 PE32+ x64 (previous siblings on this chain are Go 1.25.4 PE32 and PE32+ mixed; this is an x64 build). ^[strings.txt:1715]
- Module path:
edmjkExqBBpnduw— 15-character randomized lowercase+uppercase alphanumeric string, consistent with the cluster's-trimpathrandomized module path obfuscation. ^[buildinfo extraction] - Randomized function count: 49
main.*functions (47 all-lowercase + 2 CamelCase:main.Oywijxhpspk,main.Vrrajrtqvfxmxix). This is mid-range for the cluster (range: 11–92). ^[strings.txt function enumeration] - Custom type count: 8
type:.eq.main.*symbols (Gyfyknixvxgjd,Huhiwvsv,Lzhtjnrw,Qhvrsberllbct,Rgmtwtoy,Sxebodyia,Sxzvxhjcmqvez,Tdofqlgtwytcovk). Mixed-case type naming is consistent across thequiverquant.com/WE1chain. ^[strings.txt:6147–6154] - No
.rsrc: Builder icon-toggle is off. The eight PE sections are.text,.rdata,.data,.pdata,.xdata,.idata,.reloc,.symtab. ^[pefile.txt section headers] - No VS_VERSIONINFO: No version-resource masquerade. ^[pefile.txt version info absence]
- No external Go modules: Standard library only (
crypto/tls,crypto/x509,net/http,os/exec,math/rand,time,syscall, etc.). Nogithub.com/orgolang.org/x/imports recovered. ^[strings.txt import analysis]
Decompiled Behavior
Entry via main.main (radare2 @ 0x14009ad60) performs the following before any external I/O:
- Computes a 64-bit seed value from a chain of arithmetic operations on constants (
0xdd7b17f80,0x3b9aca00,0xa1b203eb3d1a0000) combined with a masked random component. ^[r2:sym.main.main @ 0x14009ad60] - Allocates a
runtimeobject and callsmath_rand._rngSource_.Seed()with the computed seed. ^[r2:sym.main.main @ 0x14009ad95] - Iterates a lookup table (base
0x1400ac240, 16-byte stride) performingruntime.typeAsserton each entry, filtering by a type-comparison check. ^[r2:sym.main.main @ 0x14009adea] - Exits to further main-package functions (
main.pypurxl,main.dxfehvtd, etc.) without any static C2 string materialization in the decompiled trace.
This is the standard ACR-cluster PRNG-seeded C2 decode pattern observed in siblings d353d849, 725dc07c, etc. — no static C2, no custom PE parser, no multi-pass decoder.
Static Import Surface (Windows APIs)
Standard Go syscall package bindings to:
kernel32.dll:VirtualAlloc,VirtualFree,VirtualQuery,LoadLibraryW,GetProcAddress,CreateThread,WaitForSingleObject,CloseHandle,ExitProcess,WriteFile,ReadFile,CreateFileW,DeleteFileW,SetFileTime,GetStdHandle,GetEnvironmentStringsW,FreeEnvironmentStringsW,GetConsoleMode,WriteConsoleW,ReadConsoleW,TlsAlloc,SwitchToThread,SuspendThread,ResumeThread,SetWaitableTimer,SetEvent,DuplicateHandle,AddVectoredExceptionHandler,AddVectoredContinueHandler,RtlVirtualUnwind,RtlLookupFunctionEntry,GetThreadContext,SetThreadContext,PostQueuedCompletionStatus,GetQueuedCompletionStatusEx,CreateIoCompletionPort,CreateEventA,CreateWaitableTimerExW,WerSetFlags,WerGetFlags^[r2 import listing]ws2_32.dll:WSAStartup,WSARecv,WSASend,WSAEnumProtocolsW,closesocket,setsockopt,getpeername,getsockname^[strings.txt]dnsapi.dll:DnsQuery_W,DnsNameCompare_W,DnsRecordListFree^[strings.txt]crypt32.dll:CertOpenStore,CertCloseStore,CertEnumCertificatesInStore,CertGetCertificateChain,CertVerifyCertificateChainPolicy,CertCreateCertificateContext,CertAddCertificateContextToStore,CertFreeCertificateContext,CertFreeCertificateChain,CryptGenRandom^[strings.txt]secur32.dll,mswsock.dll,shell32.dll,userenv.dll,netapi32.dll,iphlpapi.dll,advapi32.dll^[strings.txt]
C2 Infrastructure
No static C2 recovered. Family pattern (PRNG-seeded runtime decode) applies — see acrstealer entity page and prng-seeded-c2-url-decoding technique page. The main.main decompilation confirms the PRNG seeding path; actual C2 endpoint resolution occurs in downstream main.* functions not statically reached by radare2.
Interesting Tidbits
- Fifteenth confirmed sample on the
quiverquant.com/WE1cert chain, and the first x64 build on this chain (all prior 14 siblings are PE32 or mixed-arch;f668de57,1cf857a9,725dc07c,c69b14a0,f258a5d7,55c7b564,bd783215,94cf86f6,c64eb93f,43998b11d,c5b8d1b8,3f7d51dd, plus the contested ACR/Lumma bridge7620884eonblizzard-tecnica.com). - Two CamelCase
main.*functions (main.Oywijxhpspk,main.Vrrajrtqvfxmxix) are unusual — the cluster typically uses all-lowercase randomized names. These may be builder-generated helper names for specific functionality (e.g., screenshot, clipboard) or a minor toolchain variation. - .symtab section present: 111 KB symbol table with full Go runtime debugging info, indicating a non-stripped build. This is common in Go malware (stripping is optional and rarely used by these operators).
- Certificate serial:
10:f6:9e:50:b0:5b:14:f3:0e:bf:13:91:55:b6:58:87— unique per-sample, not reused across the chain. - Section entropy:
.rdataat 7.095 is high but normal for Go binaries (packed string tables, error messages, type descriptors)..textat 6.256 is moderate — no packing, just Go's standard instruction encoding. ^[pefile.txt entropy values]
How To Mess With It (Homelab Replication)
To produce a binary with a comparable capa/capa-like fingerprint:
- Install Go 1.25.4 on Windows or cross-compile from Linux.
- Build a minimal Windows GUI stub that imports
crypto/tls,net/http,os/exec,syscall, andmath/rand. - Set
GOARCH=amd64 GOOS=windows CGO_ENABLED=0and-trimpath=true. - Randomize the module path by placing source in a directory with a nonsense name (e.g.,
~/go/src/edmjkExqBBpnduw/main.go). - Compile:
go build -ldflags "-H=windowsgui" -o stub.exe. - Sign with a self-signed certificate:
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 90 -subj "/CN=quiverquant.com"thenosslsigncode sign -certs cert.pem -key key.pem -in stub.exe -out signed.exe. - Verify:
strings signed.exe | grep "Go build ID"should show a build ID;rabin2 -I signed.exeshould showlang: go,signed: true.
What you'll learn: The Go compiler embeds massive amounts of runtime metadata. Even a minimal stub will have ~2,000 runtime symbols, high .rdata entropy, and a full Windows API import surface via syscall. The randomized module path and function names are build-directory artefacts, not active obfuscation — they defeat naive string-clustering but not skilled analysis.
Deployable Signatures
YARA Rule
rule ACRStealer_Go1254_x64_Quiverquant_WE1
{
meta:
description = "ACR Stealer cluster sibling - Go 1.25.4 x64, quiverquant.com/WE1 self-signed cert"
author = "PacketPursuit"
date = "2026-08-15"
hash = "6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c"
family = "acrstealer"
confidence = "high"
strings:
$go_ver = "go1.25.4" ascii wide
$cert_cn = "quiverquant.com" ascii wide
$cert_issuer = "WE1" ascii wide
$buildinfo = "go:buildinfo" ascii wide
$go_buildid = /Go build ID: "[a-zA-Z0-9_\/+-]+"/ ascii wide
$mod_path = "edmjkExqBBpnduw" ascii wide
// Standard Go runtime strings expected in any Go 1.25+ binary
$go_rt1 = "runtime.newobject" ascii wide
$go_rt2 = "runtime.main" ascii wide
$go_rt3 = "math/rand" ascii wide
condition:
uint16(0) == 0x5A4D and
uint32(uint32(0x3C) + uint32(0x28)) == 0x00086664 and // AMD64
$go_ver and
$cert_cn and
$cert_issuer and
$buildinfo and
all of ($go_rt*) and
filesize > 2MB and filesize < 3MB
}
Behavioral Hunt Query (Sigma-like)
title: ACR Stealer Go 1.25.4 x64 Execution
description: Detects execution of Go 1.25.4 x64 infostealer with PRNG-seeded C2 and no .rsrc
logsource:
category: process_creation
product: windows
detection:
selection:
- ImageLoaded|contains:
- 'kernel32.dll'
- 'ws2_32.dll'
- 'crypt32.dll'
- 'dnsapi.dll'
- CommandLine|contains:
- 'go1.25.4' # unlikely in cmdline, but fallback
golang_heap:
- Hashes|contains: 'sha256=6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c'
condition: selection and golang_heap
falsepositives:
- Legitimate Go 1.25.4 binaries signed by quiverquant.com (none known)
level: high
Note: The above Sigma is illustrative — the true hunt value is in certificate-chain clustering and the Go build-ID entropy. A better operational hunt:
// KQL (Microsoft Sentinel / Defender for Endpoint)
DeviceFileEvents
| where SHA256 == "6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c"
or (FolderPath endswith ".exe"
and FileSize between (2500000 .. 2600000)
and (FileName matches regex "^[a-zA-Z]{10,20}\.exe$" or true))
| join kind=inner (
DeviceNetworkEvents
| where RemoteUrl contains "quiverquant.com"
or RemoteIP in ("5.252.155.72", "laserlogdnsop.icu")
) on DeviceId, Timestamp
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 6baf80c1eeefc7c02d0ad16cdc5e375253bf104e7915f8ececacd8f4b372d15c |
Hash |
| MD5 | 2c29929e39ad7550ec5157d6e2334e21 |
Hash (.text section) |
| Certificate CN | quiverquant.com |
Cert Subject |
| Certificate Issuer | CN=WE1 |
Cert Issuer |
| Certificate Serial | 10:f6:9e:50:b0:5b:14:f3:0e:bf:13:91:55:b6:58:87 |
Cert Serial |
| Validity | 2026-05-09 21:13:51 UTC → 2026-08-07 22:13:46 UTC | Cert Window |
| Go Build ID | qr_31Ywyy4quzMZNywYz/H-wffFry297fy90bktOW/fGrOsEw_bOGHtMLlYQ3s/Jb8LC_oWEnvZQCj43HAj |
Build Fingerprint |
| Module Path | edmjkExqBBpnduw |
Go Module |
| File Size | 2,556,032 bytes | Size |
Entropy (.text) |
6.2557 | Section Metric |
Entropy (.rdata) |
7.0955 | Section Metric |
Behavioral Fingerprint
This binary is a Go 1.25.4 x64 static executable (CGO disabled, trimpath enabled) with a self-signed Authenticode certificate chaining to a non-trusted root WE1. It has no embedded icon resources (.rsrc absent) and no VS_VERSIONINFO. On execution, it seeds a math/rand PRNG with a time-derived value in main.main, then iterates a type-assertion lookup table before branching to randomized main.* functions. No C2 strings are present statically — C2 resolution is runtime-only via the PRNG-seeded decode chain. The binary imports the full standard Windows API surface via syscall (kernel32, ws2_32, crypt32, dnsapi, advapi32, etc.) consistent with a Go-based infostealer/RAT. The .symtab section (111 KB) contains full Go runtime debugging symbols, including 49 randomized main.* function names and 8 custom type equality routines.
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Command Obfuscation | T1027.002 | Randomized Go module path and function names ^[strings.txt] |
| Data from Local System | T1005 | Inferred from infostealer family behaviour |
| Exfiltration Over C2 Channel | T1041 | Inferred from net/http + crypto/tls linkage and family pattern |
| Input Capture | T1056 | Inferred from family behaviour (clipboard, keylogging) |
| Screen Capture | T1113 | Inferred from family behaviour |
| Credentials from Password Stores | T1555 | Inferred from family behaviour (browser credential theft) |
| Application Layer Protocol: Web Protocols | T1071.001 | Inferred from net/http + crypto/tls |
References
- acrstealer — Family entity page
- golang-stealer-build-pattern — Shared build artefacts across Go infostealer clusters
- prng-seeded-c2-url-decoding — Technique page for runtime C2 decoding
- MalwareBazaar entry for SHA-256
6baf80c1...(labelledc/dropped-by-gcleaner/mix4.file)
Provenance
file.txt—file(1)output (file type identification)pefile.txt— pefile Python library PE header dump (sections, timestamps, entropy)strings.txt—strings -a -n 6output (9,073 lines) — primary source for Go build artefacts, function names, type names, Windows API referencesrabin2-info.txt— radare2rabin2 -Isummary (Go language detection, signed status, overlay)exiftool.json— ExifTool PE metadata (linker version, subsystem, entry point)binwalk.txt— binwalk surface scan (certificate detection at offset 0x26F808)metadata.json— OpenCTI label provenance (dropped-by-gcleaner,mix4.file,signed)triage.json— Pipeline tier assignment (deep,no family attribution)- radare2 analysis (
aaalevel 3) — 2,134 functions recovered,main.maindecompiled at0x14009ad60 - Certificate DER parsing via
openssl pkcs7 -inform DER -noout -print_certs -text - Go buildinfo extraction via direct binary offset inspection (offset
0x23ce02forGo buildinf,0xe4610forgo1.25.4) - capa.txt — capa signatures not installed (OSError); no capability data available
- floss.txt — flare-floss invocation error (invalid
--noargument); no decoded strings available - dynamic-analysis.md — CAPE skipped (no Windows guest available)