typeanalysisfamilyacrstealerconfidencehighcreated2026-07-30updated2026-07-30infostealermalware-familygolangsigninganti-analysis
SHA-256: 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e

acrstealer: 6cbac6bc — Go 1.18.5 x64 sibling, self-signed atom.hutsell.com cert, no .rsrc

Eleventh confirmed sibling in the acrstealer cluster. Go 1.18.5 PE32+ x64 (not the usual PE32), self-signed Authenticode CN=atom.hutsell.com / issuer WR3, identical certificate chain to sibling ef262340. Notable divergence: no .rsrc section — the builder stripped icon masquerade assets. OpenCTI mislabeled as remusstealer; static evidence places it squarely in the ACR cluster.

What It Is

Field Value
SHA-256 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e
File type PE32+ executable (GUI) x86-64, 6 sections ^[file.txt]
Size 1.5 MB (1,542,272 bytes) ^[exiftool.json]
Compiler Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:1153] ^[strings.txt:3529]
Module path AhfGUgsIWgxFnho ^[strings.txt:1158] ^[strings.txt:3531]
Entry point 0x5AB40 ^[pefile.txt]
Signing Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3 ^[binwalk.txt] ^[rabin2-info.txt]
Timestamp Null (0x0, 1970-01-01) ^[pefile.txt]
Family acrstealer (cluster sibling, high-confidence) ^[triage.json] ^[entities/acrstealer.md]
OpenCTI label remusstealer (contested — see remusstealer) ^[triage.json]

Cluster sibling analysis: see acrstealer for the full family fingerprint. This sample is the eleventh confirmed sibling and the second built on Go 1.18.5 (after ef262340). Unlike ef262340 (PE32 x86, 2.3 MB, .rsrc icons present), this build targets amd64 and omits the .rsrc section entirely.

How It Works

Static-only analysis (CAPE skipped — no Windows guest). Behaviour inferred from family pattern, standard Go library linkage, and decompiled entry flow.

  1. Runtime bootstrap: Standard Go runtime.main → main.main entry via pclntab-guided dispatch. ^[r2:entry0 @ 0x45ab40]
  2. Architecture divergence: GOARCH=amd64 produces a PE32+ with .text at 0x1000, .rdata at 0x85000, .data at 0x146000, .idata at 0x1BA000, .reloc at 0x1BB000, and .symtab at 0x1BE000. ^[pefile.txt]
  3. C2 resolution: No hardcoded C2 in strings. The family uses a PRNG seeded with current time to decode C2 strings via multi-pass byte transform. ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] ^[/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html]
  4. Network surface: crypto/tls and net/http packages are statically linked (evidenced by Go runtime error strings for TLS handshake and HTTP transport). ^[strings.txt:1108] This implies TLS-wrapped HTTPS C2, consistent with all other ACR siblings.
  5. Collection: Family targets browser credential stores, cryptocurrency wallets, and FTP/SSH credentials. No static confirmation in this specific binary, but the net/http + crypto/tls + runtime profile matches the family exactly.
  6. Anti-analysis: Stripped PE symbol table (IMAGE_FILE_DEBUG_STRIPPED), but Go pclntab remains intact, recovering all main.* and runtime.* names. ^[pefile.txt]

Decompiled Behavior

Entrypoint (0x0045ab40) is the standard Go runtime bootstrap: CPUID probe for feature detection, cpuid vendor-string check (GenuineIntel), then runtime.main dispatch. ^[r2:entry0 @ 0x45ab40] No meaningful static decompilation of the threat logic is available without Go-specific tooling to resolve main.main from pclntab.

The main.* function names recovered from .rdata include:

  • main.Ntfany, main.Ohwrlf, main.Zqfaps, main.Fcrfeyc ^[strings.txt:709–711]
  • main.Usphnqtwpw, main.cxkerhcivkpl, main.Uuuulxbbznyqz, main.Avttowtyfnpltf ^[strings.txt:872–978]
  • main.boukknobrlcyln, main.vybrfb, main.zpoiptgwfml, main.fiwipsvopkz ^[strings.txt:3257–3262]
  • main.rcisxclqipna, main.xxeagw, main.scuuirza, main.Isemcptav ^[strings.txt:3263–3266]
  • main.Gynrhsjzpdgk, main.odnopuwgzxqce, main.vzjpqigm, main.wikgbr ^[strings.txt:3267–3270]
  • main.bgiskhflnpg, main.fhgydzjsgo, main.mgcpghpyu, main.phincenob ^[strings.txt:3271–3274]
  • main.xtomzlasdbmsd, main.urqriragpgky, main.iuxyvyzguvlwt, main.apwlnmu ^[strings.txt:3275–3278]
  • main.ynnlxqqzpfiq, main.hqgitgjxc, main.gmakucdf, main.ssogkftkp ^[strings.txt:3279–3282]
  • main.jcrpbndw, main.znvtqhknkc, main.ynzpswlzijinb, main.bdodumzogqne ^[strings.txt:3284–3286]
  • main.uvzfixhqdizzknr, main.yllpzdgssqvfc, main.nxjqrmsymgdkym, main.yrowzrpdqutuhj ^[strings.txt:3290–3293]
  • main.qjirqjr, main.rxmreywmwoea, main.dpypjkhmpe, main.nlgpoc ^[strings.txt:3294–3297]
  • main.main, main.init ^[strings.txt:3298–3299]

These names are per-sample randomized and serve as an anti-clustering measure.

C2 Infrastructure

No static C2 recovered. The family pattern (siblings 7–9, plus 7620884e) confirms runtime-decoded C2 via PRNG-seeded string transforms. Previous siblings contacted:

  • 5.252.155.72 / laserlogdnsop.icu
  • hertzfigblob.icu
  • blizzard-tecnica.com

This sample may share the same infrastructure pool but rotates domains per build. No hardcoded IPs, domains, URLs, mutexes, or named pipes found in static strings.

Interesting Tidbits

  • OpenCTI mislabel: Tagged remusstealer by OpenCTI, but every static artefact — Go 1.18.5, randomized module path AhfGUgsIWgxFnho, self-signed atom.hutsell.com / WR3 cert, randomized main.* function names — places this sample in the acrstealer cluster. The remusstealer label should be treated as a false-positive co-label. ^[triage.json] ^[entities/remusstealer.md]
  • Certificate twin: Identical self-signed certificate chain (CN=atom.hutsell.com, issuer WR3) to sibling ef262340, confirming shared signing infrastructure or builder template. ^[/intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html]
  • No .rsrc: Unlike ef262340 (which carried four PNG icon masquerade assets), this build has IMAGE_DIRECTORY_ENTRY_RESOURCE RVA 0x0 / Size 0x0. ^[pefile.txt:205–207] The builder supports an icon-toggle option; this sample was compiled without it.
  • Cyrillic homoglyph filename: Original filename VеloсіtуGТ564.exe — uses Cyrillic е (U+0435), о (U+043E), і (U+0456), с (U+0441), у (U+0443), Т (U+0422) and G (U+0413) to visually mimic "VelocityGT564.exe". ^[triage.json]
  • AMD64 build on Go 1.18.5: All other ACR siblings from Go 1.18.5 through 1.26.2 observed in the corpus are GOARCH=386 (PE32). This is the first confirmed amd64 sibling in the cluster, suggesting the builder supports both architectures.
  • Standard syscall surface: Imports only kernel32.dll — VirtualAlloc, CreateThread, SetUnhandledExceptionFilter, GetProcAddress, LoadLibraryA/W, etc. No explicit wininet, ws2_32, crypt32, or advapi32 in the IAT; these are resolved at runtime by Go's net/http and crypto/tls packages via syscall stub. ^[pefile.txt:248–280]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.18.5 (or any Go 1.18.x) for Windows AMD64.

Build command:

GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o sample.exe .

Certificate: Self-sign with OpenSSL:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com"
openssl pkcs12 -export -in cert.pem -inkey key.pem -out cert.pfx -password pass:
# Sign with signtool or osslsigncode
osslsigncode sign -pkcs12 cert.pfx -pass "" -in sample.exe -out signed.exe

Verification: Compare the resulting PE to this sample:

  • rabin2 -I signed.exe should show lang: c, signed: true, stripped: true.
  • strings signed.exe | grep "go1." should match go1.18.5.
  • strings signed.exe | grep "mod " should show a randomized module path.

What you'll learn: How Go's -trimpath and randomized module paths poison dependency graphs, and how self-signed certificates can be batch-generated to add superficial trust to stealer builds.

Deployable Signatures

YARA rule

rule ACRStealer_Go1185_SelfSigned_Hutsell
{
    meta:
        description = "ACR Stealer cluster — Go 1.18.5 build with self-signed atom.hutsell.com certificate"
        author = "PacketPursuit"
        date = "2026-07-30"
        hash = "6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e"
        family = "acrstealer"
        confidence = "high"

    strings:
        $go_build = "go1.18.5" ascii wide
        $mod_path = /mod\t[A-Za-z0-9]{14,16}\t\(devel\)/
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $main_rand = /main\.[A-Za-z]{10,20}/

    condition:
        uint16(0) == 0x5A4D and
        $go_build and
        $mod_path and
        $cert_cn and
        $cert_issuer and
        #main_rand > 20
}

Sigma rule

title: ACR Stealer Go Binary Execution
id: 6cbac6bc-acrstealer-go-exec
status: experimental
description: Detects execution of Go-compiled infostealer with randomized module paths and self-signed certificate
logsource:
  product: windows
  category: image_load
detection:
  selection:
    - ImageLoaded|endswith: '.exe'
    - SignatureStatus: 'NotValid'
    - SignatureIssuerName|contains: 'WR3'
  condition: selection
falsepositives:
  - Unknown
level: high
tags:
  - attack.execution
  - attack.t1059
  - malware.acrstealer

IOC list

Type Value Note
SHA-256 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e Primary
SHA-1 1e70f5f492b3c6bb5f668a7e25c09de71462ad9b .text section hash
MD5 6fd1f963295849b17246f81fa20a3d25 .text section hash
Filename VеloсіtуGТ564.exe Cyrillic homoglyph masquerade
Certificate CN atom.hutsell.com Self-signed
Certificate Issuer CN=WR3 Self-signed
Go module AhfGUgsIWgxFnho Per-sample randomized
Go version go1.18.5 Build toolchain

Behavioral fingerprint statement

This binary is a Go 1.18.5 PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate (CN=atom.hutsell.com, issuer WR3), and no .rsrc section. It imports only kernel32.dll APIs (VirtualAlloc, CreateThread, LoadLibrary, GetProcAddress) and resolves higher-level network/crypto APIs at runtime via Go's syscall stub. The main package contains 20+ randomized function names (10–20 mixed-case alphanumeric characters). No hardcoded C2 strings are present; C2 is decoded at runtime via a PRNG-seeded multi-pass byte transform, consistent with the acrstealer family pattern.

Detection Signatures

Technique ATT&CK ID Evidence
Obfuscated Files or Information T1027 Randomized module paths and function names ^[strings.txt:1158]
Native API T1106 kernel32.dll API resolution via Go syscall stub ^[pefile.txt:248–280]
Virtualization/Sandbox Evasion T1497 No static C2; runtime-decoded via PRNG ^[family pattern]
Data Encrypted for Impact T1486 crypto/tls static linkage implies encrypted C2 channel ^[strings.txt:1108]
Application Layer Protocol T1071.001 HTTPS C2 via net/http + crypto/tls ^[family pattern]

References

Provenance

Analysis derived from static artefacts in wiki/wiki/raw/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e/:

  • file.txt — file(1) output
  • exiftool.json — ExifTool PE metadata
  • pefile.txt — pefile.py dump
  • strings.txt — strings(1) output
  • rabin2-info.txt — radare2 binary header summary
  • binwalk.txt — embedded artefact scan
  • triage.json — OpenCTI triage metadata
  • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • ssdeep.txt, tlsh.txt — fuzzy hashes
  • yara.txt — generic PE match only

Tools: radare2 5.x (entrypoint decompilation), openssl (certificate extraction), pefile.py (PE structure), binwalk (embedded artefact scan).