6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0eacrstealer: 6cbac6bc — Go 1.18.5 x64 sibling, self-signed atom.hutsell.com cert, no .rsrc
Eleventh confirmed sibling in the acrstealer cluster. Go 1.18.5 PE32+ x64 (not the usual PE32), self-signed Authenticode CN=atom.hutsell.com / issuer WR3, identical certificate chain to sibling ef262340. Notable divergence: no .rsrc section — the builder stripped icon masquerade assets. OpenCTI mislabeled as remusstealer; static evidence places it squarely in the ACR cluster.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e |
| File type | PE32+ executable (GUI) x86-64, 6 sections ^[file.txt] |
| Size | 1.5 MB (1,542,272 bytes) ^[exiftool.json] |
| Compiler | Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0) ^[strings.txt:1153] ^[strings.txt:3529] |
| Module path | AhfGUgsIWgxFnho ^[strings.txt:1158] ^[strings.txt:3531] |
| Entry point | 0x5AB40 ^[pefile.txt] |
| Signing | Self-signed Authenticode, CN=atom.hutsell.com, issuer WR3 ^[binwalk.txt] ^[rabin2-info.txt] |
| Timestamp | Null (0x0, 1970-01-01) ^[pefile.txt] |
| Family | acrstealer (cluster sibling, high-confidence) ^[triage.json] ^[entities/acrstealer.md] |
| OpenCTI label | remusstealer (contested — see remusstealer) ^[triage.json] |
Cluster sibling analysis: see acrstealer for the full family fingerprint. This sample is the eleventh confirmed sibling and the second built on Go 1.18.5 (after ef262340). Unlike ef262340 (PE32 x86, 2.3 MB, .rsrc icons present), this build targets amd64 and omits the .rsrc section entirely.
How It Works
Static-only analysis (CAPE skipped — no Windows guest). Behaviour inferred from family pattern, standard Go library linkage, and decompiled entry flow.
- Runtime bootstrap: Standard Go
runtime.main→main.mainentry viapclntab-guided dispatch. ^[r2:entry0 @ 0x45ab40] - Architecture divergence:
GOARCH=amd64produces a PE32+ with.textat0x1000,.rdataat0x85000,.dataat0x146000,.idataat0x1BA000,.relocat0x1BB000, and.symtabat0x1BE000. ^[pefile.txt] - C2 resolution: No hardcoded C2 in strings. The family uses a PRNG seeded with current time to decode C2 strings via multi-pass byte transform. ^[/intel/analyses/d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058c.html] ^[/intel/analyses/7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969.html]
- Network surface:
crypto/tlsandnet/httppackages are statically linked (evidenced by Go runtime error strings for TLS handshake and HTTP transport). ^[strings.txt:1108] This implies TLS-wrapped HTTPS C2, consistent with all other ACR siblings. - Collection: Family targets browser credential stores, cryptocurrency wallets, and FTP/SSH credentials. No static confirmation in this specific binary, but the
net/http+crypto/tls+runtimeprofile matches the family exactly. - Anti-analysis: Stripped PE symbol table (
IMAGE_FILE_DEBUG_STRIPPED), but Gopclntabremains intact, recovering allmain.*andruntime.*names. ^[pefile.txt]
Decompiled Behavior
Entrypoint (0x0045ab40) is the standard Go runtime bootstrap: CPUID probe for feature detection, cpuid vendor-string check (GenuineIntel), then runtime.main dispatch. ^[r2:entry0 @ 0x45ab40] No meaningful static decompilation of the threat logic is available without Go-specific tooling to resolve main.main from pclntab.
The main.* function names recovered from .rdata include:
main.Ntfany,main.Ohwrlf,main.Zqfaps,main.Fcrfeyc^[strings.txt:709–711]main.Usphnqtwpw,main.cxkerhcivkpl,main.Uuuulxbbznyqz,main.Avttowtyfnpltf^[strings.txt:872–978]main.boukknobrlcyln,main.vybrfb,main.zpoiptgwfml,main.fiwipsvopkz^[strings.txt:3257–3262]main.rcisxclqipna,main.xxeagw,main.scuuirza,main.Isemcptav^[strings.txt:3263–3266]main.Gynrhsjzpdgk,main.odnopuwgzxqce,main.vzjpqigm,main.wikgbr^[strings.txt:3267–3270]main.bgiskhflnpg,main.fhgydzjsgo,main.mgcpghpyu,main.phincenob^[strings.txt:3271–3274]main.xtomzlasdbmsd,main.urqriragpgky,main.iuxyvyzguvlwt,main.apwlnmu^[strings.txt:3275–3278]main.ynnlxqqzpfiq,main.hqgitgjxc,main.gmakucdf,main.ssogkftkp^[strings.txt:3279–3282]main.jcrpbndw,main.znvtqhknkc,main.ynzpswlzijinb,main.bdodumzogqne^[strings.txt:3284–3286]main.uvzfixhqdizzknr,main.yllpzdgssqvfc,main.nxjqrmsymgdkym,main.yrowzrpdqutuhj^[strings.txt:3290–3293]main.qjirqjr,main.rxmreywmwoea,main.dpypjkhmpe,main.nlgpoc^[strings.txt:3294–3297]main.main,main.init^[strings.txt:3298–3299]
These names are per-sample randomized and serve as an anti-clustering measure.
C2 Infrastructure
No static C2 recovered. The family pattern (siblings 7–9, plus 7620884e) confirms runtime-decoded C2 via PRNG-seeded string transforms. Previous siblings contacted:
5.252.155.72/laserlogdnsop.icuhertzfigblob.icublizzard-tecnica.com
This sample may share the same infrastructure pool but rotates domains per build. No hardcoded IPs, domains, URLs, mutexes, or named pipes found in static strings.
Interesting Tidbits
- OpenCTI mislabel: Tagged
remusstealerby OpenCTI, but every static artefact — Go 1.18.5, randomized module pathAhfGUgsIWgxFnho, self-signedatom.hutsell.com/WR3cert, randomizedmain.*function names — places this sample in the acrstealer cluster. Theremusstealerlabel should be treated as a false-positive co-label. ^[triage.json] ^[entities/remusstealer.md] - Certificate twin: Identical self-signed certificate chain (CN=
atom.hutsell.com, issuerWR3) to siblingef262340, confirming shared signing infrastructure or builder template. ^[/intel/analyses/ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7.html] - No
.rsrc: Unlikeef262340(which carried four PNG icon masquerade assets), this build hasIMAGE_DIRECTORY_ENTRY_RESOURCERVA0x0/ Size0x0. ^[pefile.txt:205–207] The builder supports an icon-toggle option; this sample was compiled without it. - Cyrillic homoglyph filename: Original filename
VеloсіtуGТ564.exe— uses Cyrillicе(U+0435),о(U+043E),і(U+0456),с(U+0441),у(U+0443),Т(U+0422) andG(U+0413) to visually mimic "VelocityGT564.exe". ^[triage.json] - AMD64 build on Go 1.18.5: All other ACR siblings from Go 1.18.5 through 1.26.2 observed in the corpus are
GOARCH=386(PE32). This is the first confirmedamd64sibling in the cluster, suggesting the builder supports both architectures. - Standard syscall surface: Imports only
kernel32.dll—VirtualAlloc,CreateThread,SetUnhandledExceptionFilter,GetProcAddress,LoadLibraryA/W, etc. No explicitwininet,ws2_32,crypt32, oradvapi32in the IAT; these are resolved at runtime by Go'snet/httpandcrypto/tlspackages viasyscallstub. ^[pefile.txt:248–280]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.18.5 (or any Go 1.18.x) for Windows AMD64.
Build command:
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags="-s -w -H=windowsgui" -o sample.exe .
Certificate: Self-sign with OpenSSL:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 90 -subj "/CN=atom.hutsell.com"
openssl pkcs12 -export -in cert.pem -inkey key.pem -out cert.pfx -password pass:
# Sign with signtool or osslsigncode
osslsigncode sign -pkcs12 cert.pfx -pass "" -in sample.exe -out signed.exe
Verification: Compare the resulting PE to this sample:
rabin2 -I signed.exeshould showlang: c,signed: true,stripped: true.strings signed.exe | grep "go1."should matchgo1.18.5.strings signed.exe | grep "mod "should show a randomized module path.
What you'll learn: How Go's -trimpath and randomized module paths poison dependency graphs, and how self-signed certificates can be batch-generated to add superficial trust to stealer builds.
Deployable Signatures
YARA rule
rule ACRStealer_Go1185_SelfSigned_Hutsell
{
meta:
description = "ACR Stealer cluster — Go 1.18.5 build with self-signed atom.hutsell.com certificate"
author = "PacketPursuit"
date = "2026-07-30"
hash = "6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e"
family = "acrstealer"
confidence = "high"
strings:
$go_build = "go1.18.5" ascii wide
$mod_path = /mod\t[A-Za-z0-9]{14,16}\t\(devel\)/
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$main_rand = /main\.[A-Za-z]{10,20}/
condition:
uint16(0) == 0x5A4D and
$go_build and
$mod_path and
$cert_cn and
$cert_issuer and
#main_rand > 20
}
Sigma rule
title: ACR Stealer Go Binary Execution
id: 6cbac6bc-acrstealer-go-exec
status: experimental
description: Detects execution of Go-compiled infostealer with randomized module paths and self-signed certificate
logsource:
product: windows
category: image_load
detection:
selection:
- ImageLoaded|endswith: '.exe'
- SignatureStatus: 'NotValid'
- SignatureIssuerName|contains: 'WR3'
condition: selection
falsepositives:
- Unknown
level: high
tags:
- attack.execution
- attack.t1059
- malware.acrstealer
IOC list
| Type | Value | Note |
|---|---|---|
| SHA-256 | 6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e |
Primary |
| SHA-1 | 1e70f5f492b3c6bb5f668a7e25c09de71462ad9b |
.text section hash |
| MD5 | 6fd1f963295849b17246f81fa20a3d25 |
.text section hash |
| Filename | VеloсіtуGТ564.exe |
Cyrillic homoglyph masquerade |
| Certificate CN | atom.hutsell.com |
Self-signed |
| Certificate Issuer | CN=WR3 |
Self-signed |
| Go module | AhfGUgsIWgxFnho |
Per-sample randomized |
| Go version | go1.18.5 |
Build toolchain |
Behavioral fingerprint statement
This binary is a Go 1.18.5 PE32+ x64 executable with a null PE timestamp, self-signed Authenticode certificate (CN=atom.hutsell.com, issuer WR3), and no .rsrc section. It imports only kernel32.dll APIs (VirtualAlloc, CreateThread, LoadLibrary, GetProcAddress) and resolves higher-level network/crypto APIs at runtime via Go's syscall stub. The main package contains 20+ randomized function names (10–20 mixed-case alphanumeric characters). No hardcoded C2 strings are present; C2 is decoded at runtime via a PRNG-seeded multi-pass byte transform, consistent with the acrstealer family pattern.
Detection Signatures
| Technique | ATT&CK ID | Evidence |
|---|---|---|
| Obfuscated Files or Information | T1027 | Randomized module paths and function names ^[strings.txt:1158] |
| Native API | T1106 | kernel32.dll API resolution via Go syscall stub ^[pefile.txt:248–280] |
| Virtualization/Sandbox Evasion | T1497 | No static C2; runtime-decoded via PRNG ^[family pattern] |
| Data Encrypted for Impact | T1486 | crypto/tls static linkage implies encrypted C2 channel ^[strings.txt:1108] |
| Application Layer Protocol | T1071.001 | HTTPS C2 via net/http + crypto/tls ^[family pattern] |
References
- Artifact ID:
05d33a5d-a44e-488c-8c9c-8fc016100365 - MalwareBazaar / OpenCTI: tagged
remusstealer(contested) - Related wiki pages: acrstealer, golang-stealer-build-pattern, remusstealer, fused-string-api-decoding
Provenance
Analysis derived from static artefacts in wiki/wiki/raw/analyses/6cbac6bcd1acb90031a31b9595deb4e9681450b9554a9e61e4fd20d81e450a0e/:
file.txt— file(1) outputexiftool.json— ExifTool PE metadatapefile.txt— pefile.py dumpstrings.txt— strings(1) outputrabin2-info.txt— radare2 binary header summarybinwalk.txt— embedded artefact scantriage.json— OpenCTI triage metadatadynamic-analysis.md— CAPE skipped (no Windows guest)ssdeep.txt,tlsh.txt— fuzzy hashesyara.txt— generic PE match only
Tools: radare2 5.x (entrypoint decompilation), openssl (certificate extraction), pefile.py (PE structure), binwalk (embedded artefact scan).