725dc07c0f1b552ac6df04855134a866679c97b320c27514050c43be51516c91Build / RE
Toolchain: Go 1.25.4 (go1.25.4), GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1714] ^[strings.txt:1718]. Build ID B-xyODf5soAklxquRjBK/ewpsdF48Lcq9DP82gLb9/Jad566hI-EP7zysUs7Zy/2-FFKt3mHJqVFLUgdhoR ^[strings.txt:10].
Module path: Randomized package name KdPawPMBlXxJKvg ^[strings.txt:1718].
Signing: Self-signed Authenticode certificate, CN=quiverquant.com, issuer WE1, validity 2026-05-09 to 2026-08-07 ^[binwalk.txt:17] ^[pefile.txt — cert extraction]. Third confirmed sample on this cert chain (after f668de57 and 1cf857a9).
Obfuscation: 92 randomized main.* function names ^[strings.txt]. No external packer (.text entropy 6.26) ^[pefile.txt]. Null PE timestamp (Go -trimpath linker behavior) ^[pefile.txt].
Resources: .rsrc section contains five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt].
Imports: Only kernel32.dll — Go fully-static binary with no external C runtime ^[rabin2-info.txt].
Anti-analysis: No debug checks, VM detection, or anti-disassembly observed. Light build.
Notable functions: main.main seeds math/rand PRNG with time.Now().UnixNano() and iterates over a list of randomized function pointers, consistent with the family-wide PRNG-seeded C2 decode pattern ^[r2:sym.main.main].
Deploy / ATT&CK
Execution: No observed persistence mechanism statically. Standard Go main.main entry point.
Network: crypto/tls and net/http packages linked statically ^[strings.txt:1644], but no C2 IP, domain, or URL present in strings — runtime-decoded via PRNG-seeded technique (see prng-seeded-c2-url-decoding) ^[strings.txt]. This is the standard acrstealer pattern.
Collection: Infostealer behavior inferred from family attribution (browser credential stores, cryptocurrency wallets, FTP/SSH credentials). No static confirmation of specific target paths in this sample.
Exfiltration: POST to C2 endpoints inferred from net/http linkage and family behavior. No static confirmation.
ATT&CK mapping:
- T1071.001 — Application Layer Protocol: Web (TLS/HTTP C2, inferred)
- T1027 — Obfuscated Files or Information (PRNG-seeded C2 decode)
- T1083 — File and Directory Discovery (infostealer family behavior)
Attribution: High-confidence acrstealer family attribution via: Go 1.25.4 + amd64 + CGO_ENABLED=0 + -trimpath + randomized module path KdPawPMBlXxJKvg + 92 randomized main.* functions + self-signed quiverquant.com/WE1 cert + five-icon .rsrc masquerade + null PE timestamp + no static C2. This is the thirtieth confirmed sibling in the acrstealer cluster, and the third confirmed sample on the quiverquant.com/WE1 cert chain (preceded by f668de57 and 1cf857a9).
Static-only: CAPE skipped — no Windows guest available ^[dynamic-analysis.md].