typeanalysisfamilyacrstealercreated2026-08-10
SHA-256: 725dc07c0f1b552ac6df04855134a866679c97b320c27514050c43be51516c91

Build / RE

Toolchain: Go 1.25.4 (go1.25.4), GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true ^[strings.txt:1714] ^[strings.txt:1718]. Build ID B-xyODf5soAklxquRjBK/ewpsdF48Lcq9DP82gLb9/Jad566hI-EP7zysUs7Zy/2-FFKt3mHJqVFLUgdhoR ^[strings.txt:10].

Module path: Randomized package name KdPawPMBlXxJKvg ^[strings.txt:1718].

Signing: Self-signed Authenticode certificate, CN=quiverquant.com, issuer WE1, validity 2026-05-09 to 2026-08-07 ^[binwalk.txt:17] ^[pefile.txt — cert extraction]. Third confirmed sample on this cert chain (after f668de57 and 1cf857a9).

Obfuscation: 92 randomized main.* function names ^[strings.txt]. No external packer (.text entropy 6.26) ^[pefile.txt]. Null PE timestamp (Go -trimpath linker behavior) ^[pefile.txt].

Resources: .rsrc section contains five PNG icons (16×16, 32×32, 64×64, 128×128, 256×256) ^[binwalk.txt].

Imports: Only kernel32.dll — Go fully-static binary with no external C runtime ^[rabin2-info.txt].

Anti-analysis: No debug checks, VM detection, or anti-disassembly observed. Light build.

Notable functions: main.main seeds math/rand PRNG with time.Now().UnixNano() and iterates over a list of randomized function pointers, consistent with the family-wide PRNG-seeded C2 decode pattern ^[r2:sym.main.main].

Deploy / ATT&CK

Execution: No observed persistence mechanism statically. Standard Go main.main entry point.

Network: crypto/tls and net/http packages linked statically ^[strings.txt:1644], but no C2 IP, domain, or URL present in strings — runtime-decoded via PRNG-seeded technique (see prng-seeded-c2-url-decoding) ^[strings.txt]. This is the standard acrstealer pattern.

Collection: Infostealer behavior inferred from family attribution (browser credential stores, cryptocurrency wallets, FTP/SSH credentials). No static confirmation of specific target paths in this sample.

Exfiltration: POST to C2 endpoints inferred from net/http linkage and family behavior. No static confirmation.

ATT&CK mapping:

  • T1071.001 — Application Layer Protocol: Web (TLS/HTTP C2, inferred)
  • T1027 — Obfuscated Files or Information (PRNG-seeded C2 decode)
  • T1083 — File and Directory Discovery (infostealer family behavior)

Attribution: High-confidence acrstealer family attribution via: Go 1.25.4 + amd64 + CGO_ENABLED=0 + -trimpath + randomized module path KdPawPMBlXxJKvg + 92 randomized main.* functions + self-signed quiverquant.com/WE1 cert + five-icon .rsrc masquerade + null PE timestamp + no static C2. This is the thirtieth confirmed sibling in the acrstealer cluster, and the third confirmed sample on the quiverquant.com/WE1 cert chain (preceded by f668de57 and 1cf857a9).

Static-only: CAPE skipped — no Windows guest available ^[dynamic-analysis.md].