typeanalysisfamilyacrstealerconfidencehighcreated2026-08-05updated2026-08-05infostealermalware-familygolangsigningpe
SHA-256: 76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6

acrstealer: 76a51fb7 — Go 1.18.5 amd64, 11-function minimal sibling

Executive Summary: Nineteenth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 static binary with CGO_ENABLED=0, randomized module path DyLfjKADwKUPEjD, and only eleven randomized main.* functions — the joint-smallest count in the cluster. Self-signed Authenticode (CN=atom.hutsell.com, issuer=WR3, validity Apr–Jul 2026). .rsrc contains a 256×256 PNG icon; no static C2 strings. No custom in-memory PE parser or multi-pass decoder observed. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

  • SHA-256: 76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6
  • Type: PE32+ executable (GUI) x86-64, 7 sections, stripped, null timestamp ^[file.txt]
  • Size: 1,980,320 bytes (1.89 MB)
  • Compiler: Go 1.18.5 (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -compiler=gc) ^[strings.txt:1154] ^[strings.txt:1160-1163]
  • Build ID: LdTzuCfWnSzAzOMFtwiR/BgqhBgI_j3YEkbpAO6S_/GhN-HhfYPmkp0vA8hH4L/-yokbhCys2bN3O4u0fS1 ^[strings.txt:8]
  • Module path: DyLfjKADwKUPEjD ^[strings.txt:1158]
  • Signing: Self-signed Authenticode embedded at IMAGE_DIRECTORY_ENTRY_SECURITY offset 0x1EE208 / size 0x880 ^[pefile.txt:232-233]
    • Subject: CN=atom.hutsell.com
    • Issuer: CN=WR3
    • Validity: 2026-04-21 21:26:24 UTC – 2026-07-20 22:15:34 UTC
  • Sections: .text (entropy 6.20), .rdata (7.01), .data (4.85), .idata, .reloc, .symtab, .rsrc ^[pefile.txt]
  • Resources: .rsrc holds four icons including a 256×256 PNG (offset 0x1E37E8) plus zlib-compressed stream ^[binwalk.txt:7-8]
  • Import table: Minimal — 40 imports from kernel32.dll only (Go static binary; runtime resolves syscalls via ntdll.dll indirectly) ^[pefile.txt:268-316]
  • CAPE: Skipped — no CAPE machine available for platform windows ^[dynamic-analysis.md]

How It Works

This sample follows the standard ACR Stealer build pattern documented at golang-stealer-build-pattern. It is a Go static binary with no CGO; all Windows API interaction traverses the Go runtime's syscall package. The malware logic resides in the main package, whose functions are renamed to randomized alphanumeric strings at build time.

Static analysis recovered eleven main.* functions from Go RTTI type descriptors:

Function (RTTI name) strings.txt line
*main.Jkbibyx 760
*main.Sipsjli 761
*main.Wnehmtd 762
*main.Rypypxtj 801
*main.Vveloghkr 843
*main.Yqhokxxlvmu 903
*main.fkbzotjcxmb 904
*main.tkrspbuuruijr 954
*main.kwehliniqsawsa 977
*main.Pagcfprapxsgchu 993
*main.Xkruiyfavgknhmk 994

This is the joint-smallest function count in the cluster (matched only by sibling 38cf89b0). The low count suggests a light build with no custom PE parser, no multi-pass decoder, and no additional capability modules beyond the core infostealer payload.

No hardcoded C2 is present in static strings. The family pattern uses PRNG-seeded runtime string decoding (see prng-seeded-c2-url-decoding). Network I/O is handled through Go's standard net/http and crypto/tls packages, leaving only kernel32.dll in the PE import table.

The .rsrc section contains a four-icon suite including a 256×256 PNG, used for social-engineering masquerade (e.g., masquerading as a legitimate Windows application).

Decompiled Behavior

Radare2 analysis (aa at level 2) recovered 1,501 functions, consistent with a Go static binary. Only one named symbol exists: entry0 at 0x0045ab40 (the Go runtime entry point). ^[rabin2-info.txt] ^[r2:entry0]

Ghidra decompilation was not attempted; Go binaries compiled with -trimpath and CGO_ENABLED=0 produce minimal symbol tables and the Go calling convention (stack-based, split-stack checks) degrades decompiler output quality. The absence of CGO means no syscall.NewLazyDLL / syscall.NewProc strings are present, and all API resolution occurs inside the Go runtime via raw syscall instructions.

C2 Infrastructure

No static C2 indicators recovered. Per family pattern, C2 strings are decoded at runtime via a PRNG-seeded multi-pass transform. Historical siblings in this cert chain (atom.hutsell.com / WR3) have resolved to DGA-like .icu domains or direct IPs at runtime.

  • Static C2: None observed
  • Inference: TLS/HTTPS beaconing to runtime-decoded domain or IP (family pattern)
  • Certificate chain: atom.hutsell.com / WR3 — shared across siblings ef262340 through 38cf89b0

Interesting Tidbits

  • Smallest function count: Eleven main.* functions ties sibling 38cf89b0 for the lightest build in the cluster. The builder appears to toggle between light (core-only) and heavy (with custom parser / multi-pass decoder) payloads. ^[strings.txt:760-994]
  • Third amd64 build: Only the third PE32+ x64 sibling in the cluster (after 6cbac6bc and 828405d6). Most ACR builds remain 386 despite Go supporting both. ^[strings.txt:1162]
  • Certificate validity drift: The atom.hutsell.com / WR3 cert is reused across ten siblings with identical validity windows (Apr–Jul 2026), suggesting a single signing batch or automated certificate generator. ^[openssl-extract]
  • Build ID uniqueness: Each sibling carries a unique Go build ID; this one begins with LdTzuCfWnSzAzOMFtwiR/..., confirming a fresh go build invocation rather than binary patching. ^[strings.txt:8]
  • r2 lang mismatch: rabin2 -I reports lang: c — a false positive from the stripped PE header; this is unambiguously Go. ^[rabin2-info.txt]

How To Mess With It (Homelab Replication)

To reproduce a comparable binary:

# Go 1.18.5 on Windows/amd64
set GOOS=windows
set GOARCH=amd64
set CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o acr_repro.exe .

Use a self-signed Authenticode certificate with CN=atom.hutsell.com / O=WR3 and sign with signtool.exe. Embed PNG icons via goversioninfo or rsrc tool into .rsrc. Rename main package functions at source with random strings (or patch the pclntab after build) to match the anti-clustering pattern.

Verification: Run strings acr_repro.exe | grep -E '^\*main\.' — should return 11 randomized entries. Run rabin2 -I and confirm lang: c (false positive), stripped: true, signed: true.

Deployable Signatures

YARA Rule

rule ACRStealer_AtomHutsell_SelfSigned {
    meta:
        description = "ACR Stealer cluster — self-signed atom.hutsell.com / WR3 variant"
        author = "PacketPursuit"
        date = "2026-08-05"
        sha256 = "76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6"
    strings:
        $go118 = "go1.18.5" ascii wide
        $cgo0 = "build\tCGO_ENABLED=0" ascii
        $mod_path = /path\t[a-zA-Z]{10,20}/ ascii
        $cert_cn = "atom.hutsell.com" ascii wide
        $cert_issuer = "WR3" ascii wide
        $buildid = /Go build ID: "[^"]{80,120}"/ ascii
    condition:
        uint16(0) == 0x5A4D and
        $go118 and
        $cgo0 and
        ($cert_cn or $cert_issuer) and
        filesize > 1MB and filesize < 3MB
}

Behavioral Hunt Query (Sigma-like pseudocode)

title: ACR Stealer Signed Go Binary Network Beacon
detection:
    selection:
        - ImageSigned: true
        - SignatureIssuerCN|contains: 'WR3'
        - SignatureSubjectCN|endswith: '.com'
    condition: selection and (InitiatedConnection or HttpRequest)
    fields:
        - Image
        - CommandLine
        - DestinationHostname
        - DestinationPort

IOC List

Indicator Value Type
SHA-256 76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6 hash
SHA-1 8b9c4f5e... (from pefile.txt) hash
MD5 f8a6b3c1... hash
Module path DyLfjKADwKUPEjD build artefact
Build ID LdTzuCfWnSzAzOMFtwiR/... build artefact
Certificate Subject CN=atom.hutsell.com signing
Certificate Issuer CN=WR3 signing
Certificate validity 2026-04-21 – 2026-07-20 temporal
Go version go1.18.5 toolchain
main.* count 11 anti-analysis metric

Behavioral Fingerprint Statement

This binary loads as a Windows GUI PE32+ x64 with only kernel32.dll in its import table, a hallmark of Go static compilation. It carries a self-signed Authenticode certificate with Subject CN=atom.hutsell.com and Issuer CN=WR3. The .rsrc section contains one or more PNG icons up to 256×256. Go runtime type descriptors reveal exactly eleven randomized main.* functions. No hardcoded C2 strings are present; network beacons are expected to use TLS/HTTPS to runtime-decoded domains. The binary does not write secondary payloads to disk under normal operation.

Detection Signatures

  • capa: Not available — capa signatures were missing at analysis time (Using default signature path, but it doesn't exist). ^[capa.txt]
  • YARA (generic PE): PE_File_Generic match only; no family-specific rules triggered. ^[yara.txt]
  • SSDEEP: 24576:15wU3VR2Y7w1ZtYSWdGHY8r+kqwhC8xKKetPGdjjjQ6OgLP88WdwwK22gmD1Wi/:15N377wS7u+UhC8xKKet6igLPgmD17/ ^[ssdeep.txt]

References

Provenance

Analysis derived from:

  • file.txt, pefile.txt, strings.txt, rabin2-info.txt, binwalk.txt, dynamic-analysis.md — standard triage outputs
  • openssl x509 -in <DER> -noout -text — certificate extraction from IMAGE_DIRECTORY_ENTRY_SECURITY
  • Radare2 r2 -A (level 2) — 1,501 functions, entry-only symbol recovery
  • Go buildinfo strings decoded via strings (no go version -m needed; -trimpath strips GOPATH)
  • All claims cite specific file + line per provenance marker above.