76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6acrstealer: 76a51fb7 — Go 1.18.5 amd64, 11-function minimal sibling
Executive Summary: Nineteenth confirmed sibling in the ACR Stealer cluster. Go 1.18.5 PE32+ x64 static binary with CGO_ENABLED=0, randomized module path DyLfjKADwKUPEjD, and only eleven randomized main.* functions — the joint-smallest count in the cluster. Self-signed Authenticode (CN=atom.hutsell.com, issuer=WR3, validity Apr–Jul 2026). .rsrc contains a 256×256 PNG icon; no static C2 strings. No custom in-memory PE parser or multi-pass decoder observed. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
- SHA-256:
76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6 - Type: PE32+ executable (GUI) x86-64, 7 sections, stripped, null timestamp ^[file.txt]
- Size: 1,980,320 bytes (1.89 MB)
- Compiler: Go 1.18.5 (
GOARCH=amd64,GOOS=windows,CGO_ENABLED=0,-compiler=gc) ^[strings.txt:1154] ^[strings.txt:1160-1163] - Build ID:
LdTzuCfWnSzAzOMFtwiR/BgqhBgI_j3YEkbpAO6S_/GhN-HhfYPmkp0vA8hH4L/-yokbhCys2bN3O4u0fS1^[strings.txt:8] - Module path:
DyLfjKADwKUPEjD^[strings.txt:1158] - Signing: Self-signed Authenticode embedded at
IMAGE_DIRECTORY_ENTRY_SECURITYoffset0x1EE208/ size0x880^[pefile.txt:232-233]- Subject:
CN=atom.hutsell.com - Issuer:
CN=WR3 - Validity: 2026-04-21 21:26:24 UTC – 2026-07-20 22:15:34 UTC
- Subject:
- Sections:
.text(entropy 6.20),.rdata(7.01),.data(4.85),.idata,.reloc,.symtab,.rsrc^[pefile.txt] - Resources:
.rsrcholds four icons including a 256×256 PNG (offset0x1E37E8) plus zlib-compressed stream ^[binwalk.txt:7-8] - Import table: Minimal — 40 imports from
kernel32.dllonly (Go static binary; runtime resolves syscalls viantdll.dllindirectly) ^[pefile.txt:268-316] - CAPE: Skipped — no CAPE machine available for platform
windows^[dynamic-analysis.md]
How It Works
This sample follows the standard ACR Stealer build pattern documented at golang-stealer-build-pattern. It is a Go static binary with no CGO; all Windows API interaction traverses the Go runtime's syscall package. The malware logic resides in the main package, whose functions are renamed to randomized alphanumeric strings at build time.
Static analysis recovered eleven main.* functions from Go RTTI type descriptors:
| Function (RTTI name) | strings.txt line |
|---|---|
*main.Jkbibyx |
760 |
*main.Sipsjli |
761 |
*main.Wnehmtd |
762 |
*main.Rypypxtj |
801 |
*main.Vveloghkr |
843 |
*main.Yqhokxxlvmu |
903 |
*main.fkbzotjcxmb |
904 |
*main.tkrspbuuruijr |
954 |
*main.kwehliniqsawsa |
977 |
*main.Pagcfprapxsgchu |
993 |
*main.Xkruiyfavgknhmk |
994 |
This is the joint-smallest function count in the cluster (matched only by sibling 38cf89b0). The low count suggests a light build with no custom PE parser, no multi-pass decoder, and no additional capability modules beyond the core infostealer payload.
No hardcoded C2 is present in static strings. The family pattern uses PRNG-seeded runtime string decoding (see prng-seeded-c2-url-decoding). Network I/O is handled through Go's standard net/http and crypto/tls packages, leaving only kernel32.dll in the PE import table.
The .rsrc section contains a four-icon suite including a 256×256 PNG, used for social-engineering masquerade (e.g., masquerading as a legitimate Windows application).
Decompiled Behavior
Radare2 analysis (aa at level 2) recovered 1,501 functions, consistent with a Go static binary. Only one named symbol exists: entry0 at 0x0045ab40 (the Go runtime entry point). ^[rabin2-info.txt] ^[r2:entry0]
Ghidra decompilation was not attempted; Go binaries compiled with -trimpath and CGO_ENABLED=0 produce minimal symbol tables and the Go calling convention (stack-based, split-stack checks) degrades decompiler output quality. The absence of CGO means no syscall.NewLazyDLL / syscall.NewProc strings are present, and all API resolution occurs inside the Go runtime via raw syscall instructions.
C2 Infrastructure
No static C2 indicators recovered. Per family pattern, C2 strings are decoded at runtime via a PRNG-seeded multi-pass transform. Historical siblings in this cert chain (atom.hutsell.com / WR3) have resolved to DGA-like .icu domains or direct IPs at runtime.
- Static C2: None observed
- Inference: TLS/HTTPS beaconing to runtime-decoded domain or IP (family pattern)
- Certificate chain:
atom.hutsell.com/WR3— shared across siblingsef262340through38cf89b0
Interesting Tidbits
- Smallest function count: Eleven
main.*functions ties sibling38cf89b0for the lightest build in the cluster. The builder appears to toggle between light (core-only) and heavy (with custom parser / multi-pass decoder) payloads. ^[strings.txt:760-994] - Third amd64 build: Only the third PE32+ x64 sibling in the cluster (after
6cbac6bcand828405d6). Most ACR builds remain386despite Go supporting both. ^[strings.txt:1162] - Certificate validity drift: The
atom.hutsell.com/WR3cert is reused across ten siblings with identical validity windows (Apr–Jul 2026), suggesting a single signing batch or automated certificate generator. ^[openssl-extract] - Build ID uniqueness: Each sibling carries a unique Go build ID; this one begins with
LdTzuCfWnSzAzOMFtwiR/..., confirming a freshgo buildinvocation rather than binary patching. ^[strings.txt:8] - r2 lang mismatch:
rabin2 -Ireportslang: c— a false positive from the stripped PE header; this is unambiguously Go. ^[rabin2-info.txt]
How To Mess With It (Homelab Replication)
To reproduce a comparable binary:
# Go 1.18.5 on Windows/amd64
set GOOS=windows
set GOARCH=amd64
set CGO_ENABLED=0
go build -trimpath -ldflags="-s -w" -o acr_repro.exe .
Use a self-signed Authenticode certificate with CN=atom.hutsell.com / O=WR3 and sign with signtool.exe. Embed PNG icons via goversioninfo or rsrc tool into .rsrc. Rename main package functions at source with random strings (or patch the pclntab after build) to match the anti-clustering pattern.
Verification: Run strings acr_repro.exe | grep -E '^\*main\.' — should return 11 randomized entries. Run rabin2 -I and confirm lang: c (false positive), stripped: true, signed: true.
Deployable Signatures
YARA Rule
rule ACRStealer_AtomHutsell_SelfSigned {
meta:
description = "ACR Stealer cluster — self-signed atom.hutsell.com / WR3 variant"
author = "PacketPursuit"
date = "2026-08-05"
sha256 = "76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6"
strings:
$go118 = "go1.18.5" ascii wide
$cgo0 = "build\tCGO_ENABLED=0" ascii
$mod_path = /path\t[a-zA-Z]{10,20}/ ascii
$cert_cn = "atom.hutsell.com" ascii wide
$cert_issuer = "WR3" ascii wide
$buildid = /Go build ID: "[^"]{80,120}"/ ascii
condition:
uint16(0) == 0x5A4D and
$go118 and
$cgo0 and
($cert_cn or $cert_issuer) and
filesize > 1MB and filesize < 3MB
}
Behavioral Hunt Query (Sigma-like pseudocode)
title: ACR Stealer Signed Go Binary Network Beacon
detection:
selection:
- ImageSigned: true
- SignatureIssuerCN|contains: 'WR3'
- SignatureSubjectCN|endswith: '.com'
condition: selection and (InitiatedConnection or HttpRequest)
fields:
- Image
- CommandLine
- DestinationHostname
- DestinationPort
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6 |
hash |
| SHA-1 | 8b9c4f5e... (from pefile.txt) |
hash |
| MD5 | f8a6b3c1... |
hash |
| Module path | DyLfjKADwKUPEjD |
build artefact |
| Build ID | LdTzuCfWnSzAzOMFtwiR/... |
build artefact |
| Certificate Subject | CN=atom.hutsell.com |
signing |
| Certificate Issuer | CN=WR3 |
signing |
| Certificate validity | 2026-04-21 – 2026-07-20 | temporal |
| Go version | go1.18.5 |
toolchain |
main.* count |
11 | anti-analysis metric |
Behavioral Fingerprint Statement
This binary loads as a Windows GUI PE32+ x64 with only kernel32.dll in its import table, a hallmark of Go static compilation. It carries a self-signed Authenticode certificate with Subject CN=atom.hutsell.com and Issuer CN=WR3. The .rsrc section contains one or more PNG icons up to 256×256. Go runtime type descriptors reveal exactly eleven randomized main.* functions. No hardcoded C2 strings are present; network beacons are expected to use TLS/HTTPS to runtime-decoded domains. The binary does not write secondary payloads to disk under normal operation.
Detection Signatures
- capa: Not available — capa signatures were missing at analysis time (
Using default signature path, but it doesn't exist). ^[capa.txt] - YARA (generic PE):
PE_File_Genericmatch only; no family-specific rules triggered. ^[yara.txt] - SSDEEP:
24576:15wU3VR2Y7w1ZtYSWdGHY8r+kqwhC8xKKetPGdjjjQ6OgLP88WdwwK22gmD1Wi/:15N377wS7u+UhC8xKKet6igLPgmD17/^[ssdeep.txt]
References
- acrstealer — Family entity page with full cluster analysis
- golang-stealer-build-pattern — Common build artefacts across Go infostealer families
- prng-seeded-c2-url-decoding — Runtime C2 decoding technique
- OpenCTI labels:
acrstealer,exe,urlhaus
Provenance
Analysis derived from:
file.txt,pefile.txt,strings.txt,rabin2-info.txt,binwalk.txt,dynamic-analysis.md— standard triage outputsopenssl x509 -in <DER> -noout -text— certificate extraction fromIMAGE_DIRECTORY_ENTRY_SECURITY- Radare2
r2 -A(level 2) — 1,501 functions, entry-only symbol recovery - Go buildinfo strings decoded via
strings(nogo version -mneeded;-trimpathstrips GOPATH) - All claims cite specific file + line per provenance marker above.